Privacy Policy

Last updated 21 August 2026

What we collect, why we collect it, who processes it on our behalf, and how to get it back or have it deleted.

1.Who is responsible

Vorly is the controller of the personal data described here. For any privacy question, or to exercise the rights in section 8, email [email protected].

2.What we collect

  • Account data. Your email address, and the name and reason you give when requesting access. We use passwordless sign-in, so we never hold a password.
  • Workspace data. Your brand name, website, category, guidelines and visual direction; the competitors you nominate; and the campaigns, concepts and creative you produce.
  • Team data. The email addresses of people you invite, and their role in your workspace.
  • Usage data.A record of billable operations, such as how many images were generated and when, so we can apply your plan’s allowance and understand our costs.
  • Billing data. Your Stripe customer and subscription identifiers, plan, and renewal date. Card details go directly to Stripe; we never receive or store them.
  • Technical data. Server logs, IP address and basic device information, generated by our hosting and bot-protection providers.

3.Why we use it

To provide the product and the features you ask for; to authenticate you; to take payment and apply your plan’s limits; to send service messages such as sign-in links and access decisions; to keep the service secure and prevent abuse; and to fix problems and improve how it works.

Our legal bases are performance of our contract with you, our legitimate interests in running and securing the product, your consent where we ask for it, and compliance with legal obligations.

We do not sell your personal data, and we do not share it for cross-context behavioural advertising.

4.AI processing

To generate research and creative, we send the relevant material — your brand details, guidelines, instructions and the public competitor data in scope — to the AI providers listed below. They process it to return a result to you.

We use these providers’ business or API services, which under their terms do not use submitted content to train their general models. Their own terms govern their handling of the data, and we choose providers on that basis.

5.Who processes data for us

We use the following subprocessors. Each receives only what it needs for its purpose.

ProviderPurposeLocation
SupabaseDatabase, authentication and file storageUnited States
RenderApplication hostingUnited States
StripePayments and subscription billingUnited States
ResendTransactional email (sign-in links, notifications)United States
AnthropicAI models for research and copyUnited States
OpenAIAI models for research and copyUnited States
GoogleGemini models for image and copy generationUnited States
OpenRouterRouting requests to AI modelsUnited States
PerplexityAI models for market researchUnited States
MetaPublic Ad Library data about the competitors you nominateUnited States
TikTokPublic advertising and content dataUnited States
logo.devCompany logos shown beside brand namesUnited States
CloudflareTurnstile bot protection on public formsGlobal

We may also disclose data where the law requires it, or to a successor if the business is acquired, in which case this policy continues to apply until you are told otherwise.

6.Cookies

We use only what the product needs to work: a cookie that keeps you signed in, a cookie remembering which brand you last had open, and Cloudflare Turnstile on public forms to block automated abuse. We do not use advertising or cross-site tracking cookies.

7.How long we keep it

We keep workspace data for as long as your account is open. After you close your account we delete or anonymise personal data within 90 days, except where we must keep records longer — invoices and payment records are kept for the period tax law requires, and limited security logs are retained for a short period.

8.Your rights

Depending on where you live, you may have the right to access a copy of your personal data, to correct it, to delete it, to restrict or object to how we use it, to receive it in a portable format, and to withdraw consent. If you are in the EEA or UK you may complain to your data protection authority.

If you are a California resident, you have the right to know what we collect, to delete it, to correct it, and not to be discriminated against for exercising those rights. We do not sell or share personal information as those terms are defined under the CCPA/CPRA.

To exercise any of these, email [email protected]. We will respond within the time the law allows and may need to verify your identity first.

9.Security

Data is encrypted in transit. Access to customer data in our database is restricted by row-level security so a workspace can only reach its own records, and administrative credentials are held server-side only. No system is perfectly secure, but we work to protect your data and will tell you and any regulator, as the law requires, if a breach affects you.

10.International transfers

Our providers are largely in the United States, so data may be transferred there. Where personal data is moved out of the EEA or UK we rely on appropriate safeguards, such as the European Commission’s standard contractual clauses.

11.Children

Vorly is a business product and is not intended for anyone under 18. We do not knowingly collect data from children. If you believe a child has given us data, contact us and we will delete it.

12.Changes

If we change this policy we will update the date at the top, and where the change is significant we will tell account owners directly.

Questions about this page? Email [email protected].