VibeCheck · legal
Privacy Policy
Last updated August 20, 2026
We collect as little as possible to run the scans you ask for, and we never store the raw secrets we find. This policy explains what we hold and why. The data controller is Nikola Djurovic, Belgrade, Serbia.
1. What we collect
- Account. Your email address and a hashed password (argon2id). We never store your password in plain text.
- Domains. The hostnames you add, their verification token and status, your monitoring preference, and any deep-scan configuration you provide.
- Scans and findings. Per-scan results and findings. The evidence attached to a finding is pre-masked — it proves an issue exists without storing the raw secret, key, or file contents.
- Anonymous free scans. Stored against a salted hash of the source IP address for abuse prevention — never the raw IP.
- Subscription. Your Paddle customer and subscription identifiers and your plan status. No card or payment details ever reach our systems — those are held by Paddle.com Market Ltd as merchant of record.
- Operational logs. Basic technical logs to run and secure the service, with secrets, cookies, authorization headers, and CSRF tokens redacted.
2. How we use it
- To run the scans you request and show you the results.
- To send the monitoring alerts you choose to enable.
- To prevent abuse of the free scanner and protect the service.
- To manage your subscription and provide support.
3. Legal bases
Where data-protection law applies, we rely on: performance of our contract with you (to provide the service), our legitimate interest in keeping the service secure and preventing abuse, your consent for optional alert channels you set up, and compliance with legal obligations.
4. Who we share it with
We do not sell your data. We share it only with the processors needed to run VibeCheck:
- Paddle — payments, tax, and subscription management, as merchant of record.
- Hosting — our infrastructure runs on servers in the European Union (Germany).
- Alert delivery — if you configure email, Slack, or Telegram alerts, we send the notifications you asked for to those destinations.
We will never publicly disclose an identifiable customer's vulnerabilities. Any awareness or marketing content uses aggregate, anonymized figures only.
5. How long we keep it
Anonymous free-scan artifacts are deleted on a rolling window (30 days by default) by an automated job. Scans on your own domains are kept for your account's history and are removed when you delete the domain. Deleting a domain cascades to its scans, findings, and alerts; deleting your account removes your domains, subscription record, and sessions.
6. Your rights
You can access, correct, export, or delete your data. The fastest route to erasure is to delete the relevant domain or your whole account from the dashboard. For any other request, email support@vibetocheck.com and we will respond within a reasonable time.
7. Cookies
We use only the cookies needed to sign you in and protect requests — a secure, HTTP-only session cookie and a CSRF-protection cookie. We do not use advertising or cross-site tracking cookies.
8. International transfers
Our servers are located in the European Union. Payment data is processed by Paddle under its own privacy terms.
9. Children
VibeCheck is not intended for anyone under 16, and we do not knowingly collect their data.
10. Changes and contact
We may update this policy; material changes update the date above. Privacy questions: support@vibetocheck.com.
Questions about this page? Email support@vibetocheck.com. See also our Terms, Privacy and Refund policies.