Privacy
How VybeOS handles your data
Last updated: September 24, 2026
We keep marketing analytics, CRM data, and connected ad and social account insights scoped to what's needed to run the product, power your dashboards, and help you understand performance.
What this covers
This notice explains how VybeOS handles data collected on our marketing site (vybeos.co) and inside the product when you use VybeOS or choose to connect advertising, social, and email marketing accounts.
On the marketing site, we currently use Google Analytics 4 (GA4) and HubSpot. In the product, customers can connect accounts from Meta (Meta Ads, Facebook Pages, and Instagram), TikTok (organic and TikTok Ads), Google Ads, YouTube, X (organic and X Ads), LinkedIn (member publishing where available, Company Page analytics, and LinkedIn Ads), Klaviyo, and Google Analytics 4 (GA4) properties so we can sync marketing content and performance data into analytics dashboards.
Data we collect
Contact details you share with us (name, email, company) and messages you send through forms or chat.
Usage data about how you browse the site (pages viewed, buttons clicked, referrers, device/browser info, approximate location) captured via cookies and similar technologies.
Account data and content you provide in the product (brand assets, campaign inputs, generated outputs) to deliver VybeOS features.
Connected-account data, when you authorize a connection: OAuth credentials and connection metadata (such as account or page IDs and names, granted scopes, and connection status). We do not receive your platform passwords.
Historical marketing and social content available through the APIs you authorize, such as posts, ads, videos, campaign or ad names, captions, media URLs or thumbnails, external content IDs, and publish timestamps.
Performance metrics reported by those platforms, which may include views, impressions, reach, likes, comments, shares, saves, clicks, engagements, conversions, conversion value, spend, video views, and other platform-specific metrics.
For Klaviyo, campaign and flow performance aggregates (such as recipients, opens, clicks, conversions, or revenue when available) and audience list or segment identifiers needed for product features.
We do not collect direct messages or private inbox content from connected social platforms.
Analytics and marketing tools
Google Analytics 4 (GA4) tracks site performance and engagement. Data is aggregated; IP is truncated where supported. We use this to understand traffic patterns and improve the site.
HubSpot powers forms, email sequences, and campaign attribution. It records form submissions, page views tied to email interactions, and campaign UTMs so we can follow up on your requests.
You can manage cookies through your browser settings or use built-in consent tools where available. Some site features may rely on these cookies to function.
Connected ad and social accounts
When you connect an account, we use the permissions you grant to sync historical content and performance metrics into VybeOS analytics dashboards so your team can review marketing performance in one place.
Meta: Connecting Meta Ads, a Facebook Page, and/or Instagram lets us read ad and organic content plus available insights (for example impressions, reach, engagement, clicks, spend, and conversions, depending on the connection and scopes).
TikTok: Connecting TikTok (organic) and/or TikTok Ads lets us read videos or ads and available performance metrics. We do not collect direct messages or private content.
Google Ads: Connecting a Google Ads account lets us read campaigns, ads, and performance metrics such as impressions, clicks, spend, and conversions when reported by Google.
YouTube: Connecting a YouTube channel lets us read video listings and available public video statistics such as views, likes, and comments.
Google Analytics 4: Connecting a GA4 property lets us read that property's report data through the Google Analytics Data API (sessions, users, add-to-carts, checkouts, key events, revenue, and their breakdown by date, channel, page, and landing page). We request only the read-only analytics scope, never write to your Google Analytics account, and show this data solely inside your VybeOS analytics dashboards.
X: Connecting X (organic) and/or X Ads lets us access the account for product features you use. Where metrics sync is available for ads connections, we may pull campaign and ad performance data such as impressions, clicks, and spend.
LinkedIn: Connecting LinkedIn (member publishing where available), LinkedIn Company Page analytics, and/or LinkedIn Ads lets us read Page or ad content and available analytics, or publish when you explicitly direct it.
Klaviyo: Connecting Klaviyo lets us read campaign and flow performance data and related account metadata needed for dashboards and email-related product features.
We do not create or publish content, ads, or campaigns on your connected accounts unless you explicitly direct that action in VybeOS.
Access tokens are stored encrypted, limited to the scopes needed for the features you use, and can be disconnected at any time inside the product or by contacting us. You may also revoke access from each platform’s settings, which invalidates our access.
How we use your data
To operate and improve the site and product, including diagnosing issues and measuring performance.
To respond to inquiries, schedule demos, and send product updates or onboarding messages.
To sync and display connected-account content and performance metrics in analytics dashboards so you can understand campaign and organic results.
To create or publish content, ads, or campaigns on connected platforms only when you explicitly direct those actions in VybeOS.
To analyze creatives and performance in the product, which may include sending relevant content or metrics to a large language model provider for inference (for example scoring or creative analysis). We do not use your connected-account data to train foundation or third-party AI models.
To protect the service, prevent abuse, and meet legal or compliance obligations.
How we share information
Service providers that support hosting, analytics, email, customer support, encryption key management, and AI inference. They process data on our behalf under confidentiality and security obligations.
Platform partners (including Meta, Google, YouTube, TikTok, X, LinkedIn, and Klaviyo) only when you have connected your accounts and within the permissions you granted, so we can sync data or carry out actions you direct.
Legal, safety, or business transfers when required (for example compliance with law, enforcing terms, or in the event of a merger or acquisition). We do not sell personal data.
Retention and security
We keep data only as long as needed for the purposes above or as required by law, then delete or de-identify it. Some platforms impose additional retention or deletion requirements; for example, LinkedIn analytics data associated with a connection may be purged after you disconnect in line with those obligations and our product implementation.
Access tokens for connected accounts are rotated or invalidated when you disconnect. We apply administrative, technical, and physical safeguards to protect data, but no system is 100% secure.
How we protect connected-account and Google user data
Encryption in transit: every connection between your browser, VybeOS, and the platform APIs we call (including Google APIs) uses HTTPS/TLS. We never transmit connected-account data over unencrypted channels.
Encryption at rest: connected-account data is stored on Google Cloud infrastructure that encrypts data at rest by default. OAuth access and refresh tokens receive an additional layer of envelope encryption: each token is encrypted with a unique AES-256-GCM data key, and that key is itself wrapped by Google Cloud Key Management Service. Tokens are decrypted only in memory, at the moment a sync runs, and are never exposed in the product, logs, or exports.
Access controls: connected-account data is scoped to the organization and brand that connected the account. Only workspace members with a role and channel grant that covers analytics for that platform can view it; access is authenticated with short-lived, signed session credentials and enforced on every request. Internal staff access is limited to what is needed to operate and support the service.
Least privilege: we request the narrowest platform permissions the feature needs. For Google Analytics that is the read-only analytics scope; VybeOS cannot modify your Google Analytics configuration or data.
Retention and deletion: when you disconnect an account, its stored tokens are invalidated and, for Google Analytics, all synced report data and any page previews we captured are deleted from our systems. A daily reconciliation job verifies that no data remains for disconnected accounts. You can also request deletion at any time via [email protected].
No selling, no advertising use, no model training: we do not sell connected-account or Google user data, do not use it for advertising, and do not use it to train foundation or third-party AI models.
Monitoring and incident response: infrastructure and application activity is logged and monitored for errors and unauthorized access. If we become aware of a security incident affecting your data, we will notify affected customers without undue delay and in accordance with applicable law.
Google API Services User Data Policy: VybeOS's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Google user data is used only to provide and improve the VybeOS features you have enabled; it is never sold, never used for serving advertisements, and only transferred to third parties as necessary to provide those features, for security purposes, to comply with applicable law, or as part of a merger or acquisition with prior notice. You can revoke VybeOS's access at any time from your Google Account permissions page.
Your choices
Opt out of marketing emails using the unsubscribe link. Transactional emails (like security notices) will still be sent.
Manage cookies in your browser or via site controls. You can also use GA opt-out tools if available in your region.
Disconnect any connected advertising, social, or email account in the product. You can also revoke access directly in those platforms.
Request access, correction, or deletion of your information by emailing [email protected]. We will verify your identity and respond as required by applicable law.