Skip to main content

Privacy Policy

Last updated: July 16, 2026

Privacy at a Glance

Vibe-Coding Workflow is designed with privacy-first principles. Your API keys are stored locally in your browser, and projects stay local unless a signed-in Basic or Pro account syncs them with our cloud database, and AI requests are routed through secure API endpoints — your keys are never logged or stored.

Data We Collect

Analytics (If Enabled)

We use Supabase to collect minimal, anonymous event data:

  • Timestamp (when the event occurred)
  • Event name (e.g., page view)
  • Event type
  • Metadata (non-identifying context)

Analytics can be disabled in cookie preferences. We never track personal information or any identifying data.

Data We Never Collect

  • Your API keys (stored only in your browser)
  • Content of your AI prompts or responses
  • Your project files or generated code (unless you authenticate and use cloud sync)
  • Personal identification information (except email when signing in)
  • Billing and credit card payment information (processed securely by Buy Me a Coffee)

Cookies & Local Storage

We use browser localStorage to store your preferences and project data. This keeps everything on your device.

For a dedicated breakdown of analytics, consent, and advertising cookies, see our Cookie Policy.

Storage Keys We Use:

  • VIBE_GEMINI_API_KEY - Your Gemini API key
  • VIBE_OPENAI_API_KEY - Your OpenAI API key
  • VIBE_ANTHROPIC_API_KEY - Your Anthropic API key
  • VIBE_OPENROUTER_API_KEY - Your OpenRouter API key
  • VIBE_COOKIE_CONSENT - Cookie preferences
  • VIBE_PROJECTS - Your saved projects

Advertising & Google AdSense

Eligible public editorial pages may display ads provided by Google AdSense. Google and other third-party vendors may place or read cookies, use web beacons, IP addresses, or other identifiers to serve, personalize, limit the frequency of, and measure advertising.

Visitors in the EEA, the UK, and Switzerland are shown a Google-certified consent message before personalized advertising is served. Advertising is not placed in the private builder, project, admin, legal, navigation, or error screens.

Learn how Google uses information from sites that use its services and manage personalized advertising in Google Ads Settings.

Cloud Synchronization & Subscriptions

Signed-in Basic and Pro accounts sync saved projects to our secure cloud database powered by Supabase. This supports access across devices. Free projects remain local unless you export them, and you can delete cloud-synced projects at any time.

We offer Basic and Pro subscriptions to support the ongoing development of the tool. Subscription processing is handled via Buy Me a Coffee. We do not store or process your financial billing details directly.

Third-Party Services

AI Processing Services:

  • Bring Your Own Key (BYOK) / Vercel AI SDK - When you provide your own API keys, requests are routed through Vercel serverless functions utilizing the Vercel AI SDK. Your keys are used only in-memory to proxy requests directly to:
    • Google AI (generativelanguage.googleapis.com)
    • OpenAI (api.openai.com)
    • Anthropic (api.anthropic.com)
    • OpenRouter (openrouter.ai)
  • Free Built-in AI / Cloudflare Workers AI - When using the free tier models, requests are processed using Cloudflare Workers AI hosting models such as Gemma 4 and GLM 5.2.

Protection and Security Services:

  • Cloudflare Turnstile - We use Cloudflare Turnstile in invisible mode to protect our APIs and forms from spam and abuse. This use is subject to the Cloudflare Turnstile Privacy Addendum.

Operational Measurement:

Vercel provides aggregate web analytics and performance measurements. Optional product analytics and Google measurement load only after you enable analytics preferences.

These services have their own privacy policies. We recommend reviewing them before using their APIs.

Your Rights

  • Access: View all your data in browser DevTools > Application > Local Storage
  • Delete: Clear all data via Settings > Data tab or clear browser storage
  • Portability: Export your projects as JSON files anytime
  • Opt-out: Disable analytics in cookie preferences

Questions?

If you have privacy questions or concerns, please contact us.

Analytics Preferences

Optional analytics help us understand how the app is used. API keys stay in browser storage. Free projects stay local; Basic and Pro projects sync to your account. Privacy Policy · Cookie Policy