LGPD

Privacy policy

This policy explains how VibeCheck handles personal data in the Service. Read it together with the Terms of use. Effective 13 August 2026.

1. Controller

The controller of personal data processed in the Service is the operator of the VibeCheck platform, reachable at vibecheck.dev. Data-subject requests, complaints, and authority contact: abuse@vibecheck.dev.

This policy applies to visitors, anonymous users, account holders, and anyone who opens a report through a shared link.

2. What data we process

We may process, depending on use:

  • account: email, password (stored in derived form by the authentication provider), account identifier, and plan;
  • scan: indicated URL and host, status, verdict, map nodes, findings (with secrets redacted), share token, date, and user-agent;
  • anti-abuse audit: hash of the IP address (not the IP in the clear), timestamps, and account–target relationship;
  • domain verification: host, method, proof token, and verification date;
  • payment, when applicable: transactional data from the intermediary (we do not store a full card number);
  • communications: messages you send to support or to the abuse channel.

We do not ask for a login on the target and we do not store the source code or the full body of responses from the scanned system. Finding evidence appears redacted. Third-party data may appear if the target itself exposes them publicly — in that case processing is residual and incidental to the check you requested.

3. Why we use data and legal bases

We process data to:

  • run the requested scan, show the map and the report (performance of a contract / pre-contractual steps, art. 7, V, LGPD);
  • create and authenticate an account, apply quotas and domain verification (contract);
  • prevent abuse, fraud, mass scanning, and use against third parties without authorization (legitimate interest and legal obligation, arts. 7, II and IX);
  • comply with an authority order, keep an audit trail, and exercise defense in proceedings (legal obligation and regular exercise of rights, arts. 7, II and VI);
  • improve checks and Service stability with aggregated or de-identified data (legitimate interest);
  • bill plans, when applicable (contract and legal obligation).

Submitting a target is your declaration of authorization. We do not use finding content to publish a ranking of vulnerable systems.

4. Sharing

We do not sell personal data. We may share with:

  • infrastructure providers (hosting, database, authentication, email, payment), as processors, to the extent necessary;
  • police, judicial, or administrative authorities, when there is a legal basis;
  • the target holder or providers, in an abuse report, to the minimum needed to identify the scan;
  • a successor in a corporate reorganization, if the operation continues under equivalent protection.

Whoever receives a report link with a token then sees the result at the corresponding layer. That is your act, not a public list of ours.

5. Retention

Without an account, the map disappears with the session. A scan of a domain you verified remains while the account exists, or until you request deletion. A scan of an unverified domain is deleted from the server after 1 hour. IP hashes and logs may be kept for the period needed for audit, defense of the Service, or a legal obligation. Backups are rotated. Anonymized data may remain.

6. Your rights

Under the LGPD, you may request confirmation of processing, access, correction, anonymization, portability, information about sharing, withdrawal of consent when that is the basis, and opposition to processing based on legitimate interest. You may also request deletion of the account and of results linked to it.

There are legal grounds to refuse or to retain (fraud, abuse, proceedings, legal obligation). Deleting the account does not automatically erase scans the law requires us to keep, nor copies that third parties opened via a link you shared.

Requests: abuse@vibecheck.dev, from the account email. You may complain to the Brazilian National Data Protection Authority (ANPD).

7. Security and transfer

We apply technical and organizational measures proportional to the risk (access control, RLS in the database, secret redaction, report tokens, IP hashing). No system is infallible. Providers may be in Brazil or abroad; in those cases we seek adequate safeguards under the LGPD.

8. Cookies and access logs

We use cookies and local storage strictly necessary for the session, authentication, and operation of the Service. Access logs (including technical identifiers) are processed for security, quotas, and compliance with the Marco Civil da Internet. We do not use a third-party ad network on this Service.

9. Minors and third-party data on the target

The Service is not intended for anyone under 18. If a target exposes third-party data (customers, end users), whoever pointed the scan is responsible for having a legal basis and authorization for that check. VibeCheck does not assume the role of processor or controller of those data subjects, except in the residual, automatic measure of the scan you triggered.

10. Changes

This policy may be updated on this page, with a new effective date. Continued use after publication constitutes notice. For a material change, we may notify the account email.

Data protection officer / data-subject channel: abuse@vibecheck.dev. Terms of use: Terms of use.

Privacy policy — VibeCheck