Privacy Policy
Last updated: August 2026
Vital Few Software LLC ("Vital Few", "we", "us", "our") operates Vital Few Prep and vitalfewprep.com. This policy explains what information we collect, how we use it, and your rights.
Information we collect
- Account information: your username, email address, password hash, account status, and account timestamps. You may also provide a first or last name, although those fields are not required to sign up.
- Billing and access information: Stripe processes your card payment and required billing address. We store Stripe identifiers, your access status and dates, billing name and address, and limited payment-method details such as brand, last four digits, and a card fingerprint used for duplicate-purchase checks. We do not store raw card numbers, CVC codes, or bank-account details in the Vital Few application.
- Orders and payment events: we store order status, totals, discounts, coupon or referral codes, purchased-item snapshots, email-delivery status, and Stripe webhook evidence so we can provide access, handle refunds and disputes, and reconcile payments.
- Study records: we store answers, selected options, confidence choices, response timing, correctness, practice and mock-session state, spaced-review progress, served-question history, study-plan preferences, and any reminder timezone, quiet hours, and categories you choose so you can leave and return to your preparation.
- Free diagnostic data: the public 30-question diagnostic stores a browser-bound run, question and option identifiers, progress, server verdicts, and small first-party event measures. These diagnostic records do not store the authored question text, answer choices, answer key, IP address, or email address. If you log in, the run can be linked to your account.
- Visit and security data: our servers may store an IP address, request path, timestamp, external referring host, campaign tags, signup attribution, login results, and login-abuse/security records. These are first-party records used for security, abuse prevention, attribution, and service measurement.
- Communications: if you contact us, apply to the affiliate program, or otherwise send a form submission, we store the name, email address, subject, channel or audience information, and message content you provide.
- Newsletter: if you subscribe, we store your email address, subscription status, signup time, and unsubscribe time so we can send Vital Few broadcasts and honor unsubscribe requests. The unsubscribe record is a suppression record, not a promise that the address is immediately erased.
The website service is a web-based study product delivered in the browser. The separate Vital Few app for iPhone and iPad stores study progress on the device and does not require a website account at launch.
How we use your information
- To provide, maintain, secure, and improve the study service
- To apply reminder preferences you explicitly enable; reminder preferences are off by default
- To process payments, refunds, disputes, and access through Stripe
- To send account, access, billing, support, and other service emails
- To send the newsletter when you subscribe and to honor unsubscribe requests
- To respond to support and affiliate requests
- To prevent abuse, unauthorized access, fraud, and repeated payment misuse
- To understand first-party acquisition and which parts of the service are useful
Third-party services
Stripe for website purchases: checkout, payment processing, subscription management, refunds, and the billing portal are provided by Stripe. Stripe receives the information needed to process your website purchase and manage billing. Its handling of payment information is described in Stripe's privacy policy.
Apple for app purchases: Apple processes App Store purchases, manages those subscriptions, and decides refund requests. At launch, the Vital Few app and website are separate products; the app does not send its purchase record or study progress to the website.
Resend: production email is delivered through Resend's SMTP service. Resend receives recipient addresses and the contents of messages sent for account access, billing, support, affiliate, and newsletter delivery.
Hosting and backups: the Vital Few application, database, sessions, logs, and operational backups run on hosting infrastructure used by Vital Few. The host operator can access data needed to operate that infrastructure. Backup copies may remain until the approved backup rotation expires.
We do not use third-party analytics or advertising trackers in the checked-in site. Stripe-hosted pages may have their own cookies and notices when you leave the Vital Few site.
Data retention
There is no single automatic retention timer for all records. While an account exists, account and study records are retained so the service can preserve access and progress. Visit, security, support, affiliate, payment, provider, and backup records follow their operational, security, accounting, dispute, and provider needs. We will publish a more precise schedule only after it has been approved.
Orders, tax and accounting evidence, fraud and dispute evidence, and payment-provider records may need to remain after an account request. Newsletter suppression records may also need to remain so an address that opted out is not sent another broadcast. Copies in provider systems and backups may persist through their own deletion and rotation processes.
Deletion requests and the current workflow
There is no self-service account-delete control today. To request access, correction, deletion, or anonymization, contact us through our contact page. We will verify the request, review active billing and the records that must be retained, and then handle the request manually through the approved operator process.
- We verify the requester and identify the account and relevant email address.
- We review active subscriptions, refunds, disputes, orders, tax/accounting needs, fraud needs, payment-provider records, support matters, and newsletter suppression.
- We stop or resolve active access and billing through the appropriate product or payment-provider process; changing local records alone does not cancel Stripe billing.
- We remove or anonymize account, attribution, and study records that are approved for removal, while retaining the documented exceptions.
- We record what was handled, what was retained, and what remains in provider systems or backups, then verify the result.
The free diagnostic is separate from account deletion: its current browser-bound run can be erased with the visible “Delete my answers and start fresh” control. That control does not delete an account or retained payment/newsletter records.
Cookies and tracking
We use functional cookies: a session cookie for login and short-lived checkout, attribution, and diagnostic state; a CSRF cookie to protect forms; and, when needed, a short-lived message cookie for status messages. We do not use third-party advertising trackers, analytics cookies, tracking pixels, embedded fonts, or third-party scripts on the Vital Few site.
Your rights
You may request access to, correction of, deletion of, or anonymization of personal data by contacting us. Some records may be retained for the exceptions described above, and no request changes a payment-provider record automatically. The end of a paid access period does not automatically delete your account.
Security
We use HTTPS, hashed passwords, database-backed sessions, CSRF protection, and brute-force login protection. Payments are handled through Stripe. No raw card number or CVC is stored in the Vital Few application.
Contact
Questions about this policy or a data request? Use our contact form.