AccountIQHUB

Privacy policy

Vibe Growth reads advertising and CRM accounts you already own and reports on them. This policy explains exactly what is collected, why, who else processes it, and how to have it removed.

Last updated 20 September 2026

Who is responsible

Vibe Growth is operated by Shaswat Singh, a sole proprietor based in Bengaluru, Karnataka, India, trading as Vibe Growth. For anything in this policy, including access and deletion requests, write to [email protected].

What is collected

Three kinds of data, and nothing else:

  • Account details. Your email address and display name, used to sign you in and to contact you about the service.
  • Authorization credentials. Access and refresh tokens for each platform you connect, encrypted at rest with AES-256-GCM. Vibe Growth never receives or stores your password for any connected platform.
  • Performance data. Daily campaign-level figures pulled from the accounts you select — spend, impressions, clicks, conversions, leads and pipeline values — plus the account names, identifiers, currency and time zone needed to label them.

What is deliberately not collected

Vibe Growth does not collect the personal profiles of people who saw or clicked your ads. The advertising figures it stores are aggregates reported by each platform, not individual-level records.

Where a CRM is connected, only the fields needed to measure the funnel are read — lifecycle stage, deal stage, amount, source attribution and timestamps. Contact names, email addresses, phone numbers and free-text notes held in your CRM are not copied into Vibe Growth.

Platforms you can connect, and what is requested

Each connection is authorized by you, is read-only, and can be withdrawn at any time. Vibe Growth requests the narrowest scope that makes the reporting work.

  • Meta Ads ads_read to read campaign performance through the Ads Insights API, and business_management to list the ad accounts you may choose from.
  • Google Ads — campaign, spend and conversion reporting.
  • Google Analytics 4 — read-only session, channel and conversion reporting.
  • Google Search Console — read-only query, impression and click data.
  • LinkedIn Ads — read-only campaign reporting.
  • HubSpot — read-only deal, lifecycle-stage and pipeline data.

Vibe Growth does not create, edit, pause or delete campaigns, and does not write to your CRM.

How the data is used

Only to provide the service to you: to show performance in your workspace, to calculate funnel and attribution figures, to detect changes worth your attention, and to answer queries you make through the MCP endpoint.

Your data is never sold, never rented, never shared with advertisers, and never used to build profiles for anyone other than you.

Who else processes it

Vibe Growth runs on a small number of infrastructure providers, each acting as a processor under instruction:

  • Supabase — managed PostgreSQL database and authentication. Stores everything described above, isolated per workspace by row-level security.
  • Vercel — application hosting and serving.
  • Cloudflare — DNS and edge delivery for vibegrowth.pro.

No other third party receives your connected-platform data. If a processor is added, this list is updated before the change takes effect.

AI features and the MCP endpoint

Vibe Growth can expose your workspace to an AI client you choose — Claude, Cursor, or another MCP-capable tool — through a token you create and can revoke. When you do that, the data those tools request flows to the AI provider you have chosen, under your agreement with them, not ours.

No customer data is used to train any AI model. The full detail is in the AI policy.

Where data is held, and for how long

Data is stored in the managed database region configured for the service and is retained while your account is open, so that period-over-period reporting continues to work.

Disconnecting a platform deletes its credentials and account list immediately. Closing your account, or a deletion request, removes everything — see data deletion, which is completed within 30 days, with encrypted backups overwritten on their normal rotation within 35 days.

Security

Platform credentials are encrypted at rest with AES-256-GCM using a key held outside the database. Every query is scoped to a single workspace and enforced by database row-level security, so one workspace cannot read another's data. Traffic is served over HTTPS.

Your rights

You can ask for a copy of the data held about you, ask for it to be corrected, ask for it to be deleted, or withdraw a platform authorization at any time. Write to [email protected]; requests are acknowledged within 7 days.

Where the GDPR applies, the lawful basis for processing is the performance of the contract between us. Where India's Digital Personal Data Protection Act applies, processing is on the basis of the consent you give when you connect an account.

Changes

Material changes are reflected in the date at the top of this page, and account holders are notified by email before the change takes effect.