Privacy Policy
Last updated: April 12, 2026
1. Introduction
This Privacy Policy describes how Vibehost collects, uses, and protects your personal data when you use our platform. We are committed to protecting your privacy and handling your data in accordance with the General Data Protection Regulation (GDPR) and the Swiss Federal Act on Data Protection (FADP).
2. Data We Collect
We collect different categories of data to provide and improve the Service:
Account Data
- Name, email address, and password (hashed)
- Company name and organizational role
- Authentication settings (2FA, SSO login)
Usage Data
- Deployment history and application logs
- Project metadata (detected framework, database configuration)
- IP address, browser type, and device information
- Action timestamps and activity logs
Deployment Data
- Source code and configuration files (transmitted via rsync/SSH)
- Environment variables and application secrets (encrypted)
- Database schemas and metadata
3. How We Use Your Data
- Provide and operate the Service, including application deployment, database provisioning, and routing
- Analyze projects via artificial intelligence for automatic framework detection and deployment configuration
- Ensure platform security, monitor for abuse, and prevent unauthorized access
- Improve the Service, fix bugs, and develop new features
4. Legal Basis for Processing
We process your personal data on the following legal bases:
- Contract performance — necessary to provide the Service you requested
- Legitimate interests — platform security, fraud prevention, and Service improvement
- Consent — for optional marketing communications and non-essential cookies
5. Data Sharing and Third Parties
Vibehost may share data with third parties in the following cases:
- AI providers — During deployment, project data is sent to third-party AI providers (such as OpenRouter, OpenAI, or Infomaniak AI, depending on instance configuration) for three purposes: project analysis (directory listings, package.json contents, framework configuration files, and environment variable key names — not values), Dockerfile generation (detected framework, build and start commands, port configuration), and database migration generation (database schemas). Environment variable values and application secrets are never transmitted to AI providers.
- LLM observability — When tracing is enabled by the instance operator, LLM inputs (the project data described above) and outputs (generated configurations) are sent to Langfuse for monitoring and quality assurance. Tracing is optional and can be disabled in the instance configuration.
- Authentication providers — If you sign in via single sign-on (SSO), authentication data (such as your name, email, and authentication tokens) is shared with the identity provider you choose (e.g., Google or Microsoft) in accordance with their respective privacy policies.
- Infrastructure providers — Hosting and cloud service providers that operate the underlying infrastructure may process data in accordance with their own privacy policies.
Vibehost does not sell your personal data to third parties. We may disclose data if required by law or to protect our rights, safety, or property.
6. Data Retention
We retain your personal data for as long as your account is active or as needed to provide the Service. Deployment data (logs, build metadata) is retained for the lifetime of the associated application and deleted within thirty (30) days of application or account deletion. Financial records (invoices) are retained for ten (10) years as required by Swiss law (CO Art. 958f).
7. Your Rights
Under the GDPR and FADP, you have the following rights:
- Right of access — Obtain a copy of your personal data
- Right to rectification — Correct inaccurate or incomplete data
- Right to erasure — Request deletion of your personal data
- Right to data portability — Receive your data in a structured, machine-readable format
- Right to object — Object to processing based on legitimate interests
- Right to withdraw consent — At any time for consent-based processing
You can delete your account and associated data directly from the Service settings. Personal data is erased within thirty (30) days of account deletion, in accordance with GDPR Art. 17 and Swiss FADP Art. 32. Financial records are retained as required by law. For any other data rights requests, please contact us at privacy@vibehost.io. We will respond within thirty (30) days.
8. Cookies and Tracking Technologies
Vibehost uses the following types of cookies:
Essential cookies
Authentication and session management cookies, strictly necessary for the Service to function. These cannot be disabled.
Analytics cookies
We use analytics services to understand how the Service is used and to improve it. These cookies are only set with your explicit consent and can be declined without affecting your use of the Service.
You can manage your cookie preferences at any time through the cookie settings accessible from the Service. Non-essential cookies are disabled by default and require your opt-in consent.
9. Data Security
We implement appropriate technical and organizational measures to protect your data, including encryption of data in transit (TLS) and at rest, password hashing, container isolation for deployed applications, and role-based access controls. While no system is completely secure, we strive to protect your data in line with industry standards.
10. International Data Transfers
Your data is primarily stored on the hosting infrastructure configured by your instance operator. If data is transferred outside the European Economic Area or Switzerland, we ensure appropriate safeguards are in place, such as the European Commission's Standard Contractual Clauses.
11. Children's Privacy
The Service is not intended for individuals under sixteen (16) years of age. We do not knowingly collect personal data from minors. If you become aware that a minor has provided us with personal data, please contact us so we can delete it.
12. Changes to This Policy
We may update this Privacy Policy periodically. Material changes will be notified via email or through the Service dashboard at least thirty (30) days before taking effect. The "Last updated" date at the top of this page indicates when the policy was last revised.
13. Contact
For any questions about this Privacy Policy or the processing of your data, please contact us at privacy@vibehost.io.