Privacy Policy
How VSRX handles information
This Privacy Policy explains what information VSRX collects, why it is used, and the choices available to you. It applies to the Service and its public website.
1. Information we collect
- Account information: email address, user ID, workspace membership, role, and authentication-related events.
- Project and scan metadata: workspace details, target paths, scan status, timestamps, findings, review decisions, redacted evidence, and report history.
- Billing information: subscription and payment status and provider identifiers. Payment card details are handled by the payment provider and are not stored by VSRX.
- Technical information: device, browser, security, diagnostic, and request information needed to operate and protect the Service.
2. What we do not need
The local-first scan workflow is designed to send scan results, metadata, and redacted evidence rather than raw project source files. You remain responsible for removing secrets and personal data from anything you choose to submit.
3. How we use information
We use information to provide and secure the Service, authenticate users, generate reports, maintain workspace boundaries, process subscriptions, provide support, investigate abuse or incidents, communicate service changes, and improve reliability. We do not sell personal information.
4. Providers and disclosures
We share information with service providers only as needed for them to perform services for us, under appropriate contractual or security controls. These providers may include:
- Supabase: authentication and database hosting;
- Vercel: application hosting and delivery;
- Stripe: subscriptions and payment processing; and
- Resend: transactional email delivery.
We may also disclose information where required by law, to protect rights and safety, or as part of a merger, acquisition, financing, or sale of assets.
5. Retention
We retain information while your workspace is active and for as long as needed for the purposes described here. After cancellation, workspace data is scheduled for deletion under the applicable retention process. Security-event audit records may be retained for one year after deletion in pseudonymised form for security and compliance purposes.
6. Security
We use reasonable administrative, technical, and organisational safeguards, including authenticated access controls and encrypted transport. No online service can guarantee absolute security; tell us promptly if you believe an account or workspace is compromised.
7. Cookies and similar technologies
VSRX uses essential session and security storage needed for sign-in and the authenticated workspace. The current product does not require advertising cookies. If optional analytics or other non-essential technologies are introduced, this policy and the applicable consent experience will be updated first.
8. Your choices and rights
Depending on where you live, you may have rights to access, correct, export, delete, or restrict processing of your personal information, and to object to or withdraw consent for certain processing. Contact the operator through the support contact provided with your account to make a request. We may need to verify your identity before completing it.
9. International processing and children
The Service may process information in countries other than your own through the providers listed above. We do not knowingly offer the Service to children under the minimum age required by applicable law.
10. Changes and contact
We may update this Policy as the Service or legal requirements change. The updated version will be posted here with a new effective date. Privacy questions should be raised through the support contact provided with your VSRX account or service communications.