Privacy Policy

Last updated: September 8, 2026

This Privacy Policy explains how VibeCoden't ("we", "us") collects, uses, and shares information when you use vibecodent.app and related services (the "Service").

Information we collect

  • Account data: email address and, when you use Google sign-in, your Google account identifier and profile email.
  • Scan data: URLs you submit for scanning, scan type (Lite, Standard, Deep), timestamps, and the resulting reports.
  • Uploaded code: if you use a code scan, the files you upload are analysed on our servers to produce your report. Findings store a hashed or shortened reference to the file and line rather than your full source code, and sensitive matches (such as keys) are redacted in the evidence we keep.
  • Repository scan data: if you connect the GitHub integration, we receive the repository name, pull request number, changed file paths and file contents you send us, plus any preview URL you provide, in order to produce the scan result and post it back to your pull request.
  • Ignored findings: when you dismiss a finding, we store which finding you dismissed for which URL, tied to your account, so it stays hidden in future scans.
  • Reviews: if you submit a review, we store your rating, review text and the account that submitted it. Approved reviews are shown publicly with the rating and text only.
  • Subscription and credit data: your plan (if any), plan status, remaining scan credits, daily Lite Scan usage and purchase records.
  • API keys: keys you create for the GitHub integration are stored in hashed form; the full key is shown to you only once at creation.
  • Preferences: your appearance (light / dark / auto) setting, stored in your browser when you are signed out and in your account when you are signed in.
  • Usage data: rate-limit counters, credit balance, and basic request metadata used to keep the Service reliable.
  • Agent (MCP) usage: if an AI agent connects to our agent integration on your behalf, we log the tool called, timestamps and the account it acted for.
  • Payment data: handled by Stripe, our payment processor; we do not store full card numbers.
  • Advertising and measurement: we use Google's advertising tag across the site to measure page views, sign-ups and completed purchases. See the Cookie Policy for details and how to opt out.
  • Anonymous Lite Scan analytics: when you run a free Lite Scan without signing in, we create a one-way hash of your IP address and browser user-agent, combined with a server-side secret. The raw IP address and user-agent are not stored. We also store the target domain you scanned, whether you are a repeat visitor, and a running count of Lite Scans from that hashed visitor identifier.

How we use information

  • Provide, operate, and improve the Service.
  • Authenticate you and secure your account.
  • Enforce rate limits and daily Lite Scan allowances, prevent abuse, and protect the Service and its users.
  • Process purchases of scan credits and manage monthly plans, including renewals and cancellations.
  • Run repository and pull request scans you request, and post results back to your pull request.
  • Publish reviews you choose to submit, after our review.
  • Measure advertising and conversion performance in aggregate.
  • Comply with legal obligations.

Anonymous Lite Scan analytics

Our free Lite Scan can be used without creating an account. To understand how this feature is used and to enforce our Lite Scan limits, we generate a pseudonymized identifier for each anonymous visitor. We do this by hashing your IP address and browser user-agent string with a secret salt that is stored only on our server. The raw IP address and user-agent are never kept; only the resulting hash is stored. Because this hash is one-way and salted, it cannot be reversed to recover your IP address or user-agent. This analytics table is only accessible internally and is not exposed to clients or third parties. Anonymous Lite Scan results are shown to you in your browser session and are not tied to any account.

Legal bases (EEA/UK)

We process personal data under the following bases: performance of a contract (providing the Service and your plan), legitimate interests (security, abuse prevention, product improvement), consent (where required, e.g. advertising and measurement tags and publishing your review), and legal obligations (e.g. tax and accounting records).

Sharing

We share data only with the providers needed to run the Service: hosting and application infrastructure, our managed database and authentication provider, Stripe for payments, Google for sign-in and for advertising measurement, and GitHub where you use the repository integration. We do not sell personal information.

Retention

Account, scan, subscription and purchase records are retained while your account is active. Uploaded code files are processed to produce a report and are not retained as source code afterwards. Anonymous Lite Scan analytics records are kept in pseudonymized form. You can request deletion at any time by contacting us. Some records may be retained where required by law or for legitimate business purposes (e.g. fraud prevention, accounting).

Your rights

Depending on where you live, you may have rights to access, correct, delete, or export your personal data, to withdraw consent, and to object to or restrict certain processing. You can delete a review you submitted or revoke an API key from your dashboard at any time. To exercise other rights, contact us at the address below.

Security

We use industry-standard safeguards including TLS in transit, encrypted storage, row-level security on user data, hashed API keys, and per-user rate limits. No system is perfectly secure; you use the Service at your own risk. See our Security page for more detail.

International transfers

Your information may be processed in countries other than your own, including the United States and the European Union, subject to appropriate safeguards.

Children

The Service is not directed to children under 16, and we do not knowingly collect their personal data.

Changes

We may update this Policy from time to time. Material changes will be posted on this page with a new "Last updated" date.

Contact

Questions or requests: contact.vibecodent@gmail.com.