Privacy
last updated 2026-10-01 · howtovibecodeit.dev
What we store, and why
- Digest emails. If you sign up for the weekly digest (or check the box at account signup), we store your email address and where you signed up from. Sending goes through Resend, our email provider, which holds a mirror of the list. Every email has a one-click unsubscribe. Unsubscribing actually works.
- Accounts. Sign-in is Google or GitHub only; we never see or store a password. We keep what the provider hands us (email, name, avatar, and the OAuth tokens that make sign-in work), your stack (the list of apps you saved), your Vibathon participation, and per session the IP address and browser it was created from, which is standard session-security bookkeeping. Sessions expire after 7 days. Account data remains until you delete it, subject to any required financial-record retention described below.
- Votes. "I replaced this" clicks are counted with a short-lived rate-limit key based on your IP. No account needed, no profile built.
- Sponsors. If you buy a sponsor slot we store the card details you give us: company name, tagline, link, logo, and a contact email. Payment runs entirely through Stripe; we never see your card number.
- Analytics. First-party PostHog (EU region), proxied through our own domain. We count pageviews and clicks to see what's working. No third-party ad trackers, no cross-site anything.
Vibathon submissions, votes and prizes
We store your account ID, entry month, project name, description, public demo or repository URL, submission time, accepted rules version, review status and moderation reasons. We use this to verify eligibility, run the two leaderboards, prevent duplicates and abuse, and contact provisional winners. Your maker handle or account name and approved project details are public. Pending submissions and review notes are available to you and the site’s moderators; sponsors cannot access private submissions.
Competition votes are tied to a signed-in account and project. We store the vote value and last update time to allow changes and prevent duplicate votes. Public pages show vote totals, not a list of named voters. Session data and rate-limit records help protect the competition from abuse.
Project drafts are saved in this browser tab’s session storage so you can return after sign-in. We restore a draft only within 24 hours of its last edit. Clear draft, a successful submission or closing the tab removes it; an expired draft is removed when you return to the form. Drafts are not competition entries, and sign-in does not submit them automatically.
We commit 40% of the site’s sponsorship revenue to Vibathon prizes, calculated after third-party payment processing fees (such as Stripe). The remaining 60% stays with the site. Sponsors buy visibility, not victory: a sponsorship can never win a prize. Sponsors of a round, their owners, directors, employees and contractors cannot enter or win that round. Sponsors receive visibility and public results, not entrant email addresses, private eligibility documents or payment details.
For a provisional winner we may request identity, age, eligibility, tax and payment information needed to verify and lawfully pay the prize. This information is used only for competition administration and payment compliance, shared only with necessary payment or compliance providers and authorities where required, and never published or sold. Final results may include the maker’s public name, project, award and prize amount. Additional publicity requires separate consent.
Deleting your account removes your competition entries, projects, votes and associated moderation records and can change the leaderboards. Required payment, refund and tax records may be retained for the legally required period with access restricted to administration. You can request access, correction or deletion of other competition data by emailing hello@howtovibecodeit.dev. The full rules and payout criteria are in our Vibathon terms.
What we don't do
- No selling or renting your data. Ever, to anyone.
- No merging you into other mailing lists.
- No pre-checked consent boxes.
Deleting your data
Delete your account on /account: it wipes your stack, removes your email from the digest list (including the Resend mirror), and deletes the account rows. There is no soft-delete and no exit survey. For anything else (a stray digest signup, a sponsor record), email digest@howtovibecodeit.dev and a member of the site team will handle your request, subject to required payment and tax-record retention.
The formal bit
Legal bases under UK GDPR: consent for the digest (the unchecked box you tick), contract for accounts, competition administration and sponsor purchases (we can't provide the thing without the data), legal obligations for required prize, payment and tax verification, and legitimate interest for rate limiting, competition integrity and first-party analytics. Optional publicity uses consent. Data lives with our processors (Railway for the database, Resend for email, Stripe for payments, PostHog EU for analytics). If you think we've handled your data badly, email us first and a human will fix it; you also have the right to complain to the ICO at ico.org.uk.
Public content
Approved Vibathon projects and other content you choose to publish are tied to your maker handle or account name. The submission surface explains what becomes public before you submit.
Terms live at /terms.