🔒

Privacy Policy

Last updated: April 30 2025

Vibe Security ("Service", "Vibe Security", "we", "us" or "our") is a software-as-a-service platform available at vibesecurity.io, app.vibesecurity.io, and any related sub-domains operated by 6GL Software Inc., 1505 Laperriere Ave, Suite 509, Ottawa, ON K1Z 7T1, Canada.

Contact: [email protected]


1 Scope

This Policy applies to:

  • Visitors to vibesecurity.io and app.vibesecurity.io
  • Users who authenticate with GitHub to access the Service
  • Repositories and data to which the Vibe Security GitHub App is granted access
  • Any related communications (e.g., e-mail alerts, customer-support requests)

It does not apply to third-party services you use independently (e.g., GitHub).


2 Key Terms

TermMeaning
Personal Information (PI)Information that identifies or relates to an identifiable individual.
Controller6GL Software Inc. (for EU/UK users) determines the purposes and means of processing PI.
Processor / Sub-processorA party that processes PI on our behalf (e.g., hosting, analytics, payment, or e-mail vendors).
GitHub DataAny data—code, metadata, issues, pull requests, commit history—retrieved from GitHub via OAuth sign-in or the Vibe Security GitHub App.
Scan ResultsMachine-generated findings and metadata produced when we analyse GitHub Data (includes code snippets from the cloned repos).

3 Information We Collect

Category What Source Purpose / Legal Basis*
Account DataGitHub username, public profile info, primary e-mail, OAuth access tokenGitHub OAuthContract performance; legitimate interest in secure authentication
Repository SelectionsList of repos you authorise (read-only)You / GitHub App installContract performance
GitHub DataCode and files cloned from authorised reposGitHub APIContract performance; legitimate interest in providing security analysis
Scan ResultsVulnerability reports, metrics, AI prompts & model outputs (may include code snippets)Generated by ServiceSame as above
Payment DataCustomer name, e-mail, card last 4 digits, billing address, subscription statusStripeContract performance
CommunicationsSupport requests, feedback, e-mailsYouLegitimate interest in customer service
Usage DataRequest logs, error logs, aggregated analyticsServer logs; Umami (cookieless)Legitimate interest in improving Service
Cookies & SimilarEssential session cookie (_django_session_). We may introduce additional cookies or trackers in the future to enhance functionality or analytics.BrowserContract performance; legitimate interest in service optimisation

*Legal bases refer to Art. 6(1) GDPR where applicable. We obtain consent where required.


4 How We Use Information

  1. Provide the Service – authenticate users, clone repos, run scans, generate and display results.
  2. Process payments – manage subscriptions and invoicing through Stripe.
  3. Communicate – send transactional e-mails (scan completion, security alerts, billing notices). Marketing e-mail requires opt-in.
  4. Improve & troubleshoot – monitor performance, debug, enhance features, and refine detection logic using aggregated or de-identified data, including anonymized vulnerability descriptions derived from false positives.
  5. Comply – meet legal, regulatory, and contractual obligations; enforce our Terms of Service.

5 LLM Processing

We upload limited code context to a large-language-model (LLM) served via OpenRouter or an equivalent provider. The LLM may use prompts and responses for model training. We have no contractual data-protection guarantees from the provider. You remain responsible for excluding sensitive materials you do not wish to share.

Consent to manual review & improvement – By using the Service you agree that Vibe Security personnel, bound by confidentiality, may manually review vulnerability findings to verify accuracy and reduce false positives. We may store and use anonymized vulnerability descriptions (with all repository-specific identifiers removed) to train and improve our models and rule-sets. No identifiable Personal Information is included in this training data.


6 Data Retention

Data typeRetention policy
Access tokensUntil you revoke GitHub access or delete your account.
Cloned codeEphemeral – wiped within 24 h after each scan completes.
Scan ResultsRetained until you delete the project or close your account, or up to 24 months for aggregate research unless earlier deletion is requested.
Payment records7 years (tax / accounting).
Server logs30 days (raw) / 12 months (aggregated).
Support communications3 years unless legal requirements necessitate longer.

7 Sharing & International Transfers

We do not sell your PI. We share it only with:

Recipient Purpose Location Safeguards
Amazon Web Services (us-east-2)Hosting & data storageUSASCCs for EU/UK data
OpenRouterLLM inferenceUSA (sub-processors may vary)No contractual guarantees
StripePayment processingUSASCCs & PCI-DSS compliance
Transactional e-mail providerService e-mailsUSASCCs
Umami (self-hosted at umami.vibesecurity.io)Cookieless analyticsUSAData remains on our AWS servers
Professional advisorsLegal/accountingCanada/USAConfidentiality obligations
Government authoritiesOnly if required by lawVariesAs legally mandated

8 Your Rights

Depending on your location, you may have the right to access, correct, erase, port, or object to processing of your PI, or withdraw consent. Contact [email protected]; we respond within 30 days.


9 Cookies & Tracking Technologies

The Service currently sets a single essential session cookie (_django_session_) and relies on cookieless analytics served from umami.vibesecurity.io. We may introduce additional cookies or similar technologies (e.g., to remember preferences, perform A/B tests, or measure traffic with other analytics tools) in the future. If we do, this Policy and our cookie banner will be updated accordingly.

You may block cookies in your browser, but the Service may not function properly without essential cookies.


10 Children

The Service is not directed to children under 13 (or the minimum age in your jurisdiction). We do not knowingly collect their data. If you believe a child has provided PI, contact us for deletion.


11 Changes to This Policy

We may update this Policy from time to time. Material changes will be announced by e-mail or prominent notice at least 14 days before taking effect. Your continued use after the effective date constitutes acceptance.


12 Contact Us

6GL Software Inc. | 1505 Laperriere Ave, Suite 509 | Ottawa ON K1Z 7T1 | Canada
📧 [email protected]

By using Vibe Security you acknowledge that you have read and understood this Privacy Policy and agree to the collection and processing of your information as described above.