Legal

Privacy Policy

Effective September 11, 2026. This describes what Vitalgate ("we," "us") actually collects when you use vitalgate.vercel.app, not a generic template — if we don't do something below, we don't do it.

1. What we collect

Account info. When you sign in with GitHub, Better Auth (our authentication library) stores your name, email, and avatar URL as given to us by GitHub — we never see your GitHub password.

Organization and team data. Your workspace name, slug, and the list of members and their roles.

Repository metadata. The repositories you connect (name, default branch, whether it's private) and the performance budgets you set for them. We never store your source code — see "Where your code runs" below.

Performance data. The Lighthouse metrics (LCP, INP, CLS, and similar) your connected repos report per pull request, along with the PR's number, title, author, and branch name.

Integration data. If you connect Slack or Discord, we store the webhook URL for your chosen channel, encrypted at rest. We don't read your Slack or Discord messages.

Session data. To keep you signed in and detect suspicious activity, we store your session token, IP address, user-agent string, and sign-in timestamps. You can view and revoke these yourself from Settings → Security.

Contact form submissions. If you use the contact form, we receive the name, email, and message you submit, relayed to us by email.

2. Where your code runs

Lighthouse audits run on your own GitHub Actions runner, using the workflow file Vitalgate commits to your repository. Your application never gets built, started, or executed on our infrastructure — only the resulting metrics (numbers, not code) are sent back to us over a signed request.

3. How we use it

To run the product: authenticate you, enforce your budgets, show your dashboard, and send the alerts you've enabled (by email, Slack, or Discord). To respond when you contact us. We don't use your data for advertising, and we don't run any analytics or ad-tracking scripts on this site.

4. Who we share it with

We don't sell your data. It's processed by:

  • GitHub — for sign-in and to read/write the repos you connect.
  • Neon — our Postgres database host, where the data above is stored.
  • Vercel — hosts this application.
  • Resend — delivers email alerts, the weekly digest, and contact form messages.
  • Slack / Discord — only if you connect them, to deliver the alerts you configure.

5. How long we keep it

We keep your data while your account and organization are active. Disconnecting a repository deletes its budgets, pull request history, and alerts immediately. We don't yet have a self-service "delete my account" button — use the contact form (see section 11) and we'll delete your account and personal data by hand, usually within a few days.

6. Security

Traffic to this site is encrypted (HTTPS/HSTS). Slack/Discord webhook URLs are encrypted at rest (AES-256-GCM) rather than stored as plain text. Passwords, where you set one, are hashed, never stored in plain text.

7. Cookies

We use one cookie to keep you signed in. That's it — no advertising cookies, no third-party tracking pixels.

8. Your rights

You can review and revoke your own active sessions from Settings → Security at any time. For anything else — access, correction, export, or deletion of your data — use the contact form. We'll respond within a reasonable time, generally within 30 days.

9. Children

Vitalgate is a developer tool for teams and isn't directed at, or knowingly used by, children under 16.

10. Changes to this policy

If we materially change what we collect or how we use it, we'll update the effective date at the top of this page.

11. Contact

Questions about this policy or your data? Use the contact form.