Data Processing Agreement
Last updated 2026-07-02
1. The roles
When you build an application with VibeHard that stores personal data belonging to your clients, patients, or customers — not VibeHard's — you are the data controller for that data, and VibeHard is a data processor acting on your instructions, via the infrastructure your application runs on.
2. What VibeHard processes on your behalf
VibeHard's infrastructure processes whatever data your generated application is designed to store — determined by the specification you approve, not by VibeHard. VibeHard does not read, use, or repurpose your application's end-user data for any purpose beyond operating the infrastructure it runs on.
3. Subprocessors
The infrastructure providers below may process your application's data as subprocessors:
| Subprocessor | Role |
|---|---|
| Supabase | Hosts the dedicated database for your application |
| Fly.io | Hosts your deployed application |
| Clerk | Authenticates users of the VibeHard platform (not necessarily your application's own end users, unless you build your app to use it) |
VibeHard will not add a new subprocessor that materially changes where or how your application's data is processed without reasonable notice.
4. Security measures
Every application VibeHard builds runs through the gate line described on the trust page before it deploys, including a live attack proving that one customer's data cannot be read by another. Secrets and credentials are encrypted at rest. Each application's database is isolated in its own project — never a table shared across customers.
5. Your obligations
You remain responsible for the lawful basis for collecting your end users' data, for any consent or disclosure your application needs to make to them, and for classifying your application's data accurately in the build specification — that classification is what determines which controls the gates enforce.
6. Data deletion
Deleting a project removes its dedicated database, including all data your application stored in it. If your application needs to support deleting an individual end user's data on request, that has to be a feature of the application itself — the gates check that a hard-delete path exists for sensitive data, but you're responsible for using it correctly.
7. Breach notification
VibeHard will notify you without undue delay if it becomes aware of a security incident affecting your application's dedicated database or the infrastructure it runs on.
8. Contact
Questions about this agreement: legal@vibehard.ai.