This Privacy Policy explains how VibeCoden't ("we", "us") collects, uses, and shares information when you use vibecodent.app and related services (the "Service").
Information we collect
- Account data: email address and, when you use Google sign-in, your Google account identifier and profile email.
- Scan data: URLs you submit for scanning, scan type, timestamps, and the resulting reports.
- Usage data: rate-limit counters, credit balance, and basic request metadata used to keep the Service reliable.
- Payment data: handled by Stripe, our payment processor; we do not store full card numbers.
- Anonymous Lite Scan analytics: When you run a free Lite Scan without signing in, we create a one-way hash of your IP address and browser user-agent, combined with a server-side secret. The raw IP address and user-agent are not stored. We also store the target domain you scanned, whether you are a repeat visitor, and a running count of Lite Scans from that hashed visitor identifier. This is used to understand anonymous usage and enforce the one Lite Scan per day limit.
How we use information
- Provide, operate, and improve the Service.
- Authenticate you and secure your account.
- Enforce rate limits, prevent abuse, and protect the Service and its users.
- Process purchases of scan credits.
- Measure anonymous Lite Scan usage (unique vs. repeat visitors) and detect abuse, without identifying individual users.
- Comply with legal obligations.
Anonymous Lite Scan analytics
Our free Lite Scan can be used without creating an account. To understand how this feature is used and to enforce the one-scan-per-day limit, we generate a pseudonymized identifier for each anonymous visitor. We do this by hashing your IP address and browser user-agent string with a secret salt that is stored only on our server. The raw IP address and user-agent are never kept; only the resulting hash is stored. Repeat visitors are identified when the same hashed identifier appears in our analytics records more than once. Because this hash is one-way and salted, we (and anyone with access to the database) cannot reverse it to recover your IP address or user-agent. This analytics table is only accessible internally and is not exposed to clients or third parties.
Legal bases (EEA/UK)
We process personal data under the following bases: performance of a contract (providing the Service), legitimate interests (security, abuse prevention, product improvement), consent (where required, e.g. non-essential cookies), and legal obligations.
Sharing
We share data only with subprocessors needed to run the Service (hosting, database/auth, payment processing, and the scanner backend). We do not sell personal information.
Retention
Account and scan records are retained while your account is active. You can request deletion at any time by contacting us. Some records may be retained where required by law or for legitimate business purposes (e.g. fraud prevention, accounting).
Your rights
Depending on where you live, you may have rights to access, correct, delete, or export your personal data, and to object to or restrict certain processing. To exercise these rights, contact us at the address below.
Security
We use industry-standard safeguards including TLS in transit, encrypted storage, row-level security on user data, and per-user rate limits. No system is perfectly secure; you use the Service at your own risk.
International transfers
Your information may be processed in countries other than your own, including the United States and the European Union, subject to appropriate safeguards.
Children
The Service is not directed to children under 16, and we do not knowingly collect their personal data.
Changes
We may update this Policy from time to time. Material changes will be posted on this page with a new "Last updated" date.
Contact
Questions or requests: contact.vibecodent@gmail.com.