Privacy
It reads your code. Here is exactly what happens to it.
A tool that reads source code owes you a straight answer about what it keeps. This is ours, written before launch so it is on the record rather than discovered afterwards.
| Access requested | Read-only. VibeCaddie never needs write access, and will not ask for it. |
|---|---|
| What it reads | The contents of the repositories you point it at, at the commit you run against. |
| What is stored | The report: findings, file paths, line numbers and the short excerpts quoted in them. |
| What is not stored | A copy of your repository. Source is read for the run and discarded when it ends. |
| Training | Your code is never used to train a model. Not ours, not a vendor’s. |
| Model providers | Audits run through a third-party model API under a zero-retention agreement. The provider is named in the docs before launch. |
| Who can see a report | You, and anyone you give access to the repository. Reports are not public and are not shared. |
| Deletion | Deleting a report deletes its findings and excerpts. Removing the app ends all access immediately. |
None of the above is live yet, because nothing has shipped. It is a commitment about how the product will behave, published now so it can be held against what launches.
Read-only is not a setting. It is the design.
VibeCaddie reports; you change the code. That division is why it never needs write access, and why removing it ends its access completely rather than leaving something behind.
If a future feature genuinely needed write access, it would be a separate, opt-in permission that you grant deliberately. It would not arrive by widening this one.
Security contact: [email protected], also published at /.well-known/security.txt.
Did you run it through a caddie?
The GitHub app is not built yet. Nothing here can be installed or bought. Leave an address and we will write when there is something to try.