Privacy Policy
What personal data VibeLock collects, why, who it is shared with, and the rights you have over it.
The short version: we collect what we need to run your account and your security program, we never store your API key values or your codebase, we do not sell or share your personal information, and we do not train models on your content.
1. Who we are
VibeLock LLC, a Delaware limited liability company is the controller of the personal data described in this policy. You can reach us at privacy@vibelock.ai.
Where we are required to appoint a representative in the European Union or the United Kingdom under Article 27 of the GDPR or UK GDPR, their details are published in this policy.
2. What we collect
- Account data
- Name, email address, hashed password or OAuth identifier, multi-factor settings, plan, and team membership.
- Project data
- Project name, technology stack, onboarding answers, and the data profile you select (for example whether you store health data).
- Security program data
- Checklist statuses and notes, vulnerability entries, threat model content, compliance control statuses and evidence links, incident records and postmortems, and generated policy documents.
- API key metadata
- Key names and service types only. We never store, receive or process actual key values.
- Scan metadata
- File paths, finding counts, severities and descriptions. We never store your codebase.
- Usage and device data
- Log data including IP address, browser and device type, pages viewed, timestamps, and actions taken, used for security, abuse prevention and product improvement.
- Session and security data
- Active sessions, login times, device and approximate location derived from IP, and failed login attempts, used to detect unauthorised access.
- Billing data
- Plan, subscription status and billing history. Card details are collected and processed directly by our payment processor. We never receive or store full card numbers.
- Support and marketing data
- Messages you send us, survey responses, feedback, and email preferences.
3. What we never collect or store
- Actual API key, token or secret values.
- Your codebase or repository contents.
- Code you submit to an AI review feature. It is transmitted to our model provider for analysis and then discarded. It is not stored, logged or retained by us.
- Full payment card numbers.
- Protected health information, unless you choose to enter it into a free-text field, which you should not do.
4. Why we process it, and our lawful basis
Where we rely on legitimate interests, we carry out and document a balancing test weighing our interest against your rights and freedoms, and we do not rely on that basis where your interests override ours. You may request a summary of the relevant assessment at privacy@vibelock.ai, and you may object to processing on this basis at any time.
- To provide the Service
- Performance of a contract with you (GDPR Art. 6(1)(b)).
- To secure the Service and prevent abuse
- Our legitimate interests in protecting the platform and our users (Art. 6(1)(f)).
- To bill you and keep financial records
- Performance of a contract, and compliance with legal obligations (Art. 6(1)(b) and (c)).
- To send service and security notifications
- Performance of a contract, and legitimate interests (Art. 6(1)(b) and (f)).
- To send marketing email
- Your consent, or our legitimate interests where permitted for existing customers. You can withdraw or opt out at any time (Art. 6(1)(a) or (f)).
- To improve the product using aggregated, anonymised data
- Our legitimate interests (Art. 6(1)(f)).
- To comply with law and respond to lawful requests
- Compliance with a legal obligation (Art. 6(1)(c)).
5. AI processing
Some features send content to a third-party large language model provider to generate documents, explanations or analysis. This applies when you generate a policy or threat model, when you request prioritised recommendations, and when you use a paste-and-review feature.
Content sent this way is processed to return a result and is then discarded. We do not store it, and our provider does not use it to train models. Where a feature keeps content on your own machine, such as a local agent scan, that content is never transmitted to us at all and only finding metadata is returned.
Model output can be wrong. Do not rely on it without human review.
6. Who we share it with
We do not sell personal information, and we do not share it for cross-context behavioural advertising. We disclose personal data only to:
- Subprocessors who provide hosting, database, email, payment and AI processing services under written contracts. The current list is published on our Subprocessors page.
- Your own team members, according to the role you assign them.
- Professional advisers, such as lawyers and accountants, under confidentiality.
- Authorities, where required by law, and where permitted we will notify you first.
- An acquirer, in connection with a merger, financing or sale of assets, subject to this policy continuing to apply.
7. International transfers
We are based in the United States and our subprocessors may process data in the United States and elsewhere. Where we transfer personal data out of the European Economic Area, the United Kingdom or Switzerland, we rely on one of the following, in this order:
- An adequacy decision, where one covers the recipient. Transfers to recipients certified under the EU-US Data Privacy Framework, and its UK Extension and Swiss-US counterpart, are made in reliance on the relevant adequacy decision.
- Where no adequacy decision applies, the European Commission Standard Contractual Clauses (Decision 2021/914), with the UK International Data Transfer Addendum for UK transfers and the Swiss amendments for Swiss transfers.
- Supplementary technical and organisational measures, including encryption in transit and at rest, application-layer encryption of vulnerability data, and access controls.
We carry out a transfer impact assessment for each transfer corridor before relying on Standard Contractual Clauses, assessing the law and practice of the destination country and whether our safeguards remain effective, in line with the European Data Protection Board recommendations on supplementary measures. Assessments are reviewed when a subprocessor, corridor or applicable adequacy decision changes.
EU data residency is available on the Founder plan. Where selected, project data is stored in EU-based infrastructure. You may request a copy of the relevant transfer mechanism by emailing privacy@vibelock.ai.
8. Automated decision-making and profiling
The Service applies fixed, published rules to evidence it observes about your application: responses from your live URL, security signals from your repository host, evidence returned by your own coding tool, and comparisons between the documents you publish and what is verified. From that it reports which published requirements your application meets. It is automated processing, and we want to be precise about what that does and does not mean.
This processing does not produce a decision with legal or similarly significant effects concerning you within the meaning of Article 22 of the GDPR. It does not determine access to a service, credit, employment or any comparable outcome, and it reaches no conclusion about you at all. It is a record of what was verified about your application, shown to you, and published only if you choose to publish it.
No language model grades you, and nothing in the Service assigns you a score or a rating. Where we use a model, it reads code or text to produce evidence for a single control, or it explains findings and drafts documents; it never performs the counting. Every change to the record resolves to a named control and the check that moved it, so you can see what changed and why, and you can re-verify any control at any time.
9. Where we get data about you, if not from you
If you were invited to a project by someone else, we did not receive your personal data from you. We received your name, email address and assigned role from the account owner who invited you, so that we could create your access.
This section is your Article 14 notice. The purposes, lawful bases, recipients, retention periods and rights described elsewhere in this policy apply to that data in the same way. If you did not expect the invitation, contact privacy@vibelock.ai and we will remove you.
10. Whether you have to provide data
Providing your name and email address is a contractual requirement: without them we cannot create an account or provide the Service. Everything else, including the content you record in your security program, is optional and provided at your discretion, though the Service becomes less useful without it. There is no statutory obligation on you to provide any of it.
11. Data protection officer
We have not appointed a data protection officer. Our processing does not meet the criteria in Article 37(1) of the GDPR: our core activities do not consist of regular and systematic monitoring of data subjects on a large scale, nor of large-scale processing of special category data. We keep this under review, and privacy@vibelock.ai reaches the person responsible for privacy at VibeLock.
12. How long we keep it
- Account and project data
- For as long as your account is active.
- After cancellation
- Retained for 90 days so you can reactivate, then permanently deleted. Published trust pages go offline after 30 days.
- After account deletion
- Deleted within 30 days, except where we must retain records to comply with law, resolve disputes or enforce agreements.
- Security log entries
- Retained for audit purposes, then purged on a rolling basis.
- Billing records
- Retained as long as required by tax and accounting law.
- Code submitted for AI review
- Not retained. Discarded after analysis.
13. Your rights
Depending on where you live, you may have some or all of the following rights. We do not discriminate against you for exercising them.
- Access: obtain a copy of the personal data we hold about you.
- Rectification: correct inaccurate or incomplete data.
- Erasure: ask us to delete your data, subject to legal retention requirements.
- Restriction: ask us to limit processing in certain circumstances.
- Portability: receive your data in a structured, machine-readable format. A full export is available in account settings.
- Objection: object to processing based on legitimate interests, including profiling.
- Withdraw consent: where processing is based on consent, withdraw it at any time without affecting prior processing.
- Opt out of sale or sharing: we do not sell or share personal information, so there is nothing to opt out of, but you may still submit a request.
- Limit use of sensitive personal information: we do not use sensitive personal information for purposes requiring this right.
- Non-discrimination: we will not deny service, charge different prices, or provide a different quality of service because you exercised a right.
- Complain: lodge a complaint with your supervisory authority. EU and UK users may complain to their national data protection authority.
14. How to exercise your rights
Use the export and delete controls in account settings, or email privacy@vibelock.ai. We will verify your identity before acting, usually by confirming control of the account email.
We respond within 30 days for GDPR and UK GDPR requests, and within 45 days for requests under California law, extendable where permitted. An authorised agent may submit a request on your behalf with proof of authorisation.
If you were invited to a project by a customer of ours, we act as a processor for that data and will route your request to them, telling you that we have done so.
If we refuse a request, we will tell you why. You may appeal that decision by replying to our response or emailing privacy@vibelock.ai with the word appeal in the subject line. A different person reviews the appeal where practicable, and we will respond within 45 days with our decision and the reasons for it. If we deny the appeal, we will tell you how to complain to your state attorney general or supervisory authority.
15. Additional disclosures for United States residents
This section supplements the rest of the policy for residents of California and other states with comprehensive privacy laws. Using the statutory categories:
In the preceding twelve months we disclosed the categories above to service providers for the business purposes described in this policy. We did not sell personal information, did not share it for cross-context behavioural advertising, and have no actual knowledge of selling or sharing the personal information of anyone under 16.
We use sensitive personal information only to perform the Service and to secure your account. We do not use or disclose it to infer characteristics, so the right to limit its use does not arise. You may still exercise every other right described above, and we will not discriminate against you for doing so.
- Identifiers
- Name, email address, account identifier, IP address. Collected from you, or from the account owner who invited you. Used to provide and secure the Service. Disclosed to hosting, database and email subprocessors.
- Commercial information
- Plan, subscription status and billing history. Collected from you and our payment processor. Used to bill you and keep records. Disclosed to the payment processor.
- Internet or network activity
- Log data, pages viewed, actions taken, device and browser type. Collected automatically. Used for security, abuse prevention and product improvement. Disclosed to hosting subprocessors.
- Geolocation data
- Approximate location derived from IP address only. Used to detect unauthorised access. Not precise geolocation.
- Professional information
- Your role in a project and the technology stack you tell us about. Collected from you. Used to tailor the checklist and frameworks shown.
- Sensitive personal information
- Account log-in credentials, being your email address in combination with a password. Collected from you. Used solely to authenticate you and secure your account.
- Inferences
- None. We do not build profiles or draw inferences about your characteristics, preferences or behaviour.
16. Cookies and tracking
We use strictly necessary cookies for authentication and security, and preference cookies to remember settings such as your theme. Where required, we ask for consent before setting any non-essential cookie. See the Cookie Policy for detail.
We honour Global Privacy Control signals where legally required.
17. Security
We encrypt data in transit using TLS and at rest using AES-256, apply row level security so one account cannot access another account data, encrypt vulnerability data at the application layer, enforce multi-factor authentication on administrative accounts, log sensitive actions, and review dependencies for known vulnerabilities.
No system is perfectly secure. If we become aware of a personal data breach affecting you, we will notify you and any competent supervisory authority as required by law, and within 72 hours where GDPR Article 33 applies.
18. Children
The Service is not directed to children. We do not knowingly collect personal data from anyone under 16, or under 13 in the United States. If you believe a child has provided us data, contact privacy@vibelock.ai and we will delete it.
19. Changes
We may update this policy. For material changes we will give notice by email or in-app before they take effect and update the date below. Continued use after that constitutes acceptance.
20. Contact
- Privacy enquiries
- privacy@vibelock.ai
- Security reports
- security@vibelock.ai
- Data protection
- privacy@vibelock.ai
Privacy Policy · Effective 17 August 2026 · All legal documents