Privacy Policy
Last updated: 2026-09-17
ApeXhit LLC ("ApeXhit", "we") built VibeDx to collect only what the product needs to work. This policy explains what we store, what we use for a single request and then discard, and what our hosting provider may log. VibeDx is multi-tenant.
Signed-in accounts
When you create a signed-in account we store your email, a password hash, and — after you enroll an authenticator — an encrypted TOTP secret we cannot recover as plaintext. One-time recovery codes are stored as one-way hashes. Self-serve sign-up records clickwrap (who agreed, when, and the Terms and Privacy URLs). Those sign-ups stay pending until the root owner approves them into a tenant; pending and denied accounts cannot use Scan, GoodVibes, or Admin and cannot see other teams' data. The root owner is apexhit00@gmail.com.
Signed-in scan history
When you run a scan while signed in, we save it so you and your team can review it later. For each saved scan we store the target URL, grade, score, findings (including a summary), who scanned (the signed-in account), an optional project label, and timestamps.
That team scan history is shared: an owner and the members they invited all see the same history, and scans any of them run are added to it. Different owners (and the members each owner invited) do not share history with each other. After approval, that sharing stays inside the assigned tenant.
GoodVibes drafts
When you generate a GoodVibes prompt while signed in, we save a draft so you and your team can copy it later. For each draft we store a form snapshot plus the generated prompt, who created it, timestamps, and an optional project label (the app name). The snapshot includes: app name, one-line pitch, app type, purpose, target user, top v1 actions, pages that must exist, what v1 will not include, canonical origin, stack, optional Vercel project URL (alias), brand colors, voice, language/locale, business name, contact email for the app's legal pages, where the business is based (state/country; a contact/jurisdiction starting point for the generated app's /terms and /privacy, not governing law and not a certification), user geography (US, EU-UK, other, or mixed; awareness only, stored on the form snapshot and shipGate, not a choice of law and not a GDPR/CCPA determination), accounts mode (and, when accounts are not "none": signup mode, roles, tenant), data-stored checkboxes, database choice, uploads choice, money mode (and processor when money is not "none"), outbound email choice, analytics choice, AI assist choice (none or grok-mcp enum only — never API keys, MCP tokens, or secret URLs), the safety-checklist snapshot, and brand-asset URLs (logo or favicon) after those files are stored in Blob. The generated prompt includes a prescribed data map, Keep it clean, Legal bar, ship-gate class (EARLY-SHIP, LAWYER-REQUIRED, or HOLD-REASK), and a locked LEGAL STACK block derived from those same choices (where rows, files, secrets, sessions, payments, analytics, and optional AI-assist processing live; a locked /terms and /privacy skeleton). We also store the ship-gate class, hard-stop ids, residual-risk note, user geography, whether soft-ship is allowed, and the legal-stack check label/source (preview vs live staged pages) on that snapshot. The Legal bar and legal-stack check are product controls / research notes, not attorney copy, and do not make the generated app lawful or compliant with all laws. No secret fields were added to the form.
GoodVibes has no secret fields. We do not store pasted cookies, API keys, MCP tokens, or other credentials from this flow. The AI assist snapshot is the enum only. Team visibility matches scan history: an owner and the members they invited share drafts; different owners' teams do not.
Request-only — not stored
These are used only to run that one scan request and are not saved to our database:
- Session cookies the Founder pastes to scan behind a login (Founder-only; not used on Active Scan POSTs)
- Pasted
package.jsoncontents - Pasted source code
- A Supabase anon (public) key, used for a single read-only Row Level Security probe. A service_role JWT is rejected.
CI API keys
Keys you mint for CI/CD are stored as a one-way hash. The plaintext key is shown once when you create it. We cannot show it again.
What is processed transiently
To run a scan, our serverless function makes outbound HTTP/TLS requests to the URL you provide and, if you supply a package.json, a batch lookup to the public OSV.dev vulnerability database (Google/OpenSSF). Package names and version ranges are sent to OSV.dev for that lookup only.
Hosting & infrastructure
VibeDx is hosted on Vercel. Standard platform-level access logs (IP address, request path, timing) may be retained by Vercel per its own privacy policy for operational and abuse-prevention purposes — we do not separately collect or analyze this data.
Cookies & tracking
VibeDx does not use analytics or advertising cookies. Your light/dark/system theme preference is stored locally in your browser only.
Contact
Privacy questions: apexhit01@gmail.com.
