Vibe Sensei

Privacy Policy

Last updated: March 2026

1. Who we are

Vibe Sensei is a SaaS product operated by an individual developer based in Quebec, Canada. Contact: [email protected]

2. What data we collect

  • GitHub account data — your email address, display name, avatar URL and GitHub user ID, collected via GitHub OAuth at sign-in.
  • GitHub tokens — your OAuth access token and optional Personal Access Token (PAT). Both are encrypted at rest using Fernet symmetric encryption before storage.
  • Repository and commit data — names and diffs of commits from repositories you choose to track. Commit diffs are sent to an AI provider (Gemini) to generate flashcards and challenges, and are not stored permanently.
  • Usage data — counts of flashcards and challenges generated per month, used solely to enforce plan limits.
  • Product analytics — anonymized or pseudonymized events (page views, button clicks, feature usage) to understand where the product funnel drops off and improve the experience. We do not use this data for advertising.
  • Billing data — if you subscribe to a paid plan, payment is handled by Lemon Squeezy. We store only your Lemon Squeezy customer ID and subscription status. We never see or store your payment card details.

3. How we use your data

  • To authenticate you and maintain your session.
  • To fetch commits and diffs from GitHub on your behalf.
  • To generate flashcards and challenges using the Gemini AI API.
  • To enforce free/premium plan usage limits.
  • To process subscription payments via Lemon Squeezy.

We do not sell your data. We do not use your data for advertising.

4. Third-party services

  • GitHub — OAuth authentication and repository access. GitHub Privacy Policy
  • Google Gemini — AI generation of flashcards and challenges from commit diffs. Data sent to Gemini is not stored by us after generation. Google Privacy Policy
  • Lemon Squeezy — payment processing and subscription management. Lemon Squeezy Privacy Policy
  • Supabase — PostgreSQL database hosting. Data is stored in Supabase-managed infrastructure. Supabase Privacy Policy
  • PostHog — product analytics (funnels, feature usage). Session recording is disabled. Used only to improve the product, not for advertising. PostHog Privacy Policy

5. Cookies

Vibe Sensei uses cookies and local storage for authentication and product analytics:

  • access_token — HttpOnly, signed JWT token used to authenticate your requests. Never accessible by JavaScript.
  • user — your display name, avatar and plan, stored client-side for UI rendering.
  • PostHog — a small cookie / localStorage entry to distinguish anonymous visitors across pages for product analytics. Not used for advertising or cross-site tracking.

We do not use advertising cookies or tracking pixels. You can contact us to request deletion of analytics data associated with your account.

6. Data retention

Your data is retained for as long as your account is active. You can delete your account and all associated data by contacting us at [email protected]. We will process deletion requests within 30 days.

7. Your rights

Under Quebec Law 25 and, where applicable, the GDPR, you have the right to access, correct, export or delete your personal data. To exercise any of these rights, contact us at [email protected].

8. Changes to this policy

We may update this policy as the product evolves. Material changes will be communicated via the app or email. Continued use of the service after changes constitutes acceptance.