Privacy Policy
Effective September 11, 2026. This policy applies to the Vortelon website, mobile applications, administration service, customer support, and related AI-assisted mobile development services (collectively, the “Service”). By using the Service, you acknowledge that you have read this policy. If you disagree, stop using the Service.
1. Who we are
The Service operator is the individual or legal entity doing business as Vortelon under the legal or DBA name shown in the Business information section on this page ("Vortelon," "we," "us," or "our"). Our website is https://vortelon.com. Send privacy questions, rights requests, or complaints to support@vortelon.com. The published name must match the operating entity registered with the payment provider.
2. Information we collect
- Account data: email address, secure password hash, verification state, login sessions, language, and account status. We do not store plaintext passwords.
- Subscription and transaction data: plan, order number, amount, currency, payment status, renewal, and refund records. Stripe, Apple, Google, or another payment provider normally handles complete payment-card details directly; we receive transaction identifiers and required status data.
- Project and AI interaction data: prompts, code, file excerpts, configuration, feedback, and generated output you choose to submit. The scope depends on enabled features and directories you authorize.
- Device and diagnostic data: device identifiers, platform, application version, IP address, timestamps, crash or error logs, security risk events, and basic performance data.
- Communications: messages and tickets exchanged with product, billing, or security support.
- Cookies and local storage: data needed for sessions, security, language preferences, and consented analytics.
3. Purposes and legal bases
We process data to perform our contract by creating accounts, delivering subscriptions, operating AI features, supporting users, and processing payments; for legitimate interests in security, fraud prevention, debugging, and reliability; to satisfy legal duties involving financial, security, and compliance records; and, where consent is required, only after consent for non-essential cookies or marketing. Consent may be withdrawn without affecting earlier lawful processing.
4. AI and project content
To generate output, the Service may send necessary prompts and context to the selected model provider. Do not submit unnecessary personal data, trade secrets, regulated health or financial information, government identifiers, payment-card data, or third-party material you lack authority to process. We do not use project content to sell personal information, and we do not use private project content to train public models without disclosure.
5. How information is shared
We disclose information only as needed to infrastructure, database, email, error monitoring, support, AI model, and payment providers subject to contractual confidentiality and security duties. We may also disclose necessary data to comply with valid legal process, protect users or the public, investigate abuse, or complete a merger, financing, or asset transfer. A transaction recipient must continue to honor this policy or provide notice of material changes. We do not sell personal information.
6. International processing
Providers may operate outside your country or region. For cross-border transfers, we use recognized contractual clauses, adequacy decisions, or other legally accepted safeguards where required. Data-protection rules vary by jurisdiction; contact us for information about safeguards applicable to a particular transfer.
7. Retention
We retain information needed to provide the Service while an account exists. After closure, account and project data is generally deleted or anonymized from active systems within 30 to 90 days, while backups expire on their rotation cycle. Transaction, tax, audit, security, and dispute records may be kept longer when legally required. A valid preservation demand or unresolved refund or dispute extends retention for relevant records.
8. Security
We use access controls, password hashing, encryption in transit, least privilege, audit logging, backups, and vulnerability remediation. No system can guarantee absolute security. If an incident requires notice, we will notify affected users and authorities within applicable deadlines. Use a unique strong password, protect your email account, and report suspicious activity promptly.
9. Your choices and rights
Depending on local law, you may request access, correction, deletion, restriction or objection, a portable copy, withdrawal of consent, and review by a regulator. Send requests from the account email and describe the requested action; identity verification may be required. We normally respond within 30 days, subject to lawful extensions. Contract, antifraud, financial, or legal obligations may prevent immediate deletion of some records.
10. Children
The Service is not directed to children under 13 and does not knowingly collect their personal information. Users below the age of independent consent in their region need authorization from a parent or guardian. Contact us immediately if you believe a child submitted data without appropriate permission.
11. Third-party links and platforms
The Service may connect to GitHub, model providers, application stores, or other third parties. Their own policies govern data they collect independently. Review their permissions and privacy terms before enabling an integration.
12. Changes and contact
We publish revisions on this page and identify their effective date. Material changes will be announced in the Service or through the account email before they take effect where required. Review updates before continuing to use the Service. Questions may be sent to support@vortelon.com.