Vistai

Security

Security & Privacy

How we protect your account, your goals, and your data.

All systems secure & operational

Authentication & access

Vistai uses Sign in with Google. We never ask for or store a separate Vistai password — your account is linked to your Google identity through secure, industry-standard authentication.

Every protected action in the app validates your session. Sign out from Settings at any time to end your session on the current device. If you lose access to your Google account, contact support@vistai.site so we can help you recover your Vistai profile.

Data storage & sync

Your Growthverse — planets, daily tasks, streaks, badges, and profile — syncs to encrypted cloud storage so you can continue on any device. We also cache data locally so the app feels fast and stays usable on slower connections.

  • Planets and task history are tied to your account, not a single browser.
  • Completed work syncs in the background when you are online.
  • We retain data only as long as your account is active or as required to operate the service.

AI & Orba privacy

Orba coaching and daily mission generation run through secure server-side processing. Requests are scoped to your goals and tasks — we do not use your chats to train public AI models.

Orba works best when you ask about your planets and missions. Avoid sharing passwords, financial details, or other highly sensitive personal information in chat. Orba is a coach, not a vault.

  • Ask Orba message limits depend on your plan tier.
  • Orba Companion follows the same privacy principles after you link your account.
  • AI output can be wrong — use your judgment on important decisions.

Connectors & Vistai MCP

Plus and Max accounts can link GitHub, Notion, Figma, WakaTime, LeetCode, Hashnode, Dev.to, Medium, Stack Overflow, Kaggle, Codeforces, and Google Scholar via Connectors — activity syncs in the cloud to your private Skill Graph. Vistai MCP exposes that graph (missions, streak, domains) to AI tools such as Cursor and Claude through our hosted endpoint at mcp.vistai.site.

  • OAuth tokens and API keys are encrypted at rest (AES-256-GCM) and never shown in the UI or sent to MCP clients.
  • Some connectors use a public username only (LeetCode, Medium, Stack Overflow).
  • Disconnect a Connector anytime to revoke access and stop future syncs.
  • MCP session tokens are per-user, encrypted, and rotatable from Settings.
  • Skill Graph and MCP data are private — not exposed on public profile URLs.

Setup guides: Connector documentation · MCP documentation

Data protection

We follow a minimal-data approach: collect what we need to run Vistai, protect it in transit and at rest, and give you control over what is public.

  • Transport encryption for data moving between your browser and our servers.
  • Access controls so only authorized systems and team members can reach production data.
  • Public profiles are opt-in — usernames, streaks, and badges display only when you choose.

Found a vulnerability or suspicious activity? Email support@vistai.site with details. For general questions, our Discord server is also monitored by the team.

Need help? Email support@vistai.site or join our Discord community for updates, feedback, and support from the team and other builders.