← Back to vibecodingsecure.com

Privacy Policy

Last updated: 30 August 2026

This policy explains what personal data we process, why, and your rights under the EU General Data Protection Regulation (GDPR).

1. Who is responsible (data controller)

The controller of your personal data is Javier Beltran Garrido, an individual trader (sole trader) established in Cyprus, European Union.

2. What data we process and why

3. Legal bases (Article 6 GDPR)

4. Your scan results are sensitive — our commitment

The results of a security scan reveal weaknesses in your application, so we treat them as strictly confidential. We do not sell them, and we do not share them with anyone except the sub-processors listed below that are strictly needed to run the service.

We keep detailed scan results for no longer than 90 days and then delete them. The free scan stores nothing about the result. Paid reports are generated on demand by scanning your site live, so we do not keep a standing copy of your secrets. For Monitoring, we keep only the most recent scan snapshot needed to detect changes, and we delete it within 30 days after you cancel.

5. How long we keep data (retention)

6. Who processes data for us (sub-processors)

We put the data-processing terms required by the GDPR in place with our processors.

7. International transfers

Our own infrastructure is located in the EU. Some providers (for example, Stripe) may process data outside the European Economic Area; where they do, they rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses.

8. Cookies and tracking

We keep this minimal. We do not use advertising or cross-site tracking cookies. Our site uses only what is strictly necessary to function. Stripe may set its own cookies during checkout to process your payment and prevent fraud.

9. Your rights

Under the GDPR you have the right to access your data, and to rectify, erase, restrict or object to its processing, to data portability, and to withdraw consent. To exercise any of these, email support@vibecodingsecure.com; we respond within one month.

You also have the right to lodge a complaint with a supervisory authority. Our lead authority is the Office of the Commissioner for Personal Data Protection of the Republic of Cyprus (www.dataprotection.gov.cy). You may also complain to the authority in your own EU country of residence.

10. Security

We serve the site over HTTPS, we never store your card data (Stripe handles all payments and is PCI DSS Level 1), and we limit who can access our systems. No method is completely secure, but we take reasonable technical and organisational measures to protect your data.

11. Children

The service is intended for developers and businesses and is not directed at children under 18. We do not knowingly collect data from children.

12. Changes

We may update this policy. The "Last updated" date at the top shows the current version.

13. Contact

Privacy questions: support@vibecodingsecure.com.

VibeCodingSecure — operated by Javier Beltran Garrido, Cyprus (EU) · support@vibecodingsecure.com