1. Scope, operator, and our role
This Privacy Policy explains how MB Nordhub, operating Vibosome, handles personal data on vibosome.com, during a Mailroom beta or pilot request, in the invite-only Mailroom service, and in the retained automation platform, Agent API, MCP, billing, support, and documentation features. "Vibosome", "we", "us", and "our" mean MB Nordhub.
MB Nordhub generally acts as controller for public-site, beta-lead, account, security, service-usage, support, and business records. When a Customer connects a business mailbox or runs an automation on personal data for its own purposes, the Customer will usually determine those purposes and may be controller while MB Nordhub may act as processor or service provider. Roles depend on the facts and applicable law; this Policy is not a blanket data processing agreement or legal conclusion for every workflow.
Historical research records may be retained only where needed for lawful business, security, or deletion obligations. We do not claim that Mailroom or the retained platform is certified for a particular regulated sector or compliance framework.
2. Public-site and beta-request data
When you request Mailroom access or contact us, we may collect your name, email, company or project, role, mailbox category, workflow focus, optional link, and the note you choose to provide. We also process bounded anti-spam fields and submission timing. The form is for fit assessment and contact; it does not ask for a mailbox password, API key, payment-card number, production mailbox content, or file upload.
When you browse the public site, ordinary server handling can process IP address, request path, timestamp, browser or device information, referrer, language, errors, and security events. Vibosome also uses bounded first-party daily aggregate funnel counters for an allowlisted set of public pages and steps. Those aggregate buckets do not retain raw visitor events, email addresses, IP addresses, user-agent strings, cookies, Google click identifiers, or visitor identifiers and currently rotate after about 120 days.
Optional analytics and advertising measurement follow the cookie and consent choices described below. We do not sell personal data and do not use mailbox credentials or Customer message content for advertising.
3. Mailroom account and authentication data
Mailroom is currently invite-only. Amazon Cognito and the protected authentication proxy process the invited email address, provider subject or user identifier, account status, email-verification state, password authentication, multi-factor enrollment and challenge state, sign-in timestamps, session identifiers, and related security events. Vibosome receives the identity information needed to enforce the exact invited owner; application pages do not receive the Cognito password.
The current beta is limited to one authorized owner. Authentication, profile, mailbox state, queues, drafts, proposals, approvals, and artifacts are not designed as tenant-partitioned multi-user data. We do not represent the current deployment as appropriate for adding more users without an architecture change.
4. Mailbox connection and message data
When the owner connects a mailbox, Mailroom processes the mailbox address, IMAP and SMTP host, port and TLS configuration, mailbox password or application password, connection-test result, connection revision, provider identity, and status. The credential is used server-side for mailbox access and is encrypted at rest in the current hosted beta. The browser receives connection status rather than the stored credential value.
To provide mailbox features, Mailroom can process folder names, message UIDs and identifiers, sender and recipient addresses, reply-to data, dates, subjects, thread headers, bodies and quoted text, flags, attachment names, sizes and media types, relevant Sent-folder excerpts, drafts, groups, proposals, approval records, delivery outcomes, exports, signatures, and signature-logo assets. The mailbox provider remains the source of the original mail; Mailroom also keeps local state and artifacts needed for its workflow.
Attachment bytes may be retrieved from the mailbox for an explicit guarded download, preview, export, forwarding, or approved delivery path. File content can be unsafe or sensitive. A preview or metadata check is not a guarantee that an attachment is harmless.
5. Mailroom AI data flow
Mailroom uses the OpenAI Responses API to interpret a user's command and call bounded server tools. Depending on the request, OpenAI may process the command, trusted mailbox-profile fields, selected-message text, message metadata, and up to a bounded correlated set of relevant Sent-message text, plus tool results necessary to prepare a draft, organize mail, or propose an action. Email and Sent content are treated as untrusted data, not instructions.
The current implementation sends Responses requests with store: false. This controls OpenAI application-state storage for those requests but is not a promise that no provider-side operational processing or legally required retention can occur; OpenAI's applicable service terms and privacy documentation also govern its handling.
Mailbox credentials, raw attachment bytes, full mailbox dumps, and signature-logo bytes are not intentionally sent to OpenAI. The product does not intentionally send more mailbox context than the bounded tool flow needs. Nevertheless, selected email text can contain personal or confidential information, so the Customer must have authority and a lawful basis to submit it for AI processing.
6. Drafts, approvals, and actions
Mailroom stores local editable compose and reply drafts, frozen signature revisions, recipient and thread data, source references, action proposals, approval decisions, and outcomes needed to present and audit the workflow. Compose and reply drafts require human review. Sending, forwarding, moving, deleting, and other external or destructive actions are staged behind the available approval controls.
We process this data to show the owner exactly what is proposed, prevent stale actions from silently changing after review, execute an approved action, diagnose a failure, and maintain security evidence. Approval records do not establish that the message, recipient, attachment, instruction, or underlying legal basis was correct; the Customer remains responsible for that review.
7. Retained automation-platform data
For the retained hosted-automation platform, we may process account and workspace data; project names and selected files; commands, schedules, runtimes, dependencies and configuration; variables and masked secret metadata; run history, logs, outputs, artifacts and errors; AI explanations and repair context; approvals; scoped agent tokens and MCP identity bindings; usage, billing, support, and security records.
Customer code determines what an automation reads, writes, logs, or sends. If it prints a secret or personal data to logs or outputs, that information can become part of stored run history and support context. Customers must minimize inputs, keep secrets in the designated controls, and establish their own lawful basis and notices.
AI support on the automation platform may process bounded project summaries, redacted logs, errors, metadata, and tool context. We try to avoid known secret values, but redaction cannot detect every unusual credential or confidential value.
8. How and why we use data
We use data to assess beta fit; create and secure accounts; connect and test a mailbox; read requested mail; search and correlate bounded context; create and preserve drafts; display and execute approved actions; manage profiles and signatures; operate automations; apply limits; provide support; monitor health and cost; prevent abuse; investigate incidents; maintain records; and comply with law.
Where GDPR or similar law applies, contractual necessity or steps requested before a contract may cover account, beta-application, mailbox, workflow, support, and billing processing needed to provide an accepted service. Legitimate interests may cover service security, fraud and abuse prevention, reliability, troubleshooting, limited product improvement, business administration, and legal claims, subject to balancing and applicable rights. Consent may apply to optional analytics or advertising measurement. Legal obligations may require tax, accounting, fraud, corporate, court, or regulatory records.
For Customer mailbox and automation content, the Customer is responsible for the lawful basis, transparency, recipient and worker rights, provider permissions, and any instructions that apply to us as processor. Contact us before production use if a data processing agreement or special restriction is required.
9. Providers and disclosures
The current Mailroom beta uses Amazon Web Services in the Frankfurt region for compute, networking, encrypted storage, snapshots, container images, secrets infrastructure, logs, alarms, budget controls, and Amazon Cognito authentication. OpenAI processes the bounded AI context described above. Hostinger is the currently allowed hosted-beta mailbox provider and processes the Customer's source mailbox and IMAP/SMTP transport under the Customer's account and Hostinger's terms.
The retained automation platform may also use Stripe for applicable subscription and card-payment processing; Google or GitHub for applicable sign-in; WorkOS only for the conditional external MCP flow described below; and infrastructure, DNS, email, monitoring, package-registry, analytics, professional-adviser, and support providers where needed. Full card numbers are handled by Stripe, not stored by Vibosome.
We may disclose limited data to service providers under applicable terms, advisers, accountants, insurers, an acquirer in a business transaction, or public authorities where lawfully required. We may also disclose information needed to prevent harm, investigate abuse, protect rights, or enforce the Terms. We do not authorize providers to use Customer data for unrelated Vibosome advertising.
10. Conditional WorkOS MCP data flow
External MCP OAuth and WorkOS Standalone Connect are disabled in production today. If that production gate is later passed, WorkOS (AuthKit/Connect) will provide MCP authentication, consent, application/grant records, and OAuth token issuance for the retained automation platform. For that purpose, Vibosome may send a stable local customer identifier, email address, display name, and short-lived external-authentication identifier. WorkOS may hold related user, consent, application, grant, and token records.
After WorkOS resolves the exact subject, Vibosome records the exact issuer and subject as the local customer's MCP OAuth identity. Vibosome does not send project source, variables, run logs, outputs, or AI prompt content to WorkOS for authentication. That flow uses stateless signed-token verification and does not use unsupported cross-client introspection.
Local account deletion does not by itself prove that WorkOS erased its copy. Provider-side reconciliation is required. Deleting an authorized application blocks new authorization and refresh-token use, but WorkOS does not provide an immediate revocation path for an already-issued access token in this flow; an issued token may remain valid until its signed expiry. Before activation, Vibosome requires a configured maximum lifetime of no more than 3,600 seconds.
11. Retention and deletion
There is no single retention period for every Vibosome record. We keep data while needed to run an active beta, accepted pilot, account, mailbox connection, automation, support case, security control, or legal obligation. Mailroom profile data, local workflow state, drafts, proposals, approvals, exports, signatures, and encrypted connection data currently persist until removed through a supported control or operator process. Disconnecting the mailbox clears the active connection according to the product flow but does not delete source mail from Hostinger.
The current Mailroom beta uses retained encrypted storage and encrypted lifecycle snapshots. Deleted or changed data can remain in a recent snapshot until that snapshot expires under the current backup lifecycle. Because backup and release configuration can change, contact us before relying on a particular deletion or recovery window. We may keep security, abuse, tax, accounting, contract, consent, and dispute records longer where necessary.
Automation-platform project files, variables, logs, outputs, and artifacts follow the applicable plan, controls, operational backups, and deletion process. WorkOS provider records follow the conditional limits above. Local deletion is not proof that AWS, OpenAI, Hostinger, Stripe, Cognito, WorkOS, or another independent provider has erased records it lawfully controls under its own terms.
12. Security and beta limitations
Current measures include HTTPS, Cognito authentication, software-token MFA, an exact-owner access boundary, server-side mailbox credentials, encryption at rest for the active credential record and production volumes, narrow network exposure, host IAM roles instead of embedded AWS access keys, secret stores, approval gates, immutable deployment images, backups, logging, monitoring, alarms, and guarded mailbox operations.
These are risk-reduction measures, not a guarantee or certification. The beta is one owner, one mailbox, one API process, one EC2 host, and one Availability Zone. It is not multi-tenant or highly available. No SOC 2, ISO 27001, HIPAA, PCI DSS service-provider certification, or similar compliance status is claimed by this Policy.
You must use strong unique credentials, MFA, least privilege, safe endpoints, mailbox-provider protections, and careful approval review. Report a suspected vulnerability through https://vibosome.com/security/disclosure and do not access or retain data that is not yours.
13. International transfers
MB Nordhub is established in Lithuania. Mailroom infrastructure is currently in AWS's Frankfurt region, while OpenAI and other providers may process data in the United States or other countries. Hostinger and Customer-selected services process data in the locations described in their own terms.
Where applicable, transfers may rely on adequacy decisions, contractual terms, standard contractual clauses, or another lawful mechanism available to the relevant parties. This Policy does not promise that every Customer workflow has completed its own transfer assessment. A Customer acting as controller must determine whether its notices, contracts, provider settings, and transfer safeguards are sufficient before connecting production data.
14. Your rights and choices
Depending on the law that applies, you may have rights to access, correct, delete, restrict, port, or object to certain processing, withdraw consent, and complain to a data protection authority. Rights can be limited by identity verification, another person's rights, Customer-controller instructions, security, legal claims, tax or accounting duties, and technical backup rotation.
Use https://vibosome.com/contact and select the privacy or data-request category. We may need to verify the invited account, mailbox relationship, or authority before acting. If the data is controlled by a Vibosome Customer, we may direct you to that Customer or assist it under applicable processor instructions.
You can disconnect the active mailbox through the product where available, manage automation projects and tokens through platform controls, and change optional measurement through cookie settings. Contact us for the current process if a control is unavailable.
15. Cookies and measurement
Necessary cookies and browser storage support authentication, OAuth or Cognito state, sessions, security, CSRF and abuse protection, preferences, and consent records. Blocking them can prevent private features from working.
Optional Google Analytics and Google Ads measurement are controlled through the site's consent interface. Advanced Consent Mode defaults analytics storage, ad storage, ad user data, and ad personalization to denied before optional measurement. Limited cookieless denied-state pings may transmit technical, page, consent-state, and campaign-request data to Google; optional cookies and identified Vibosome conversion events are not enabled until the relevant choice. Ad personalization remains denied.
If you grant optional measurement, Google may process page views, approximate location, browser or device type, referrer, interactions, campaign parameters, and permitted conversion signals under its own terms. You can change the choice later through the footer cookie settings or browser controls. We do not intentionally send mailbox content, project secrets, credentials, or payment-card details to analytics.
16. Children, sensitive data, changes, and contact
Vibosome is not intended for children under 16, and we do not knowingly invite them. Do not connect a mailbox or automation containing health records, biometric data, government identifiers, authentication secrets, payment-card data outside the payment provider, criminal-offence data, or other special or high-risk data without a written agreement and appropriate controls.
We may update this Policy when the product, provider set, architecture, or law changes. We will publish the current date and try to give reasonable notice of material changes where practical.
For privacy requests, use https://vibosome.com/contact and choose the privacy/data-request category. For security reports, use https://vibosome.com/security/disclosure. People in the EEA may also complain to their competent supervisory authority, including Lithuania's State Data Protection Inspectorate where appropriate.