1. Information we process
Supabase Auth processes your email, hashed authentication credential, session, and recovery requests. Vyben stores the projects, tiles, connections, instructions, snippets, agent assignments, and settings that you create, with some workspace data cached on your device for offline use.
A remote coding job includes the selected repository, base branch and commit, your instruction, execution settings, status events, usage, test summaries, changed-file metadata, and resulting review branch or pull-request references. GitHub-hosted Actions checks out the selected repository in an ephemeral runner and may send relevant prompts and code context to the AI provider you select.
The coding job cannot push. A separate finalisation job validates the
bounded patch and may push only an isolated
vyben/<job-id> branch. Vyben does not merge your
default branch, and opens a draft pull request only after your
explicit approval. Handoff artifacts are configured for one-day
retention.
Provider API keys are encrypted in Supabase Vault and used only on the server. The runner receives a short-lived job token, not your provider key. Prompts and relevant code are processed under the selected AI provider's terms; Vyben does not train its own models on them.
GitHub data includes App installation and repository identifiers, permissions, branch and commit references, workflow runs, and pull requests. Short-lived user authorisation verifies your installations and is not retained after connection. Installation tokens are minted when needed and are not stored in the database.
Apple, Google, RevenueCat, and Stripe process subscriptions. Vyben does not store complete card or bank details. Limited security data such as timestamps, request identifiers, error codes, rate-limit counters, and IP-derived infrastructure information is used to operate and protect the service, never for advertising or cross-app tracking.
2. Why we use it
- Create and secure accounts and synchronise workspaces.
- Connect repositories and run only the jobs you request.
- Show progress, comparisons, audit history, and draft PRs.
- Manage subscriptions, support, deletion, and abuse prevention.
3. Service providers
| Provider | Purpose |
|---|---|
| Supabase | Authentication, database, Realtime, Vault, and private artifacts |
| GitHub | App access, repositories, Actions, review branches, and draft PRs |
| Selected AI provider | Generation requested by you |
| Apple, Google, RevenueCat, Stripe | Payments and entitlement reconciliation |
| Hosting and email providers | API, website, security, email, and support delivery |
4. Security and retention
We use TLS, Row Level Security, encrypted credential storage, platform-secure token storage, short-lived scoped credentials, and bounded remote execution. Workspace and remote-job records remain while your account is active unless deleted sooner. Billing and security records may be retained where reasonably required for disputes, fraud prevention, reconciliation, or law.
5. Deletion and choices
You can edit your workspace, remove provider keys, disconnect the GitHub App, manage permissions and subscriptions, request an export, and delete your account in the app. Deletion removes active Vyben account content, subject to provider and backup retention. Existing GitHub branches or PRs remain in your repository. Stripe billing is cancelled during account deletion; App Store and Play Store subscriptions must also be managed in the store that sold them.
6. Children, transfers, and tracking
Vyben is not directed to children under 13. Providers may process data in other countries under their applicable safeguards. Vyben does not track users across other companies' apps or sites for advertising and does not use App Tracking Transparency identifiers.
7. Changes and contact
Material changes will be dated here and notified where required. For privacy, export, or deletion questions, email hello@vyben.app or visit support.
This policy covers the Vyben app with bundle identifier
app.vyben.mobile and its cloud services.