Privacy Policy
Last updated 21 August 2026
What we collect, why we collect it, who processes it on our behalf, and how to get it back or have it deleted.
1.Who is responsible
Vorly is the controller of the personal data described here. For any privacy question, or to exercise the rights in section 8, email [email protected].
2.What we collect
- Account data. Your email address, and the name and reason you give when requesting access. We use passwordless sign-in, so we never hold a password.
- Workspace data. Your brand name, website, category, guidelines and visual direction; the competitors you nominate; and the campaigns, concepts and creative you produce.
- Team data. The email addresses of people you invite, and their role in your workspace.
- Usage data.A record of billable operations, such as how many images were generated and when, so we can apply your plan’s allowance and understand our costs.
- Billing data. Your Stripe customer and subscription identifiers, plan, and renewal date. Card details go directly to Stripe; we never receive or store them.
- Technical data. Server logs, IP address and basic device information, generated by our hosting and bot-protection providers.
3.Why we use it
To provide the product and the features you ask for; to authenticate you; to take payment and apply your plan’s limits; to send service messages such as sign-in links and access decisions; to keep the service secure and prevent abuse; and to fix problems and improve how it works.
Our legal bases are performance of our contract with you, our legitimate interests in running and securing the product, your consent where we ask for it, and compliance with legal obligations.
We do not sell your personal data, and we do not share it for cross-context behavioural advertising.
4.AI processing
To generate research and creative, we send the relevant material — your brand details, guidelines, instructions and the public competitor data in scope — to the AI providers listed below. They process it to return a result to you.
We use these providers’ business or API services, which under their terms do not use submitted content to train their general models. Their own terms govern their handling of the data, and we choose providers on that basis.
5.Who processes data for us
We use the following subprocessors. Each receives only what it needs for its purpose.
| Provider | Purpose | Location |
|---|---|---|
| Supabase | Database, authentication and file storage | United States |
| Render | Application hosting | United States |
| Stripe | Payments and subscription billing | United States |
| Resend | Transactional email (sign-in links, notifications) | United States |
| Anthropic | AI models for research and copy | United States |
| OpenAI | AI models for research and copy | United States |
| Gemini models for image and copy generation | United States | |
| OpenRouter | Routing requests to AI models | United States |
| Perplexity | AI models for market research | United States |
| Meta | Public Ad Library data about the competitors you nominate | United States |
| TikTok | Public advertising and content data | United States |
| logo.dev | Company logos shown beside brand names | United States |
| Cloudflare | Turnstile bot protection on public forms | Global |
We may also disclose data where the law requires it, or to a successor if the business is acquired, in which case this policy continues to apply until you are told otherwise.
6.Cookies
We use only what the product needs to work: a cookie that keeps you signed in, a cookie remembering which brand you last had open, and Cloudflare Turnstile on public forms to block automated abuse. We do not use advertising or cross-site tracking cookies.
7.How long we keep it
We keep workspace data for as long as your account is open. After you close your account we delete or anonymise personal data within 90 days, except where we must keep records longer — invoices and payment records are kept for the period tax law requires, and limited security logs are retained for a short period.
8.Your rights
Depending on where you live, you may have the right to access a copy of your personal data, to correct it, to delete it, to restrict or object to how we use it, to receive it in a portable format, and to withdraw consent. If you are in the EEA or UK you may complain to your data protection authority.
If you are a California resident, you have the right to know what we collect, to delete it, to correct it, and not to be discriminated against for exercising those rights. We do not sell or share personal information as those terms are defined under the CCPA/CPRA.
To exercise any of these, email [email protected]. We will respond within the time the law allows and may need to verify your identity first.
9.Security
Data is encrypted in transit. Access to customer data in our database is restricted by row-level security so a workspace can only reach its own records, and administrative credentials are held server-side only. No system is perfectly secure, but we work to protect your data and will tell you and any regulator, as the law requires, if a breach affects you.
10.International transfers
Our providers are largely in the United States, so data may be transferred there. Where personal data is moved out of the EEA or UK we rely on appropriate safeguards, such as the European Commission’s standard contractual clauses.
11.Children
Vorly is a business product and is not intended for anyone under 18. We do not knowingly collect data from children. If you believe a child has given us data, contact us and we will delete it.
12.Changes
If we change this policy we will update the date at the top, and where the change is significant we will tell account owners directly.
Questions about this page? Email [email protected].