← Back to VibeZero

Privacy Policy

Effective July 20, 2026

This policy explains how VibeZero collects, uses, shares, and protects information when you use our website, application, security scanning, reports, and related services.

Information we collect

We collect account and authentication details, workspace and project information, GitHub App installation and repository metadata, deployed URLs you submit, and communications you send us.

When you request a scan, VibeZero temporarily accesses repository source code and processes runtime responses. We store scan status, normalized findings, evidence, fix tasks, release decisions, reports, and audit events. We do not retain a cloned repository after the scan unless you explicitly request a workflow that requires it.

Stripe processes payment details; VibeZero stores billing identifiers and subscription status rather than full card numbers. When analytics is configured, PostHog may receive device, browser, page, and product-usage events.

How we use information

We use information to provide and secure the service, authorize repository and project access, run requested scans, correlate evidence, generate remediation tasks and reports, verify fixes, administer subscriptions, support users, prevent abuse, and improve product reliability. Customer code is not used to train models.

Service providers

We use service providers for infrastructure, authentication and data storage, repository access, payments, AI-assisted analysis, email delivery, and optional analytics. These currently include Cloudflare, Supabase, GitHub, Stripe, OpenAI, and PostHog where configured. They process information under their own terms and our service arrangements.

Retention and deletion

Ephemeral repository clones are deleted after scanning. Product records such as findings, tasks, reports, billing history, and audit events are retained while needed to provide the service, meet legal or security obligations, and resolve disputes. You may request project or account deletion by contacting us; some records may be retained where required by law or legitimate security and accounting needs.

Security and international processing

We use access controls, tenant-scoped authorization, isolated scanning environments, secret masking, and provider-signature checks designed to protect information. No system is completely secure. Our providers may process information in countries other than your own, subject to applicable transfer safeguards.

Your choices and rights

Depending on where you live, you may have rights to access, correct, delete, restrict, or export personal information, or object to certain processing. You can also control browser storage and analytics using browser settings. Contact us to exercise applicable rights.

Children and changes

VibeZero is intended for business users and is not directed to children. We may update this policy as the service changes and will post the new effective date on this page.

Contact

Privacy questions and requests can be sent to sales@vibezero.io.