What we know about you, and why.
We ask for an email address, an app to check, and sometimes a test login. This page says what happens to each of them, who else sees them, and how long they last.
Last updated
1. Who is responsible for your data
The controller is Andrea Finotti, Corso Monte Cucco 121, 10141 Torino (Italy). For anything in this policy, including a request to see or delete your data, write to support@vibeguard.tech.
We are a small operation. There is no data protection officer, because the law does not require us to appoint one — the address above reaches the person who decides.
2. What we collect, and why
Your account. Email address and password (stored hashed, never in readable form). We need it to give you an account and to send you your reports. Legal basis: performing our contract with you.
Your applications. The address of each app you register, and anything you add to a check — focus areas, your notes, and optionally a test login. Legal basis: performing our contract.
What a check produces. Requests and responses the engine saw, screenshots, and the findings and report built from them. This is evidence about your application, and it can contain whatever your application returned during the check. Legal basis: performing our contract.
Payments. Stripe takes your card details directly; we never see them. We keep what we are required to keep for accounting: the amount, the date, the product and your receipt. Legal basis: a legal obligation.
Messages you send us. What you write through Contact us or an assessment request, and our reply. Legal basis: performing our contract, and our legitimate interest in answering you and keeping a record of it.
Security records. An audit log of significant actions, with a hashed IP address rather than the address itself. Legal basis: our legitimate interest in being able to investigate abuse of a service that runs security tools.
3. Your test login, specifically
If you give us credentials so a check can get past your login, they are encrypted before they are stored, are used only to run that check, and are deleted with it. They are never shown back to you, never written into a report, and never sent in an email.
We still tell you to create a throwaway account and revoke it afterwards, and we mean it. A credential you control is one we cannot leave behind, whatever our intentions.
4. What we never do
- We do not sell your data, and we do not share it for anyone else's advertising.
- We do not use your findings to market to you, and we do not disclose them to anyone.
- We do not use the contents of your application to train any model — ours or anyone else's. See clause 5 for how that is enforced rather than merely promised.
- We make no automated decisions with a legal effect on you, and we do not profile you.
5. Who else processes it
We use the providers below. Each acts on our instructions under a data processing agreement, and each sees only what its job requires.
| Provider | What it does | Where |
|---|---|---|
| Vercel | Website and application hosting | EU / United States |
| Supabase | Database, authentication and file storage | Ireland (eu-west-1) |
| Hetzner | The machines that run security checks | Germany |
| Stripe | Payment processing and receipts | EU / United States |
| Resend (Amazon SES) | Transactional email | EU / United States |
| ImprovMX | Forwarding email sent to our published addresses | EU / United States |
| OpenRouter | Routes each request to the model that drives the security engine | United States |
| The inference provider OpenRouter routes to | Runs the model itself, under a zero-retention policy | United States or elsewhere |
| Microsoft Clarity | Anonymous usage analytics on the public site | EU / United States |
Worth knowing about the model provider. The engine that carries out a check is driven by a large language model reached through OpenRouter, and what it sends includes what your application returned during the check. So this is the entry to read twice, and here is what we do about it.
We route only to zero-retention endpoints. Our account rejects any request that would require the provider to store it. In practice that means what your check sends is used to produce your answer and then gone: it is not kept, not logged for the provider's own purposes, and never used to train any model. Endpoints that train on request data are switched off for our account entirely, paid and free alike.
Inference runs outside the EEA, typically in the United States. Where a transfer leaves the EEA it relies on the European Commission's standard contractual clauses. If your organisation needs inference to stay inside the EU, ask before you buy — it is a thing we can arrange, not a thing we would rather you did not notice.
6. How long we keep it
Scan evidence and reports: 90 days after the check, so you can use the re-check and download what you need. Then deleted.
Test logins: deleted with the check they belong to.
Your account: until you close it.
Receipts and accounting records: ten years, because Italian tax law requires it. This is the one thing that survives a deletion request — the record keeps the amount and the date, and stops pointing at the app it was for.
Messages and audit records: up to twenty-four months.
You do not have to wait for any of this: from your dashboard you can delete an app, a single check or a report at any time, files included.
7. Cookies and analytics
The dashboard sets a session cookie so you stay signed in. It is strictly necessary — there is no signed-in product without it — so it needs no consent, and we set no advertising cookies at all.
On the public pages we use Microsoft Clarity to see which pages people read and where they get stuck. It is configured to mask text and input, so it records how the page was used and not what anyone typed. It does not run on the signed-in dashboard.
8. Your rights
You can ask us to show you the data we hold about you, correct it, delete it, restrict what we do with it, hand it over in a portable form, or object to processing we base on a legitimate interest. Where we rely on consent, you can withdraw it at any time.
Write to support@vibeguard.tech. We answer within thirty days, and there is no charge. We may ask you to confirm you are who you say you are — for an account holding security findings, that is protection, not obstruction.
If you think we have got it wrong you can complain to your national supervisory authority; in Italy that is the Garante per la protezione dei dati personali.
9. If something goes wrong
If a breach puts your data at risk we notify the supervisory authority within 72 hours where the law requires it, and we tell you directly when the risk to you is high. Found a security problem in VibeGuard itself? Write to security@vibeguard.tech — see the security page.
10. Changes to this policy
We date substantive changes at the top of this page. If a change materially affects what we do with data we already hold, we tell you by email rather than leaving you to notice.
See also the terms of service and the security page, which covers how we treat your application during a check.