Privacy Policy
Privacy Policy
Effective date: March 25, 2026 Last updated: March 25, 2026
Data controller:
Conversem Ruben Remy (sole proprietor) Laan van Tudor 133, 2135 WD Hoofddorp, The Netherlands KVK: 69426937 | BTW: NL002212501B15 Email: [email protected]
Our philosophy
Vibes to Bucks is designed with privacy at its core. Your usage data stays on your machine. We don’t run servers that collect your data, we don’t use analytics or tracking, and we don’t sell or share your information with anyone.
This policy explains exactly what data is processed, where it lives, and who has access to it.
What data is processed and where
Data stored locally on your machine
The following data is stored in a local SQLite database and YAML configuration file on your computer. It never leaves your machine unless you explicitly initiate a sync.
- AI usage data β Cost, token counts, model used, request type, and timestamp for each Cursor AI interaction
- Workspace context β Workspace folder path, git remote URL, git branch name, hostname
- Configuration β Your project mappings, cost multiplier settings, preferences
- Exchange rates β Cached USD/EUR conversion rates (no personal data)
- Provider cache β Cached contact and project names from your billing provider (to avoid repeated API calls)
You have full control over this data. You can inspect, export, or delete the database file at any time (~/.vibes-to-bucks/ledger.db).
Data processed by third parties
| Service | What is sent | When | Purpose |
|---|---|---|---|
| Lemon Squeezy | License key, hashed machine identifier | At activation and periodic validation | License verification |
| Moneybird | Time entry data (hours, amounts, descriptions) | When you trigger a sync (Pro) | Billing sync |
| Harvest | Time entry data (hours, amounts, descriptions) | When you trigger a sync (Pro) | Billing sync |
| OpenAI / Anthropic | Commit messages (as prompt input) | When you request AI summaries (Pro) | Generating time entry descriptions |
| Frankfurter | None (public API, no authentication) | Automatically for exchange rates | Currency conversion |
All third-party connections (except Frankfurter) use your own accounts and API keys. We don’t have access to your credentials β they’re stored in VS Code’s SecretStorage on your machine.
Legal bases for processing (GDPR Art. 6)
- License validation β Performance of a contract (Art. 6(1)(b)). Necessary to deliver the product you purchased.
- Billing sync β Your consent (Art. 6(1)(a)). You explicitly configure your billing provider and choose when to sync.
- AI summaries β Your consent (Art. 6(1)(a)). You provide your own API key and explicitly initiate each request.
- Exchange rates β Legitimate interest (Art. 6(1)(f)). No personal data is involved.
Third-party services
When you use features that connect to third-party services, those providers act as independent data controllers and process data according to their own privacy policies:
- Lemon Squeezy Privacy Policy
- Moneybird Privacy Statement
- Harvest Privacy Policy
- OpenAI Privacy Policy
- Anthropic Privacy Policy
Obligation to provide data
Providing your license key and machine identifier is a contractual requirement necessary for license validation. Without it, the extension cannot verify your Pro license and Pro features will not be available.
All other data sharing (billing sync, AI summaries) is entirely voluntary.
International data transfers
Vibes to Bucks is available worldwide. Regardless of where you are located, the limited personal data involved in license validation is processed by services in various jurisdictions:
- Lemon Squeezy, OpenAI, Anthropic, Harvest β US-based. For users in the EU/EEA/UK, data transfers rely on Standard Contractual Clauses (SCCs) and/or Data Processing Agreements as required under GDPR Chapter V and UK GDPR. For users outside the EU, these services process data under their own privacy policies.
- Moneybird β Based in The Netherlands.
- Frankfurter β Public API, no personal data transferred.
Data retention
- Local data β Stored on your machine indefinitely until you delete it. Uninstalling the extension does not automatically remove the database; you can delete
~/.vibes-to-bucks/manually. - License data β Retained by Lemon Squeezy according to their retention policy. We do not maintain a separate database of your purchase or license information.
- Billing provider data β Time entries synced to Moneybird or Harvest are retained by those services per your account settings.
Your rights
All users
Since your data is stored locally, you already have direct access and full control. You can view, export, or delete your data at any time. For data held by Lemon Squeezy (license/payment information), contact us and we will facilitate your request.
EU/EEA residents (GDPR)
Under the GDPR, you have the right to:
- Access your personal data (Art. 15)
- Rectify inaccurate data (Art. 16)
- Erase your data (“right to be forgotten”) (Art. 17)
- Restrict processing (Art. 18)
- Data portability β receive your data in a structured format (Art. 20)
- Object to processing based on legitimate interest (Art. 21)
- Withdraw consent at any time for consent-based processing (Art. 7)
We will respond to data subject requests within 30 days, as required by GDPR Art. 12(3).
You also have the right to lodge a complaint with the Autoriteit Persoonsgegevens (Dutch Data Protection Authority): https://autoriteitpersoonsgegevens.nl
UK residents (UK GDPR)
If you are based in the United Kingdom, you have equivalent rights under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. You may lodge a complaint with the Information Commissioner’s Office (ICO): https://ico.org.uk
California residents (CCPA/CPRA)
If you are a California resident, the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA) provide you with additional rights:
- Right to know β You can request what personal information we collect, use, and disclose. See the sections above for a complete description.
- Right to delete β You can request deletion of your personal information. Since your data is stored locally, you can delete it directly.
- Right to opt out of sale or sharing β We do not sell or share your personal information with third parties for advertising or cross-context behavioral advertising purposes. There is nothing to opt out of.
- Right to non-discrimination β We will not discriminate against you for exercising your privacy rights.
Categories of personal information collected (as defined by the CCPA):
| Category | Collected? | Details |
|---|---|---|
| Identifiers | Yes | License key, hashed machine ID (for license validation only) |
| Commercial information | Yes | Purchase/subscription records (held by Lemon Squeezy) |
| Internet or network activity | No | β |
| Geolocation data | No | β |
| Biometric information | No | β |
| Professional/employment info | No | β |
| Education information | No | β |
| Sensitive personal information | No | β |
We have not sold or shared personal information in the preceding 12 months.
Brazilian residents (LGPD)
If you are based in Brazil, you have rights under the Lei Geral de ProteΓ§Γ£o de Dados (LGPD), including access, correction, deletion, and portability. Contact us to exercise these rights.
All other jurisdictions
We respect privacy rights globally. If your local law grants you specific data protection rights not listed above, contact us and we will work with you to honor them.
Data security
We take appropriate measures to protect the data involved in Vibes to Bucks:
- API keys and credentials are stored in VS Code SecretStorage (encrypted by the OS keychain).
- Machine identifiers are hashed before being sent to Lemon Squeezy for license validation.
- All third-party connections use HTTPS (TLS encryption in transit).
- Your usage data is stored in a local database on your machine β it never touches our servers.
Automated decision-making
Vibes to Bucks does not use automated decision-making or profiling as defined in GDPR Art. 22.
Cookies and tracking
We don’t use cookies in the extension. The extension contains no web tracking, analytics pixels, fingerprinting, or telemetry of any kind.
Do Not Track
Some browsers transmit a “Do Not Track” (DNT) signal. Since Vibes to Bucks does not track users in any way β neither in the extension nor on our website β there is no tracking behavior to disable. We honor DNT by default through our design.
Children
Vibes to Bucks is a professional developer tool and is not directed at children. We do not knowingly collect personal data from anyone under the age of 16 (the threshold under the Dutch GDPR implementation) or under the age of 13 (the threshold under the US Children’s Online Privacy Protection Act, COPPA).
If you believe a child has provided us with personal data, please contact us and we will take steps to delete it.
Changes to this policy
We may update this Privacy Policy from time to time. When we do, we’ll update the “Last updated” date at the top. Significant changes will be communicated through our website and/or the extension changelog.
Contact
For privacy-related questions or to exercise your rights:
Email: [email protected] Address: Conversem, Laan van Tudor 133, 2135 WD Hoofddorp, The Netherlands