Legal

Privacy Policy

What personal data VibeLock collects, why, who it is shared with, and the rights you have over it.

Effective 17 August 2026Updated 17 August 2026

The short version: we collect what we need to run your account and your security program, we never store your API key values or your codebase, we do not sell or share your personal information, and we do not train models on your content.

1. Who we are

VibeLock LLC, a Delaware limited liability company is the controller of the personal data described in this policy. You can reach us at privacy@vibelock.ai.

Where we are required to appoint a representative in the European Union or the United Kingdom under Article 27 of the GDPR or UK GDPR, their details are published in this policy.

2. What we collect

Account data
Name, email address, hashed password or OAuth identifier, multi-factor settings, plan, and team membership.
Project data
Project name, technology stack, onboarding answers, and the data profile you select (for example whether you store health data).
Security program data
Checklist statuses and notes, vulnerability entries, threat model content, compliance control statuses and evidence links, incident records and postmortems, and generated policy documents.
API key metadata
Key names and service types only. We never store, receive or process actual key values.
Scan metadata
File paths, finding counts, severities and descriptions. We never store your codebase.
Usage and device data
Log data including IP address, browser and device type, pages viewed, timestamps, and actions taken, used for security, abuse prevention and product improvement.
Session and security data
Active sessions, login times, device and approximate location derived from IP, and failed login attempts, used to detect unauthorised access.
Billing data
Plan, subscription status and billing history. Card details are collected and processed directly by our payment processor. We never receive or store full card numbers.
Support and marketing data
Messages you send us, survey responses, feedback, and email preferences.

3. What we never collect or store

  • Actual API key, token or secret values.
  • Your codebase or repository contents.
  • Code you submit to an AI review feature. It is transmitted to our model provider for analysis and then discarded. It is not stored, logged or retained by us.
  • Full payment card numbers.
  • Protected health information, unless you choose to enter it into a free-text field, which you should not do.

4. Why we process it, and our lawful basis

Where we rely on legitimate interests, we carry out and document a balancing test weighing our interest against your rights and freedoms, and we do not rely on that basis where your interests override ours. You may request a summary of the relevant assessment at privacy@vibelock.ai, and you may object to processing on this basis at any time.

To provide the Service
Performance of a contract with you (GDPR Art. 6(1)(b)).
To secure the Service and prevent abuse
Our legitimate interests in protecting the platform and our users (Art. 6(1)(f)).
To bill you and keep financial records
Performance of a contract, and compliance with legal obligations (Art. 6(1)(b) and (c)).
To send service and security notifications
Performance of a contract, and legitimate interests (Art. 6(1)(b) and (f)).
To send marketing email
Your consent, or our legitimate interests where permitted for existing customers. You can withdraw or opt out at any time (Art. 6(1)(a) or (f)).
To improve the product using aggregated, anonymised data
Our legitimate interests (Art. 6(1)(f)).
To comply with law and respond to lawful requests
Compliance with a legal obligation (Art. 6(1)(c)).

5. AI processing

Some features send content to a third-party large language model provider to generate documents, explanations or analysis. This applies when you generate a policy or threat model, when you request prioritised recommendations, and when you use a paste-and-review feature.

Content sent this way is processed to return a result and is then discarded. We do not store it, and our provider does not use it to train models. Where a feature keeps content on your own machine, such as a local agent scan, that content is never transmitted to us at all and only finding metadata is returned.

Model output can be wrong. Do not rely on it without human review.

6. Who we share it with

We do not sell personal information, and we do not share it for cross-context behavioural advertising. We disclose personal data only to:

  • Subprocessors who provide hosting, database, email, payment and AI processing services under written contracts. The current list is published on our Subprocessors page.
  • Your own team members, according to the role you assign them.
  • Professional advisers, such as lawyers and accountants, under confidentiality.
  • Authorities, where required by law, and where permitted we will notify you first.
  • An acquirer, in connection with a merger, financing or sale of assets, subject to this policy continuing to apply.

7. International transfers

We are based in the United States and our subprocessors may process data in the United States and elsewhere. Where we transfer personal data out of the European Economic Area, the United Kingdom or Switzerland, we rely on one of the following, in this order:

  • An adequacy decision, where one covers the recipient. Transfers to recipients certified under the EU-US Data Privacy Framework, and its UK Extension and Swiss-US counterpart, are made in reliance on the relevant adequacy decision.
  • Where no adequacy decision applies, the European Commission Standard Contractual Clauses (Decision 2021/914), with the UK International Data Transfer Addendum for UK transfers and the Swiss amendments for Swiss transfers.
  • Supplementary technical and organisational measures, including encryption in transit and at rest, application-layer encryption of vulnerability data, and access controls.

We carry out a transfer impact assessment for each transfer corridor before relying on Standard Contractual Clauses, assessing the law and practice of the destination country and whether our safeguards remain effective, in line with the European Data Protection Board recommendations on supplementary measures. Assessments are reviewed when a subprocessor, corridor or applicable adequacy decision changes.

EU data residency is available on the Founder plan. Where selected, project data is stored in EU-based infrastructure. You may request a copy of the relevant transfer mechanism by emailing privacy@vibelock.ai.

8. Automated decision-making and profiling

The Service applies fixed, published rules to evidence it observes about your application: responses from your live URL, security signals from your repository host, evidence returned by your own coding tool, and comparisons between the documents you publish and what is verified. From that it reports which published requirements your application meets. It is automated processing, and we want to be precise about what that does and does not mean.

This processing does not produce a decision with legal or similarly significant effects concerning you within the meaning of Article 22 of the GDPR. It does not determine access to a service, credit, employment or any comparable outcome, and it reaches no conclusion about you at all. It is a record of what was verified about your application, shown to you, and published only if you choose to publish it.

No language model grades you, and nothing in the Service assigns you a score or a rating. Where we use a model, it reads code or text to produce evidence for a single control, or it explains findings and drafts documents; it never performs the counting. Every change to the record resolves to a named control and the check that moved it, so you can see what changed and why, and you can re-verify any control at any time.

9. Where we get data about you, if not from you

If you were invited to a project by someone else, we did not receive your personal data from you. We received your name, email address and assigned role from the account owner who invited you, so that we could create your access.

This section is your Article 14 notice. The purposes, lawful bases, recipients, retention periods and rights described elsewhere in this policy apply to that data in the same way. If you did not expect the invitation, contact privacy@vibelock.ai and we will remove you.

10. Whether you have to provide data

Providing your name and email address is a contractual requirement: without them we cannot create an account or provide the Service. Everything else, including the content you record in your security program, is optional and provided at your discretion, though the Service becomes less useful without it. There is no statutory obligation on you to provide any of it.

11. Data protection officer

We have not appointed a data protection officer. Our processing does not meet the criteria in Article 37(1) of the GDPR: our core activities do not consist of regular and systematic monitoring of data subjects on a large scale, nor of large-scale processing of special category data. We keep this under review, and privacy@vibelock.ai reaches the person responsible for privacy at VibeLock.

12. How long we keep it

Account and project data
For as long as your account is active.
After cancellation
Retained for 90 days so you can reactivate, then permanently deleted. Published trust pages go offline after 30 days.
After account deletion
Deleted within 30 days, except where we must retain records to comply with law, resolve disputes or enforce agreements.
Security log entries
Retained for audit purposes, then purged on a rolling basis.
Billing records
Retained as long as required by tax and accounting law.
Code submitted for AI review
Not retained. Discarded after analysis.

13. Your rights

Depending on where you live, you may have some or all of the following rights. We do not discriminate against you for exercising them.

  • Access: obtain a copy of the personal data we hold about you.
  • Rectification: correct inaccurate or incomplete data.
  • Erasure: ask us to delete your data, subject to legal retention requirements.
  • Restriction: ask us to limit processing in certain circumstances.
  • Portability: receive your data in a structured, machine-readable format. A full export is available in account settings.
  • Objection: object to processing based on legitimate interests, including profiling.
  • Withdraw consent: where processing is based on consent, withdraw it at any time without affecting prior processing.
  • Opt out of sale or sharing: we do not sell or share personal information, so there is nothing to opt out of, but you may still submit a request.
  • Limit use of sensitive personal information: we do not use sensitive personal information for purposes requiring this right.
  • Non-discrimination: we will not deny service, charge different prices, or provide a different quality of service because you exercised a right.
  • Complain: lodge a complaint with your supervisory authority. EU and UK users may complain to their national data protection authority.

14. How to exercise your rights

Use the export and delete controls in account settings, or email privacy@vibelock.ai. We will verify your identity before acting, usually by confirming control of the account email.

We respond within 30 days for GDPR and UK GDPR requests, and within 45 days for requests under California law, extendable where permitted. An authorised agent may submit a request on your behalf with proof of authorisation.

If you were invited to a project by a customer of ours, we act as a processor for that data and will route your request to them, telling you that we have done so.

If we refuse a request, we will tell you why. You may appeal that decision by replying to our response or emailing privacy@vibelock.ai with the word appeal in the subject line. A different person reviews the appeal where practicable, and we will respond within 45 days with our decision and the reasons for it. If we deny the appeal, we will tell you how to complain to your state attorney general or supervisory authority.

15. Additional disclosures for United States residents

This section supplements the rest of the policy for residents of California and other states with comprehensive privacy laws. Using the statutory categories:

In the preceding twelve months we disclosed the categories above to service providers for the business purposes described in this policy. We did not sell personal information, did not share it for cross-context behavioural advertising, and have no actual knowledge of selling or sharing the personal information of anyone under 16.

We use sensitive personal information only to perform the Service and to secure your account. We do not use or disclose it to infer characteristics, so the right to limit its use does not arise. You may still exercise every other right described above, and we will not discriminate against you for doing so.

Identifiers
Name, email address, account identifier, IP address. Collected from you, or from the account owner who invited you. Used to provide and secure the Service. Disclosed to hosting, database and email subprocessors.
Commercial information
Plan, subscription status and billing history. Collected from you and our payment processor. Used to bill you and keep records. Disclosed to the payment processor.
Internet or network activity
Log data, pages viewed, actions taken, device and browser type. Collected automatically. Used for security, abuse prevention and product improvement. Disclosed to hosting subprocessors.
Geolocation data
Approximate location derived from IP address only. Used to detect unauthorised access. Not precise geolocation.
Professional information
Your role in a project and the technology stack you tell us about. Collected from you. Used to tailor the checklist and frameworks shown.
Sensitive personal information
Account log-in credentials, being your email address in combination with a password. Collected from you. Used solely to authenticate you and secure your account.
Inferences
None. We do not build profiles or draw inferences about your characteristics, preferences or behaviour.

16. Cookies and tracking

We use strictly necessary cookies for authentication and security, and preference cookies to remember settings such as your theme. Where required, we ask for consent before setting any non-essential cookie. See the Cookie Policy for detail.

We honour Global Privacy Control signals where legally required.

17. Security

We encrypt data in transit using TLS and at rest using AES-256, apply row level security so one account cannot access another account data, encrypt vulnerability data at the application layer, enforce multi-factor authentication on administrative accounts, log sensitive actions, and review dependencies for known vulnerabilities.

No system is perfectly secure. If we become aware of a personal data breach affecting you, we will notify you and any competent supervisory authority as required by law, and within 72 hours where GDPR Article 33 applies.

18. Children

The Service is not directed to children. We do not knowingly collect personal data from anyone under 16, or under 13 in the United States. If you believe a child has provided us data, contact privacy@vibelock.ai and we will delete it.

19. Changes

We may update this policy. For material changes we will give notice by email or in-app before they take effect and update the date below. Continued use after that constitutes acceptance.

20. Contact

Privacy enquiries
privacy@vibelock.ai
Security reports
security@vibelock.ai
Data protection
privacy@vibelock.ai

Privacy Policy · Effective 17 August 2026 · All legal documents