Last updated: 30 August 2026
This policy explains what personal data we process, why, and your rights under the EU General Data Protection Regulation (GDPR).
The controller of your personal data is Javier Beltran Garrido, an individual trader (sole trader) established in Cyprus, European Union.
The results of a security scan reveal weaknesses in your application, so we treat them as strictly confidential. We do not sell them, and we do not share them with anyone except the sub-processors listed below that are strictly needed to run the service.
We keep detailed scan results for no longer than 90 days and then delete them. The free scan stores nothing about the result. Paid reports are generated on demand by scanning your site live, so we do not keep a standing copy of your secrets. For Monitoring, we keep only the most recent scan snapshot needed to detect changes, and we delete it within 30 days after you cancel.
We put the data-processing terms required by the GDPR in place with our processors.
Our own infrastructure is located in the EU. Some providers (for example, Stripe) may process data outside the European Economic Area; where they do, they rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses.
We keep this minimal. We do not use advertising or cross-site tracking cookies. Our site uses only what is strictly necessary to function. Stripe may set its own cookies during checkout to process your payment and prevent fraud.
Under the GDPR you have the right to access your data, and to rectify, erase, restrict or object to its processing, to data portability, and to withdraw consent. To exercise any of these, email support@vibecodingsecure.com; we respond within one month.
You also have the right to lodge a complaint with a supervisory authority. Our lead authority is the Office of the Commissioner for Personal Data Protection of the Republic of Cyprus (www.dataprotection.gov.cy). You may also complain to the authority in your own EU country of residence.
We serve the site over HTTPS, we never store your card data (Stripe handles all payments and is PCI DSS Level 1), and we limit who can access our systems. No method is completely secure, but we take reasonable technical and organisational measures to protect your data.
The service is intended for developers and businesses and is not directed at children under 18. We do not knowingly collect data from children.
We may update this policy. The "Last updated" date at the top shows the current version.
Privacy questions: support@vibecodingsecure.com.
VibeCodingSecure — operated by Javier Beltran Garrido, Cyprus (EU) · support@vibecodingsecure.com