Privacy Policy

Last updated: July 13, 2026 (v3.1)

Summary at a glance.

We collect the minimum data we need to run CheckVibe, secure your account, deliver scan results you request, and meet our legal duties. We do not sell or rent personal data, we do not share data for cross-context behavioral advertising, we do not run advertising cookies, and we do not use your Customer Content to train third-party AI models. You can delete your account and associated personal data at any time from your account deletion page. The full policy below explains the legal details.

1. Introduction & Scope

CheckVibe ("we," "us," or "our"), based in Switzerland, operates the checkvibe.dev website and the related security-scanning platform (the "Service"). This Privacy Policy explains what information we collect, why we collect it, how we use, share, retain, and protect it, and the rights you have under applicable data-protection laws.

This Policy applies to all visitors of our website, customers of our Service, individual users acting on behalf of an organization, and individuals whose information is processed through the Service (including, in limited circumstances, end-visitors of websites operated by our customers). It does not apply to third-party websites, products, or services we link to or that you connect to the Service.

This Policy should be read together with our Terms of Service, Cookie Policy, Data Processing Addendum, and Subprocessor List.

2. Data Controller & Contact

For purposes of the EU and UK General Data Protection Regulations (GDPR/UK GDPR), the Swiss Federal Act on Data Protection (revFADP/nFADP), and analogous laws, the data controller in respect of personal data we collect about our website visitors and account holders is:

Controller: CheckVibe, Switzerland

Email: support@checkvibe.dev

Privacy & data-subject requests: support@checkvibe.dev

CheckVibe is not currently required under Art. 37 GDPR to appoint a formal Data Protection Officer (DPO), but you can address all privacy enquiries to the contact above and we will respond promptly. For data we process on behalf of our business customers (for example, scan-related data collected through their account), we act as a processor and the customer is the controller. See our Data Processing Addendum.

EU/UK representatives. As a Switzerland-based processor not established in the EU/UK, CheckVibe's processing of EU/UK personal data is limited and does not currently meet the thresholds requiring the appointment of an Art. 27 GDPR or UK GDPR Article 27 representative. We will appoint a representative if and when our activities meet that threshold. EU and UK data subjects may continue to send all requests and complaints to support@checkvibe.dev.

3. Information We Collect

We collect the following categories of information:

3.1 Account Information

Email address, password hash (we never store passwords in plain text), display name (if provided), authentication-provider identifier (if you sign in via a third-party provider), account-creation and last-sign-in timestamps, and the version, time, and signup method by which you accepted our Terms and Privacy Policy.

3.2 Service & Scan Data

Scan history; URLs, domains, repositories, and projects you submit; scan results, severity ratings, and remediation suggestions; project configuration; saved settings; threshold alerts; and feature-usage patterns. Scan results may incorporate publicly available data about your scanned property (HTTP headers, TLS configuration, DNS records, public source code, certificate-transparency log entries, public CVE records, public WHOIS data).

3.3 Payment & Billing Information

When you subscribe to a paid plan, billing details are processed by Stripe, Inc. We receive a Stripe customer ID, plan/subscription status, transaction history, billing email, country, postal code, and tax identifier (where applicable). We do not store your full credit-card number, CVC/CVV, or full bank-account number on our servers. See Stripe's Privacy Policy.

3.4 Technical & Log Data

IP address, user-agent string, device identifiers, browser type and version, operating system, language preferences, referring URL, pages requested, response codes, request timestamps, session identifiers, and similar diagnostic telemetry generated automatically by your interactions with the Service. This data is used for security, fraud prevention, service operation, abuse mitigation, debugging, and performance monitoring.

3.5 User-Provided Credentials & Integration Tokens

When you connect an integration (such as GitHub or Supabase), you may provide repository URLs, project URLs, OAuth tokens, personal access tokens, or other credentials. We store these credentials encrypted at rest and use them only to perform the scans you initiate. We never transmit them outside the subprocessors strictly required to execute the requested scan. You can revoke and delete these credentials at any time by removing the associated project or disconnecting the integration.

3.6 Threat-Detection Visitor Data (Optional Customer Feature)

Our optional real-time threat-detection feature, which you (the customer) may deploy on your own scanned site by adding a JavaScript snippet, collects limited end-visitor telemetry on that site: IP address, user-agent, page URL, referrer, timestamps, request fingerprints, and behavioral signals (such as automated-client heuristics). This data is processed solely to detect malicious activity, bots, attempted abuse, and security threats for the benefit of the deploying customer. It is not used for advertising, retargeting, sale, profiling for cross-context behavioral advertising, or profile-building of identified individuals.

Customer responsibility. If you (the customer) deploy the threat-detection script on your site, you are the controller of the resulting visitor data and you are responsible for providing the appropriate notice to, and (where required) collecting consent from, your visitors under the ePrivacy Directive, GDPR, the FADP, the CCPA/CPRA, and any other applicable law. CheckVibe acts as a processor of that data on your behalf in accordance with our Data Processing Addendum.

3.7 Support & Communications Data

When you contact us (via email, in-product chat, or otherwise), we collect your email address, message content, attachments, and metadata necessary to respond. Support correspondence is retained for the duration of your account plus thirty (30) days after account closure, and then deleted, unless retention is required by law, dispute, or ongoing security investigation.

3.8 Marketing & Outreach (Limited)

If you (or your organization) is publicly identified as the operator of a website with demonstrable security issues we discovered during a publicly observable scan, we may, on a limited, individualized basis and in our legitimate interest, send a one-off notification email to a public contact address. You can opt out of any further outreach by replying to the message or contacting support@checkvibe.dev.

3.9 Categories of Sensitive Personal Information

CheckVibe does not knowingly request or process "sensitive personal information" (as defined under CPRA, GDPR Art. 9, or similar laws) for inferring characteristics about you. We do not collect genetic, biometric, health, racial, ethnic, religious, philosophical, union-membership, sex-life, sexual-orientation, or precise-geolocation data, nor government identifiers, financial account login credentials, mail/email contents, or messages. If such data inadvertently appears in scanned content or support correspondence, we will treat it with the elevated standards required by applicable law and you may request deletion.

4. Legal Bases for Processing (GDPR / UK GDPR / FADP)

Under the EU GDPR, UK GDPR, and the Swiss revFADP, we rely on the following legal bases:

Performance of a contract (Art. 6(1)(b)): Processing account, scan, integration, and payment data to create your account, deliver the Service, run scans you initiate, take pre-contractual steps at your request, and fulfil our other obligations under the Terms of Service.

Legitimate interests (Art. 6(1)(f)): Operating, securing, and improving the Service; fraud and abuse prevention; protecting the rights, property, and safety of CheckVibe, our users, and third parties; investigating security incidents; aggregated analytics; and limited outreach about security issues we discover. Where we rely on legitimate interests, we have balanced our interests against your rights and freedoms.

Consent (Art. 6(1)(a)): Any non-essential cookies; optional integrations; and any future optional marketing communications. You can withdraw consent at any time without affecting prior processing.

Compliance with a legal obligation (Art. 6(1)(c)): Keeping accounting and tax records, responding to lawful requests by authorities, and meeting our other statutory obligations.

Vital interests / public interest (Art. 6(1)(d)/(e)): Rarely, where necessary to protect a person's vital interests or where required for a public-interest task laid down by law.

For Swiss FADP purposes, processing is carried out on equivalent bases (consent, contract, law, or overriding legitimate interest). For UK GDPR purposes, equivalent bases apply.

5. How We Use Information

To create and maintain your account and authenticate you when you log in.

To provide, operate, and maintain the Service, including delivering scan results, running automated checks, surfacing alerts, and managing integrations.

To process payments, manage subscriptions, issue invoices, and handle billing disputes.

To send transactional, security, and service-related communications (such as scan completion notices, threat alerts, and policy updates).

To detect, prevent, investigate, and respond to fraud, abuse, security incidents, unlawful activity, and violations of our Terms or Acceptable Use Policy.

To provide customer support and respond to inquiries.

To monitor and improve the performance, reliability, security, and quality of the Service, including by analyzing aggregated usage and conducting limited product research.

To comply with legal obligations, court orders, lawful requests by public authorities, and to enforce our agreements and protect our rights.

To plan, evaluate, and execute business transactions such as mergers, acquisitions, financings, or reorganizations.

To anonymize or aggregate data for any lawful purpose, including statistical analysis, benchmarking, and product development.

6. Categories of Recipients & Third-Party Services

We share personal data only with the categories of recipients listed below and only to the extent strictly necessary for the relevant purpose. A current list of our principal subprocessors is maintained at checkvibe.dev/subprocessors.

Infrastructure & hosting providers - Vercel Inc. (web hosting, edge functions, CDN), Supabase Inc. (authentication, database, file storage).

Payment processor - Stripe, Inc. (subscription billing, invoicing, fraud screening).

Transactional email - Resend, Inc. (delivery of account, security, scan, support, and outreach email).

Third-party data sources used to run scans - Google Safe Browsing, Google Gemini (AI analysis), the U.S. National Vulnerability Database (NVD), public certificate-transparency logs, public DNS resolvers, public WHOIS services, and GitHub (only when you connect a repository).

Error monitoring & observability - Sentry (error reporting from our backend, where enabled) and PostHog (product analytics from the dashboard, where enabled). Both are configured to minimize personal data.

Professional advisors - lawyers, accountants, auditors, insurers, and consultants under confidentiality obligations.

Authorities - courts, regulators, law-enforcement, and other public bodies, where required by law or to defend or assert legal claims.

Successors in interest - in connection with a merger, acquisition, reorganization, financing, bankruptcy, or sale of assets, subject to appropriate confidentiality and continuity of this Policy.

Each subprocessor is bound by contractual obligations consistent with applicable data-protection law, including, where required, Standard Contractual Clauses (SCCs) and UK Addenda. We share only the minimum data necessary for each recipient's purpose.

7. International Data Transfers

CheckVibe is based in Switzerland. Some of our service providers process personal data in countries outside of Switzerland and the European Economic Area (EEA), including in the United States. When we transfer personal data internationally, we rely on one or more transfer mechanisms recognized under applicable law, including:

European Commission adequacy decisions (where available, including for transfers under the EU-U.S. Data Privacy Framework where the recipient is certified);

Swiss Federal Council adequacy decisions and the Swiss-U.S. Data Privacy Framework;

UK adequacy regulations and the UK Extension to the Data Privacy Framework;

European Commission Standard Contractual Clauses (SCCs) and the UK International Data Transfer Addendum;

Supplementary technical and organizational measures (such as encryption in transit and at rest, access controls, and minimization).

A copy of the relevant transfer mechanism for a specific recipient is available on request by writing to support@checkvibe.dev.

8. Data Retention

We retain personal data only for as long as necessary for the purposes set out in this Policy or as required by law. Indicative retention periods:

Account data: active for the life of your account; deleted within thirty (30) days of account closure, except where retention is required by law.

Scan results & project data: retained for the duration of your subscription; deleted within thirty (30) days of account closure.

User-provided credentials & integration tokens: deleted immediately when you remove the associated project, disconnect the integration, or delete your account.

Payment records, invoices, and tax-related accounting data: up to ten (10) years where required by Swiss tax and commercial law (Code des obligations Art. 957a), and similar laws in other jurisdictions.

Terms-acceptance records: retained for the life of the account and afterward for as long as reasonably necessary to establish, exercise, or defend legal claims or comply with law.

Server, security, and abuse logs: up to ninety (90) days for security and debugging, and longer where retention is necessary to investigate or respond to an incident or to defend legal claims.

Threat-detection visitor data: retained per the customer's configured retention window, by default up to ninety (90) days; aggregated indicators may be kept longer in de-identified form.

Support correspondence: account life plus thirty (30) days.

Back-ups: back-ups containing personal data are retained for short, rolling periods and overwritten on a regular schedule; deletion from production triggers deletion from back-ups on the next overwrite cycle.

When retention is no longer required, personal data is deleted or anonymized so it can no longer be linked to you. Anonymized and aggregated data may be retained indefinitely.

9. Cookies, Storage Technologies & Tracking

We use a minimal set of strictly necessary cookies and similar local-storage technologies for authentication, security, and session management. We do not use advertising or third-party tracking cookies. For details, see our Cookie Policy.

Do Not Track / Global Privacy Control. Because we do not engage in cross-context behavioral advertising and do not sell personal data, browser-based "Do Not Track" signals and Global Privacy Control (GPC) signals do not change our processing. We honor GPC as an opt-out request to the extent required by applicable law.

10. Security

We implement appropriate technical and organizational measures designed to protect personal data against unauthorized or unlawful processing and against accidental loss, destruction, damage, alteration, or disclosure, including without limitation: TLS encryption in transit; encryption of sensitive credentials at rest; secure password hashing; role-based access controls; row-level security on our database; principle of least privilege; multi-factor authentication for administrative accounts; logging and monitoring; periodic vulnerability assessment of our own platform; vendor-risk review of subprocessors; and security training for personnel with access to personal data.

No method of transmission over the Internet or method of electronic storage is 100% secure. While we strive to use commercially acceptable means to protect your data, we cannot guarantee absolute security. You are responsible for keeping your account credentials confidential and notifying us of any suspected compromise.

11. Data Breach Notification

In the event of a personal-data breach that is likely to result in a risk to the rights and freedoms of natural persons, we will notify the competent supervisory authority without undue delay and, where feasible, not later than seventy-two (72) hours after becoming aware of it, as required by Art. 33 GDPR (or analogous obligations under the FADP, UK GDPR, or other applicable law). Where the breach is likely to result in a high risk to affected individuals, we will also notify those individuals without undue delay as required by Art. 34 GDPR.

12. Automated Decision-Making & Profiling

We do not make decisions that produce legal effects or similarly significant effects on you based solely on automated processing (within the meaning of Art. 22 GDPR). Our scanning, threat-detection, and AI-assisted analysis features apply automated rules to data you submit, but the outputs are informational and require human review and action; they are not used to make decisions that legally or significantly affect any individual.

13. Your Rights - EEA, UK & Switzerland (GDPR, UK GDPR, FADP)

Subject to conditions and exceptions in applicable law, you may have the following rights with respect to personal data we hold about you:

Right of access - request confirmation that we process your personal data and a copy of that data.

Right to rectification - have inaccurate or incomplete data corrected.

Right to erasure ("right to be forgotten") - have your data deleted (instantly available from your account deletion page).

Right to restriction of processing - ask us to limit processing in certain circumstances.

Right to data portability - receive your data in a structured, commonly used, machine-readable format and have it transmitted to another controller where technically feasible.

Right to object - object to processing based on legitimate interests, including profiling, and to object to direct marketing.

Right to withdraw consent - where processing is based on consent, withdraw consent at any time without affecting prior processing.

Right not to be subject to automated decision-making - see Section 12; we do not make such decisions.

Right to lodge a complaint - file a complaint with a supervisory authority. In Switzerland, this is the Federal Data Protection and Information Commissioner (FDPIC). In the EEA, you may contact the supervisory authority of your country of habitual residence, place of work, or place of the alleged infringement. In the UK, you may contact the Information Commissioner's Office (ICO).

You can exercise the right to erasure instantly from your account deletion page. For all other requests, contact support@checkvibe.dev. We will respond within thirty (30) days (extendable by sixty (60) days for complex requests, with notice to you). We may need to verify your identity before responding.

14. Your Rights - California (CCPA / CPRA)

If you are a California resident, you have additional rights under the California Consumer Privacy Act, as amended by the California Privacy Rights Act (collectively, "CCPA/CPRA"):

Right to know - request information about the categories and specific pieces of personal information we have collected, the sources, the purposes of collection, and the third parties with whom we share it.

Right to delete - delete your personal information (instantly from your account deletion page).

Right to correct - request correction of inaccurate personal information.

Right to opt out of sale or sharing - we do not sell personal information for monetary or other valuable consideration, and we do not share personal information for cross-context behavioral advertising. We have not done so in the preceding twelve (12) months.

Right to limit use of sensitive personal information - we do not collect sensitive personal information for inferring characteristics; only the limited categories required to provide the Service are processed and only for permitted business purposes.

Right to non-discrimination - we will not discriminate against you for exercising any CCPA/CPRA right.

Right to designate an authorized agent - you may use an authorized agent to make a request, subject to identity verification.

Categories of personal information collected in the preceding 12 months: identifiers (email, IP); commercial information (subscription, payment metadata); internet or other electronic-network activity (log, telemetry); inferences for security and abuse detection only. We have not sold or shared (for cross-context behavioral advertising) any personal information in the preceding 12 months. We do not knowingly sell or share information of consumers under sixteen (16).

To exercise a right, use your account deletion page or email support@checkvibe.dev with the subject "CCPA Request."

15. Other U.S. State Privacy Rights

Residents of Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA), Utah (UCPA), Texas (TDPSA), Oregon (OCPA), Montana (MCDPA), Iowa (ICDPA), Tennessee (TIPA), Indiana (ICDPA), New Hampshire, Delaware, New Jersey, Maryland, Minnesota, Rhode Island, and Florida (FDBR), and any other U.S. state that grants equivalent rights, have, subject to the conditions and exceptions of their respective laws, the right to access, correct, delete, and obtain a portable copy of their personal data, and to opt out of (i) the sale of personal data, (ii) targeted advertising, and (iii) profiling for decisions that produce legal or similarly significant effects. CheckVibe does not engage in (i), (ii), or (iii). To exercise other rights, follow the instructions in Section 14 or contact support@checkvibe.dev. Appeals of our decisions on such requests can be sent to the same address with the subject "Privacy Appeal."

16. Other Jurisdictions

Brazil (LGPD). Brazilian data subjects have rights of access, correction, anonymization, blocking, deletion, portability, information about sharing, and withdrawal of consent. Direct requests to support@checkvibe.dev.

Canada (PIPEDA, Quebec Law 25). Canadian residents may request access to and correction of personal information and withdraw consent subject to legal and contractual restrictions. Quebec residents may additionally request the cessation of dissemination, de-indexing, and portability where applicable.

Australia. Australian residents may access and correct their personal information under the Australian Privacy Principles.

Japan, South Korea, Singapore, India, others. We honor analogous rights under applicable local data-protection laws to the extent they apply to our processing.

17. Children's Privacy

The Service is not directed to, and we do not knowingly collect personal data from, anyone under the age of sixteen (16) (or the higher minimum age in your jurisdiction, including eighteen (18) where required). We do not knowingly collect "personal information from children" within the meaning of the U.S. Children's Online Privacy Protection Act (COPPA). If you are a parent or guardian and believe that we have collected personal data from your child, please contact us at support@checkvibe.dev and we will promptly delete it.

18. No Sale, No Cross-Context Advertising, No AI-Model Training on Customer Content

CheckVibe does not sell personal data for money or any other valuable consideration. We do not share personal data for cross-context behavioral advertising. We do not use Customer Content (such as your scan data, source code, repository contents, or integration credentials) to train, fine-tune, or evaluate any third-party large-language model or machine-learning model except as strictly necessary to run the specific scan or feature you requested.

19. Changes to This Policy

We may update this Privacy Policy from time to time. For material changes, we will provide advance notice (generally at least thirty (30) days) by email and/or by posting a prominent notice in the Service. The current version is always available at checkvibe.dev/privacy with a "Last updated" date and version number. Non-material changes (such as clarifications or typographical corrections) take effect on posting. Continued use of the Service after changes take effect constitutes acceptance.

20. Contact Us

If you have questions about this Privacy Policy, your personal data, or wish to exercise your rights, contact us:

Privacy & data-subject requests: support@checkvibe.dev

General: support@checkvibe.dev

Website: checkvibe.dev

See also: Terms of Service · Cookie Policy · DPA · Subprocessors · Disclaimer