Privacy Policy
Last updated: January 2026
1. Core Architecture Guarantee
CoreVibbe is engineered under a zero-execution paradigm. Uploaded project archives (.zip) are extracted exclusively into temporary server memory. We never execute uploaded code, install npm/pip dependencies, run build scripts, or trigger arbitrary binaries.
2. Automatic Pre-AI Secret Redaction
Before any project information is processed by our rule engines or sent to Gemini AI for contextual analysis, our local sanitization engine scans for and redacts API keys, database connection strings, JWT secrets, passwords, and private key blocks.
3. Information We Collect
When creating an account, we store your email address, name, and a secure bcrypt hash of your password. We store generated audit metadata (framework, health score, finding summaries) when you explicitly save a report.
4. Your Data Rights
You have full ownership of your reports. You can delete saved audits at any time from your dashboard, which permanently removes the audit record from our PostgreSQL database.