Legal

Privacy Policy

How we collect, use, store, and share personal data when you use VStok.

Last updated: 2026-06-30

Operator: FLOWPIX LIMITED (Company No. 16157203)

Product: VStok (https://vstok.net)

Registered office: 128 City Road, London, EC1V 2NX, United Kingdom

Jurisdiction: England and Wales

Privacy contact: privacy@novol.dev

Effective date: June 30, 2026

1. Scope

This Privacy Policy explains how FLOWPIX LIMITED, operating the VStokproduct ("we", "us"), collects, uses, stores, and shares personal data when you visit vstok.net, create an account, use the VStok platform, contact us, or interact with our billing flows.

This policy applies to the public website, authentication pages, and the web application used for AI visibility tracking, audits, reports, and related features.

2. Personal data we collect

  • Account and identity data — email address, password (hashed), full name, locale preference, and authentication session data.
  • Social sign-in data — when you use Google or Apple login, profile basics from the identity provider processed through Supabase Auth.
  • Project and brand data — brand names, project names, categories, languages, countries, website and app store URLs, competitor names and URLs, product details, custom prompts, and optional project logos you upload.
  • AI audit and analytics data — prompts sent to LLM APIs, raw and parsed model responses, visibility scores, sentiment, mentions, citation sources, site crawl results, and app listing audit findings.
  • Usage data — plan limits, usage counters (AI checks, prompts, reports, audits per billing period), and feature activity within your account.
  • Billing data — subscription plan, currency, billing period, Stripe customer and subscription references, YooKassa payment IDs and status, and invoice-related metadata.
  • Transactional email metadata — when we send account, verification, or password-reset messages through Resend (or Supabase Auth email, depending on configuration).
  • Support communications — messages you send to us by email or support channels.
  • Technical data — browser type, request metadata, and diagnostics processed by our infrastructure providers as needed to operate the Service.
  • Browser storage — cookies and local storage as described in our Cookie Policy.

3. How we use personal data

  • To create and manage accounts and authenticate users.
  • To deliver AI visibility tracking, audits, reports, and related product features.
  • To process subscriptions, billing events, plan changes, and support requests.
  • To send transactional notifications (account verification, password reset, billing-related messages).
  • To secure the Service, prevent misuse, and maintain platform integrity.
  • To comply with legal obligations, enforce our terms, and protect our legal rights.

We do not sell personal data.

4. Legal bases

Where UK GDPR or similar laws apply, we generally rely on:

  • Performance of a contract — to provide your account and the Service you request.
  • Legitimate interests — to secure, operate, and improve the platform in a proportionate way.
  • Compliance with legal obligations — including accounting, tax, and fraud prevention.
  • Consent — where required by law for optional technologies or communications.

5. AI processing and third-party content

Core features transmit your brand, competitor, URL, and prompt data to large language model providers (OpenAI, Google Gemini, Perplexity) to generate and parse audit results. This processing is necessary to provide the Service you request.

Site and app listing audits may fetch publicly available content from URLs you specify. We process that content to generate technical and visibility insights.

6. Sharing personal data and subprocessors

We share personal data with service providers that help us run the Service. A summary is on our Subprocessors page. Providers include, among others:

  • Supabase — authentication, database, and file storage.
  • OpenAI, Google (Gemini), Perplexity — AI audit and content generation.
  • Stripe — payments and subscriptions (USD/EUR).
  • YooKassa — payments (RUB).
  • Resend — transactional email.
  • Google and Apple — OAuth sign-in (via Supabase Auth).

We may disclose information if required by law, regulation, or valid legal process.

7. Public reports

When you generate a shareable report link, anyone with the link can access the report content without logging in. Report tokens are designed to be unguessable, but you control distribution. Do not share links if you do not want the content to be accessible to recipients.

8. International transfers

We and our subprocessors may process data in the United Kingdom, European Economic Area, United States, and other countries. Where we transfer personal data outside the UK or EEA, we implement appropriate safeguards as required by applicable data protection law.

9. Retention

We retain personal data for as long as your account is active and as needed to provide the Service, resolve disputes, enforce agreements, and comply with legal obligations. After account deletion, we delete or anonymize data within a reasonable period unless retention is required by law.

10. Your rights

Depending on your location, you may have rights to access, rectify, erase, restrict, or object to certain processing of your personal data, and to data portability.

To exercise these rights, email privacy@novol.dev. You may also lodge a complaint with your local supervisory authority.

11. Children

The Service is intended for business users and not for children. We do not knowingly collect personal data from anyone under 18.

12. Changes to this policy

We may update this Privacy Policy from time to time. When we make material changes, we may update the effective date and take reasonable steps to notify users where appropriate.

13. Contact

Privacy questions or requests: privacy@novol.dev.

FLOWPIX LIMITED · Company details · Terms of Service · Privacy Policy · legal@novol.dev