Contract
Terms of use
By accessing, creating an account, or pasting an address into VibeCheck, you agree to these Terms. If you do not agree, do not use the service. Effective 3 September 2026.
1. Who we are and what these Terms cover
These Terms of Use (“Terms”) govern access to and use of the VibeCheck platform, available at vibecheck.dev and related addresses (the “Service”, “we”). The Service offers a passive, automatic check of the public surface of web applications indicated by the user.
The contract is between you (“you”, “user”) — a natural or legal person who uses the Service — and the operator of the VibeCheck platform. Abuse reports and legal notices: abuse@vibecheck.dev.
2. Acceptance
Use of the Service, including anonymously, constitutes full acceptance of these Terms and of the Privacy policy. Creating an account, verifying a domain, starting a scan, or opening a report shares the same acceptance.
If you use the Service on behalf of a company, client, or third party, you represent that you have authority to bind them to these Terms. Responsibility for authorizing the target remains yours and that of the person or entity you represent.
3. Eligibility
The Service is intended for people 18 or older with legal capacity. Accounts of minors or of anyone who cannot contract are void and may be terminated without notice. Use must comply with Brazilian law, including the Marco Civil da Internet (Law 12.965/2014), the Carolina Dieckmann Law (Law 12.737/2012), the Criminal Code, and the LGPD (Law 13.709/2018).
4. What the Service is — and is not
VibeCheck performs a passive, automatic check: it reads what the target’s public surface already exposes to the browser (pages, scripts, headers, and responses obtained without authenticating to the target). It does not ask for a login on the audited system and does not store the target’s source code.
The Service is not, and must not be treated as:
- penetration testing (pentest), red team, bug bounty, or a formal audit;
- certification, attestation, expert report, or a security guarantee;
- legal advice, compliance (LGPD, PCI, SOC 2, ISO 27001 or equivalents), or a professional opinion;
- continuous monitoring, a WAF, antivirus, or active protection of the target;
- proof that the target is secure, compliant, or free of vulnerabilities.
Findings may be incomplete, outdated, false positives, or false negatives. The absence of findings does not mean the app is secure. Decisions to publish, hire, invest, attest compliance, or skip an independent audit are exclusively yours.
4A. Intrusive checks — opt-in, your domain only
On a domain you have verified, and only after you check an explicit box in the product, the Service may run a short set of intrusive probes. These are not the default scan. They send real requests that may create data in your app: a probe account you must delete, a SQL error in your logs, a burst of requests, a form post from a foreign Origin. We do not delete what they create — you do.
By checking that box you declare that:
- you own the verified domain, or you have current written authorization covering this kind of probe;
- you accept the side effects listed above, including leftover probe data;
- you are not asking us, or an automated agent acting for you, to run these probes on a third-party system;
- an agent (Claude Code, Codex, or similar) cannot accept this consent on your behalf — only you, in the product, can.
Without a current consent row for that host, the Service refuses the probes (HTTP 403). Revoking consent from the same screen stops future intrusive scans; it does not undo effects already produced. This section is the versioned record (`2026-intrusive-v1`) stored with your consent.
5. Target authorization — your declaration
You may only point VibeCheck at a target you own, or for which you have prior, express, written authorization from the owner or from whoever has authority to authorize the check. Scanning someone else’s system without permission may constitute a crime and a civil wrong.
By pasting or submitting an address, you declare, warrant, and assume that:
- you are the holder of the domain, application, or infrastructure, or you have current written authorization from the holder;
- the authorization covers the kind of check the Service performs;
- you are not using the Service to recon, pressure, extort, defame, or attack third parties;
- you alone bear criminal, civil, and administrative responsibility for pointing at the target.
Domain verification in the product (file, meta tag, or DNS) serves quota and result disclosure. It does not replace legal authorization, does not prove ownership to third parties, and does not transfer to us the duty to check whether you may actually scan that target. We are not required to validate the declaration before running the scan.
VibeCheck is a tool you trigger. The initiative, the choice of target, and the legal risk of pointing are yours. We keep an audit trail (including IP hash, time, user-agent, account, and host) to defend the Service and to respond to a competent authority.
6. Acceptable use
It is prohibited, among other conduct, to:
- use the Service to attack, enumerate, overload, defraud, or pressure third parties;
- exploit findings against systems you are not authorized to test or fix;
- bypass quota, automate mass scanning, create accounts in series, or evade domain verification, rate limits, or disclosure layers;
- point the scanner at internal networks, private IPs, localhost, cloud metadata, or targets the Service refuses, except an environment we expressly authorize;
- reverse-engineer, scrape, or copy checks, prompts, or the interface to compete with the Service;
- resell, sublicense, or present VibeCheck as a pentest, seal, or certification;
- publish, sell, or use third-party reports to harass, extort, or obtain an unlawful advantage;
- interfere with the operation, security, or integrity of the platform.
An attempt at abuse may terminate the account, refuse future scans, and be reported to authorities, providers, and the target’s holder, without prior notice and without refund.
7. Account, quotas, and domain verification
Without an account, the anonymous scan is limited (by IP and by host) and the map may disappear with the session. With an account, permanent history is that of the domains you verified; a scan of an unverified domain expires in 1 hour and is deleted from the server. On a third-party domain the quota is restricted on every plan: the limit protects the target — speed against someone else’s system is not for sale.
You are responsible for keeping credentials, for use of the account, and for maintaining a valid email. Notices sent to that email are deemed received. We may refuse, suspend, or delete accounts, scans, or verifications at our discretion, including for suspected abuse, legal risk, or an official order.
8. Plans, payment, and cooling-off
Plans, prices, intervals, and caps may change. Amounts paid do not guarantee a result, the absence of flaws in the target, or uninterrupted availability. Features marked “coming soon” are not a contractual obligation until they are actually made available.
When there is a charge, a distance contract with a natural-person consumer observes the cooling-off right of art. 49 of the Brazilian Consumer Defense Code, within the legal period, if the Service has not yet been substantially used. Business subscriptions follow the conditions of the contract. Taxes, improper chargebacks, and default costs may be charged. Closing the account does not generate a pro-rata refund, except where the law requires it.
9. Results, prompts, and sharing
Reports, maps, redacted evidence, and fix prompts are informational. You receive a limited, revocable, non-transferable license to use them to fix systems you are authorized to treat. You may not present them as our expert report, nor as a guarantee given by VibeCheck.
Links with a share token are a key. Whoever discloses the link is responsible for third-party access. Result pages are not a public index of targets: do not publish galleries, rankings, or lists of scanned systems.
Secrets that happen to be captured on the public surface appear redacted. That does not eliminate the risk that the target is already exposed, nor create a duty for us to notify the system owner or to keep the original proof.
10. Intellectual property
The Service, the VibeCheck mark, the check catalog, the interface, the graph, texts, prompts, and software are ours or our licensors’. You do not acquire rights in them beyond the personal or business license of use provided in these Terms. The target, the content, and the data you indicate remain with whoever already held them — the scan does not transfer ownership.
11. Data
We process personal data under the Privacy policy. In short: we keep the scan result (host, nodes, findings, audit metadata) on the domain you verified. A scan without verification vanishes in 1 hour. We do not store the target’s source code. Without an account, the map disappears with the session, but audit records may be retained for the period needed for security and legal obligations.
12. Availability and changes to the Service
The Service is provided “as is” and “as available”. We do not promise an SLA, complete coverage of vulnerabilities, scan time, or compatibility with every target. We may filter targets, change checks, quotas, disclosure layers, and discontinue features or the entire Service, with or without notice, to the extent permitted by law.
13. Disclaimer of warranties
To the maximum extent permitted by Brazilian law, the Service is offered without warranties of merchantability, fitness for a particular purpose, accuracy, non-infringement, or result. We do not warrant that the scan will be uninterrupted, error-free, or that the target will remain secure after the check.
Nothing in these Terms excludes rights the law treats as non-waivable, especially consumer rights in a consumer relationship, when applicable.
14. Limitation of liability
To the maximum extent permitted by law, VibeCheck, its operators, administrators, employees, and partners are not liable for:
- damages arising from a scan without authorization — the exclusive responsibility of whoever pointed at the target;
- failures, breaches, leaks, or unavailability of the target, before or after the scan;
- decisions made on the basis of findings, the absence of findings, or fix prompts;
- lost profits, loss of chance, reputational harm, data loss, or indirect damages;
- conduct of other users, of third-party providers, or of whoever received a report link;
- force majeure, internet failure, cloud failure, or third-party infrastructure failure.
Except for willful misconduct or gross negligence, and except for non-waivable consumer rights, our total liability for any claim related to the Service is limited to the amount you actually paid in the 12 months before the event — or to zero, if use was free.
15. Indemnity
You will indemnify and hold VibeCheck and its operators harmless from any claim, investigation, fine, damage, cost, and fees arising from: (a) a scan or use without authorization; (b) a breach of these Terms or of the law; (c) content, a target, or a report you indicate or share; (d) a dispute with the target’s owner, the target’s end users, or authorities. We may assume the defense with counsel of our choosing; you will cooperate.
16. Suspension, termination, and abuse reports
We may refuse, interrupt, or delete scans, accounts, and associated data, without notice, if there is a violation, legal risk, official order, default, or discontinuation of the Service. You may close the account by requesting deletion through the channels in the Privacy policy. Termination does not eliminate obligations already due, the duty to indemnify, or records that the law or the defense of the Service require us to keep.
A system holder who receives scanner traffic and wants to complain: abuse@vibecheck.dev, with evidence (time, IP, URL, X-Scanner headers). That does not authorize the complainant to use the Service against whoever pointed at the target; it is an operational channel.
17. Third parties
The Service depends on providers (hosting, database, authentication, payment, when applicable). Sites and APIs you point at are not ours. Links, prompts, and references to Lovable, Cursor, Supabase, Stripe, and similar products do not imply partnership, endorsement, or responsibility for the target or for those products.
18. Changes to these Terms
We may change these Terms at any time by publishing the new version on this page with an effective date. Continued use after publication constitutes acceptance. If the change is substantial and you have an account, we may notify the registered email. If you do not agree, stop using the Service and request account closure.
19. Governing law, venue, and consumers
These Terms are governed by the laws of the Federative Republic of Brazil. Except for a legally privileged consumer venue, the courts of the operator’s domicile are elected, with waiver of any other, however privileged.
If you are a consumer, the mandatory rules of the CDC prevail. Clauses that are ineffective in that case are interpreted so as to preserve the rest of the contract.
20. General
If any clause is invalid, the others remain. Forbearance is not a waiver. You may not assign the contract without our written consent; we may assign it to a successor of the operation. These Terms, the Privacy policy, and the current plan conditions constitute the entire agreement about the Service and supersede prior arrangements. Electronic communications satisfy written form when the law allows.
Questions about these Terms or reports of misuse: abuse@vibecheck.dev. Personal data processing: Privacy policy.