1. Privacy, security and accessibility
  2. /Security

Security

Last updated: September 9, 2026

Vivipod is an asynchronous video discussion platform for education. Schools trust us with student recordings, comments and account details, and this page summarizes how we protect them. Institutions that need more detail can request our security documentation below.

Security documentation

DocumentAvailability
HECVAT 4.1.6 responseOn request for institutional reviews
Accessibility Conformance Report (ACR / VPATĀ®)Public
Data Privacy Agreement coveragePublic, with signed agreements on request
Privacy Policy and Terms of ServicePublic

To request our HECVAT (Higher Education Community Vendor Assessment Toolkit) response, email us from your institutional address with your institution name, role and the questionnaire version you need. We also complete institution-specific security questionnaires and can provide a named security contact for your review. The HECVAT is a self-assessment, not a certification.

Infrastructure security

  • Cloud hosting. Vivipod runs on Cloudflare's global platform. We operate no servers of our own, and Cloudflare manages the physical and network layers.
  • Encryption. Data is encrypted in transit with TLS and at rest in our databases and media storage, with keys managed by the platform.
  • Separated environments. Staging and production are separate deployments with separate data.
  • Secrets management. Credentials and signing keys are held in the platform's secret store, never in source code.
  • Media access. Recordings are served through signed access links rather than public storage URLs.

Product security

  • Sign-in. People sign in with a one-time code sent to their email address, or with Google. Vivipod does not store passwords. Sign-in is rate limited. Sessions expire after seven days without activity and thirty days after sign-in, are revoked server-side on log out, and anyone can end every session on their account from Settings.
  • Access control. Spaces have owners, administrators and members. Roles determine who can manage a Space, see private content and publish posts.
  • Sharing controls. Content is private to a Space by default. Public sharing is an explicit choice made by the Space's administrators.
  • Change management. Changes are reviewed and tested before release, and dependencies are kept current.
  • Vulnerability reporting. Email support@vivipod.com to report a suspected vulnerability. Describe the affected feature and how to reproduce it, without including student records or credentials.

Data and privacy

Data we collect

  • Account details: name, email address and username.
  • Content added through use of the product: recordings, comments, captions and transcripts.
  • Space and Topic membership and roles.
  • Billing references for paid plans. Payment details are entered on Stripe's hosted checkout and never reach Vivipod.

Data we do not collect

  • Card numbers or bank details.
  • Passwords.
  • Health information.

How we handle it

  • Student data is used only to provide the service. We do not sell personal information or use it for advertising.
  • Speech-to-text captions are off by default and turned on per Topic by a Space administrator. Vivipod does not train AI models on your content and operates no model-training pipeline; captions come from a pretrained speech-to-text model running in our own Cloudflare account.
  • Deleted recordings are hidden immediately and their files become eligible for permanent removal after a 30-day recovery window. Account and data deletion requests are honoured on request, and institutions can export their media where they are authorized to access it.
  • Our Privacy Policy describes data categories, retention and your rights in full.

Subprocessors

ProviderPurpose
CloudflareHosting, database and media storage, speech-to-text for captions, email routing
GoogleOptional Google sign-in
StripeSubscription checkout and billing
ResendTransactional email delivery, being consolidated into Cloudflare

The Privacy Policy carries the full provider list and what each one processes.

Accessibility

We aim to meet WCAG 2.2 Levels A and AA and publish our known gaps. Our accessibility statement and Accessibility Conformance Report describe what is supported, how we test, and known limitations.

Compliance and assurance

  • Data privacy agreements. We sign student data privacy agreements with schools and districts, including SDPC/NDPA-aligned agreements. See our DPA coverage map.
  • HECVAT. Our HECVAT 4.1.6 response is available to institutions on request and is refreshed as the product changes.
  • Certifications. Vivipod does not currently hold SOC 2 or ISO 27001 certification. Cloudflare's, Google's and Stripe's certifications cover their own services, not Vivipod.

Frequently asked questions

Where is our data stored? On Cloudflare's platform, with Vivipod operated from the United States. Talk to us if your institution has regional processing requirements.

Do you support single sign-on? Google sign-in is supported. Institution-managed SAML or directory provisioning is not currently offered.

Do you have a HECVAT? Yes. Request it above and we will send the current response.

Who do I contact? support@vivipod.com reaches the team that handles security and privacy questions.