Security

The smallest data footprint I can ship.

Vibes is built around a privacy thesis — and that thesis only holds if the security work is real. Here's what I do, with enough specificity that an actual security person can hold me to it.

Last reviewed · April 30, 2026

What I do

Five things I actually do.


What I don't store

A list of deliberate absences.


If something goes wrong

Disclosure. Within 72 hours.

If I discover a security incident affecting user data, I commit to disclosing it within 72 hours via a banner on this site, an in-app notice, and a direct email to anyone whose data was implicated. I will publish a written postmortem describing what happened, what data was affected, and what I changed. No corporate-comms theater.

If you've found a vulnerability, please email security@vibesmusic.app. I don't run a bounty program yet but I'll send you a real thank-you, credit you in the changelog if you want, and treat the report as the gift that it is.


Audits

Soon. Not yet.

As of April 2026, Vibes hasn't been formally audited by a third party. That'll change once I'm past TestFlight; I'll publish the report here when it does. Until then, every claim on this page is verifiable from the iOS binary plus the published privacy policy, and any security researcher who wants to poke at the app should treat themselves as authorized to do so under standard safe-harbor terms.

Get the app    Report a vulnerability