Privacy Policy
Effective September 29, 2026 · Last updated
Who we are
VibeTagging is an AI measurement assistant for Google Tag Manager, operated by Peter Šutarík (“VibeTagging”, “we”). You connect your own AI agent to VibeTagging, VibeTagging checks your tracking every morning and, on paid plans, watches your container for changes during the day, and it works on your Google Tag Manager, Google Analytics and (if you allow it) Google Ads accounts at your direction.
Questions about this policy or your data: privacy@TODO-replace-with-real-domain.example TODO: placeholder address
What data we collect and why
- Google account email and basic profile — collected when you sign in with Google, used to create and identify your VibeTagging account.
- Google Tag Manager container configuration — tags, triggers, variables, and versions — read to produce audits, change reviews and the checks for changes (every morning, and on paid plans also during the day at an interval set by the plan). Edited only at your direction or by the background agent inside isolated GTM workspaces named for the incident or request, and never published without an explicit approval click by a person in VibeTagging.
- Google Analytics (GA4) report data — aggregate daily event counts, key events, custom definitions and data streams — read-only, used to verify that the tracking you configured works and to alert you when it breaks. We never modify your Analytics configuration.
- Google Ads account data — only when you grant Google Ads access: your conversion actions and aggregate daily conversion counts — read-only, used to alert you when a conversion stops being recorded. We never change campaigns, budgets or conversion settings.
- Website journey captures — when you monitor a website, VibeTagging's browser replays the journeys you set up (for example a test checkout) and records what the pages push to their dataLayer, the tracking requests they try to send and the consent state. By default those tracking requests are captured and blocked: requests to the GA4, Google Ads, Meta, TikTok and LinkedIn endpoints are answered by VibeTagging's browser itself and never leave it, so test purchases and conversions sent there do not land in your reports. Tracking that does not go to those endpoints is not intercepted: first-party or server-side tagging collectors on your own paths, other vendors' pixels, and requests that reach a platform only through a redirect can still go out. Your team can choose, per property, to send them to the platforms instead; GA4 hits are then marked as internal traffic. These captures can contain personal data if a site puts it there, so values are cut to 200 characters on screen and in anything the background agent sees, raw captures are deleted after 30 days, and screenshots are taken only when a step fails. Journeys that VibeTagging's agents write use test data (example.com addresses, test products), never real personal data, and are written to stop before a form is sent or an order is placed unless you allow test submissions for that property. That setting is guidance for the agents that write journeys, not enforced when a journey runs: journeys your team writes or edits itself run as written, so what they enter and submit is up to you.
- The optional monitor cookie — if you set a monitor token so your firewall or bot protection lets VibeTagging's browser through, the browser carries it as the cookie vibetagging_monitor, set for your own site's domain: it is sent only to hosts under that domain (its subdomains included, so also to a subdomain you point at another provider), never to other domains, not even through a redirect. You can rotate or remove the token in the property's journey test settings.
- Google OAuth refresh tokens — stored encrypted at rest with AES-256-GCM so VibeTagging can check your accounts every morning and act between sessions. A token is scoped to the individual user account that granted it; what it reads is visible only to members of the organization that owns the property. No cross-customer access and no aggregation across customers.
- Tracking plans, incidents and approvals — the tracking plan, the incidents, fixes, requests and approvals your organization works on, and the notes people add to them.
- Audit logs of agent actions — every tool call an agent makes through VibeTagging (your own agent or VibeTagging's background agent) is recorded in an activity log visible to your organization, with secrets and journey test data masked, so you can always see what was done on your accounts.
We do not serve ads, we do not sell your data, and we do not share your data with third parties — except the subprocessors that run the service:
- Vercelweb application hosting
- RailwayMCP server and background worker hosting
- Supabasedatabase hosting
- Resendtransactional email delivery
- Anthropic (Claude API)the background agent that diagnoses incidents and drafts fixes
Integrations you add yourself (a Slack channel, email recipients, a GitHub repository or a Jira Cloud project for developer tickets) receive the alerts, digests and tickets you asked for; GitHub tickets are only filed to private repositories, and Jira tickets to the project you chose.
The background agent and the Claude API
On plans that include it, VibeTagging's background agent diagnoses incidents, drafts fixes and plans requests. It runs on Anthropic's Claude API. For each run, the Claude API receives what that task needs: the incident or request, the relevant part of the tracking plan and of the GTM container, and shortened journey evidence. Anthropic processes it as our subprocessor under its commercial API terms and does not use it to train its models.
The agent works only through VibeTagging's own tools, on one property at a time, for at most an hour. It can never publish a container version or approve a tracking plan change; a person does that in VibeTagging after the automated checks pass. Organizations on any paid plan can use their own Anthropic API key instead of ours; their runs are then processed under their own agreement with Anthropic.
Google API Services User Data Policy — Limited Use
VibeTagging's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically: data obtained via Google APIs is used only to provide and improve the user-facing features described above (audit, documentation, implementation in workspaces, verification, monitoring, incident diagnosis); it is not transferred to third parties except as necessary to provide those features (including to the subprocessors named above), to comply with applicable law, or as part of a merger or acquisition with notice; it is not used for serving advertisements; it is not used to train generalized machine-learning or AI models; and humans do not read this data except with your explicit permission, for security purposes, to comply with applicable law, or in aggregated and anonymized form for internal operations.
Data retention and deletion
- Encrypted Google refresh tokens: until you revoke access (see below).
- Raw journey captures and failure screenshots: 30 days; the pass or fail result of each check is kept.
- Background agent transcripts: 30 days; the run's usage and outcome are kept.
- Aggregate GA4 and Google Ads daily counts: 400 days, for baselines and trends.
- Check history: 180 days. Container snapshots: the latest 50 per property, plus any an incident or fix refers to.
- Incidents, timelines, tracking plan versions and the audit log: kept while your organization exists, so fixes and approvals stay traceable.
You can revoke Google access at any time from your Google account at myaccount.google.com/permissions, or ask us to delete the stored token at the contact address above. Once access is revoked, VibeTagging marks the connection as failed and stops using it: until it is reconnected, the property's daily checks are skipped and the digest says so.
On an account deletion request, we delete your stored tokens and Google-derived data (container snapshots, journey captures, documentation, audit data) held for your organization. Send deletion requests to the contact address above.
Changes to this policy
If this policy changes, we will post the new version on this page and update the effective date above. Material changes will be announced to signed-in users.