VibeAudit

Privacy & security

What VibeAudit does with your code and data

Last updated 2026-09-03.

What we access

For public repositories we download a snapshot (tarball) of the repository you paste. For private repositories, you install the VibeAudit GitHub App on the repositories you choose; it requests read-only Contents and Metadata permissions and your account's email address. We never request write access.

What we store

  • The generated report (findings, score, summary) and the repository name, so the report link keeps working.
  • Account basics if you sign in: GitHub user id, login, name, avatar, email, and your credit balance.
  • Payment records from PayPal: order id, amount, payer email. We never see card numbers.
  • Basic visit attribution (which link a report visitor came from, a hashed IP, user agent) to measure our own outreach.

We do not store your source code. The snapshot lives in memory only for the duration of the analysis. Your GitHub token is kept in an encrypted cookie in your browser and is used once per audit to download the snapshot; it is never written to our database or logs.

Who else sees it

The source snapshot is sent to Anthropic's API (Claude) to produce the report, under Anthropic's commercial API terms: not used to train models, retained for up to 30 days for abuse monitoring. Our database is hosted on Supabase, the app on Vercel, payments by PayPal. No advertising or analytics trackers.

Private repositories

Reports for private repositories are visible only to the GitHub account that created them. They are excluded from public pages, badges and search engines. You can uninstall the GitHub App at any time from your GitHub settings, which revokes our access immediately.

Deletion

Email dlagywns9992@gmail.com with the report link and we will delete the report and any account data within 7 days. Reports for public repositories that we published on our public audits page will be removed on the maintainer's request.

Security

All traffic is HTTPS. Database access is server-side only with row-level security enabled. Secrets are stored as encrypted environment variables. If you find a vulnerability in VibeAudit itself, email dlagywns9992@gmail.com; we reply within 72 hours and will credit you if you want.

Limitations

Reports are generated by an AI model and can contain false positives or miss issues. They are informational and not a substitute for a professional security assessment. Refunds: if an audit fails to run you get a re-run or a refund.