Privacy Policy
What VibeScore collects when you create an account or submit a listing, and what a usage report does and doesn't contain.
Last updated: 2026-08-14
1. What we collect
Account information. Your name, email address, and either a hashed password or a linked OAuth account (Google), depending on how you sign up. If you set up a builder profile, also your handle, bio, and any website, GitHub or Twitter links you add.
Listing content. Everything you submit for an app — its name, tagline, description, category, links, and any logo or screenshot you upload.
Usage reports. When you upload a vibescore-cli or ccusage report to get a listing verified, we store the parsed contents — token counts, cost, timing, and session identifiers — so the numbers on your listing can be recomputed and checked against later snapshots. Section 3 below covers what that specifically does and doesn't include.
Technical information. Your IP address and browser user agent, recorded against login sessions and account activity for security purposes (detecting suspicious sign-ins, rate-limiting abuse). Standard session cookies from our authentication provider.
Approximate location, for every visitor. To power the "who's on the site right now" panel on the boards, every page view resolves your IP to a country — nothing more precise — using an offline lookup we run ourselves, not a third-party geolocation service. The IP address itself is not stored: what gets written is a two-letter country code (or none, if it can't be resolved) against a random, pseudonymous id in a cookie, never against your account or email. Section 7 covers that cookie.
2. Why we collect it
To create and secure your account, publish and display your listings, verify build metrics against the report you provided, send transactional email (verification, password reset, moderation updates), and keep the Service working — rate limiting, abuse prevention, and diagnosing issues.
3. What a report contains
A usage report you upload is parsed for the numbers a listing needs: tokens, cost, timestamps, and session identifiers. vibescore-cli is built to leave your filesystem layout out of it — it reports a project's folder name, never its full path — so what you paste doesn't disclose where your code lives on disk. We store what the report contains; we don't separately collect anything from your machine.
4. Sharing and third parties
We don't sell your data. It's shared only with the services that make the Service work:
- Database and hosting — where your account and listing data live.
- File storage — for uploaded logos and screenshots.
- Resend — sends transactional email (verification, password reset, notifications) on our behalf.
- Google — if you sign in with Google, they handle that authentication; we receive your name, email, and profile image from them.
- Vercel Analytics — aggregate, cookieless page-view analytics. It doesn't identify you individually.
Approximate location (Section 1) is resolved with an offline database we run ourselves — your IP address is never sent to a third-party geolocation service.
If a payment processor is used for a featured placement, they receive your payment details directly — we don't store card numbers.
5. Retention
Your account and listing data persist as long as your account exists. Deleting a listing removes it and its build history immediately. Deleting your account removes your published listings and profile from public view; some records may be retained briefly where needed for security, abuse prevention, or as required by law.
6. Your choices
You can edit or delete a listing at any time from your dashboard. You can update your profile, or delete your account entirely, from account settings. For anything you can't do yourself — including requesting a copy of your data or its full deletion — contact us and we'll handle it.
7. Cookies
We use a session cookie to keep you signed in, and a cookie to remember your light/dark theme preference. We also set a random, pseudonymous id in a cookie for every visitor, signed in or not — it's what lets the "who's on the site right now" panel and your own view-count analytics tell one visit from another, and it's never linked to your account, name or email. None of these are used for advertising or cross-site tracking.
8. Security
Data is encrypted in transit. Access to production data is limited to what's needed to operate the Service. Passwords are stored hashed, never in plain text.
9. Children
The Service isn't directed at children, and you must be old enough to enter a binding contract in your jurisdiction to create an account.
10. Changes
We may update this policy as the Service changes. We'll update the date at the top when we do; continuing to use the Service after a change means you accept the update.
11. Contact
Questions about this policy, or a request about your data: support@shipaisaas.com.