VibeCodeStorage
Last updated 6 October 2026

Privacy Notice

Halfpenny Technologies Limited operates VibeCodeStorage and is responsible for the personal data it uses to run the website, secure the service and answer enquiries. Company number: 17287043. Registered office: 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom. Contact contact form for privacy questions.

What we process

No name, email address or payment details are requested to create a store. The API stores encrypted record envelopes, opaque record identifiers, store identifiers, a hash of the access token, creation and expiry dates, revision numbers, storage usage, last successful activity time and request counters. The official SDK keeps the encryption key on your device; we do not receive it. Encryption does not make all associated metadata anonymous.

Connections expose technical information such as IP addresses, request paths, timestamps and response status to our infrastructure providers. The application uses connection information for temporary rate limits and does not intentionally log request bodies or credentials. If you use our contact form, we receive your email address, optional name, chosen topic and message. If you opt into the pilot, your voluntary check-ins and agreed follow-up help us understand setup difficulties and repeat use; we track these separately from anonymous store totals. These messages are stored as readable correspondence in our private admin inbox, separately from encrypted customer records. Do not send encryption keys, access tokens or private exports.

Optional service notices

If you choose service notices, we store your email, request and confirmation times, and confirmation/unsubscribe token hashes separately from stores. We use these details with your consent to send confirmation and important service notices through Resend. No marketing is included. Confirmation links expire after 24 hours; unconfirmed requests are removed on subsequent requests or hourly cleanup. Confirmed subscriptions remain until you unsubscribe or the mailing list closes. Unsubscribing removes the active subscription; backup copies may remain until they expire. Resend processes recipients, message contents and delivery information under its privacy policy. You can withdraw consent through the link in your email. Email signup does not prove ownership or recover store credentials.

Why we use it

We use store and request information to provide the service and enforce its limits, based on performance of our agreement with you where applicable. We rely on legitimate interests in operating a secure, reliable service for abuse prevention, technical troubleshooting and responding to ordinary enquiries. We may also process information to meet legal obligations. We do not sell personal data or use stored content for advertising or AI training.

Providers and international processing

The API runs on Render in Frankfurt, Germany. Cloudflare provides domain and DNS services. These providers may process technical information through their global systems, including outside the UK. We also use an email provider to handle correspondence. Provider processing is subject to their applicable terms and privacy arrangements; a Frankfurt deployment does not mean all support or technical data stays in Germany.

See Render's privacy policy and Cloudflare's privacy policy for their processing information. We may disclose information where legally required or necessary to protect the service. This pilot is not offered for storing other people's personal information or workloads requiring a data-processing agreement.

Retention and deletion

Stored records remain in the active database until you delete them, destroy the store, or we remove them for operational, legal or abuse reasons. Automatic deletion at expiry is not implemented. Store deletion removes its active database records; SQLite journals, disk snapshots and provider backups may retain copies until overwritten or expired. We cannot promise immediate removal from every provider backup.

Daily aggregate traffic, error counts and request timings are retained for up to 90 days; these aggregates contain no store identifiers or record contents. Last successful activity time is retained with each store until deletion. Request counters are retained as part of store metadata; monthly usage counters reset with a new month when a metered request is made. Rate-limit windows are held in memory and expire or reset on restart. Provider technical-log retention is controlled by the applicable hosting service. Contact-form messages are deleted from the active inbox after 90 days by an hourly cleanup. Application-consistent backups retain up to three daily copies, and provider backups may retain copies until they expire. Any subsequent email correspondence is retained only as long as needed to handle the enquiry and related legal or security issues.

Cookies and local storage

This website does not add analytics, advertising cookies or tracking scripts. Hosting providers may process connection information to deliver and protect it. The CLI saves store credentials locally on your device; it is your responsibility to protect those files. Linked sites such as npm and GitHub have their own privacy practices.

Your choices and rights

Depending on the circumstances, you may request access, correction, deletion, restriction or portability of your personal data, and object to processing based on legitimate interests. Contact us to make a request. We may need proportionate verification, but do not send secret credentials. Anonymous stores and encryption can limit what we can identify or recover; store data can be exported or deleted using your own credentials.

You can complain to the UK Information Commissioner's Office or another applicable supervisory authority. We do not make decisions with legal or similarly significant effects about individuals using automated profiling. The service is intended for adults, not children.

Updates

We will update this notice when our processing changes and show the updated date here. Material changes will be highlighted on the website where practical.

Provisional stores and retries

New stores that have not received a successful write are removed after four hours. For up to seven days we retain hashed creation-request identifiers and expired credential hashes to handle retries and explain expiry; no encryption keys are retained. Hourly aggregate provisioning outcomes are retained for 30 days. Temporary copies may remain in backups until those expire.

Share-link records

For new scoped share links, the API stores hashed access tokens and creation-request identifiers, the permission, creation and expiry times, and revocation time. It does not store the link’s encryption key. Expired grant records are eligible for removal seven days after expiry during later share creation; store deletion removes them from the active database. Backup copies may remain until backup retention expires. Share links are secrets; do not send them in support messages.

Auth preview

When enabled, we process app names, callback addresses, public app IDs, opaque customer IDs, passkey public keys and counters, hashed sessions and recovery/reset tokens, and record metadata. We do not receive passkey private keys or biometric readings. Customer-private data arrives encrypted and data keys remain with customers; app-managed content is decrypted by the service for authorised requests and values are encrypted at rest with a service-held key. App-managed record names remain visible. App operators may access content through scoped support grants.

Sign-in flows and authorization codes expire after five minutes; sessions after one hour; support grants and reset links after 15 minutes. Account/credential/data records remain until verified deletion or service closure. Support/reset audit events, including account IDs, actions and operator-supplied reasons, are retained for 90 days. Do not put customer content in those reasons. Backups can retain earlier copies under the backup policy. The Auth flow uses a short-lived, secure HttpOnly sign-in cookie. The browser client stores sessions in sessionStorage and optionally remembers customer-private data keys in localStorage. No customer email is collected by this Auth release. Contact us for account deletion; do not send secret credentials.