Who is responsible
Marc Arndt, Berghalde 96, 69126 Heidelberg, Germany, runs vibeship.eu and is responsible for the personal data described here. Reach us at support@vibeship.eu.
The free check
You do not need an account. We store the web address you enter and the results of the check, so that the link to your report keeps working. Anyone with that link can open the report. We do not record who ran it.
Visiting the site
We count visits with a tool we host ourselves. It sets no cookies, does not identify you, and shares nothing with anyone else.
Advertising
We advertise on Facebook and Instagram. To measure whether those adverts work we can load the Meta Pixel, but only after you have said yes to the question we ask on your first visit. With your yes, it tells Meta which pages you visited, when you started a free check and when you bought a subscription, and it sets a cookie in your browser so that Meta can match those visits to its own records. Meta's privacy policy covers what it does with that data. If you say no, nothing is loaded from Meta and the site works the same. We remember your answer for six months, and you can change it here at any time.
Your account
When you sign in we receive your email address and name from our sign-in service, which we also host. We use them to show you your own reports and to reply when you write to us. Your browser gets one cookie that keeps you signed in; it is necessary for the service and holds nothing but a random reference. We store only a scrambled fingerprint of it, never the value itself.
Paying
Payments are handled by Stripe. Stripe receives your email address and your card details; we receive confirmation of what you bought and never see the card. Stripe's own privacy policy covers what it does with the data it holds. We keep records of what you paid for as long as tax law requires us to.
The deep test
To run it, you give us the address of your site, optionally a link to where the code lives, and optionally a sign-in for your site so the test can get behind the login. The sign-in password is stored encrypted and is used only to sign in to your site during a test. Results are kept so you can compare runs over time.
If you let us read your source code, that permission is granted on GitHub and we keep only its reference number. The code is copied into temporary storage for the stage that reads it and deleted when the stage finishes. Where the test finds a leaked password or key, the report records where it is, never the value.
One stage of the deep test judges whether your site says what its buyers look for. To do that, the visible text of your public pages is sent to an AI model through a service called OpenRouter. Only public page text goes; nothing about your account, your sign-in, or your code.
Questions and feedback
When you send us a question from inside the product, we store the message and a pointer to what you were looking at, so we can answer in context. Staff are notified by email that a message arrived, but that email never carries your message itself.
Where your data is kept
On servers in Germany, within the European Union. Stripe and GitHub process data under their own terms, which include the safeguards the EU requires for transfers outside it.
How long we keep it
- Free-check reports: until you ask us to remove them.
- Account, deep-test settings and reports: while your account exists, and removed when you ask us to delete it.
- Payment records: as long as tax law requires.
- Copied source code: minutes, deleted when the stage that read it finishes.
Your rights
Under the GDPR you can ask what we hold about you, have it corrected or deleted, receive a copy of it, or object to how we use it. Email support@vibeship.eu from the address you signed in with and we will act within a month. You can also complain to the data protection authority in your country.
Changes
If we change this page in a way that matters, we will say so on the dashboard before it takes effect. The date at the top is the date of the last change.