Your application.
Our storage infrastructure.
VibeCodeStorage provides a hosted encrypted-storage API and optional client libraries and UI components.
The developer's application
The app operator deploys the application, chooses its audience and features, and controls the user experience and access rules. Shared user accounts, identity verification, authentication and application-level authorization are the operator's design decisions. A share token is a bearer permission; it does not identify a person.
The storage service
Halfpenny Technologies Limited operates the API, stores encrypted records, and enforces store and share-token permissions, quotas, expiry and revocation. The main SDK and Connect encrypt before upload. Auth customer-private mode also keeps keys with customers; app-managed Auth lets the service decrypt authorised requests using service-held keys. App operators can use the API directly or deploy our optional components on their own origin.
Our hosted example is ours
The notebook on our Connect page is a demonstration application operated by Halfpenny Technologies Limited. It uses real pilot storage. Its operator is distinct from the operators of independently deployed apps.
Sharing and security
New share links use separate read-only or editing tokens, with expiry and owner-controlled revocation. Neither grants store deletion or link-management rights. Recipients still receive the encryption key, and can retain downloaded data. Old owner-credential links are not retroactively revoked.
Legal scope follows the actual service
Each operator must assess the obligations applicable to the service it actually provides, including its functionality, audience and control. This architectural description is not a claim of exemption from the Online Safety Act or a transfer of statutory duties. We must assess our own API and hosted examples; developers must assess their deployed applications. Seek appropriate advice for your particular service.
Does your app need customer accounts?
Use the Auth preview for passkey sign-in and per-customer records. Choose customer-private encryption or app-managed data with authorised support access. Check hosted availability before setup. Use Connect for account-free browser storage, or the Node SDK on a trusted backend.