← VIVI

Privacy Policy

Version 1.0 · Effective July 21, 2026

This Privacy Policy describes how BubbleShare Inc. (“we”, “us”) collects, uses, stores, and protects personal data in connection with VIVI, our AEO/GEO visibility monitoring service. It applies to the VIVI application and is specific to VIVI (separate from the general bubbleshare.io documents).

1. Data we collect

  • Account & identity — your name and email, managed through our authentication provider (WorkOS). We use these to sign you in and manage your organization (workspace) and access.
  • Workspace — the company name you provide at sign-up (used to name your trial workspace) and your consent records.
  • Usage & log data — IP address, browser/device info, access times, and pages visited, collected automatically (including via cookies).
  • Monitoring configuration — the brands, domains, and prompts you set up for monitoring. This is business data, not personal data.

We do not collect payment cards or phone numbers for the self-serve trial, and we do not store your password (your credentials are held by WorkOS).

2. How we use it

  • Provide, operate, and secure the VIVI service and your workspace
  • Run daily crawls and aggregate visibility metrics you configure
  • Respond to support requests and communicate service notices
  • Send marketing communications only where you separately opt in (see §7)
  • Comply with applicable laws

3. Where your data is stored (processors)

We rely on the following processors to operate VIVI:

  • WorkOS, Inc. — authentication, account & organization management. Holds your name, email, and organization membership.
  • Vercel, Inc. — application hosting (access logs, request data).
  • Timescale, Inc. (Tiger Data Cloud) — service database (hosted in Japan, AP-NORTHEAST-1). Stores organization/user identifiers, your monitoring configuration, usage data, and consent records. It does not hold your direct identity (name/email/credentials), which remain with WorkOS.
  • Inngest, Inc. — background workflow processing (crawl and aggregation jobs).

To produce monitoring results, VIVI also sends your configured prompts to third-party search/AI engines and crawling/LLM providers. This involves your monitoring configuration (business data), not your personal data.

4. Google user data (Google Analytics & Search Console integration)

If you choose to connect your brand's Google account in Settings › Integrations, VIVI accesses Google user data strictly as described in this section. VIVI's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

  • What we access — read-only scopes only (analytics.readonly and webmasters.readonly). From Google Analytics 4 we read aggregate reporting data: dimensions date, host name, page path, and session source/medium; metrics sessions, page views, key events (conversions), and revenue. From Search Console we read daily impressions and clicks per page. We do not read user-level, demographic, or personally identifying data from your Google account, and we cannot modify anything in it.
  • What we use it for — solely to render your own workspace's dashboards (search performance, traffic and conversion funnels, and AI-answer-engine inflow analysis for the connected brand). Google user data is only visible to members of the workspace that connected it.
  • Third-party sharing — we do not share Google user data with third parties and do not sell it. It is stored only with the infrastructure processors listed in §3, acting on our behalf. Our staff do not read it except with your permission (support), for security investigation, or where required by law.
  • Storage & protection — OAuth tokens are stored encrypted in a dedicated secrets vault (WorkOS Vault); the aggregated metrics are stored in our service database (Tiger Data Cloud, Japan), scoped to your workspace. All transfers use HTTPS and access is restricted per §10.
  • Retention — synced Google data is retained only while the integration remains connected.
  • Deletion — disconnecting the integration in Settings › Integrations immediately deletes the stored OAuth tokens and purges all synced Google Analytics / Search Console data for that brand from our database. Closing your account or workspace deletes it likewise. You can also request deletion anytime at admin@bubbleshare.io. You may additionally revoke VIVI's access from your Google account security settings.
  • Prohibited uses — we do not use Google user data for advertising (including personalized or retargeted ads), do not sell it, and do not use it to determine credit-worthiness or for lending purposes. It is never used to train generalized AI/ML models.

5. Overseas transfer of personal data

Operating VIVI requires transferring personal data outside the Republic of Korea to the processors below. You may decline; however, declining prevents account creation and use of the service.

RecipientCountryItemsPurposeRetention
WorkOS, Inc.USAName, email, organization infoAuthentication & account managementUntil account closure or contract end
Vercel, Inc.USAAccess logs, request dataHostingUntil the processing purpose is met
Timescale, Inc. (Tiger Data Cloud)Japan (AP-NORTHEAST-1)Identifiers, usage data, consent recordsDatabase storage & operationUntil account closure or contract end
Inngest, Inc.USAIdentifiers, request dataBackground workflow processingTransient / job duration

6. Retention

  • Account & workspace data: until you close your account or the contract ends
  • Automatically collected log/cookie data: up to 12 months from collection
  • Trial data: deleted within 6 months after the trial ends if not converted
  • Records required by law (where billing occurs): retained for the statutory periods under applicable Korean law

When no longer needed, data is securely deleted or anonymized.

7. Marketing communications (optional)

Only if you separately opt in, we may email you product news, events, and offers. This is optional and is not a condition of using VIVI. You can withdraw consent anytime via the unsubscribe link or by emailing admin@bubbleshare.io.

8. Cookies

We use cookies for session authentication, usage analysis, and personalization. You may disable cookies in your browser, though some features may be limited.

During sign-up we also set a short-lived, secure functional cookie that temporarily holds the information you enter on the sign-up screen (your company name and consent choices) so we can finish creating your workspace after authentication. It expires automatically and is deleted as soon as sign-up completes.

9. Your rights

You may request access to, correction of, or deletion of your personal data, and object to or restrict processing, by emailing admin@bubbleshare.io.

10. Security

Sensitive data is encrypted in transit (HTTPS) and at rest where applicable, access is restricted, and we monitor for anomalies.

11. Contact

Privacy Officer: Sooah Lee · admin@bubbleshare.io · BubbleShare Inc., Republic of Korea.