Changelog
Every published change to the legal text, newest first. Each entry lists the documents it changes and says whether the change is material. A material change makes the products show the terms pop-up again, so users must re-accept.
Dates are the "Last updated" dates in the documents and in versions.json.
2026-09-26 — ReMail: unsubscribe, suppression, postal address, self-service deletion, clickwrap
- Documents: remail/terms, remail/privacy. The 25 September 2026 versions are archived.
- What changed:
- Terms §1: acceptance is now a tick box plus click, and it is recorded.
- Terms §9.3: rewritten. ReMail adds a per-recipient unsubscribe link with three choices, plus one-click unsubscribe headers. It keeps a suppression list, and live sends require a postal address in the footer. Customers must not remove the link or the address, and they remain responsible for other opt-outs, copied recipients, consent records and address accuracy.
- Terms §12.1: says our servers enforce the Airtable limits.
- Terms §13.2: templates no longer contain placeholder unsubscribe links.
- Privacy §1 and §9: Recipients can unsubscribe using the link.
- Privacy §2.1: now lists the sender postal address and terms acceptance records.
- Privacy §2.2: the suppression list, stored as a keyed hash only.
- Privacy §2.4: the application's own fonts are self-hosted; the customer's brand fonts are disclosed.
- Privacy §3: now says we honour unsubscribes.
- Privacy §4: an opt-out at sign-up and a My account switch.
- Privacy §7: the suppression list is stored in coded form only.
- Privacy §8: suppression list and terms acceptance retention; self-service deletion of keys, logos, brands, projects and the account.
- Obligations: makes R-01, R-02, R-03, R-04, R-08, R-10, R-11 and R-12 published promises. Adds R-23. R-07, R-09 and R-17 are met by the same release.
- Material: yes. The ReMail pop-up (R-10) must ask everyone to accept version
remail:2026-09-26.
2026-09-26 — Privacy: what Google sign-in shares, and admin sign-in link expiry
- Documents: vibekit/privacy, remail/privacy. The 25 September 2026 versions are archived.
- What changed: corrections, so the policies describe what the products actually do (obligations V-03 and V-06).
- Privacy §2.1 (both): if you sign in with Google, we also have your name and the address of your Google profile picture.
- Privacy §2.3 (both): customers' admin Google sign-in goes through Supabase, which requests the
emailandprofilescopes, so Google shares the email address, whether it is verified, the name and the profile-picture address. Supabase stores them; we use the name only in product-update and onboarding emails and don't use the picture. End users' sign-in to a Customer Application still requests onlyopenidandemail(VibeKit). - Privacy §4 (both): the product-update list gets your name too, when we have it.
- VibeKit privacy §10: end users' sign-in links and codes last 15 minutes; customers' admin sign-in links and codes last 1 hour.
- Material: yes. It changes what data we say we collect, who we share it with (the name, with Resend) and how long sign-in links last.
acceptance.vibekitandacceptance.remailare now 2026-09-26, so both products must bump their terms versions.
2026-09-25 — Moved into aextra-legal
- Documents: vibekit/terms, vibekit/privacy, remail/terms, remail/privacy (dated 25 September 2026). New pages: subprocessors, data-processing.
- What changed: nothing in the wording. The four documents were moved here byte for byte from the product repos: VibeKit from
Airconnex/aextra-vibekitapps/admin/src/content/at8f8914f, and ReMail fromAirconnex/aextra-remailapps/admin/src/content/atb264ac9. Before the move, each file was checked to be identical to the text served at vibekit.aextra.ai and remail.aextra.ai. The only edits are internal links, rewritten for the new paths (/terms→/vibekit/termsor/remail/terms, and the same for/privacy); that is three links per product.subprocessorsanddata-processingquote the provider tables and processor terms from those documents word for word, with a sentence of introduction. - Material: no. Versions stay at 2026-09-25, so no one is asked to re-accept.
2026-09-25 — VibeKit and ReMail rewrite (before this repo existed)
- Documents: vibekit/terms, vibekit/privacy (rewritten for VibeKit; published at vibekit.aextra.ai), remail/terms, remail/privacy (ReMail's own documents; published at remail.aextra.ai).
- Material: yes. VibeKit introduced its terms pop-up at
TERMS_VERSION = '2026-09-25'. ReMail has no pop-up yet (obligation R-10). - Superseded: the Aeropage-branded Terms of 12 June 2026 and Privacy Policy of 29 July 2026, which both products served until then (ReMail from 20 September 2026). They are archived under each product.
2026-07-29 — Aeropage Privacy Policy (before this repo existed)
- Documents: vibekit/privacy (archived as
archive/vibekit/privacy/2026-07-29.md; ReMail also served it from 20 September 2026:archive/remail/privacy/2026-07-29.md). - Material: not recorded. There was no terms pop-up at the time.
2026-06-12 — Aeropage Terms of Service (before this repo existed)
- Documents: vibekit/terms (archived as
archive/vibekit/terms/2026-06-12.md; ReMail also served it from 20 September 2026:archive/remail/terms/2026-06-12.md). - Material: not recorded. There was no terms pop-up at the time.