Privacy Policy
How we collect, use, store, and share personal data when you use VStok.
Last updated: 2026-06-30
Operator: FLOWPIX LIMITED (Company No. 16157203)
Product: VStok (https://vstok.net)
Registered office: 128 City Road, London, EC1V 2NX, United Kingdom
Jurisdiction: England and Wales
Privacy contact: privacy@novol.dev
Effective date: August 13, 2026
1. Scope
This Privacy Policy explains how FLOWPIX LIMITED, operating the VStok product ("we", "us"), collects, uses, stores, and shares personal data when you visit vstok.net, create an account, use the VStok platform, contact us, or interact with our billing flows.
This policy applies to the public website, authentication pages, and the web application used for AI visibility tracking, audits, reports, and related features.
2. Personal data we collect
- Account and identity data — email address, password (hashed), full name, locale preference, and authentication session data.
- Social sign-in data — when you use Google or Apple login, profile basics from the identity provider processed through Supabase Auth.
- Project and brand data — brand names, project names, categories, languages, countries, website and app store URLs, competitor names and URLs, product details, custom prompts, and optional project logos you upload.
- AI audit and analytics data — prompts sent to LLM APIs, raw and parsed model responses, visibility scores, sentiment, mentions, citation sources, site crawl results, and app listing audit findings.
- Agent Execution data — GitHub installation and repository mapping, default branch and production environment, recommendation and policy snapshots, provider and execution state, branch name, commit SHA, draft pull request URL and number, changed file paths, named check and deployment metadata, verification results, and append-only consent and execution events. VStok does not request or store repository source files or diffs.
- Usage data — plan limits, usage counters (AI checks, prompts, reports, audits per billing period), and feature activity within your account.
- Billing data — subscription plan, currency, billing period, Stripe customer and subscription references, YooKassa payment IDs and status, and invoice-related metadata.
- Transactional email metadata — when we send account, verification, or password-reset messages through Resend (or Supabase Auth email, depending on configuration).
- Support communications — messages you send to us by email or support channels.
- Technical data — browser type, request metadata, and diagnostics processed by our infrastructure providers as needed to operate the Service.
- Browser storage — cookies and local storage as described in our Cookie Policy.
3. How we use personal data
- To create and manage accounts and authenticate users.
- To deliver AI visibility tracking, audits, reports, and related product features.
- To coordinate customer-authorized Agent Execution, enforce repository policies, observe draft pull requests and deployments, and verify deployed changes.
- To process subscriptions, billing events, plan changes, and support requests.
- To send transactional notifications (account verification, password reset, billing-related messages).
- To secure the Service, prevent misuse, and maintain platform integrity.
- To comply with legal obligations, enforce our terms, and protect our legal rights.
We do not sell personal data.
4. Legal bases
Where UK GDPR or similar laws apply, we generally rely on:
- Performance of a contract — to provide your account and the Service you request.
- Legitimate interests — to secure, operate, and improve the platform in a proportionate way.
- Compliance with legal obligations — including accounting, tax, and fraud prevention.
- Consent — where required by law for optional technologies or communications.
5. AI processing, Agent Execution, and third-party content
Core features transmit your brand, competitor, URL, and prompt data to large language model providers (OpenAI, Google Gemini, Perplexity) to generate and parse audit results. This processing is necessary to provide the Service you request.
Site and app listing audits may fetch publicly available content from URLs you specify. We process that content to generate technical and visibility insights.
If you connect Codex, Cursor, or Claude, the customer-authorized agent receives selected recommendation context, target URLs, evidence, acceptance criteria, required checks, and execution policy through OAuth. Crawled evidence is marked as untrusted content. The coding agent reads and changes source in your repository under your provider account; VStok receives only execution metadata and does not receive source files or diffs.
The optional VStok GitHub App observes repository metadata, pull requests, checks, and deployments and may publish a VStok policy check. The App does not request Contents write, branch write, or merge permission. We do not store Codex, Cursor, or Claude provider API keys.
6. Sharing personal data and subprocessors
We share personal data with service providers that help us run the Service. A summary is on our Subprocessors page. Providers include, among others:
- Supabase — authentication, database, and file storage.
- OpenAI, Google (Gemini), Perplexity — AI audit and content generation.
- Stripe — payments and subscriptions (USD/EUR).
- YooKassa — payments (RUB).
- Resend — transactional email.
- Google and Apple — OAuth sign-in (via Supabase Auth).
- GitHub — optional repository installation, pull request, check, and deployment metadata for Agent Execution.
- Customer-selected Codex, Cursor, or Claude providers — recommendation context and execution instructions when you explicitly connect and use that provider.
We may disclose information if required by law, regulation, or valid legal process.
7. Public reports
When you generate a shareable report link, anyone with the link can access the report content without logging in. Report tokens are designed to be unguessable, but you control distribution. Do not share links if you do not want the content to be accessible to recipients.
8. International transfers
We and our subprocessors may process data in the United Kingdom, European Economic Area, United States, and other countries. Where we transfer personal data outside the UK or EEA, we implement appropriate safeguards as required by applicable data protection law.
9. Retention
We retain personal data for as long as your account is active and as needed to provide the Service, resolve disputes, enforce agreements, and comply with legal obligations. After account deletion, we delete or anonymize data within a reasonable period unless retention is required by law.
OAuth connection metadata is retained until you revoke or delete the connection. We may retain security, consent, policy, claim, report, and verification audit records for a reasonable period after revocation where needed to investigate abuse, resolve disputes, or comply with law.
10. Your rights
Depending on your location, you may have rights to access, rectify, erase, restrict, or object to certain processing of your personal data, and to data portability.
To exercise these rights, email privacy@novol.dev. You may also lodge a complaint with your local supervisory authority.
11. Children
The Service is intended for business users and not for children. We do not knowingly collect personal data from anyone under 18.
12. Changes to this policy
We may update this Privacy Policy from time to time. When we make material changes, we may update the effective date and take reasonable steps to notify users where appropriate.
13. Contact
Privacy questions or requests: privacy@novol.dev.
FLOWPIX LIMITED · Company details · Terms of Service · Privacy Policy · legal@novol.dev