vybel
Sign in

Privacy

Publisher and data controller

What we collect

Your code is analyzed, then deleted as soon as the analysis ends; no code is executed. The report (grades, issues found, short code excerpts, fix prompts) is kept and available to anyone who has its link; the report of a private repository is visible to your account only. The project’s identity (repository address, package name, fingerprint of the file paths) is kept to apply the rule of one free analysis per project. Your email address: if you create an account, to identify you and, with Vybel Pro, to send you alerts and the Monday recap; if you join the Vybel Pro waitlist, to let you know when your access opens. How you heard about Vybel, to know which channels bring visitors. Your payments: if you pay for an analysis, Stripe processes the payment; we receive your email address and billing details to issue the invoice and send it to you, never your card number. Your messages: what you write in the contact form (name, email, message) reaches us by email so we can answer; questions asked to the assistant are sent to the provider of the AI model (see Processors) to generate the answer, and Vybel does not keep them. Sending a report by email: your address is kept with the reference of the report sent, as a record of that email; if you tick the box provided, it is also used to send you the tips and offers of Vybel. Clicks in our emails: the links in our emails go through our email provider, which counts clicks to measure the reach of our emails; nothing is read on your device.

GitHub or GitLab connection

If you connect GitHub, Vybel only reads the repositories you chose on GitHub, read-only. Each analysis uses a token valid for one hour, limited to the analyzed repository; the copy of the code is deleted at the end of the analysis. Your connection token is stored encrypted; “Disconnect GitHub” revokes it, and you can remove the app at any time in your GitHub settings. If you connect GitLab, Vybel reads your projects read-only with your connection token, stored encrypted and renewed automatically; “Disconnect GitLab” revokes it, and you can withdraw the access of Vybel at any time in your GitLab settings.

Legal bases

The analysis, sending a report by email, the management of your account, the alerts and the recap rely on the performance of the service you request; the waitlist and our tips and offers rely on your consent, which you can withdraw at any time in one click. Invoicing of paid analyses relies on our legal obligations.

Retention

Code is deleted as soon as the analysis ends. Reports are kept while the service is running and deleted on request. Account data is kept while the account is active: you can delete it at any time from “My account”. Waitlist addresses are kept until your access opens or until you unsubscribe. Addresses a report was sent to are kept three years at most after the last email; if you agreed to our tips and offers, until you unsubscribe, and three years at most without any exchange with you. Invoices are kept for 10 years, as the law requires. Contact messages are kept while we handle your request, then three years at most.

Security

Traffic is encrypted (HTTPS/TLS). Sign-in codes, sessions and API keys are never stored in plain text.

Your rights

Under the GDPR, you can access, correct, erase or export your data, object to its processing or restrict it by writing to contact@onvaou.app. You can also lodge a complaint with the data protection authority of your country.

Processors

Hosting: Railway (servers in Europe). Email delivery: Resend. Payments: Stripe (Stripe Payments Europe, Ireland). No data is ever sold or shared with third parties.

Cookies

The Vybel website uses no advertising cookies and no audience measurement cookies. Only technical cookies are set: chosen language, sign-in session and anonymous identification of the analyses started from your browser.

Changes

This policy may change; the current version is always available on this page.