Back to Vibe Architect
Privacy Policy

How Vibe Architect handles your data

Last updated: 10 March 2026 · This is a temporary policy for the MVP phase. A full policy will follow before commercial launch.

1.

Data Controller

Vibe Architect is operated as an independent product. For data-related enquiries, contact us at support@kozo.one.

2.

What We Process

When you upload a codebase for scanning, we extract and process metadata only. This includes:

  • File paths and file names
  • Line counts per file
  • Language detection results (e.g. TypeScript: 80%, Python: 20%)
  • Dependency lists from package.json / pyproject.toml
  • Test file ratios and folder depth metrics
  • Presence or absence of security-relevant files (e.g. .env.example)

We never process, store, or transmit your source code.

Your actual code contents are read locally in your browser and discarded immediately. Only the extracted metadata is sent to our servers.

3.

Where We Process

All server-side processing takes place exclusively on infrastructure located in Frankfurt, Germany (EU), operated via Vercel and Supabase. Your metadata does not leave the EU except as described in Section 4.

4.

AI Processing

Extracted metadata (not source code) is passed to Claude (Anthropic) to generate your debt score, refactor roadmap, and AI constitution. Anthropic may process this data on servers located in the United States under standard contractual clauses (SCCs) in accordance with GDPR Article 46. No personally identifiable code, credentials, or source content is included in these requests.

5.

Retention

Scan metadata and generated constitutions are retained for 90 days from the date of creation, after which they are automatically and permanently deleted. You may delete any scan or constitution from your account at any time before that date.

6.

Your Rights (GDPR)

As a data subject under the GDPR, you have the right to:

  • Access the personal data we hold about you
  • Request correction of inaccurate data
  • Request deletion of your data at any time
  • Data portability — receive your data in a structured, machine-readable format
  • Object to processing based on legitimate interests
  • Lodge a complaint with your national supervisory authority

To exercise any of these rights, contact support@kozo.one. We will respond within 30 days.

7.

Cookies

We use essential cookies only — specifically the session cookie required to keep you logged in. We do not use tracking cookies, advertising cookies, or any third-party analytics that set cookies without your explicit consent.

8.

Changes to This Policy

This is a temporary privacy policy for the MVP phase. A full, legally reviewed policy will replace it before any commercial launch. We will notify users of material changes via email at least 14 days before they take effect.

Questions? Email support@kozo.one