Skip to main content
← Back to the home page

Privacy and Cookie Policy

VibeTune528, Tune in to your heart

Last updated: September 2026

Who is responsible for the information

VibeTune528, operated by Yoni Yarom, is the controller of the information collected through the website and the services described in this policy. For privacy inquiries: office@vibetune528.co.il.

What information may be collected

Essential information, not dependent on consent

  • Contact details provided voluntarily, such as name, phone, email address, subject and message content.
  • When a visitor explicitly requests a personal copy of a Frequency Compass journey, we collect name, email address, locale, request reference, lifecycle timestamps, status and a minimized technical journey description, such as registered frequency IDs, durations, layers, effect IDs, visual settings and references to up to three selected, predefined anchor phrases. It excludes the wording of mapping answers and choice labels, affirmation or anchor wording, personal or free text, health information and payment-card details.
  • At the Compass entry gate, age, experience-boundary and safe-use confirmations stay only in temporary page memory. A copy request requires fresh 18+, copy-scope, contact-purpose and retention acknowledgements; the request record keeps the acknowledgement time and text version, while the four checkbox values are not stored as separate columns. To prevent misuse and limit requests to one per email address in 24 hours, the email address, IP address and user agent are used to create HMAC identifiers; raw IP and user-agent values are not stored in the request queue.
  • Hosting, security and server request records, processed by the hosting and security providers as an inherent part of running the website. These records may include IP address, device and browser type, request time and security identifiers. They are required for functioning, preventing misuse and documenting faults, and are therefore not conditional on consent to optional cookies.
  • Cookie preferences and the time the choice was saved in the browser.
  • If you choose to create an account or sign in, Supabase Auth processes an email address, an internal account identifier, verification state, linked sign-in providers and minimized profile information received from the provider, such as a name and profile image. Email and password or Google may be used; Facebook sign-in is displayed only after a separate gate and provider-configuration verification. Sign-in tokens are kept in necessary browser storage to maintain the session and are not used for measurement or advertising. The email address, account identifier and provider subject are never displayed publicly.
  • The Daily Frequency section displays aggregate article view, like and share counts. A view is registered only after the article remains open for a minimum period and approximately no more than once per article per day; a share action is counted approximately once per channel, article and day. To prevent repeat counting and abuse, the IP address and user agent are used server-side only to create a one-way HMAC identifier; their raw values are not stored in the section's tables.
  • When Daily Frequency conversations are enabled, comments and replies are stored as plain text together with the author's chosen public name, an approved profile image or symbol, article and parent-message association, timestamps, approval state, and like, reply and report counters. A signed-in author is linked internally to the account; a guest provides only a public name. Likes require a signed-in account. A report contains a structured reason and may include an internal account link or a source HMAC. Raw IP address and user agent are used transiently only to create the HMAC and verify Turnstile, and are not stored in the community tables; the Turnstile token is not retained.

Optional mailing, only after explicit sign-up

  • When signing up to receive a digital gift or email content, the email address, sign-up source, status and date of marketing consent, and a random identifier for unsubscribing are saved. Marketing content is sent only if explicit consent was given for it, and the sign-up can be removed at any time via the link in every message.

Optional measurement, only after consent

  • Usage data via Google Analytics, such as traffic source, pages viewed, time on site and interactions on the site. Google's measurement code loads and transmits data only after explicit approval in the consent mechanism. If measurement is not approved, the code does not load; after consent is withdrawn, measurement is disabled and no further events are sent.
  • Daily Frequency conversation measurement is limited to fixed event names and low-cardinality context, such as opening the conversation, submission, reply, like, report or sign-in start. Comment content, name or nickname, email address, account or provider identifier, comment identifier, report reason, avatar URL, article slug and HMAC values are never sent to analytics.

It's important to clarify: declining optional measurement does not mean no information is processed at all. The hosting and security records described above continue to exist, as they are required to run the site and keep it secure.

There is no need to provide medical, mental-health, financial or other sensitive information in the form. Such information, if provided at the sender's own initiative, will be used only to understand the initial inquiry.

In the private Frequency Compass route, the experience is composed in the browser. Mapping answers, moment intensity, body cue, images, north-star direction, element gate and personal text stay in page memory on the device and are not included in a personal-copy request; public media assets may still be fetched from the media host, which receives the asset request and ordinary network metadata. The answers disappear on reset or refresh. While the copy flow is disabled, no form is shown and no request is accepted; after controlled activation, submitting a request does not charge the visitor or collect card details, and a manual payment link is sent separately by email only after manual processing.

When the smart personal V5 route is enabled, and only after a separate checkbox that is not preselected, the VibeTune528 server may keep a private service record containing eligible structured choices and free text, excluding the preferred name and form of address that remain in temporary page memory, together with the generated meaning map, participant review and journey result. The record is used only to personalize the current journey, verify integrity and support manual service-quality review; it is not identity-linked continuity. Only an approved minimized profile required for formulation is sent to n8n Cloud and the OpenAI API; preferred name and form of address are neither stored in the service record nor sent to the AI providers. At composition, only the formulation and information the participant approved are sent, without resending the raw answer map. Access codes, Turnstile tokens, authorization tokens, signatures, contact details, account or device identifiers, audio and frequency data are not stored in the record. Use only a short nickname in the preferred-name field and do not enter full names, identifying details, secrets or information about another person in free text. A V5 failure does not start a local journey in its place; the visitor may retry, exit, or return and explicitly choose a separate route.

Responsibility is shared but not identical: the user controls the free text and is responsible for not including a full name, contact details, identifying information, confidential information or information about another person, and for using only a short nickname in the preferred-name field. Such details are not required to use the route. VibeTune528 remains responsible for defining and limiting the processing purpose, selecting and governing processors, restricting access, using reasonable security measures, and handling applicable rights and security incidents as required by law. No online system can guarantee absolute immunity, so consent does not remove the user's responsibility for the content entered and does not remove VibeTune528's obligations.

The Compass offers a separate on-device symbol-learning option, off by default. After explicit activation, local storage keeps only consent/version and expiry times, internal symbol IDs and bounded numeric counters for up to 180 days. It does not keep names, forms of address, answers, emotions, goals, future-self wording, free text, frequencies or recipes. Turning the switch off deletes the complete record, and the information is not sent to us, analytics or other users.

Evidence of cookie choices

In addition to saving the preference in the browser, the server also keeps an evidentiary record whenever a choice is made, an approval, rejection, update or withdrawal. The purpose of the record is to document which version of the notice was shown and what was chosen, to handle disputes and to preserve the integrity of the consent mechanism.

The record includes the date, type of action, cookie categories, document version and its hash, the page path without parameters, language, and hashed browser identifiers, IP address and user agent where available. The IP address, user-agent string and the local identifier are not stored in the record in their raw form. Events are linked to each other via hashing for sequence verification, and access to them is server-side only.

Purposes of use

The information is used to respond to inquiries, arrange a call or service, run and secure the website, handle faults and reports, comply with legal obligations, and improve the service and user experience. Where separate consent was given, the information is also used to send marketing content and mailings by email until the sign-up is cancelled.

Information submitted in a personal-copy request is used only to open the request, prevent abuse, send a manual payment link, verify payment, prepare the copy and deliver it manually. It is not used to build an emotional profile, make a diagnosis or send marketing without separate consent.

Information in the smart personal V5 route is used to tailor and create the current journey, check safety and quality, and support manual service-quality review by a person explicitly authorized for a documented purpose. It is not used for advertising, marketing, CRM, pricing, a persistent profile, cross-user learning, automated decision-making about the participant or model training.

Account information is used for authentication, for maintaining one VibeTune identity across the Love Wall and Daily Frequency conversations, for profile management and for securely attributing account actions. Community content and related information are used for publication only after approval, conversation and like display, duplicate and abuse prevention, report handling and moderation. They are not used for targeted advertising, sale, model training or account merging based on a name or unverified email address.

Access and permissions

Full access to the site's administrative information is limited to Yoni Yarom. Elena Driga may be granted partial and limited access, restricted to the areas and information required for her role, subject to dedicated permission. If full Compass V5 service records are stored, they are not available through the public site or an ordinary user role: application access is restricted to Yoni or a treating or operations professional explicitly authorized for a documented purpose, using dedicated server operations only. Every list display, read or deletion is entered in an access log retained for 24 months. Infrastructure providers may process information technically only to the extent required to operate the service.

For Daily Frequency conversations, the public sees only approved, non-deleted comments and replies through a minimized view containing text, a public name and a profile image or symbol approved for publication. Email addresses, account IDs, provider subject IDs, HMAC values and report details are excluded from the public view. Authorized administrators may also review pending content, reports and moderation state; deletion, restoration and source blocking require stepped-up administrator verification. The moderation audit keeps action and state identifiers but not comment bodies, email addresses or HMAC values.

Data retention

Personal note images and recordings have an independent default lifetime of 30 days; an extension requires explicit, recorded approval for that asset. Note deletion immediately schedules its assets for deletion with a target within 24 hours, including the existing recovery window. Provider outages can delay completion; unresolved requests remain tracked and retryable. Operational asset, note and creator identifiers and extension records are scheduled for removal seven days after deletion is confirmed. Email is resolved from the existing account for authorized administrators only, without a registry email snapshot. Consent and security evidence follows its separate policies.

Contact details and personal operational information are generally retained for up to 12 months from the date of collection or last activity, after which they are intended for deletion, minimization or anonymization, unless longer retention is required for a legal obligation, dispute, security or protection of rights.

A focused exception applies to a Frequency Compass personal-copy request: an active unpaid request and its minimized technical description expire after 72 hours. On expiry, cancellation or verified completion of delivery, contact details, abuse-prevention identifiers and the technical description are immediately erased or overwritten in the operational request queue and database, and the minimized row and status history are deleted after 30 days. If payment is confirmed in time, the minimum queue data is kept for preparation, sending and a short check for a failed handoff or necessary resend; the operational target is to complete delivery verification within 72 hours of sending and, in every case, complete verified delivery or a refund, cancellation and redaction within seven calendar days of payment confirmation. Only after delivery verification is the request marked delivered and the operational queue data immediately redacted. Operational email may include the address, request reference, payment link and a delivery attachment or link; it is scheduled for deletion from the active business mailbox within 30 days after the process ends, while an externally hosted artifact is scheduled for deletion within seven days of verified delivery or immediately after cancellation and refund. The paid flow will not be activated until working mailbox and delivery-provider retention/deletion controls are configured. Payment or bookkeeping records required by law are maintained separately from this request system.

In the appointment system, an expired exact-time request is deleted after 30 days; hashed identifiers used to prevent misuse are erased after 90 days; and the remaining request record is deleted 12 months after the latest activity. Deletion is automated in the active database. Provider backup and recovery copies age out under the provider's recovery lifecycle and are not returned to active processing except for disaster recovery.

Mailing subscriber details are retained for as long as the sign-up is active and are required to send the content. After unsubscribing, marketing mailings stop, and a minimized suppression record is kept to the extent required to honor the removal request and prevent re-registration without consent; the remaining information will be deleted or minimized in accordance with the obligations and needs detailed here.

Hashed identifiers used to prevent duplicate article-view or share counting are deleted after 35 days; aggregate counts, which contain no visitor identifier, are retained as public article data. A hashed like identifier is kept while the like remains active so duplicate likes can be prevented and the like can be removed with another click.

When Daily Frequency conversations are enabled, an approved comment remains until the author or an authorized administrator removes it, or until the article is retired under the content policy. An author deletion request immediately purges the comment body and author snapshot. Administrator soft deletion removes the comment from public view, remains reversible for 30 days, and then permanently purges the body and author snapshot. The body and author snapshot of an unresolved pending comment are removed after 30 days; the bodies and author snapshots of hidden or rejected comments, and resolved reports, are removed after 180 days; a minimized moderation log that excludes comment bodies is retained for up to 730 days. A comment source HMAC is removed after eight days, rate-limit buckets within seven days after their window ends, and both the reporter account link and reporter HMAC after 90 days. A guest-source block is temporary and never lasts more than 30 days. A like remains while active. Account deletion must remove account-bound likes and reports and allow comments to be removed or anonymized according to the user's choice. The community remains disabled until these database lifecycle jobs and the account-deletion path have been verified in production, and until external provider avatars use a reviewed first-party proxy/cache or are disabled in favor of local emoji/initial fallback; provider backup aging follows the provider's recovery cycle.

The Compass on-device symbol-learning record lasts no more than 180 days from explicit activation. Expired, unknown-version, corrupt or oversized records are deleted when read. Turning learning off immediately removes the single local key.

When the private V5 storage boundary is enabled, the allowlisted service record—excluding preferred name and form of address—is intended to be retained for up to 90 days and then automatically deleted. The current browser does not provide a participant-held case reference, so locating or deleting a V5 case early is not promised from identity alone; rights requests are assessed under applicable law and verifiable information. The minimized access log contains operator ID, purpose, action and time, but not answer content, and is retained for 24 months. Access codes, Turnstile tokens, authorization tokens, review tickets and signatures are not kept in the record. The V5 contract requires n8n not to retain successful, failed, manual or progress execution content; no live execution content was observable in this review. OpenAI calls use store=false; unless Zero Data Retention has been approved for the account, content may be included in OpenAI abuse-monitoring logs for up to 30 days. Provider backup aging remains subject to the recovery cycles and actual account settings.

An exception to this is the consent-evidence repository: cookie-choice records are minimized, hashed server records that cannot be edited in the ordinary way, and each record has a defined retention period of seven years. Consent events in contact forms, the digital gift and the Love Wall are also shown in the admin interface with a seven-year evidentiary retention period. The length of this period, its necessity and the method of deletion at its end are subject to periodic review and legal examination; nothing here determines that it is required in every case.

Earlier deletion may be requested subject to law, record integrity and the needs described above. A request will be assessed by the type of information rather than by a uniform rule.

Vendors and third parties

The information is not sold. Depending on the component used, the following may be involved:

  • Lovable, application hosting and infrastructure, including the gateway connecting to email services and the broker client used to start Google sign-in.
  • Supabase, database, authentication, session storage, profiles and server-side community services.
  • Cloudflare Turnstile, automated-use detection and form security, as an essential component.
  • Cloudinary, delivery of public image and video files and, only after the activation gates are completed, direct upload, technical normalization, protected storage, temporary moderation preview, delivery and deletion of personal images and voice recordings explicitly selected in the Love Wall.
  • Google Fonts, font delivery, when the browser requests them from the provider.
  • Google Analytics, optional measurement, only after explicit approval.
  • Meta / Facebook, display of public posts and the page feed only after the visitor explicitly chooses to load the content.
  • Google Identity, user-initiated account sign-in and minimized profile information; an approved profile image may be loaded from Google alongside approved community content.
  • Meta / Facebook Login, user-initiated sign-in only after a separate gate and verification of the Meta and Supabase settings; an approved profile image may be loaded from Meta alongside approved community content.
  • Google Gmail / Google Workspace, sending digital gifts, mailings and operational correspondence.
  • n8n Cloud, secure orchestration of the smart personal route.
  • OpenAI API, generation and quality review of the current journey.
  • Google Calendar, checking free/busy on configured calendars and creating or removing a private neutral event on the business calendar when confirming an appointment.

Vendors may process information outside Israel in accordance with the arrangements applicable to the service. Free-text content from forms, card content or private links is not knowingly sent to the measurement tool. Opening a WhatsApp link is a user-initiated action that transfers the user to Meta/WhatsApp's service under its own terms and policy.

The Love Wall personal-image and voice feature remains off until its privacy, security and provider gates are complete. If it is enabled and explicitly selected, the browser will transfer the file directly to Cloudinary, so the provider receives the file and ordinary network data. The asset will remain protected, will be opened by an authorized administrator only through an explicit temporary moderation preview, and will be delivered to the selected audience only after human approval and authorization of the note opening. VibeTune528 will not enable automated transcription, facial or speaker recognition, biometric identification, AI processing, model training or targeted advertising for this flow. Activation is conditional on verification of the DPA, subprocessors, transfers and regions, backup and deletion cycles, normalization and metadata stripping, and the live account settings.

For a personal-copy request, Supabase privately stores the request details and minimized technical description, Cloudflare Turnstile checks for abuse, and Gmail / Google Workspace carries the operational correspondence. The wording of mapping answers and choice labels, anchor-phrase wording and personal or free text are not included; the technical description may contain references to selected, predefined anchor phrases.

When the visitor selects and consents to the smart personal V5 route, Supabase stores the complete private service record. The VibeTune528 server sends n8n Cloud and the OpenAI API only the allowed minimized profile and later only the formulation the participant reviewed and approved; Cloudflare Turnstile receives a verification token and ordinary network data, not Compass answers. The providers may use subprocessors and may process information outside Israel, including in Europe and the United States, according to the account settings and applicable arrangements. Under OpenAI's business API terms, customer content is not used to develop or improve models unless the customer expressly agrees; VibeTune528 does not give that permission for Compass answers.

Facebook embeds do not load when the page first opens. Only after an explicit click to display a post or feed does the browser connect to Meta, which may receive network data and use technologies under its terms and privacy policy. The visitor can choose the external link instead.

When signing in with Google or, after separate activation, Facebook, the identity provider and Supabase process the sign-in request, provider subject and approved minimized profile information. Google sign-in is started through Lovable's Cloud Auth client and continues into the same Supabase session. VibeTune528 uses a single Supabase identifier as the account identifier and does not publish the email address or a separate provider-subject field. An additional provider may be linked only from an authenticated session through the authentication provider's linking mechanism; accounts are not merged by name or unverified email.

Daily Frequency conversations are stored in Supabase and reviewed before publication. Guests pass distinct Turnstile checks for comment submission and reporting; Cloudflare receives a token and ordinary network data, while only a one-way source HMAC is stored in the database. A profile image is displayed only with an approved comment, from a restricted HTTPS provider allowlist, lazily and without a referrer; Google, Meta or the image provider may receive the file request and ordinary network metadata. If no safe image is available, a local symbol or initial is shown.

Cookies, advertising and mailing

Advertising pixels, ad personalization or storage for advertising purposes are not currently activated on the site; the advertising categories in the consent mechanism remain declined. If such a tool is activated in the future, the policy and mechanism will be updated before activation and appropriate consent will be requested.

Separately from advertising cookies, the site offers an optional sign-up for email mailings. This consent is not pre-checked, is given only through an explicit action, and can be withdrawn at any time via the unsubscribe link in every message.

User rights

Subject to law, you may request to review, correct, update or delete your information, and to withdraw consent to processing based on consent. To protect the requester's privacy, we may ask for reasonable details to verify identity.

Data security

Reasonable organizational and technological measures are taken to reduce unauthorized access, misuse or exposure. However, no online system is completely immune to risks.

Cookie policy

Essential cookies and storage are used for operation, security and saving preferences, and always run. Optional measurement via Google Analytics is activated only after explicit approval in the consent mechanism. If consent is declined the code does not load; after it is withdrawn, measurement is disabled and no further events are sent. The site remains fully usable even without measurement, and there is no blocking of content or services due to declining optional cookies.

Marketing cookies are not currently active on the site and are not part of the consent mechanism.

Embedded Facebook content does not load automatically and is independent of the measurement preference. It loads only after the visitor selects its dedicated display control; Meta's terms and technologies apply from that point.

A VibeTune account session is kept in necessary Supabase browser storage so sign-in continues between pages. It is independent of analytics consent, is not used for advertising, and can be removed by signing out or clearing site data. Facebook sign-in remains hidden while its separate activation gate is off.

In the daily frequency section you can write a personal reflection. The text is saved only in your browser's local storage, after an explicit save action, and is never sent to us or to any third party. You can delete it at any time from the page or by clearing your browser data.

Optional Compass symbol learning is separate local storage and is never required to use a journey. It is enabled only through its dedicated switch, keeps symbol IDs and numeric counters only for up to 180 days, and is fully deleted when the switch is turned off or site data is cleared.

You can approve, decline or change your choice at any time. The choice is saved for up to 12 months, after which a new choice will be requested.

The Love Wall

The Love Wall has separate information characteristics, including user content, consents, sharing links and moderation. For details, see the Love Wall privacy policy.

Updates and contact

This policy may be updated in accordance with changes in the service or the law. A material change will be posted on the site. For questions or privacy requests, please contact office@vibetune528.co.il.