Privacy Policy
Effective September 11, 2026. This describes what Vitalgate ("we," "us") actually collects when you use vitalgate.vercel.app, not a generic template — if we don't do something below, we don't do it.
1. What we collect
Account info. When you sign in with GitHub, Better Auth (our authentication library) stores your name, email, and avatar URL as given to us by GitHub — we never see your GitHub password.
Organization and team data. Your workspace name, slug, and the list of members and their roles.
Repository metadata. The repositories you connect (name, default branch, whether it's private) and the performance budgets you set for them. We never store your source code — see "Where your code runs" below.
Performance data. The Lighthouse metrics (LCP, INP, CLS, and similar) your connected repos report per pull request, along with the PR's number, title, author, and branch name.
Integration data. If you connect Slack or Discord, we store the webhook URL for your chosen channel, encrypted at rest. We don't read your Slack or Discord messages.
Session data. To keep you signed in and detect suspicious activity, we store your session token, IP address, user-agent string, and sign-in timestamps. You can view and revoke these yourself from Settings → Security.
Contact form submissions. If you use the contact form, we receive the name, email, and message you submit, relayed to us by email.
2. Where your code runs
Lighthouse audits run on your own GitHub Actions runner, using the workflow file Vitalgate commits to your repository. Your application never gets built, started, or executed on our infrastructure — only the resulting metrics (numbers, not code) are sent back to us over a signed request.
3. How we use it
To run the product: authenticate you, enforce your budgets, show your dashboard, and send the alerts you've enabled (by email, Slack, or Discord). To respond when you contact us. We don't use your data for advertising, and we don't run any analytics or ad-tracking scripts on this site.
4. Who we share it with
We don't sell your data. It's processed by:
- GitHub — for sign-in and to read/write the repos you connect.
- Neon — our Postgres database host, where the data above is stored.
- Vercel — hosts this application.
- Resend — delivers email alerts, the weekly digest, and contact form messages.
- Slack / Discord — only if you connect them, to deliver the alerts you configure.
5. How long we keep it
We keep your data while your account and organization are active. Disconnecting a repository deletes its budgets, pull request history, and alerts immediately. We don't yet have a self-service "delete my account" button — use the contact form (see section 11) and we'll delete your account and personal data by hand, usually within a few days.
6. Security
Traffic to this site is encrypted (HTTPS/HSTS). Slack/Discord webhook URLs are encrypted at rest (AES-256-GCM) rather than stored as plain text. Passwords, where you set one, are hashed, never stored in plain text.
7. Cookies
We use one cookie to keep you signed in. That's it — no advertising cookies, no third-party tracking pixels.
8. Your rights
You can review and revoke your own active sessions from Settings → Security at any time. For anything else — access, correction, export, or deletion of your data — use the contact form. We'll respond within a reasonable time, generally within 30 days.
9. Children
Vitalgate is a developer tool for teams and isn't directed at, or knowingly used by, children under 16.
10. Changes to this policy
If we materially change what we collect or how we use it, we'll update the effective date at the top of this page.
11. Contact
Questions about this policy or your data? Use the contact form.