Privacy Policy
Last updated June 29, 2026
This Privacy Notice for the service (doing business as VibeShield) (“we,” “us,” or “our”), describes how and why we might access, collect, store, use, and/or share (“process”) your personal information when you use our Services, including when you:
- Visit our website at https://vibeshield.org, or any website of ours that links to this Privacy Notice
- Use the service — a security scanner for AI-built applications. Results include a 0-100 security score, detailed vulnerability findings, and fix prompts. Scan results are retained for 7 days (Free/BYOK) or 365 days (Pro). We do not sell user data or share scan results with third parties.
- Engage with us in other related ways
Questions or concerns? Reading this Privacy Notice will help you understand your privacy rights and choices. If you do not agree with our policies and practices, please do not use our Services. If you still have any questions or concerns, please contact us at privacy@vibeshield.org.
Summary of Key Points
What personal information do we process? When you visit, use, or navigate our Services, we may process personal information depending on how you interact with us and the Services, the choices you make, and the products and features you use.
Do we process any sensitive personal information? We do not process sensitive personal information.
Do we collect any information from third parties? We do not collect any information from third parties.
How do we process your information? We process your information to provide, improve, and administer our Services, communicate with you, for security and fraud prevention, and to comply with law. We process your information only when we have a valid legal reason to do so.
In what situations and with which parties do we share personal information? We may share information in specific situations and with specific third parties. See Section 4 for details.
How do we keep your information safe? We have organizational and technical processes and procedures in place to protect your personal information. However, no electronic transmission over the internet or information storage technology can be guaranteed to be 100% secure.
What are your rights? Depending on where you are located geographically, the applicable privacy law may mean you have certain rights regarding your personal information.
How do you exercise your rights? The easiest way to exercise your rights is by contacting us at privacy@vibeshield.org. We will consider and act upon any request in accordance with applicable data protection laws.
1. What Information Do We Collect?
Personal information you disclose to us
We collect personal information that you provide to us.
We collect personal information that you voluntarily provide to us when you register on the Services, express an interest in obtaining information about us or our products and Services, when you participate in activities on the Services, or otherwise when you contact us.
Personal Information Provided by You. The personal information we collect may include:
- Email addresses
- Passwords
- Contact or authentication data
Sensitive Information. We do not process sensitive information.
Payment Data. We may collect data necessary to process your payment if you choose to make purchases. All payment data is handled and stored by Stripe, Inc. You may find their privacy notice at https://stripe.com/privacy.
Social Media Login Data. We may provide you with the option to register using third-party authentication providers such as Google. If you choose to register this way, we will collect the email address associated with your account from that provider.
All personal information that you provide to us must be true, complete, and accurate, and you must notify us of any changes to such personal information.
2. How Do We Process Your Information?
We process your information to provide, improve, and administer our Services, communicate with you, for security and fraud prevention, and to comply with law.
We process your personal information for a variety of reasons, including:
- To facilitate account creation and authentication. We process your information so you can create and log in to your account.
- To deliver and facilitate delivery of services to the user. We process your information to provide you with the requested service — scanning URLs and code for security vulnerabilities and generating fix prompts.
- To respond to user inquiries / offer support to users. We process your information to respond to your inquiries and solve any potential issues.
- To send administrative information to you. We process your information to send you details about our products and services, changes to our terms and policies, and other similar information.
- To protect our Services. We process your information as part of our efforts to keep our Services safe and secure, including fraud monitoring and prevention.
- To analyze and improve our Services. We use cookieless product analytics (PostHog) to understand how users interact with the scanner, identify friction points, and improve the user experience. This analytics does not use cookies or persistent identifiers. See Section 16 for details.
- To enforce usage quotas and prevent abuse of the service. We process IP addresses (hashed) and anonymous session identifiers to enforce per-user rate limits and scan quotas. This is necessary to maintain fair access for all users.
- To save or protect an individuals vital interest. We may process your information when necessary to prevent harm.
3. What Legal Bases Do We Rely On To Process Your Information?
We only process your personal information when we believe it is necessary and we have a valid legal reason to do so under applicable law.
If you are located in the EU or UK, this section applies to you.
The General Data Protection Regulation (GDPR) and UK GDPR require us to explain the valid legal bases we rely on in order to process your personal information. We may rely on the following legal bases:
- Consent. We may process your information if you have given us permission to use your personal information for a specific purpose. You can withdraw your consent at any time.
- Performance of a Contract. We may process your personal information when we believe it is necessary to fulfill our contractual obligations to you, including providing our Services.
- Legitimate Interests. We may process your information when we believe it is reasonably necessary to achieve our legitimate business interests, such as diagnosing problems, preventing fraudulent activities, analyzing service usage to improve our product, and enforcing usage quotas to maintain fair access.
- Legal Obligations. We may process your information where we believe it is necessary for compliance with our legal obligations.
- Vital Interests. We may process your information where we believe it is necessary to protect your vital interests or the vital interests of a third party.
In legal terms, we are generally the “data controller” under European data protection laws of the personal information described in this Privacy Notice.
If you are located in Canada, this section applies to you.
We may process your information if you have given us specific permission (express consent) to use your personal information for a specific purpose, or in situations where your permission can be inferred (implied consent). You can withdraw your consent at any time.
4. When And With Whom Do We Share Your Personal Information?
We may share information in specific situations described in this section and/or with the following third parties.
Vendors, Consultants, and Other Third-Party Service Providers. We may share your data with third-party vendors, service providers, contractors, or agents who perform services for us or on our behalf and require access to such information to do that work. We have contracts in place with our third parties designed to help safeguard your personal information. The categories of third parties we may share personal information with are:
- Cloud Infrastructure: Database, authentication, and hosting providers
- Product Analytics: PostHog, Inc. (cookieless analytics — see Section 16)
- Error Monitoring: Sentry (Functional Software, Inc.) — crash and error reporting
- Payment Processing: Stripe, Inc. (when you make a purchase)
- AI Services: Anthropic, DeepSeek, OpenAI (when AI-powered fix prompts are generated)
5. Do We Offer Artificial Intelligence-Based Products?
We offer products, features, or tools powered by artificial intelligence.
As part of our Services, we offer AI-powered fix prompt generation. These tools enhance your experience by generating actionable security fix instructions based on scan findings.
Use of AI Technologies. We provide AI Products through third-party service providers including Anthropic, DeepSeek, and OpenAI. Your scan findings and fix prompt requests are shared with and processed by these providers to generate the fix prompts.
AI Functions: AI applications and text analysis — generating security remediation instructions from vulnerability findings.
Opt-out: Users who do not wish their scan data to be processed by AI can use the deterministic template mode, which generates fix prompts without sending data to any AI provider. This is the default behavior when no API key is configured.
6. How Do We Handle Bring Your Own Key (BYOK)?
Users may optionally provide their own API key (DeepSeek, OpenAI, or Anthropic) for AI-powered fix prompt generation. This key is stored exclusively in your browser's localStorage and is sent to our API only on a per-request basis when you generate a fix prompt. We never store, log, persist, or have access to your BYOK API key on our servers. You are responsible for all usage charges incurred through your key.
7. How Do We Handle Your Social Logins?
Our Services offer you the ability to register and log in using your Google account. Where you choose to do this, we will receive your email address from Google. We will use the information we receive only for the purposes described in this Privacy Notice.
7. How Long Do We Keep Your Information?
Account information (email, authentication data) is retained for as long as the user has an account with us. Scan results are retained for 7 days on Free and BYOK plans, and 365 days (1 year) on the Pro plan, after which they are automatically deleted. When we have no ongoing legitimate business need to process your personal information, we will either delete or anonymize it.
8. How Do We Keep Your Information Safe?
We have implemented appropriate and reasonable technical and organizational security measures designed to protect the security of any personal information we process, including: rate limiting, input validation, parameterized database queries, JWT-based authentication, security headers (CSP, HSTS, X-Frame-Options), encrypted storage of secrets, and automatic redaction of sensitive data from scan evidence. However, no electronic transmission over the Internet or information storage technology can be guaranteed to be 100% secure.
9. Do We Collect Information From Minors?
By using the Services, you represent that you are at least 14. If we learn that personal information from users less than 14 years of age has been collected, we will deactivate the account and take reasonable measures to promptly delete such data from our records. If you become aware of any data we may have collected from children under age 14, please contact us at privacy@vibeshield.org.
10. What Are Your Privacy Rights?
In some regions (like the EEA, UK, Switzerland, and Canada), you have certain rights under applicable data protection laws. These may include the right (i) to request access and obtain a copy of your personal information, (ii) to request rectification or erasure; (iii) to restrict the processing of your personal information; (iv) to data portability; and (v) not to be subject to automated decision-making. You can make such a request by contacting us using the details in Section 14.
If you are located in the EEA or UK and you believe we are unlawfully processing your personal information, you also have the right to complain to your Member State data protection authority or UK data protection authority.
Account Information. If you would at any time like to review or change the information in your account or terminate your account, you can log in to your account settings and update your user account, or contact us. Upon your request to terminate your account, we will deactivate or delete your account and information from our active databases.
11. Controls For Do-Not-Track Features
Most web browsers and some mobile operating systems include a Do-Not-Track (“DNT”) feature. At this stage, no uniform technology standard for recognizing and implementing DNT signals has been finalized. As such, we do not currently respond to DNT browser signals.
12. Do United States Residents Have Specific Privacy Rights?
If you are a resident of California, Colorado, Connecticut, Delaware, Florida, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Utah, or Virginia, you may have specific rights regarding your personal information.
Categories of Personal Information We Collect
| Category | Examples | Collected |
|---|---|---|
| A. Identifiers | Contact details, email address, account name | Yes |
| B. Personal information | Name, contact information | No |
| C. Protected characteristics | Gender, age, race, ethnicity | No |
| D. Commercial information | Transaction information, purchase history | Yes |
| E. Biometric information | Fingerprints, voiceprints | No |
| F. Internet activity | Page views, feature usage (cookieless, anonymous by default) | Yes* |
| G. Geolocation data | Device location | No |
| H. Sensory data | Images, audio/video recordings | No |
| I. Professional information | Job title, work history | No |
| J. Education information | Student records | No |
| K. Inferences | Profiles, preferences | No |
| L. Sensitive information | — | No |
* Category F: We collect page views and feature usage through cookieless analytics (PostHog). This data is anonymous by default, does not use cookies, and does not track you across websites. See Section 16.
We have not sold or shared any personal information to third parties for a business or commercial purpose in the preceding twelve (12) months.
Your Rights
You have rights under certain US state data protection laws, including the right to know, access, correct, delete, and obtain a copy of your data, as well as the right to non-discrimination for exercising your rights. To exercise these rights, contact us at privacy@vibeshield.org.
13. Do We Make Updates To This Notice?
We may update this Privacy Notice from time to time. The updated version will be indicated by an updated date at the top. We encourage you to review this Privacy Notice frequently.
14. How Can You Contact Us About This Notice?
If you have questions or comments about this notice, you may email us at privacy@vibeshield.org.
Lithuania
Data controller: Individuali veikla (individual activity), Republic of Lithuania. For GDPR purposes, the data controller is the natural person operating under individualios veiklos pažymėjimas (individual activity certificate) issued by the State Tax Inspectorate (VMI) of the Republic of Lithuania.
If you are a resident in the European Economic Area or Switzerland, we are the “data controller” of your personal information. You can contact us at privacy@vibeshield.org.
15. How Can You Review, Update, Or Delete The Data We Collect From You?
Based on the applicable laws of your country or state of residence in the US, you may have the right to request access to the personal information we collect from you, details about how we have processed it, correct inaccuracies, or delete your personal information. To request to review, update, or delete your personal information, please contact us at privacy@vibeshield.org.
16. Cookieless Analytics
We use product analytics without cookies or persistent identifiers.
We use PostHog, Inc. for product analytics to understand how users interact with the service and improve our service. PostHog is configured in a privacy-first mode:
- No cookies. Analytics data is stored in browser memory only and cleared when you close the browser.
- No cross-session tracking. We do not track you across visits or across websites.
- No session recording. Screen recordings of user activity are disabled.
- IP anonymization. Full IP addresses are not stored.
- No personal identifiers. Events are anonymous by default unless you log in.
This configuration qualifies under the GDPR legitimate interest legal basis for product analytics and does not require a cookie consent banner. PostHog EU data centers process all analytics data.
To opt out of analytics entirely, contact us at privacy@vibeshield.org and we will exclude your account from all analytics processing.
17. Cookies And Similar Technologies
We use strictly necessary cookies for authentication (Supabase Auth) and service operation (anonymous quota enforcement). No advertising, tracking, or profiling cookies are used. Stripe, Inc. sets functional cookies during the payment process for fraud prevention. For a complete list of cookies, their purposes, and durations, see our Cookie Policy.