Privacy Policy.
Last updated 25 September 2026
The short version: we collect only what it takes to give you an account and take a payment: your email, and your billing details through Stripe. Page views are counted without cookies. No ad trackers, no selling data, no marketing email. You can see, correct or delete your data at any time by emailing hello@viberdy.dev.
01Who we are
viberdy.dev is run by the operator below, who is the data controller for the personal data described here, under the EU General Data Protection Regulation (GDPR) and, for people in the United Kingdom, the UK GDPR and Data Protection Act 2018.
BL/.NK StudioTODO: full legal name, sole trader
TODO: street, postcode, city, Czech Republic
Company ID (IČO): TODO: IČO
Registered in the Czech Trade Register (zapsán v živnostenském rejstříku)
Email: hello@viberdy.dev
Phone: TODO: phone number
We have not appointed a data protection officer; write to the email above about anything in this policy.
02What we collect, and why
Browsing the site
You can use the free library without an account. Our hosting provider records standard server logs (IP address, browser type, the page requested and the time) to deliver the site and keep it secure.
To see which pages are useful, we use Vercel Web Analytics, which counts page views without cookies. It doesn't follow you across sites or build a profile of you. According to Vercel, visits are grouped using a hash that is discarded after 24 hours, and we only ever see totals: pages, referrers, approximate location (country) and device type. We run no advertising or tracking scripts.
Legal basis: our legitimate interest in running a secure, working website and understanding, in aggregate, how it is used (Art. 6(1)(f)). You can switch analytics off in this browser at any time:
Your account
When you sign in we store your email address. If you sign in with GitHub or Google, we also receive what that provider shares with us: your account ID, email address, and your name, username and profile picture. Sign-in records (such as the time of your last sign-in and the IP address used) are kept for security. Legal basis: performing our contract with you (Art. 6(1)(b)), and security as a legitimate interest (Art. 6(1)(f)).
Do you have to give us this? Your email is needed to create an account, and billing details are needed to buy a plan (tax law also requires them for invoices). Without them we can't provide the plan. The free library needs neither.
Purchases
Payments are handled by Stripe. We never see or store your card details. We receive and keep your name, email, billing country and address (used to calculate tax), what you bought, the amounts, and your subscription status, plus Stripe's reference numbers for your customer record and subscription. When you tick the box at checkout, we also record the time and the version of our Terms you agreed to. Legal basis: performing our contract (Art. 6(1)(b)), and keeping accounting and tax records as the law requires (Art. 6(1)(c)). Stripe screens payments for fraud, in our and Stripe's legitimate interest (Art. 6(1)(f)).
Teams
A team owner gives us the team name, the number of seats and the email addresses of the people they invite. We use those addresses only to send the invitation and to switch on Pro for the person who accepts it. Legal basis: performing our contract with the team owner, and the legitimate interest of the team in giving its members access.
CLI keys
If you create a key for installing Pro components from the command line, we store only a one-way hash of it (never the key itself), its first few characters so you can recognise it, and when it was last used. Legal basis: performing our contract (Art. 6(1)(b)).
Emails we send
Only emails you need: sign-in links, team invitations, and purchase confirmations and receipts. We don't send marketing email. If we ever do, we will ask first. Legal basis: performing our contract (Art. 6(1)(b)).
When you write to us
We keep your message and our reply so we can help you and have a record of what was agreed. Legal basis: performing our contract, or our legitimate interest in answering you.
05International transfers
Some providers above process data outside the European Economic Area and the UK, mainly in the USA. Where they do, the transfer is covered by the EU–US Data Privacy Framework (and its UK Extension) for certified providers, or by the European Commission's Standard Contractual Clauses (with the UK Addendum) as part of our agreements with them. You can ask us for a copy of these safeguards.
06How long we keep it
- Account data: for as long as you have an account. Delete it yourself at any time from your account page (Delete account), which also cancels any subscription straight away, or ask us and we'll do it within 30 days. Records we must keep by law are listed below.
- Purchase and invoice records: for as long as Czech tax and accounting law requires, which can be up to 10 years.
- Team invitations: until the invitation is accepted, withdrawn, or the team is closed.
- CLI keys: until you revoke them or delete your account.
- Server, sign-in and security logs: for the short period our providers keep them, typically a few days and never more than 90 days.
- Emails with us: for up to 3 years after the conversation ends, unless they are part of a purchase record.
07Your rights
Under the EU and UK GDPR you can ask us to:
- give you a copy of the personal data we hold about you (access);
- correct it if it is wrong (rectification);
- delete it (erasure), except what we must keep by law;
- limit how we use it (restriction);
- send it to you or another service in a machine-readable format (portability);
- stop using it where we rely on legitimate interests (objection).
Your right to object: you can object at any time, on grounds relating to your situation, to processing based on our legitimate interests. We'll stop unless we have compelling grounds or need the data for legal claims.
To use any of these, email hello@viberdy.dev from the address on your account, so we can confirm it is you, or delete your account yourself from the account page. We reply within one month. It costs nothing.
You can also complain to a data protection authority. Ours is the Czech Office for Personal Data Protection (uoou.gov.cz). You can also go to the authority where you live, which in the UK is the Information Commissioner's Office (ico.org.uk). We'd appreciate the chance to sort it out with you first.
08Security
Everything is served over HTTPS. Database access is locked down so a browser can read nothing directly, CLI keys are stored only as hashes, and card details never reach our servers. No system is perfectly secure; if a breach ever puts your data at risk, we will tell you and the authorities as the law requires.
09Children
viberdy.dev is a tool for developers and is not meant for children under 16. We don't knowingly collect their data; if you believe a child has given us personal data, write to us and we will delete it.
10Automated decisions
We don't make decisions about you based solely on automated processing, and we don't profile you. Stripe may automatically decline a payment it suspects is fraudulent; contact us and a person will review it.
11Changes to this policy
When this policy changes, the date at the top changes too. If a change matters for how we use your data, we'll email account holders before it takes effect. The Terms of Service explain the rest of how the service works.