Information we collect
We collect account information supplied by you or your sign-in provider, such as your name, email address, profile image, and authentication identifiers. We store the projects, subscriptions, budgets, usage entries, people labels, and settings you add to Vibe Costs.
If you connect a supported provider, we store the credential encrypted at rest and use it only to request the billing or usage information you asked us to retrieve. Restricted inbound tokens are stored as one-way hashes. We retain masked hints, such as the last four characters, so you can identify a connection without exposing the credential.
We also process basic operational information such as IP addresses, request timing, client-error reports, and service logs to secure and operate the service. Stripe supplies payment and subscription identifiers; Vibe Costs does not store full card details.
How we use information
- Authenticate your account and keep each customer’s data separate.
- Calculate spend, renewals, budgets, project attribution, and dashboard views.
- Fetch data from providers you deliberately connect.
- Process subscriptions, prevent abuse, diagnose errors, and protect the service.
- Send essential account, authentication, billing, or support messages.
Service providers
We use service providers only where needed to operate Vibe Costs: Stripe for billing; Google, GitHub, and an email provider for authentication; Hetzner for application hosting; and Cloudflare for network delivery and encrypted backups. A provider you connect receives the credential and request necessary to return your billing data under your existing relationship with that provider.
Cookies and local storage
Vibe Costs uses essential authentication cookies. We also remember functional preferences such as timezone, theme, and the sign-in method you last used. We do not currently use advertising cookies or sell browsing profiles.
Retention and deletion
Your active account data is retained while your account remains open. You can export your data from Settings. To delete your account and associated data, contact us through the support page from the account address. Deleted data can remain in encrypted disaster-recovery backups for up to 72 hours before expiring through the normal backup cycle.
Security
We use HTTPS, tenant-scoped database operations, encrypted credential storage, signed Stripe webhooks, rate limits, and restricted provider credentials where supported. No internet service can promise absolute security. Please report a suspected issue through the support page.
Your choices
You may request access, correction, export, or deletion of personal information by contacting us. Depending on where you live, additional privacy rights may apply. We will verify requests using the account email or another appropriate method.
Changes and contact
We may update this policy as the service changes. Material changes will be dated here and, when appropriate, communicated in the product. Send questions and privacy requests through the support page.