Privacy Policy

Last updated: May 21, 2026

What we collect

When you create an account, we store your email address and display name. If you sign in with Google, we receive your email address and name from Google — we do not store your Google password or any other Google account data.

When you submit a listing, we store the title, URL, description, category, price, and any optional pitch or due diligence information you provide.

When a buyer sends you an inquiry, we store a one-time relay token containing an encrypted version of the buyer's email address. The token expires after 24 hours.

We do not use cookies beyond what is strictly necessary for authentication (Supabase session tokens).

How we use it

Your email address is used to authenticate your account and to forward buyer inquiries to you via our email relay. We do not send marketing emails.

Listing content (title, URL, description, screenshot) is passed to Google's Gemini AI to generate an automated quality score and critique. This data is processed according to Google's API terms.

Your app's public URL may be visited by microlink.io to capture a screenshot for your listing.

What we share

We do not sell your data. We do not share your personal information with third parties except as required to operate the service:

  • Supabase — database and authentication hosting
  • Google Gemini — AI scoring of listing content
  • Resend — transactional email delivery
  • microlink.io — screenshot capture of listed app URLs
  • Vercel — hosting and CDN

Email relay

When a buyer contacts a seller, their message is forwarded once to the seller's email address. The buyer's email is included in the relay so the seller can reply directly. After forwarding, we do not store the conversation. The relay token expires after 24 hours and cannot be used again.

Data retention

Your account and listings are retained until you delete them. You can delete a listing at any time from its detail page. To delete your account and all associated data, contact us at the email below.

Relay tokens expire and are invalidated after 24 hours. Expired tokens are not deleted immediately but cannot be used to send further messages.

Your rights

You can request a copy of your data or ask us to delete it at any time by emailing us. We will respond within 30 days.

Contact

Questions about this policy: privacy@vibesandbox.store