Information we collect
We collect account information supplied by you or your sign-in provider, such as your name, email address, profile image, and authentication identifiers. We store the projects, subscriptions, budgets, usage entries, people labels, and settings you add to Vibe Costs.
If you connect a supported provider, we store the credential encrypted at rest and use it only to request the billing or usage information you asked us to retrieve. Restricted inbound tokens are stored as one-way hashes. We retain masked hints, such as the last four characters, so you can identify a connection without exposing the credential.
If you request a future provider connection, we store the provider, request time, and whether you separately consented to an introduction. Public connector-demand counts are aggregated and never include your name or email. Introduction permission is optional and can be withdrawn from the connector ledger.
We also process basic operational information such as IP addresses, request timing, client-error reports, and service logs to secure and operate the service. Stripe supplies payment and subscription identifiers; Vibe Costs does not store full card details.
How we use information
- Authenticate your account and keep each customer’s data separate.
- Calculate spend, renewals, budgets, project attribution, and dashboard views.
- Fetch data from providers you deliberately connect.
- Aggregate explicit connector requests and, only with your consent, arrange a provider introduction.
- Process subscriptions, prevent abuse, diagnose errors, and protect the service.
- Send essential account, authentication, billing, or support messages.
Service providers
We use service providers only where needed to operate Vibe Costs: Stripe for billing; Google and GitHub for optional authentication; Hetzner for application hosting; and Cloudflare for network delivery. Passkey private keys and biometric checks remain on your device or chosen passkey provider. A provider you connect receives the credential and request necessary to return your billing data under your existing relationship with that provider. The current production inventory is published on our subprocessors and service providers page.
Cookies and local storage
Vibe Costs uses essential authentication cookies. We also remember functional preferences such as timezone, theme, and the sign-in method you last used. We do not currently use advertising cookies or sell browsing profiles.
Retention and deletion
Current projects, subscriptions, budgets, settings, and active connections remain while your account is open. Expired authorization handoffs are removed within 24 hours; connector diagnostics and expired machine grants within 90 days; balance observations within 400 days; security history within two years; and normalized financial history within seven years. We do not retain raw provider response bodies.
You can export or permanently delete your account from Settings. Deletion requires a recent passkey confirmation, cancels Vibe Costs billing, attempts to revoke connected OAuth grants, and removes the live account and its credentials, ledger, balances, projects, agents, and audit history. Vibe Costs does not currently retain an off-server production backup; this policy will be updated before encrypted disaster-recovery backups are activated.
Security
We use HTTPS, tenant-scoped database operations, encrypted credential storage, signed Stripe webhooks, rate limits, and restricted provider credentials where supported. No internet service can promise absolute security. Please report a suspected issue through the support page.
Your choices
You may request access, correction, export, or deletion of personal information by contacting us. Depending on where you live, additional privacy rights may apply. We will verify requests using the account email or another appropriate method.
Changes and contact
We may update this policy as the service changes. Material changes will be dated here and, when appropriate, communicated in the product. Send questions and privacy requests through the support page.