Privacy
Last updated 6 October 2026
VibeStack is a vibecoding workspace for schools, built by AutoBricks AI. This policy covers the platform at vibestack.autobricks.ai and the sites pupils publish from it. It is written to be read, not to be survived.
Who we are
AutoBricks AI, a Singapore business and the agentic AI wing of Hexcore Labs. Questions about anything on this page go to hello@autobricks.ai.
Who this is for
VibeStack is built for pupils aged 18 and below, and it is used through a school. The school or programme is our customer and decides who gets an account; a pupil does not sign up on their own and does not agree to anything on their own. There is no open registration — an account cannot exist without a signup code issued by a teacher or an administrator.
If you are a parent and want to know what we hold about your child, ask their teacher or write to us and we will tell you.
What we hold
- The account. An email address, a display name if one is set, and when it was created. Passwords are not ours — they are held by our authentication provider, and nobody here can read one.
- The work. Projects, every version of their files, notebooks, and any dataset a pupil uploads to one.
- The conversation. Every prompt a pupil sends to the assistant and every reply, with the model used, the token counts and what it cost.
- App data. If a pupil’s published site has sign-ups, the accounts its visitors make belong to that pupil’s project. Those passwords are stored hashed and kept out of the downloadable database file on purpose.
We do not ask for a date of birth, a phone number, an address, or a payment method.
How we use it
To run the thing: to show a pupil their work, to send a prompt to a model and bring the answer back, to serve a published site, and to count tokens against a weekly allowance so one runaway project cannot spend a class’s share. We do not sell it, we do not advertise against it, and we do not build profiles from it.
Who can see a pupil’s work
The pupil, and an administrator at their school or programme. Separation between accounts is enforced in the database itself rather than by application code, so one pupil cannot reach another’s projects, notebooks or data even if something above it goes wrong.
An administrator can open an account and see it as its owner does. That exists so a teacher can answer “it does not work” without walking across the room, and anyone whose account can be viewed this way should be told that it can.
The model
Prompts are sent to our model provider, BytePlus ModelArk, from our server and on our credentials. A pupil never holds a key. We do not send them your pupils’ names or email addresses — a prompt goes out as the text of the conversation and the project’s files, and nothing identifying is attached to it.
Where it lives
Accounts and work are in a managed Postgres database in Singapore. Identity is held in VibeStack’s own system and is shared with no other AutoBricks product — a pupil’s login exists here and nowhere else. Uploaded datasets and each project’s database file sit on the server’s own disk.
Python in notebooks runs in the pupil’s browser, not on our server. A dataset they analyse is uploaded so it can be reopened later; the analysis itself never leaves their machine.
Cookies
Three, all strictly necessary and none of them for tracking: two that keep a pupil signed in, and one that records when an administrator is viewing another account. A published pupil site sets one more, which keeps a visitor to that site signed in to that site.
There is no analytics, no advertising pixel, and no third-party tracker anywhere on this platform.
How long we keep it
For as long as the account exists. Deleting an account deletes its projects, versions, notebooks, uploaded files, database files and conversation history, and removes the login itself. Backups age out on their own within a month.
Your rights
Under Singapore’s Personal Data Protection Act you can ask what we hold about an account, ask us to correct it, and ask us to delete it. Write to hello@autobricks.ai and we will come back within a few working days. A pupil’s request is confirmed with their school first, because the school is who the account belongs to.
Security
Connections are encrypted. Accounts are isolated from each other in the database. A pupil’s published site runs on its own address under its own policy, so code they write cannot reach the platform or another pupil’s work. Nobody here can read a password.
Changes
If this page changes in a way that matters, the date at the top changes and we tell the schools using the platform. Carrying on using it after that is agreement to the new version.