FreshVibe privacy policy

Last updated: 6 August 2026

About this policy

FreshVibe is the platform Freshwater Futures Pty Ltd (ACN 674 518 784, ABN 75 674 518 784) (“we”, “us”, or “our”) runs for hackathons, workshops, and discovery sessions. It has two parts, and this policy covers both:

  • Shaping ideas, at vibe.freshhub.ai, where you talk to an AI assistant about a problem, publish a brief, comment and vote on other people's briefs, and form teams.
  • Building prototypes, at build.freshhub.ai, where you get a cloud development workspace with an AI coding agent, a terminal, and a live preview of what you build.

This policy sits alongside our general Privacy Policy. Where the two differ on something specific to FreshVibe, this policy applies.

We handle personal information in accordance with the Australian Privacy Principles under the Privacy Act 1988 (Cth).

FreshVibe is for participants aged 18 or over, as our terms and conditions require. We do not knowingly collect information from anyone under 18. If you believe we have, email us and we will delete it.

Who is responsible for your information

Freshwater Futures Pty Ltd is responsible for the personal information this policy describes. We handle it in our own right rather than as an agent of the organisation hosting your event, which means your access, correction, and deletion rights sit with us. Email us and we will deal with it, whoever sent you. Accountability rests with our director and with the authorised person who handles participant data: the same two named personnel described under Data security below.

The host organisation has a role of its own. It decides who is invited, it sees the participation and outcome information set out under Who can see your information, and what its people contribute sits in its workspace for as long as it is a client of ours. None of that displaces our responsibility to you.

Self-hosted deployments are not covered by this policy. Where an organisation runs FreshVibe in its own environment, it handles the information in that deployment itself, and you should ask it for its own privacy policy. This policy covers FreshVibe as we run it, at vibe.freshhub.ai and build.freshhub.ai.

While FreshVibe is in early access

FreshVibe is still in early access, meaning it is running with the people it is being built for while we finish building it. What this policy describes is that early-access configuration. It involves full capture of how you use the product, so we can support you through the programme and find what is broken and fix it. That covers the session recordings, the AI prompts and responses, and the activity records set out below.

That capture is a condition of taking part, not a choice you make. There is currently no way to use FreshVibe with it switched off, so we are not going to describe it as consent. We intend to make it optional as the product matures, and we will update this policy when it is. If it is a problem for you, raise it with the organisation hosting your event, or with us, before you start.

We use what we capture in early access for two purposes: supporting the people taking part in the programme, and developing the product. Those sit alongside running your event itself, and the complete list of what we use information for is under How we use your information below.

We do not share what we capture with anyone outside Freshwater Futures, other than the service providers listed below, which process it on our behalf so the product can run. We do not use it for marketing. Sharing it more widely, or using it to market to you, would need us to ask the organisation hosting your event first and for it to agree. If you opted in to updates from us, that is separate: we use your contact details to send those, not the material described here, and you can opt out at any time.

This is not a permanent arrangement. How much we capture is tied to what we still need in order to develop the product and run the programme, and it narrows as that need falls away. We review this policy as the product changes, and update it to reflect what we are actually capturing.

Where your organisation has a written agreement with us, that agreement decides what applies to your event, and we will tell you before you start.

Information we collect

From your sign-in

Both parts of FreshVibe use single sign-on through FreshAuth, our own service at auth.freshhub.ai, which may in turn use your Google account or your organisation's identity provider. From it we receive your name, email address, and profile picture, along with the organisations you belong to and your role in them.

From onboarding

  • Your organisation and its approximate size
  • The track you choose (executive, engineer, or expert)
  • A short description of your role, in your own words
  • The date and time you accepted this policy and our terms
  • Whether you opted in to marketing updates, which is optional and separate from the consent above

When you shape ideas

  • Your conversations with the AI assistant, stored in full so you can return to them
  • Idea drafts and published briefs, including the problem, impact, feasibility, and target user you describe
  • Comments, votes, and expressions of interest in joining a team
  • Context the assistant saves about you during a conversation, such as the projects, team, or goals you mention

When you build

  • The contents of your cloud workspace: source code, files, configuration, and anything else you or the agent write to disk
  • Your instructions to the AI coding agent, and its responses
  • Commands you run in the workspace terminal, and their output
  • Workspace metadata: when it was created, which starter project you chose, which agent you connected, and when it was running
  • Preview links you generate, and requests made to them

Activity records

We keep an activity log of key actions in your workspace: signing in and out, choosing a track, updating your profile, sending a message to the assistant, generating or saving a draft, and publishing a brief. Each entry records your name, email address, and the time.

Technical and usage information

We collect standard product analytics: pages viewed, features used, interactions with the interface, your browser and device type, and an approximate location derived from your IP address. We also collect application and workspace logs used to diagnose faults.

Session recordings

We record browsing sessions in FreshVibe so we can see how people move through the product and diagnose faults. A recording captures the pages you see, your mouse movement and clicks, the text you type into the interface, your browser's console output, and the network requests the app makes, including their contents. Recordings are kept for 30 days and then deleted. Recording is part of the early-access capture described above.

How we use your information

  • To run the event or session you are taking part in
  • To give you an assistant and a coding agent that respond in context
  • To provision, run, and clean up your cloud workspace
  • To show your ideas, comments, and votes to others in your workspace
  • To help form balanced teams around the ideas people back
  • To give the host organisation a picture of participation and outcomes
  • To keep the service secure, diagnose faults, and improve how it works
  • To send you updates about our services, using your contact details and only if you opted in
  • To meet our legal obligations

AI processing

Both parts of FreshVibe send your content to third-party AI providers to generate responses. This is central to how the product works, so please read this section.

When you shape ideas, what you type into the assistant, and the idea content it helps you draft, is routed through OpenRouter to a model on our curated list. That list currently contains Anthropic models only. We select models whose API terms do not permit prompts or responses to be retained for training. If your organisation connects its own OpenRouter account and chooses its own model, the terms of the provider it routes to apply instead, and we cannot guarantee the same position.

When you build, your instructions and the contents of the files the agent reads go to the provider of whichever coding agent you connect. You sign in to that agent under your own or your organisation's account, and that provider's terms and privacy policy govern what it does with the code and prompts it receives. Choose accordingly.

We record AI interactions, including prompts and responses, in our analytics so we can monitor quality, cost, and failures. This is part of the early-access capture described above.

Cloud workspaces

When you build, we provision a development workspace for you on a third-party sandbox provider. Your code, files, and terminal session live on that provider's infrastructure while the workspace exists, not on your own machine.

Starter projects are cloned into your workspace from public repositories we maintain on GitHub. That is a one-way copy into your workspace: GitHub does not receive or process your information as part of it. If you separately connect a coding agent or a repository that needs a GitHub account, you authorise that connection yourself and the access it receives is determined by what you approve at the time.

Preview links are public

When you preview what you have built, FreshVibe generates a web address that serves your running prototype. Anyone who has that address can open it. It is not protected by your sign-in. Treat a preview as published to the internet: do not put real customer data, credentials, or anything confidential behind one.

Who can see your information

FreshVibe is a shared workspace, so some of what you do is visible to other people:

  • Other participants in your workspace can see your name, your track, the briefs you publish, your comments, and the ideas you have backed or offered to join. Your team-mates can see the code in a workspace you share with them.
  • Administrators and hosts at your organisation can additionally see participant email addresses, the full activity log, and event-level statistics. This access is role-based and controlled by your organisation.
  • Freshwater Futures restricts access to production systems and customer data to a small number of named personnel, currently two, who use it only to run the event, provide support, or investigate a fault. There is no routine staff access beyond them.

Your private conversations with the assistant are not shown to other participants. They are stored on our systems, are accessible to those named personnel, and are processed by the AI providers described above.

Where your information is stored

FreshVibe is hosted on Railway, which runs on Amazon Web Services in the Asia Pacific (Singapore) region, with Cloudflare in front of it. Your account details, briefs, comments, and activity records are stored there. Where your organisation has chosen a private-cloud deployment, its data is stored in the environment set out in its agreement with us.

Service providers

We use the following providers to run FreshVibe. Each handles only what it needs to.

  • Railway, on Amazon Web Services, for application hosting and databases
  • Cloudflare for network delivery and protection
  • A third-party remote sandbox provider, currently Sprites, for the cloud development workspaces. If we change provider we will update this list and tell participants at any active event
  • OpenRouter and Anthropic for the AI assistant
  • The provider of whichever coding agent or subscription tool you connect, under your own account. It runs on our infrastructure, but what that provider does with the prompts and code it receives is governed by its own privacy terms, not by this policy
  • PostHog for product analytics and AI interaction monitoring
  • Postmark for the internal email notifications we send ourselves, such as a new workspace request

We do not sell your personal information, and we do not disclose it for advertising. Beyond the providers listed above, which process information on our behalf so the product can run, we do not share what you do in FreshVibe with anyone outside Freshwater Futures unless we have asked the organisation hosting your event and it has agreed, or the law requires it.

Overseas disclosure

Running FreshVibe involves disclosing your information to recipients outside Australia. Storing it in Singapore is itself such a disclosure: our hosting, databases, and cloud workspaces are in Singapore. Our AI, analytics, and email providers are based in, or process data in, the United States.

Before disclosing information overseas we take reasonable steps to ensure the recipient handles it in a way consistent with the Australian Privacy Principles, as APP 8 requires, and we remain accountable to you for their handling. We cannot control it to the same degree as our own. If you would rather your information were not disclosed overseas, FreshVibe is not able to operate on that basis, so tell us before you start and we will talk to your host about alternatives.

Cookies

FreshVibe uses two kinds of cookies:

  • Essential cookies keep you signed in across both parts of the platform. Without them it cannot work.
  • Analytics cookies let us count usage and understand how the product is used.

You can block or delete cookies in your browser settings, and most browsers let you refuse them selectively. Blocking essential cookies will sign you out and stop FreshVibe working. Analytics and session recording are part of the early-access capture described above rather than something you can switch off on its own, so if that concerns you, raise it with your host or with us before you start.

Data security

We implement appropriate technical and organisational measures to protect your personal information against unauthorised access, alteration, disclosure, or destruction. Privileged keys for deploying infrastructure and reaching production data are held by a small number of named personnel, currently two. Administrator access within a workspace is role-based. No system is perfectly secure, so we cannot guarantee absolute security.

If you find a security vulnerability in FreshVibe, please report it to legal@freshwaterfutures.com rather than testing it further. We will not pursue you over a good-faith report made that way.

If we become aware of a data breach that is likely to result in serious harm, we will assess it promptly and notify affected organisations and individuals, and the Office of the Australian Information Commissioner where required, as soon as practicable and in line with our obligations under the Notifiable Data Breaches scheme in the Privacy Act. We aim to complete that assessment and notify within 72 hours of becoming aware, and if a matter needs longer we will say so.

Backups

We take daily backups kept for six days, weekly backups kept for one month, and monthly backups kept for three months. Because of this, information you ask us to delete may persist in backups for up to three months after deletion from the live system, after which it is overwritten in the normal cycle.

How long we keep it

Cloud workspaces are temporary, but their contents are archived. The running workspace is shut down after your event. Its contents are automatically copied to our object storage first, and we keep that archive for as long as your organisation is engaged with us, so the work can be picked back up. We delete an archive on request, and we remove it along with the rest of the workspace when the engagement ends. Export or push anything you want to keep in your own hands regardless.

Session recordings are kept for 30 days and then deleted, whether or not the engagement is still running.

Everything else is held against the host organisation rather than against you. Ideas, briefs, comments, and activity records live in that organisation's workspace, so we keep them for as long as the organisation is a client of ours, and we delete them on request. This is worth understanding if you took part as an employee or an invited guest: what you contributed sits in the host's workspace and follows the host's retention, not a clock of your own.

You can still ask us to access, correct, or delete the personal information we hold about you, as set out under Your rights below. Where that information is bound up in a shared workspace, we will handle the request with the host organisation. We may keep aggregated, de-identified statistics indefinitely, and we do not attempt to re-identify anyone from them.

Your rights

You can ask us to access, correct, or delete the personal information we hold about you, or to export it. Email legal@freshwaterfutures.com. We will acknowledge your request promptly and respond within 30 days, as the Australian Privacy Principles require. If we refuse access or a correction, we will tell you why and how to complain.

Note that deleting your account does not automatically withdraw briefs you have already published into a shared workspace, or code you have contributed to a team project, because other participants may have built on them. Tell us if you want those removed as well and we will handle it with the host organisation.

Complaints

If you think we have mishandled your personal information, contact us at legal@freshwaterfutures.com and we will investigate. If you are not satisfied with our response, you can complain to the Office of the Australian Information Commissioner at oaic.gov.au.

Changes to this policy

We may update this policy from time to time, and we will change the “Last updated” date above when we do. Where a change materially affects how we handle your information, we will tell participants in the app before it takes effect, and we will do the same during an active event.

Contact us

Freshwater Futures Pty Ltd
ACN 674 518 784, ABN 75 674 518 784
legal@freshwaterfutures.com