Pre-launch. The GitHub app is not built yet. Nothing here can be installed or bought.

Privacy

It reads your code. Here is exactly what happens to it.

A tool that reads source code owes you a straight answer about what it keeps. This is ours, written before launch so it is on the record rather than discovered afterwards.

Access requestedRead-only. VibeCaddie never needs write access, and will not ask for it.
What it readsThe contents of the repositories you point it at, at the commit you run against.
What is storedThe report: findings, file paths, line numbers and the short excerpts quoted in them.
What is not storedA copy of your repository. Source is read for the run and discarded when it ends.
TrainingYour code is never used to train a model. Not ours, not a vendor’s.
Model providersAudits run through a third-party model API under a zero-retention agreement. The provider is named in the docs before launch.
Who can see a reportYou, and anyone you give access to the repository. Reports are not public and are not shared.
DeletionDeleting a report deletes its findings and excerpts. Removing the app ends all access immediately.

None of the above is live yet, because nothing has shipped. It is a commitment about how the product will behave, published now so it can be held against what launches.

Read-only is not a setting. It is the design.

VibeCaddie reports; you change the code. That division is why it never needs write access, and why removing it ends its access completely rather than leaving something behind.

If a future feature genuinely needed write access, it would be a separate, opt-in permission that you grant deliberately. It would not arrive by widening this one.

Security contact: [email protected], also published at /.well-known/security.txt.

Did you run it through a caddie?

The GitHub app is not built yet. Nothing here can be installed or bought. Leave an address and we will write when there is something to try.