Privacy Policy
Last updated 2026-07-02
1. Who this covers
This policy covers information VibeHard collects about you, the person building applications with VibeHard. It does not cover how your generated application handles the data of its end users — that's your responsibility as the operator of what you build, and it's the subject of the Data Processing Agreement for the parts VibeHard's infrastructure touches on your behalf.
2. What VibeHard collects about you
| Category | Examples | Why |
|---|---|---|
| Account | Email, name, profile picture (via Google sign-in or email/password) | Authenticate you, identify your account |
| Build content | The app ideas and prompts you type, the resulting spec and generated code | To draft, build, and gate your application |
| Usage | Build counts, plan tier, timestamps | Enforce plan limits, billing |
| Payment | Handled entirely by Stripe — VibeHard does not store card numbers | Billing |
3. Who VibeHard shares it with
VibeHard uses a small set of infrastructure providers to operate. Each processes a narrow slice of your data to do its specific job:
- Clerk — authentication (your sign-in identity)
- Supabase — the dedicated database provisioned for each application you build
- Fly.io — hosting for deployed applications
- OpenRouter (or your own model key, on Pro) — the language model calls that draft specs and generate code from your prompts
- Stripe — billing and payment processing
VibeHard does not sell your data. It is not shared with anyone outside this list except where required by law.
4. Where your build data lives
Each application you build gets its own dedicated database project, provisioned and managed by VibeHard by default. It is never stored in a table shared with another customer's application. The spec, generated code, and gate findings for a build are retained so you can resume or redeploy it; deleting a project removes its dedicated database.
5. Your choices
- You can delete individual builds/projects from your account.
- You can close your account at any time, which removes your account data and the dedicated databases for your applications.
- You can bring your own model key (Pro plan) so your prompts route through your own provider account instead of the platform's.
6. Security
Secrets (API keys, database credentials) are stored encrypted, never in plaintext logs. Every application VibeHard builds runs through the same gate line described on the trust page, including a live attack against the database to prove one customer's data can't be read by another.
7. Contact
Questions about this policy or a request about your data: privacy@vibehard.ai.