How we handle your data
Plain answers to the questions people ask before uploading a company spreadsheet.
This page describes what actually happens to a file from the moment you upload it. The Privacy Policy is the binding document; this page is the practical version.
1. Uploading a file
- Your browser uploads the file directly to a private storage bucket using a one-time upload link that expires after 10 minutes. Our server chooses the storage path; the browser cannot.
- The bucket blocks all public access and encrypts every object at rest with AES-256.
- The file is checked by its content (not its name), and archives and executables are rejected.
- It is then moved to private storage tied to your account, where only you can read it. Nothing is sent to an AI model at upload time.
2. Generating the dashboard
- The AI model does not receive your file. It receives the column names, up to 20 sample rows, and summary statistics computed from all rows (minimum, maximum, average and sum per numeric column, and up to 10 distinct values for the first few text columns).
- For live spreadsheets, the first 5 rows are additionally sent to a model that classifies the columns.
- We use Anthropic (Claude) and OpenAI models through their commercial APIs. Under those terms the providers do not train on API data, and we do not train any model on your data.
- As soon as the dashboard is live, the uploaded file is deleted from our storage. If you upload a file and never generate, an automated job removes it within a few hours.
3. Where the dashboard's data lives
- A dashboard built from an uploaded file carries its own copy of the data so it works without us. That copy is stored in a private code repository and served with the dashboard.
- Because of that, anyone who can open the dashboard can also retrieve the rows behind it. Dashboards are public by link by default. On paid plans you can make a dashboard private with a password, which protects the data as well as the charts. See Sharing and privacy.
4. Live Google Sheets
- A live dashboard does not store your rows. It reads the sheet each time it is opened.
- It reads through a reader account that you share the file with as a Viewer, or through a public link if you chose that. The reader account can only open files that have been shared with it.
- The Google permission we request (
drive.file) covers only files you pick in the picker. - Tokens from your Google, Dropbox or OneDrive connection are stored encrypted (AES-256-GCM) and are never copied into a published dashboard.
5. Where everything is hosted
Our application, database, file storage and published dashboards run in the United States, in the AWS us-east-1 region and the same region at our hosting providers. VibeFactory is operated by a company registered in Poland (EU), VAT ID PL6811862916. We do not currently offer EU-only data hosting.
6. Who processes your data
| Provider | What they handle |
|---|---|
| Supabase | Account database, sign-in, and the private file storage tied to your account |
| Vercel | Hosting for the VibeFactory application and for published dashboards |
| Amazon Web Services (S3) | Encrypted staging bucket that receives uploads |
| GitHub | Private code repositories that hold each dashboard, including its data copy |
| Reading the sheets and Drive files you connect | |
| Anthropic, OpenAI | AI models that receive the column names, samples and statistics described above |
| Stripe | Payments. We never see your card number. |
| Resend | Transactional email, including emailed exports |
7. Access controls
- Every project, data source and stored file is isolated per user with database row-level security.
- Teammates you add through the Sharing tab see only the projects you shared.
- Password-protected dashboards ask for the password before any data is served.
8. Deleting things
- Delete a dashboard: removes the published site, its code repository and its data copy.
- $0.99 single reports are taken offline automatically after 30 days.
- Delete your account (Settings, Danger zone): removes all projects and files, all published dashboards, chat history, connected-service credentials and secrets, and cancels any subscription. Anonymised billing records are kept for accounting.
- Deleted files are removed from primary storage immediately. Backup copies in the upload bucket expire within 30 days.
9. Analytics and cookies
No analytics or advertising scripts load until you accept cookies. Visitors in the EU, UK and Switzerland get an opt-in banner; elsewhere you can opt out from the footer. After consent we load Google Analytics (with IP anonymisation), Google Ads conversion tracking and Ahrefs analytics. Signing in uses a session cookie that is not used for tracking.
Questions
If you need a data processing agreement, a sub-processor notification, or have a question this page does not answer, write to us through support.