Trust

Security at VibaCloud

Last updated: 1 August 2026

Your calendar and your timesheets say a lot about how you spend your working life, so we treat them carefully. This page answers the questions we are asked most often, in plain language. It is not a substitute for our Privacy Policy, which covers what we collect and why in full. If your question is not answered here, just ask us.

Do you store my password?

Most people sign in with their Microsoft or Google account. When you do, the sign-in happens entirely on Microsoft's or Google's own pages. We never see your password and we never store it, so there is no VibaCloud password to lose.

If you prefer an email and password login, the password is stored only as a salted hash using the industry-standard hasher built into ASP.NET Core Identity. We cannot read it back, and neither can anyone else. We never store passwords in plain text.

What can VibaCloud see in my calendar?

We ask Microsoft and Google for read-only calendar access. In practice that means:

  • We can read the events you choose to import: titles, dates, times and category colours.
  • We cannot create, change or delete anything in your calendar.
  • We cannot read your email, and we cannot send email from your account.

The exact permissions are shown to you by Microsoft or Google on their consent screen when you first connect, and you can revoke them at any time, either from Connected Calendars inside VibaCloud or from your Microsoft or Google account's security settings.

Is my data encrypted?

Yes, in transit. Every connection between your browser and VibaCloud uses HTTPS, and we enforce it with HSTS so your browser will refuse to talk to us insecurely. Your data is stored in a secured database, access to it is restricted, and every query is scoped to your account. The sign-in tokens that connect us to Microsoft and Google are held server-side and are never exposed to the browser.

Who can see my timesheets and hours?

By default, only you. VibaCloud is built around personal data: your imported events, drafts and submitted weeks belong to your account and nobody else's.

If you join a team, your timesheets still stay personal. Team admins can review a week only once you submit it, and even then they see only the entries tagged to clients your team shares. Anything untagged, and any work for your own private clients, stays visible to you alone. There is no way for a teammate to browse your calendar or your drafts.

Admins also get dashboards, reports and spreadsheet exports built from that same submitted, team-tagged work, so they can see your hours and their value alongside everyone else's. The same boundary applies throughout: those figures are recalculated from the team's share alone, so your private hours never appear in them, not even as a total. Weeks you submitted before you joined the team are excluded as well. The privacy policy spells out exactly what an admin can and cannot see.

Who at VibaCloud can see my data?

VibaCloud is a small company, and that is an advantage here: production access is restricted to the people who run the service, not spread across a large staff. We only look at customer data when it is needed to help you with a support request, to fix an incident, or where the law requires it. We do not browse timesheets or calendars out of curiosity, and we never use your content for anything beyond running the service for you.

Do you handle my card details?

No. VibaCloud does not take card payments today, so we never see or store card numbers. The payment details on your invoices (bank account, PayPal and so on) are text you write yourself for your clients, shown only on the invoices you create.

Can I delete my account and my data?

Yes, and you do not need to ask us. You can delete your account yourself from your profile page, which removes your personal data. Disconnecting a calendar provider is separate and gentler: it revokes our access to that calendar but keeps your VibaCloud account and timesheets intact.

Do you sell my data or use it for advertising?

No. We do not sell personal data, and we do not use your calendar or timesheet content for advertising. Our use of Google user data follows Google's Limited Use requirements. The Privacy Policy spells all of this out.

How should I protect my own account?

  • Sign in with Microsoft or Google where you can, and turn on two-step verification on that account. Because VibaCloud trusts their sign-in, their protection becomes yours.
  • If you use an email and password login, choose a strong password you use nowhere else.
  • Sign out on shared or public computers rather than just closing the tab.

Found a security problem?

If you believe you have found a vulnerability in VibaCloud, please tell us before you tell anyone else. Report it through our contact page with enough detail for us to reproduce it, and we will respond as quickly as we can. We are grateful for responsible disclosure and we will never take action against anyone reporting a genuine issue in good faith.

An honest note

No online service can promise perfect security, and we will not pretend otherwise. What we can promise is that we take it seriously, we keep our approach under review, and if something ever goes wrong that affects your data, we will tell you plainly and quickly. Specifically, if a breach ever affects your personal data, we will notify you without undue delay and report it to the UK Information Commissioner's Office within 72 hours where required, in line with UK GDPR, including what happened, what data was affected and what we are doing about it.

An unhandled error has occurred. Reload 🗙

Rejoining the server...

Rejoin failed... trying again in seconds.

Failed to rejoin.
Please retry or reload the page.

The session has been paused by the server.

Failed to resume the session.
Please retry or reload the page.