Privacy
Privacy policy
The site is built to know as little about you as possible.
howmuchtovibecode.com is operated by MB Viksva, a small partnership (mažoji bendrija) registered in Lithuania. For data-protection purposes MB Viksva is the company legally responsible for everything described here (the controller), reachable at mbviksva@gmail.com.
Effective 10 August 2026. There are no accounts on this site, no newsletter, no advertising, and nothing that follows you to another site. What is left is short enough to read in full, so it is written out in full below rather than summarised.
What we do with your data, and why
One entry for each thing we do with data. If it is not on this list, it does not happen.
1 · The AI plan
Your idea description
If you use the optional AI step on the calculator, the text you type is sent to OpenAI (United States). An AI model reads it and works out three things: the closest app type, the features your idea needs, and whether AI app builders are a good fit for it. Nothing else about you goes with it — no name, no email, no account, because none exists.
Legal basis: performance of the service you asked for, GDPR Art. 6(1)(b).
If you choose “Private”, the text is not stored. Our computer turns your words into a one-way fingerprint — a scrambled code that cannot be unscrambled back into your text — and keeps only that code plus the verdict. Ask the same idea again and the answer comes back instantly, without paying for a second run.
One honest note about the company at the other end. Under OpenAI’s own data rules for the businesses that build on it, OpenAI keeps the text sent to it for up to 30 days to watch for abuse, then deletes it. It does not use that text to train its models. “Not stored” above describes this site’s storage; those 30 days are OpenAI’s.
2 · Only if you say yes
Public wall submissions
The AI plan makes you choose, every time, before it runs: private, or public. Only if you pick “Public wall” do we store the idea text itself, together with the verdict it received and the moment you agreed to it. Both options are free and give you the same verdict. The choice is about publishing, never about price.
Legal basis: consent, GDPR Art. 6(1)(a).
Submissions go into a queue, not straight onto the site. Every entry starts as pending, and is only ever published after a person reads it. The wall itself does not exist yet; when it does, entries carry the idea and its verdict, and nothing about who wrote it.
Withdrawing is one email. Write to mbviksva@gmail.com with the reference shown after your submission (or just the idea text) and the entry comes off the site and the stored text is deleted. You do not need to explain why.
3 · Keeping it free
Abuse prevention
The AI plan costs us real money every time it runs, so each visitor is limited to five runs an hour. Your IP address — the number your internet connection shows to every site you visit — is never stored as an address. It is mixed with the day’s date, scrambled into a one-way code, and only that code is written down. Today’s code cannot be matched against yesterday’s, so the counter cannot be used to recognise you, and the record is deleted within 48 hours.
The AI plan is also protected by Google reCAPTCHA Enterprise, through a Google service called Firebase App Check. Together they confirm that the request came from a real browser on this site, and not from an automated program draining the budget. To do that, Google looks at signals from your device and your connection, and may set functional cookies or leave a small note in your browser, strictly for that purpose. It runs only when you actually use the AI plan — the rest of the site never loads it. Google’s own Privacy Policy and Terms of Service apply to that processing.
Legal basis: legitimate interest in keeping a free service alive and unabused, GDPR Art. 6(1)(f).
4 · Serving the pages
Hosting logs
The pages of this site are simple pre-made files sitting on a shared host (Hostinger). Like every computer that serves web pages, it keeps a routine log of visits — IP address, the time, the page asked for, and which browser asked — which we do not analyse, export, or join to anything else.
Legal basis: legitimate interest in operating and securing the site, GDPR Art. 6(1)(f).
What we don’t do
- No ad trackers. No pixels, no remarketing tags, no third-party advertising of any kind.
- No analytics scripts. We do not measure you at all — not even anonymously, not even in aggregate.
- No cookie banner, because there is nothing to consent to. The site sets no cookies of its own; the only thing kept in your browser is what reCAPTCHA needs when you use the AI plan, and that is there purely to make the check work.
- No sale of data, and no sharing with anyone beyond the companies that handle data for us (listed below).
- No profiles. Nothing here is designed to recognise a returning visitor, and the one counter we keep is mixed with the day’s date before scrambling so that it cannot.
- No accounts, no newsletter — there is nothing to sign up for, and no list to be added to until you ask for one.
Where the data goes
Three companies handle data for us, each under their standard data-processing terms:
- OpenAI (United States) — receives your idea description so the AI plan can read it, and nothing else.
- Google (United States / EU) — reCAPTCHA Enterprise and Firebase App Check, which keep the free AI plan from being drained. Google’s Firebase cloud service also provides the computers that run the AI plan (Cloud Functions) and the place the saved verdicts and any public wall entries are stored (Firestore). That storage sits in Google’s data-centre region us-central1, in the United States.
- Hostinger (Lithuania, EU) — serves the pre-made pages and keeps the routine visit logs described above.
The work done by OpenAI and Google means data leaves the EU/EEA. Those transfers rely on the EU–US Data Privacy Framework and/or the European Commission’s standard contractual clauses — the standard legal agreements that keep European data protection attached to the data when it travels — as set out in each company’s data-processing terms.
How long things are kept
* RETENTION *
The cache row keeps no text and nothing about you — a scrambled code and a verdict. That is why it can be kept forever.
Anonymous answer cache: kept indefinitely, because there is nothing personal in it — a one-way fingerprint of the tidied-up description (a SHA-256 code, which cannot be turned back into words), the verdict, the name of the AI model, the date, and how many characters you typed. No text, no IP address, nothing that points back to a person.
Public wall entries: kept until you withdraw consent, or until we remove the entry ourselves. There is no timer on consent.
Hourly-limit counters: written with a 48-hour expiry date and deleted automatically.
Visit logs: kept for as long as our host keeps them by default; we neither extend them nor read them routinely.
Your rights
Under the GDPR (Arts. 15–21) you can ask to see the data we hold about you (access), correct it (rectification), have it deleted (erasure), have us stop using it for a while (restriction), or get a copy you can take elsewhere (portability). You can object to anything we do on the basis of legitimate interest. You can withdraw consent at any time; that stops any future use, and does not make what already happened unlawful.
Send any of those to mbviksva@gmail.com. We answer within 30 days. One honest limit: the anonymous records — the answer cache and the hourly counters — carry nothing that ties them to you, so we cannot tell which entry is yours. GDPR Art. 11 does not ask us to collect extra information about you just to work it out. For a public wall entry it is simple: the reference shown after you submit, or the idea text itself, is enough.
You also have the right to complain to your data-protection supervisory authority, which is normally the one in the EU/EEA country where you live or work. Ours is the Lithuanian State Data Protection Inspectorate (VDAI).
Real-build submissions
If you email a real build for the real builds page, your email address and whatever you put in the message are processed for one purpose: publishing the entry. Legal basis is consent (Art. 6(1)(a)) — you sent it in order to have it published — and the withdrawal route is the same one: email mbviksva@gmail.com and it comes down.
Send only what you are happy to see published. Anonymous is fine.
Changes
When this policy changes, the updated version is published on this page with a new effective date at the top. There is no mailing list to notify, which is rather the point.
Questions about any of it: mbviksva@gmail.com.