Privacy Policy
Last updated: August 15, 2026
This Privacy Policy explains how Super Vibe ("we", "us", "our") handles information when you use this website and the Super Vibe Chrome extension (together, the "Service"). Super Vibe is an AllThingsGHL product. The short version: your credentials stay in your browser, your code content never reaches us, and we don't sell data.
1. Information We Collect
Signup Information
When you request a free license key we collect your email address and, if you choose to give it, your name. That's the whole form. We use these to send your key, to greet you by name in the welcome email, and to send occasional product updates you can opt out of.
Your HighLevel Session — Never Stored
AI Studio runs inside a frame on HighLevel's own pages, and its authentication token is created inside that frame. When you run an operation, the extension reads that token from the requests AI Studio's own app is already making, inside that frame — it never creates a token of its own, and it never sees your HighLevel password. The token lives only in that frame's memory for the duration of a call. It is never written to disk, never stored by the extension, and never transmitted to us or to anyone other than HighLevel's own servers, where it was already going.
Your GitHub Token — Stored Locally, Only Locally
Connecting GitHub stores a GitHub access token in your browser's local extension storage on your computer. It is used to read and write the repositories you selected, directly between your browser and GitHub. It is never sent to us. Disconnecting removes it from this computer; to revoke it everywhere, remove Super Vibe in your GitHub settings.
Usage Telemetry — Counts, Not Content
To know whether the product works and where it fails, the extension reports basic operation telemetry to us:
- The operation type (save to GitHub, bring into HighLevel, or a check)
- The compatibility verdict (supported, needs review, unsupported) and which checks fired
- Project and repository names
- Counts — files moved, warnings shown, whether a build succeeded
Telemetry never includes the content of your code — no file contents, no environment values, no commit contents. Your source code moves directly between your browser, GitHub, and HighLevel; it does not pass through our servers.
Website Analytics
On this website we may collect basic, consent-gated analytics: pages visited and general usage. The cookie banner controls this; declining keeps analytics off. We do not use advertising pixels or tracking SDKs.
2. How We Use Your Data
- Provide the Service — issue and validate your license key, and diagnose failed operations from telemetry when you ask for help.
- Improve the product — aggregate verdicts and failure counts tell us which project shapes to support next. We never read your code, because we never have it.
- Communicate with you — deliver your key and send product emails. Every marketing email has an unsubscribe link that works.
- Enforce terms — detect abuse of the free key system.
3. Chrome Extension Privacy
The Super Vibe Chrome extension:
- Does not track your browsing activity — it acts only when you open it and run an operation
- Does not collect your HighLevel or GitHub passwords, ever
- Does not store your HighLevel session token — it is read in-memory from AI Studio's own requests and discarded
- Does not send your code, files, or environment values to our servers
- Does not inject ads, trackers, or third-party scripts into any page
- Stores locally your GitHub token, your license key, and your settings — in browser extension storage on your machine
4. Data Sharing
We do not sell, rent, or share your data with third parties. Period.
The only exceptions:
- Infrastructure providers — Supabase (database and signup handling), Vercel (website hosting), and Resend (transactional email — how your key reaches your inbox). These providers process data on our behalf.
- Services you connect yourself — GitHub and HighLevel see the requests your own browser makes to them. Their privacy policies govern their side.
- Legal requirements — if required by law, subpoena, or court order.
5. Data Storage & Security
The data we do hold (signup details and telemetry) is stored on Supabase with TLS 1.2+ encryption in transit and AES-256 encryption at rest. The most sensitive credentials in the system — your HighLevel session and your GitHub token — are never on our servers at all, which is the strongest protection we can offer them.
6. Data Retention
- Signup data: retained while your key is active, deleted within 30 days of a deletion request.
- Telemetry: retained in aggregate; operation-level records are pruned periodically.
- Local extension data: yours — remove the extension or use its Disconnect controls and it's gone from your machine.
7. Your Rights
You have the right to:
- Access the data we hold about you — email us and we'll send it
- Correct your email or name
- Delete your data — email us and we'll remove your signup record and key
- Unsubscribe from product emails at any time
For GDPR, CCPA, or other data rights requests, contact us.
8. Cookies
This website uses localStorage to remember your cookie choice and, if you signed up here, your email — so the form doesn't ask twice. Analytics cookies are set only if you accept them in the banner. We do not use advertising cookies.
9. Children's Privacy
Super Vibe is not intended for use by anyone under 18. We do not knowingly collect data from minors.
10. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated by email at least 14 days before taking effect.
11. Contact
Questions about privacy? Contact us. See also our Terms of Service.