Privacy Policy
Who we are
needavibecoder.com is operated by Bicraw AI Technologies, Bampslaan 1, 3500 Hasselt, Belgium. Enterprise number: BE 0658.917.436. Contact: hello@bicraw.ai
What we collect
When you enter a GitHub username into the Vibe Check, we pull publicly available data from GitHub's API:
- Profile info (username, display name, avatar, bio, links)
- Public repository data (names, languages, stars, topics, dates)
- Recent activity (push events from the last 30 days)
- Repository contents (package.json, config files — to detect frameworks and AI tools)
No private repos. No auth tokens. No access to anything GitHub doesn't already show the world
How we use it
- Scoring: We crunch the public data into a vibe score (0-100) across 5 categories
- AI roast generation: Your profile stats and score are sent to DeepSeek (a third-party AI provider) to generate a personalized roast and description. DeepSeek receives your username, score, repo names, languages, and stats — no private data
- Storage: Your quiz result (username, score, verdict, roast, profile stats) is saved to our database so results load instantly on repeat visits and for the public leaderboard
- Leaderboard: Your username, score, and verdict appear on the public leaderboard, visible to anyone who visits the site
Ship or Shit (URL roasts)
When you submit a URL to Ship or Shit, we fetch the public page content at that URL — the same thing any visitor would see. We then:
- Extract visible text, headings, meta tags, and basic page structure
- Score the page across 8 categories (idea + execution) on a 0-100 scale
- Send the extracted content to a third-party AI provider (DeepSeek) to generate a roast and verdict. No private data, no auth, no cookies — just what's already public
- Store the URL, domain, scores, roast, and verdict in our database so results load instantly on repeat visits and for the public leaderboard
- Display the domain, scores, and verdict on the public Ship or Shit leaderboard, visible to anyone who visits the site
Anyone can submit any public URL — it doesn't have to be theirs. If your site appears and you want it removed, email privacy@needavibecoder.com with the URL. We'll wipe it within 48 hours
Account data
When you create an account (via Clerk authentication), we store:
- Your user ID from the authentication provider
- Developer profiles (headline, bio, skills, GitHub info, availability)
- Company profiles (name, website, description, industry)
- Job postings and applications you create
This data is stored in Convex and linked to your authenticated account
Developer dashboard data
When you use the developer dashboard to build your profile, we collect and process:
- Linked sources: GitHub username, LinkedIn URL, personal website, and portfolio URLs you provide. We fetch public content from these to extract skills, experience, and projects
- CV uploads: If you upload a CV, the file is stored on Convex file storage and parsed for profile data. You can delete it from the dashboard at any time
- AI extraction: Content from your sources and CV is sent to a third-party AI provider (DeepSeek) to generate a self-description, skills list, and structured profile. AI providers process this data per their own privacy policies and we don't use it to train models
- Projects: Project titles, descriptions, links, and images you add to your portfolio
- Messages: Messages exchanged between you and companies through the dashboard inbox are stored in Convex so both parties can read them
- Job applications: Applications you submit, including any cover note and the profile snapshot shared with the company
Once you publish your profile, the parts marked public (headline, bio, skills, projects, linked sources) are visible to anyone browsing the developer directory
Third parties
- GitHub API — to fetch public profile data
- DeepSeek API — to generate AI roasts and extract profile data from your sources/CV. Their data is processed per their privacy policy
- Clerk — authentication provider handling sign-in, sign-up, and session management
- Convex — database hosting where quiz results and account data are stored
- Vercel — hosting and CDN
Legal basis (GDPR)
We process personal data under Article 6(1)(f) — legitimate interest. The data is already public on GitHub, the processing is lightweight (scoring and entertainment), and the impact on data subjects is minimal. We balance this against your rights by:
- Only using data that's already publicly available
- Offering removal on request — no questions asked
- Not using the data for profiling, advertising, or any purpose beyond the quiz
If you're in the EU/EEA and believe your rights under GDPR have been violated, you have the right to lodge a complaint with your local data protection authority
Important: anyone can quiz anyone
The person who enters a GitHub username might not be the account owner. By design, the quiz works on any public GitHub profile. If your profile appears on our leaderboard and you didn't put it there — someone else did
Account deletion & GDPR right to erasure
You can delete your account at any time through Clerk's account management. When you do, we automatically and permanently delete all your data from our systems:
- Your developer profile
- Your company profile
- All job postings you created
- All applications you submitted or received
- Uploaded CVs and linked sources
- Messages you sent or received through the dashboard
This happens automatically via webhook — no email required, no waiting period. Your data is gone the moment your account is deleted
Get quiz data removed
Quiz results (leaderboard entries, roasts) are stored separately from accounts. To remove quiz data, email us at:
privacy@needavibecoder.com
Include your GitHub username. We'll wipe it within 48 hours. No questions asked
Cookies & tracking
We use basic analytics. No ad trackers. No selling your data. We don't even have a marketing team to sell it to
Changes
We might update this policy. If we do, it'll show up here. Last updated: April 6, 2026