Privacy Policy

Last updated: August 2026

Vital Few Software LLC ("Vital Few", "we", "us", "our") operates Vital Few Prep and vitalfewprep.com. This policy explains what information we collect, how we use it, and your rights.

Information we collect

The website service is a web-based study product delivered in the browser. The separate Vital Few app for iPhone and iPad stores study progress on the device and does not require a website account at launch.

How we use your information

Third-party services

Stripe for website purchases: checkout, payment processing, subscription management, refunds, and the billing portal are provided by Stripe. Stripe receives the information needed to process your website purchase and manage billing. Its handling of payment information is described in Stripe's privacy policy.

Apple for app purchases: Apple processes App Store purchases, manages those subscriptions, and decides refund requests. At launch, the Vital Few app and website are separate products; the app does not send its purchase record or study progress to the website.

Resend: production email is delivered through Resend's SMTP service. Resend receives recipient addresses and the contents of messages sent for account access, billing, support, affiliate, and newsletter delivery.

Hosting and backups: the Vital Few application, database, sessions, logs, and operational backups run on hosting infrastructure used by Vital Few. The host operator can access data needed to operate that infrastructure. Backup copies may remain until the approved backup rotation expires.

We do not use third-party analytics or advertising trackers in the checked-in site. Stripe-hosted pages may have their own cookies and notices when you leave the Vital Few site.

Data retention

There is no single automatic retention timer for all records. While an account exists, account and study records are retained so the service can preserve access and progress. Visit, security, support, affiliate, payment, provider, and backup records follow their operational, security, accounting, dispute, and provider needs. We will publish a more precise schedule only after it has been approved.

Orders, tax and accounting evidence, fraud and dispute evidence, and payment-provider records may need to remain after an account request. Newsletter suppression records may also need to remain so an address that opted out is not sent another broadcast. Copies in provider systems and backups may persist through their own deletion and rotation processes.

Deletion requests and the current workflow

There is no self-service account-delete control today. To request access, correction, deletion, or anonymization, contact us through our contact page. We will verify the request, review active billing and the records that must be retained, and then handle the request manually through the approved operator process.

  1. We verify the requester and identify the account and relevant email address.
  2. We review active subscriptions, refunds, disputes, orders, tax/accounting needs, fraud needs, payment-provider records, support matters, and newsletter suppression.
  3. We stop or resolve active access and billing through the appropriate product or payment-provider process; changing local records alone does not cancel Stripe billing.
  4. We remove or anonymize account, attribution, and study records that are approved for removal, while retaining the documented exceptions.
  5. We record what was handled, what was retained, and what remains in provider systems or backups, then verify the result.

The free diagnostic is separate from account deletion: its current browser-bound run can be erased with the visible “Delete my answers and start fresh” control. That control does not delete an account or retained payment/newsletter records.

Cookies and tracking

We use functional cookies: a session cookie for login and short-lived checkout, attribution, and diagnostic state; a CSRF cookie to protect forms; and, when needed, a short-lived message cookie for status messages. We do not use third-party advertising trackers, analytics cookies, tracking pixels, embedded fonts, or third-party scripts on the Vital Few site.

Your rights

You may request access to, correction of, deletion of, or anonymization of personal data by contacting us. Some records may be retained for the exceptions described above, and no request changes a payment-provider record automatically. The end of a paid access period does not automatically delete your account.

Security

We use HTTPS, hashed passwords, database-backed sessions, CSRF protection, and brute-force login protection. Payments are handled through Stripe. No raw card number or CVC is stored in the Vital Few application.

Contact

Questions about this policy or a data request? Use our contact form.