Skip to content
VibeProtect
What we check
Lovable Replit Bolt Cursor
Pricing MCP Sign in Scan free

legal

Privacy Policy

Last updated October 1, 2026

1. Who we are

VibeProtect is operated by Instant City Solutions LLC, a Florida limited liability company based in Miami, Florida. This policy explains what we collect when you use vibeprotect.dev, why, and what control you have over it. Instant City Solutions LLC is the controller of the personal data described here.

2. What we collect

Account information. Your email address and a password. Passwords are handled by Amazon Cognito and are never visible to us in plain text. If you invite teammates, we store their email address and role.

Apps and scan results. The addresses of the apps you add, the verification tokens issued for them, and the results of every scan: findings, grades, response headers, certificate details, the builder and framework we detected, and the differences between scans.

Secrets we find. When a scan finds a key or password, we store only a redacted form (for example sk-proj-Ab…9xQ) and where it was found. We never store the full value, never log it, and never use it.

Repository data. If you install our GitHub App, we store the installation, which repositories you linked, and their names and branches. During a repo scan we download the repository's files, analyze them, and discard them when the scan ends. We keep the findings (file path, line number, the redacted secret or the package and version), not your code.

Notification settings. The email addresses, Slack or Discord channels and webhook URLs you configure for alerts, and delivery outcomes for them.

Billing information. Payments are processed by Stripe. We receive and store a Stripe customer identifier, your plan, subscription status, and billing period. We never receive or store full card numbers.

API keys and connected agents. If you create API keys or connect an AI agent over MCP, we store a hash of each key or token, its name, and when it was last used.

Technical logs. Standard server and access logs (IP address, timestamp, user agent, and the request made), kept for a limited period for security, abuse prevention and debugging.

We do not use advertising trackers, and we do not sell personal data or scan results. The marketing pages of this site set no cookies. They load fonts from Google Fonts, which means your browser asks Google's servers for them.

3. How we use it

  • To run the service: sign you in, verify that you control your apps, run scans, write fix prompts, and show you results.
  • To send the notifications you ask for: alerts, digests, and account emails.
  • To enforce plan limits and process payments.
  • To detect, investigate and prevent abuse, including attempts to scan apps the account holder does not control.
  • To diagnose faults and improve the service.
  • To comply with legal obligations.

Where the GDPR applies, our legal bases are performance of our contract with you (running the service and billing), our legitimate interests (security, abuse prevention, service improvement), and compliance with legal obligations.

4. Who we share it with

We use a small number of processors, and only for the purposes above:

  • Amazon Web Services: hosting, storage, authentication and email delivery, in the US East (N. Virginia) region.
  • Stripe: subscription billing and payment processing.
  • GitHub: if you install our GitHub App, we call GitHub's API to read the repositories you chose.
  • OSV.dev, the open vulnerability database run by Google: during a repo scan we send it the names and versions of the packages your project uses, never your code.
  • Any Slack, Discord or webhook endpoint you configure yourself, which receives the alerts you asked us to send there.

We may also disclose information if required by law, to enforce our Terms of Service, or to protect the rights and safety of our users or the public. If the business is acquired or merged, account data may transfer as part of that transaction; we will give notice before your data becomes subject to a different policy.

5. Scanning

A live app scan only runs against an app whose owner has verified control of its exact address. It reads what any visitor's browser receives: pages, JavaScript, headers and the HTTPS certificate. It does not sign in, submit forms or write anything.

The scanner identifies itself with the User-Agent VibeProtect-Scanner/1.0 (+https://vibeprotect.dev/scanner) so anyone reviewing their own logs can tell what it is.

6. Cookies and local storage

The application at /app uses browser local storage to keep you signed in: session and refresh tokens issued by Amazon Cognito. These are strictly necessary for the service to work. We do not use analytics, advertising, or cross-site tracking cookies anywhere on this site.

7. How long we keep it

  • Account, team and app records: for as long as your account is open.
  • Scan results and findings: for as long as your account is open, so you can see how your app changes over time.
  • Repository files: only for the duration of a scan.
  • Billing records: as long as required for tax and accounting purposes.
  • Technical logs: 30 days.

When you close your account, we delete your account, apps, scan results and notification settings within 30 days, except where we must keep records to meet a legal obligation.

8. Your rights

Depending on where you live, you may have the right to access, correct, export, or delete your personal data, to object to or restrict certain processing, and to withdraw consent. California residents have the right to know what we collect, to request deletion, and not to be discriminated against for exercising those rights. We do not sell or share personal information for cross-context behavioral advertising.

Email support@vibeprotect.dev to make a request. We will respond within 30 days and may need to verify your identity first. If you are in the EEA or UK, you also have the right to complain to your local data protection authority.

9. International transfers

We operate in the United States and store data in the US East (N. Virginia) AWS region. If you use VibeProtect from outside the United States, your data will be transferred to and processed there, under appropriate safeguards where required.

10. Security

Data is encrypted in transit and at rest. Each customer's data is partitioned by account so it cannot be read across accounts. Access to production systems is limited to people who need it. No system is perfectly secure, but if a breach affects your personal data we will notify you and any relevant regulator as required by law.

11. Children

VibeProtect is not intended for anyone under 18, and we do not knowingly collect data from children. If you believe a child has given us personal data, contact us and we will delete it.

12. Changes to this policy

We may update this policy. If a change is material, we will notify the email on your account at least 14 days before it takes effect, and we will always update the date at the top of this page.

13. Contact

Instant City Solutions LLC
Miami, Florida, United States
support@vibeprotect.dev

VibeProtect

Security checks for apps you built by prompting. Made in Miami by Instant City Solutions LLC.

Product
What we check Pricing Verifying your app MCP server
Built with
Lovable Replit Bolt Cursor
Company
Support About our scanner Terms Privacy Report abuse
© 2026 Instant City Solutions LLC we only scan apps you prove you own