Privacy policy
What we collect, why we collect it, and how to get it back or get rid of it. Last updated 3 September 2026.
Who this covers
This policy covers vibeinfra.id
and the VibeInfra API at api.vibeinfra.id, operated by VibeInfra. Contact
us about anything on this page at
[email protected].
What we collect and why
| Data | When | Why |
|---|---|---|
| Account identifier, username, email address and avatar URL from GitHub or Google | When you sign in | To create and recognise your account. We never receive your password — sign-in is OAuth, so your provider authenticates you and tells us only these fields. |
Session token in a cookie named vibe_jwt |
While signed in | To keep you signed in. The cookie is HttpOnly and SameSite=Lax, so it is not readable by page scripts, and it expires after 30 days. |
| Lab progress: which incidents you started and completed, XP, grading results and after-action reports | As you use labs | To show your progress, award XP and populate the leaderboard. |
| Commands you run inside a lab sandbox | During a lab session | To grade the incident and generate your after-action report. These are commands in a disposable practice container, not on any system of yours. |
| Phone number | Only at checkout | Required by our payment provider to issue an invoice. It is stored encrypted at rest with AES-256-GCM as a separate layer on top of database and disk encryption. |
| Waitlist details: email, name, GitHub username, role, experience, company, interests, IP address, country and referrer | Only if you submit the waitlist form | To manage early access and understand who is asking for it. |
| Product analytics events and IP address | As you use the site | To understand which parts of the product work — where people get stuck, which incidents get abandoned. IP addresses are used for abuse prevention and rate limiting. |
The public catalog, glossary, capacity and telemetry endpoints are unauthenticated: reading them does not require an account and does not create one.
What is visible to others
The leaderboard and hall of fame show your username, avatar, XP and number of completed labs. Nothing else about your account is public — not your email address, not your progress on a specific incident, not your session commands. If you would rather not appear on the leaderboard, email us.
How long we keep it
- Account and progress data — while your account exists, and deleted when you ask us to delete it.
- Session cookie — 30 days, or until you sign out.
- Sandbox containers and their contents — destroyed when the session ends. They are disposable by design; nothing in a lab container survives it.
- Payment records — kept as long as tax and accounting rules require.
Your choices
Email [email protected] to get a copy of your data, correct it, delete your account, or ask us to stop sending you email. We will confirm your identity through the address on your account before acting on a request, and aim to respond within 30 days.
Depending on where you live, you may have additional statutory rights — for example under the GDPR or Indonesia's Personal Data Protection Law. Ask and we will honour them.
Security
Traffic is served over HTTPS. Session cookies are HttpOnly and scoped with
SameSite=Lax. Phone numbers are encrypted per-user at the column level with
AES-256-GCM. Write endpoints are rate limited per user rather than per IP, so one
person cannot exhaust another's budget or evade a limit by changing address. No system
is perfectly secure; if you find a weakness, please tell us — see the
contact page.
Children
VibeInfra is built for working and aspiring infrastructure engineers and is not directed at children under 13. We do not knowingly collect their data; if we learn we have, we delete it.
Changes to this policy
When this policy changes materially we will update the date at the top of this page and say so in-product. Continuing to use VibeInfra after a change means the updated policy applies.