Privacy Policy
Last updated: 4 October 2026
This notice, provided under Articles 13 and 14 of Regulation (EU) 2016/679 (GDPR), explains how we process the personal data of people who visit codemyvibeapp.com and of people who use the CodeMyVibe platform at app.codemyvibeapp.com, its apps and the preview sites at previewmyvibe.com.
Data controller
The data controller is CodeMyVibe, VAT number IT 06422300654. For any privacy question and to exercise your rights, write to [email protected].
What data we process
- Browsing data: IP address, date and time, requested page, browser and operating system, automatically recorded by the server in technical logs.
- Account data: name, email, password (stored only in encrypted, non-reversible form), language and preferences; if you sign in with Google, also your Google account identifier and profile picture.
- Content: the requests you write in the chat, the images and screenshots you attach, project files, generated images and the data you enter in your projects' backend.
- Usage data: projects, credits used, plan, access dates and invitations received through the Invite and earn programme.
- Integrations: the GitHub, GitLab or Bitbucket tokens you choose to connect, stored encrypted.
Why we process it and on what legal basis
- Providing the service you request: account, building projects, previews, publishing, exporting and support. Legal basis: performance of a contract (Art. 6(1)(b) GDPR).
- Protecting the service: security, prevention of abuse and fraud, technical operation of the site. Legal basis: legitimate interest (Art. 6(1)(f) GDPR).
- Improving the service and supporting you: internal statistics and internal notifications to our staff about use of the platform. Legal basis: legitimate interest (Art. 6(1)(f) GDPR).
- Complying with legal, accounting and tax obligations. Legal basis: legal obligation (Art. 6(1)(c) GDPR).
We do not use your data for advertising or profiling, and we do not sell it to anyone.
Artificial intelligence
To build your projects, the requests you write, the images you attach and the necessary files are sent to artificial intelligence models through Cloudflare AI Gateway. The model providers (for example Google, Anthropic and OpenAI) process them to generate the response, in accordance with their terms for API use. Please do not include personal data about other people or special categories of data (for example health data) in your requests unless strictly necessary.
Who we share data with
Data is processed by us and by providers who help us deliver the service, appointed as data processors (Art. 28 GDPR) or acting as independent controllers for their own services:
- Aruba S.p.A. (Italy): servers on which the service runs and the data is stored;
- Cloudflare, Inc.: domain management (DNS) and connection to the artificial intelligence models;
- the artificial intelligence model providers reached through Cloudflare;
- Google: only if you choose "Continue with Google";
- GitHub, GitLab and Atlassian (Bitbucket): only if you connect a repository, to send your project files to it;
- Telegram: internal service notifications to our staff (account name and email, and usage events);
- advisers and public authorities, where required by law.
Transfers outside the European Union
Some providers are based in the United States. In these cases the transfer takes place on the basis of the EU-U.S. Data Privacy Framework or the standard contractual clauses approved by the European Commission.
How long we keep data
- Technical server logs: 14 days.
- Account, projects and content: as long as the account remains active. After the account is closed they are deleted; backup copies are overwritten within 14 days.
- Billing data, if any: for the period required by law (10 years).
Sites and apps you create with CodeMyVibe
For the data of users of the sites and apps you create (for example sign-ups and content saved in the project backend), you are the data controller: CodeMyVibe processes it on your behalf, as data processor, solely to provide you with the service. The sites you create have their own Privacy Policy, which you can complete with your business details.
Your rights
You can at any time request access to your data, rectification, erasure, restriction of processing and portability, and object to processing based on legitimate interest (Articles 15-22 GDPR), by writing to [email protected]. You can also ask for your account to be closed and your data deleted. If you believe the processing is not lawful, you can lodge a complaint with the Italian Data Protection Authority (Garante per la protezione dei dati personali) (www.garanteprivacy.it) or with the authority in your country.
Security
Connections are always encrypted (HTTPS), passwords and integration tokens are stored encrypted, access to the servers is restricted and data is backed up.
Minors
The service is intended for people aged 18 or over. We do not knowingly collect data from minors.
Changes
We may update this notice when the service changes. The date of the last update is shown at the top; we will notify you in the platform of any significant changes.