Legal & Compliance

Transparency is our currency. Review our operating agreements and compliance standards below.

Terms of Service

Published: February 10, 2026 · Updated: September 19, 2026

1. Acceptance of Terms

By accessing and using SirVibeAlot ("the Service"), you agree to be bound by these Terms. If you disagree with any part of the terms, you may not access the Service.

2. Service Description

SirVibeAlot provides billing reconciliation and dashboarding services for agencies using Replit. We process deployment data to generate client-facing financial reports.

3. Data Accuracy

While we aim to map deployment IDs accurately, the User is ultimately responsible for verifying all billing data before sending invoices to clients. SirVibeAlot is not liable for billing errors resulting from incorrect manual mappings.

4. Subscription & Billing

Beta access is currently provided free of charge to Founding Members. Future paid tiers will be communicated 30 days in advance.

Privacy Policy

Published: February 10, 2026 · Updated: September 19, 2026

1. Data Collection

We collect and process the following information to operate the Service:

  • Access applications: first and last name, agency name, work email, estimated monthly Replit spend, application status and submission date.
  • Account and security data: username, email, role, avatar URL, a bcrypt-hashed password, password-reset token hashes and related timestamps.
  • Client and deployment data: agency and client names, app names, domains, Replit Deployment IDs, active status and markup settings.
  • Invoice and reconciliation data: deployment descriptions and IDs, categories, costs, billing period, invoice number and dates, amount due, client mappings, markups, totals and reconciliation results.
  • Session data: a session identifier and the signed-in user's ID and role.

Uploaded PDF invoices are parsed in memory. We do not retain the original uploaded PDF, but we do retain the invoice-derived and reconciliation data listed above.

2. Data Usage

We use this information to review access applications, provide and secure accounts, maintain client and deployment records, reconcile invoices, generate dashboards and reports, send service and security emails, and administer the Service. We do not sell or rent personal or client data.

3. Service Providers

We disclose information to service providers only as needed to operate the Service. The Service is hosted on Replit, uses PostgreSQL to store application data and sessions, and uses Resend to deliver application, account and password-reset emails. These providers may process data on our behalf under their own applicable terms and privacy commitments.

4. Security

We use reasonable technical and organisational measures intended to protect information. Passwords are hashed using bcrypt, password-reset tokens are stored as hashes, and production session cookies use HttpOnly, SameSite=Lax and Secure attributes. No method of storage or transmission is completely secure, and we do not guarantee absolute security.

5. Retention

We retain information only for as long as reasonably needed to provide and secure the Service, meet legal obligations, resolve disputes and enforce agreements. Retention may vary by record type and legal requirement. When information is no longer needed, we will delete or anonymise it where reasonably feasible.

6. Your Requests

You may request access to, correction of, export of or deletion of your information by emailing hello@sirvibealot.com. We may need to verify your identity and may retain information where required by law or for legitimate security, dispute-resolution or record-keeping purposes. The Admin dashboard supports deletion of some records, but it does not currently provide complete self-service export or deletion of every record type.

Cookie Policy

Published: February 10, 2026 · Updated: September 19, 2026

1. Session Cookie

When you sign in, we use a connect.sid cookie to maintain your authenticated session. It lasts for up to 30 days and is configured as HttpOnly and SameSite=Lax, with the Secure attribute enabled in production. Blocking it will prevent signed-in features from working.

2. Preference Cookie

We use a sidebar_state cookie for up to seven days to remember whether the application sidebar is open or closed. This cookie is not used for advertising or cross-site tracking.

3. Analytics and Browser Storage

We do not currently use analytics or advertising cookies, and the Service does not currently store data in localStorage or sessionStorage. We will update this policy if those practices change.

Compliance

Published: February 10, 2026 · Updated: September 19, 2026

Privacy Rights

Depending on where you live, applicable privacy law may provide rights relating to your personal information. You may submit an access, correction, export or deletion request to hello@sirvibealot.com. These rights may be subject to identity verification, legal exceptions and retention obligations.

Financial Data

SirVibeAlot does not process payments directly. All financial calculations are estimates based on provided inputs and are not legal financial documents.