Privacy Policy
Effective August 22, 2026 · rev 2026-08-22.draft-5
This policy covers the Vorza website, free scans, journey demos, and paid audits. The short version: we collect the minimum needed to run your audit, credentials are sealed so we cannot read them, and everything has a deletion story.
What we collect
- Email addresses — for audit delivery, plan-generation tokens, journey demos, and the waitlist. Payment details go directly to Stripe; we never see or store card numbers.
- Audit targets and run evidence — the target you specify, generated evaluation plans, and recordings of agent runs (the product itself).
- Sealed credentials — encrypted in your browser to the audit worker's key. The web application stores only ciphertext it cannot decrypt, plus the variable names for display.
- Operational logs — standard request logs and error traces.
Retention
- Sealed credentials: deleted the moment your audit completes, fails, is refunded, or needs your action — enforced in code and by a daily sweep.
- Audit evidence and reports: retained 180 days after completion, then purged. [FOUNDER: confirm window]
- Journey demo recordings: retained 90 days.
- Waitlist and marketing data: kept until you unsubscribe; every marketing email carries a one-click unsubscribe.
Processors we rely on
Stripe (payments), Vercel (hosting and aggregate page analytics), Supabase (database and evidence storage), Resend (email), E2B (sandboxes), PostHog (product analytics, hosted in the EU), Anthropic and agent vendors (the models the audits exercise). Each receives only what its role requires; credentials reach only the audit worker.
Analytics
We measure how the product is used — pages visited, features tried, and the country a visit comes from — to improve it. We also collect error reports when a page breaks, and may record anonymized product sessions with all text, inputs, and identifiers masked. Analytics data is processed by PostHog on EU servers, is never used for advertising, and never includes your credentials, audit evidence, or the contents of anything you submit. [FOUNDER: confirm analytics wording, incl. error reports + masked replay.]
What we don't do
- No selling or renting personal data.
- No advertising trackers.
- No training models on your credentials or private run evidence.
Your rights
Email admin@vorza.dev to access or delete your data (waitlist entries, audit emails and links, journey records). Deletion requests are honored within 30 days. EU/UK residents: the legal bases we rely on are contract performance (audits) and consent (marketing). [FOUNDER: confirm DSAR window + controller entity.]