Privacy Policy
Last updated: September 30, 2026
This policy explains what data VibeShield ("VibeShield", "we", "us") collects through the hosted web app at usevibeshield.com, why, and the choices you have. VibeShield only ever scans the public URL of an app — we never ask for, or store, login credentials for the apps you scan. Our CLI and VS Code extension run entirely on your own machine and don't need an account.
1. Information we collect
- Free scans without an account — the URL you submit, the scan results, and your IP address (used only to rate-limit free scans). The results can only be opened in the browser that started the scan, using a random token stored in that browser. If you don't save the scan to an account, it's deleted automatically after 30 days.
- Account information — your name, email address and password. Passwords are hashed (bcrypt) before storage; we never store or can look up your password.
- Scan data — the target URLs you submit, findings and reports, attack-surface data, and a log of the requests a scan made. Secret values found in a scan (API keys, tokens) are redacted before they're stored — reports keep only a short prefix as evidence.
- Your app's Supabase project — when your app's public code contains a Supabase URL and public key, the scan asks your Supabase project which tables that key can read and how many rows each has. We request row counts only — never the rows themselves — and we don't store your key.
- Shared reports — if you create a public share link, anyone with that link can view that report (without the request log) until you turn sharing off.
- Paid-plan integrations — if you use them: your company name and logo URL for white-label reports (Pro and Business); and on Business, a GitHub token (encrypted at rest), a Slack or Discord webhook URL (encrypted at rest), deploy-hook secrets, and CI API keys (we store only a hash of each key).
- Billing data — Pro and Business are sold by Paddle, our merchant of record. We never receive your card number; we only receive your Paddle customer and subscription ids, the subscription status and its renewal or end date.
- Security & audit logs — sign-ins, scans and account changes, with a timestamp and IP address, to detect abuse and investigate incidents. These logs never contain passwords, tokens or secrets.
- Cookies & browser storage — one essential, HTTP-only session cookie keeps you signed in. Your browser's local storage holds a few preferences (sidebar layout, the AI tool you build with) and free-scan tokens. We don't use analytics or advertising cookies.
2. How we use this information
- Run the scans you ask for, and show you your scans, projects and reports;
- Run the monitoring you turn on — scheduled scans, deploy scans, and alerts about new serious issues;
- Maintain your account and enforce plan limits, such as the monthly scan quota and free-scan rate limit;
- Secure the service — rate limiting, abuse detection and incident investigation; and
- Answer AI-assistant questions, only when you ask one.
"Copy AI fix prompt" builds the prompt in your browser from your report. It isn't sent to us or to any AI provider — you choose where to paste it.
3. Who we share data with
We don't sell your data. We share it only with the providers needed to run VibeShield:
- Our database and hosting infrastructure, to store your account and scan data;
- Resend, to send alert emails — your email address and the alert's content;
- Slack or Discord, only if you connect a webhook — the alert message is posted to your channel;
- Anthropic and/or OpenRouter, only for a question you send the AI assistant;
- GitHub, only if you connect it, to run the scan or post the comment you request;
- Paddle, to sell Pro or Business, take payment, handle tax and manage your subscription; and
- Law enforcement or other parties, only where required by law or to protect our legal rights.
4. Data retention
Unsaved free scans are deleted after 30 days. Account and scan data is kept while your account is active so your history stays available. To delete your account and its data, email privacy@usevibeshield.com and we'll process it within a reasonable time.
5. Security
Passwords are hashed with bcrypt; GitHub tokens and alert webhooks are encrypted at rest; API keys are stored only as hashes; session cookies are HTTP-only; and secrets found during a scan are redacted before storage. No method of storage or transmission is 100% secure, but we build VibeShield the way we'd expect an app we scanned to be built.
6. Your rights and choices
You can update your profile, turn off sharing, disconnect integrations, revoke API keys, and export reports (PDF or JSON) at any time from Settings and your reports. For access, correction, deletion or portability requests beyond that, contact privacy@usevibeshield.com. Depending on where you live you may have further rights under laws like the GDPR or CCPA; we honor equivalent requests from everyone, regardless of location.
7. Children's privacy
VibeShield isn't directed at children, and we don't knowingly collect information from anyone under 16. If you believe a child has given us data, contact us and we'll remove it.
8. International users
Your data may be processed in a country other than the one you live in. For Pro and Business payments, Paddle handles the tax and payment-compliance obligations of international billing as our merchant of record.
9. Changes to this policy
We'll update the "Last updated" date above when this policy changes, and for material changes we'll make a reasonable effort to let you know.
10. Contact
Questions about this policy? Email privacy@usevibeshield.com.
This page is a plain-language template and isn't legal advice — if you operate VibeShield commercially, have it reviewed by counsel for your jurisdiction before relying on it.