vipe.ai
VIPE

Privacy Policy

Last updated: September 2026

Who is responsible

vipe.ai is operated by its owner, who is the controller of the personal data described in this policy and is responsible for how it is processed. For any privacy or legal question, including exercising your rights, contact masonwalet@gmail.com.

What we collect

• Email address — if you submit it through the "Get feature updates" form, or when you buy scan credits. The web scanner and credits work without an account: credits are linked to your email address, and there are no passwords. • Your Vipe account (optional) — Vipe Pro and the Vipe editor extension need an account, which you create by signing in with GitHub. GitHub then shares your GitHub user ID, username, name, profile picture and email address with us. We get no access to your repositories. • Subscription records — if you subscribe to Vipe Pro: your Stripe customer ID, your subscription's status, and when the current billing period ends. Your card details stay with Stripe. • Connected editors — for each editor you connect to your account: the editor (for example VS Code or Cursor), a device label your editor sends (usually your computer's name), when it was connected and last used, and a hashed access token. We never store the token itself. • AI fix usage — how many of your free AI fixes you have used. • Purchase records — for each credit purchase we store the Stripe checkout session ID, your email address, the number of credits, the amount paid, and whether you consented to immediate delivery. We do not receive or store your card details; these are handled by Stripe. • Usage records — a scan log (email if you use credits, and a salted hash of your IP address) and your credit balance. The hash is used to enforce one free scan per person and to prevent abuse and referral fraud; we do not store your raw IP address in our database. If you use a referral link, we also store a referral code linked to your email address. • Anonymised scan statistics — the type of issue found and the technology context (for example, "SQL injection in Express"), with a running count. This contains none of your code and cannot be traced back to you. • Browser storage — your email address and referral code are kept in your browser's local storage so you don't have to re-enter them. This stays on your device and you can clear it at any time. If you sign in, your browser also keeps a sign-in cookie (see Cookies and analytics). We do not collect any other personal data.

Why we process your data

• To deliver the service you request — running scans, managing credits and processing purchases (performance of a contract). • To provide your account — signing you in, running your Vipe Pro subscription, counting free AI fixes, and keeping track of the editors you've connected so you can disconnect them (performance of a contract). • To prevent abuse and fraud — rate limiting, one free scan per person, referral integrity (our legitimate interest in keeping the service secure and fair). • To meet legal obligations — for example keeping purchase records for accounting purposes. • To send product updates — only if you signed up for them (your consent, which you can withdraw at any time).

Your code

Code you paste or upload is sent to our server solely to run a security analysis. It is processed and then immediately deleted — we do not store, log, or retain your code after the scan completes. To generate fix suggestions and explanations, your code is sent to Anthropic (see Third-party processors below). Your code is never used by us to train machine learning models and is never shared with third parties beyond what is required to perform the analysis. In the Vipe editor extension, detection runs on your own machine and your code is not sent to us. When you ask for an AI fix, only the flagged snippet — a few lines around the finding — is sent to our server and to Anthropic to write the fix and its explanation. It is not stored.

How we use your email

We use your email address to keep track of your scan credits and purchases and, if you signed up for updates, to send you occasional product updates about vipe.ai. We do not sell, rent, or share your email with any third party for marketing purposes. You can request access to or deletion of your email at any time by contacting us.

Third-party processors

We use the following service providers, who process personal data on our behalf or as part of delivering the service: • Anthropic — AI processing. Receives your code to generate security fix suggestions and plain-English explanations. Anthropic handles this data under its own commercial terms and privacy policy. • Supabase — database and sign-in. Stores email addresses, credit balances, purchase and scan records, and hashed IP addresses and, if you have an account, your GitHub profile details, subscription status and connected-editor records. Supabase Auth also runs the GitHub sign-in. Data is stored on servers located in the EU. • GitHub — sign-in. When you choose "Continue with GitHub", GitHub confirms who you are and shares the profile details listed above. GitHub acts as an independent controller under its own privacy statement. Your profile picture is loaded from GitHub's servers when it is shown on the site. • Stripe — payments. Processes your payment when you buy credits or subscribe to Vipe Pro, and receives your payment details and email address. For Vipe Pro, Stripe also runs the recurring billing and the customer portal where you manage or cancel your subscription. Stripe acts as an independent controller for payment processing and fraud prevention, under its own privacy policy. We receive only confirmation of payments, your email address, the amounts paid and the state of your subscription. • Vercel — hosting and analytics. Hosts the vipe.ai application and may log standard web server data (IP address, request path, timestamp) for up to 30 days for operational purposes. Vercel also provides Web Analytics (see Cookies and analytics below). Some of these providers are based in, or process data in, the United States. Where personal data is transferred outside the EU/EEA, this relies on safeguards such as the EU–US Data Privacy Framework or Standard Contractual Clauses, as provided by each provider.

Cookies and analytics

vipe.ai does not use tracking cookies or advertising cookies, and does not show a cookie banner because none is needed. We use Vercel Web Analytics to understand how many people visit the site and which pages they view. It is cookieless: it does not set cookies or store anything on your device, and it does not track you across websites or build a profile of you. Page views are recorded with the page path only — we remove query strings (such as referral codes) before anything is sent. Vercel may set a minimal technical cookie required for routing. Separately, the site stores your email address and referral code in your browser's local storage, as described above. If you sign in, we set cookies that are strictly necessary for your account: a session cookie from our sign-in service (Supabase) that keeps you signed in, and — only for the few minutes a sign-in takes — cookies that secure the GitHub sign-in and remember which page to return you to. They are not used for tracking.

How long we keep data

Your code is deleted as soon as the scan completes. Email addresses for updates are kept until you unsubscribe or ask us to delete them. Credit, purchase and scan records are kept for as long as needed to provide your credits and to meet legal and accounting obligations, and are then deleted or anonymised. Account data is kept while you have an account. Connected-editor records stay until you disconnect the editor or delete your account. Subscription records are kept as long as needed for billing and to meet legal and accounting obligations. You can ask us to delete your account at any time by emailing us.

Your rights

Under the GDPR (and similar laws), you have the right to: • Access — get a copy of the personal data we hold about you • Rectification — have inaccurate data corrected • Erasure — have your data deleted, where no legal obligation requires us to keep it • Restriction and objection — limit or object to certain processing • Data portability — receive your data in a common format • Withdraw consent — at any time, for anything based on your consent (for example product updates), without affecting earlier processing To exercise any of these rights, email masonwalet@gmail.com and we will respond within one month. We may need to verify that the request comes from the email address in question. California residents have similar rights under the CCPA. You also have the right to lodge a complaint with a data protection authority. In the Netherlands this is the Autoriteit Persoonsgegevens (autoriteitpersoonsgegevens.nl); you may also contact the authority in your own EU/EEA country of residence.

Contact

Questions about this policy, or requests relating to your personal data: masonwalet@gmail.com.

Changes to this policy

We may update this policy as the product evolves. The "last updated" date at the top of the page will reflect any changes. Continued use of vipe.ai after an update constitutes acceptance of the revised policy.

Questions? masonwalet@gmail.com