Terms & privacy
Plain language, because that’s the whole point of the tool. Last updated 21 August 2026.
How it works
vibecheck is a self-scan tool: you point it at your own app and it shows you what a stranger can already see. It performs no attacks — no injection, no authentication bypass, no writes, and no attempt to reach anything private.
- ·The URL checks read only publicly-accessible content — the same pages, headers, and files any visitor, browser, or search crawler can already fetch.
- ·The database check runs entirely in your own browser, using the anon/public key your app already ships. It mirrors exactly what any anonymous visitor can read — a mirror, not an exploit. Your key and your data never reach our servers.
- ·A public GitHub repo is read from its public source; a mobile app you upload is unzipped and scanned in your browser and never leaves your device.
Acceptable use
Only scan applications you own or are explicitly authorized to test. You are responsible for your use of vibecheck and for having the right to scan any target you enter. Do not use it to probe, attack, or gain unauthorized access to systems you do not control. It exists for checking your own apps and for legitimate, authorized security testing.
Privacy
- ·We store nothing about your scan — not the URL you entered, not your keys, not the findings — unless you press Save.
- ·If you do press Save, we store that one report: the site’s hostname, the grade, the counts and the findings, at an unlisted link nothing on this site links to or indexes. We never store your keys. It is deleted automatically after 90 days, and anyone who has the link can read it — so send it to your team rather than posting it.
- ·The database probes run client-side, so your keys and data never touch our servers.
- ·We use privacy-friendly, cookieless analytics (Vercel Web Analytics). No cookies, no cross-site tracking, no personal data, no account.
- ·When a scan finishes we count the shape of the result: the scan mode, the grade, how many checks passed and failed, which backend family the app uses (Supabase, Firebase, both, or none), and a yes/no for each kind of problem — was a database reachable, was any table readable by an anonymous key, were dev artifacts served, and so on. We never record the URL, your keys, hostnames, table or column names, file paths, or row counts. That is not a promise about our intentions: the rule is that every recorded value must be a yes/no, a number, or one of a few fixed words — which no hostname or table name can be — and it is enforced in code and covered by tests you can read in lib/scan/telemetry.ts.
- ·Why we count it: so we can eventually publish aggregate findings — “of N apps scanned, X% exposed at least one table to an anonymous key”. Nobody can answer that today. It only works if the counting happens as scans run, because we keep nothing to go back and mine. Counts only, never an app.
- ·No signup. The only personal data we ever store is your email, and only if you volunteer it to join the optional monitoring waitlist — used solely to email you about that feature.
No warranty, not advice
vibecheck is provided “as is”, without warranty of any kind. Its findings are observations from the outside — not a penetration test, and not security, legal, or compliance advice. A clean result does not guarantee your app is secure. Use your own judgment and, where it matters, a professional review.
Open source
vibecheck is free and open source (MIT) — you can read exactly what it does and self-host it: github.com/FedericoTs/vibecheck.
Contact
Built by Federico Sciuca. Questions: federicosciuca@droplab.io.