Back to Home

Privacy Policy

Last Updated: September 22, 2026

1. Introduction

Welcome to Vorflux ("we," "our," or "us"). We are committed to protecting your personal information and your right to privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website and use our AI coding agent services.

By using Vorflux, you agree to the collection and use of information in accordance with this policy. If you do not agree with the terms of this Privacy Policy, please do not access or use our services.

2. Information We Collect

2.1 Personal Information

We collect personal information that you voluntarily provide to us when you:

  • Register for our waitlist or create an account
  • Subscribe to our services
  • Contact us for support or inquiries
  • Participate in surveys or promotions

This information may include:

  • Name and contact information (email address, phone number)
  • Company name and role
  • Account and authentication information, such as your email address and identity-provider identifiers
  • Payment and billing information
  • Communication preferences

2.2 Technical and Usage Data

When you access our services, we automatically collect certain information, including:

  • Device information (IP address, browser type, operating system)
  • Usage data (pages visited, features used, time spent)
  • Log data (access times, error logs, performance metrics)
  • Cookies and similar tracking technologies

2.3 Operational Data

To provide our AI coding agent services, we collect:

  • Repository and codebase data from connected systems
  • Issue and task data from project management tools
  • Integration data from third-party services you connect
  • Prompts, model responses, session transcripts, session logs, and agent activity data
  • Credentials and secrets that you provide for connected services
  • Monitoring, error, incident, and customer-support context
  • Optional testing evidence, such as saved browser state, screenshots, and recordings, when you request authenticated or visual testing
  • Performance metrics and analytics data

3. How We Use Your Information

We use the information we collect for the following purposes:

  • To provide, operate, and maintain our services
  • To process your transactions and manage your account
  • To send you notifications and communications related to agent sessions and task progress
  • To configure and personalize the Services for your account
  • To provide customer support and respond to inquiries
  • To send marketing communications (with your consent)
  • To detect, prevent, and address technical issues and security threats
  • To comply with legal obligations and enforce our terms
  • To use aggregated, anonymized operational metrics that contain no source code, prompt or response content, or personal information for capacity planning and reliability engineering

4. AI and Data Processing

Vorflux uses artificial intelligence and machine learning to power autonomous coding agents that analyze, debug, and resolve issues across your codebase. We process your operational data only to provide the Services to you, including to:

  • Analyze code, identify bugs, and generate fixes
  • Identify patterns and root causes in your codebase
  • Generate pull requests, tests, and code improvements

Vorflux does not use your source code, prompts, agent transcripts, or other customer data to train, fine-tune, evaluate, benchmark, or otherwise improve a machine-learning model. We do not permit model providers to use that data to train their models. We also do not access or analyze customer data to improve, benchmark, or develop the Vorflux product without your prior written consent for a specific purpose and scope. Accepting this Privacy Policy or our Terms of Service is not that consent. You may withdraw consent at any time. If you use your own provider credentials or sign in through a model provider, that provider's terms apply to its processing.

5. Information Sharing and Disclosure

We do not sell your personal information. We may share your information in the following circumstances:

5.1 Service Providers

We may share your information with third-party service providers who perform services on our behalf, including:

  • Cloud hosting, databases, storage, encryption, backup, and workflow infrastructure, including Amazon Web Services, Cloudflare, and Temporal
  • Model inference providers, including OpenAI, Anthropic, Google Cloud, and other providers that you select or that we confirm with you in advance
  • Authentication providers, including Auth0
  • Execution tracing providers, including Laminar; when tracing is enabled, traces may contain agent-session content
  • Operational logging, error diagnostics, and product analytics providers, including Oodle, Sentry, and PostHog
  • Source-control and build providers, including GitHub
  • Payment processors and billing services
  • Customer support, internal collaboration, messaging, and on-call providers, including Google Workspace, Slack, Atlassian, Intercom, Twilio, and PagerDuty

We maintain a current subprocessor list with data-access categories and make it available on request. We will notify affected customers before adding a new subprocessor that will process customer data or changing a subprocessor's processing location. Where account-level provider restrictions are configured, providers outside that approved list receive no inference context. Our managed OpenAI, Anthropic, and Google Cloud arrangements use zero-data-retention terms. Zero-data-retention terms are not available for every supported provider, so we will confirm the applicable retention terms with you before using another managed provider. A provider's retention terms are separate from its prohibition on using customer data for model training.

5.2 Authorized Human Access

Authorized Vorflux engineering and support personnel may access production data when necessary to provide support, investigate incidents, maintain security, or operate the Services. This personnel may include our India-based team. Access is limited by role, protected by authentication and audit controls, and subject to confidentiality obligations. Customer approval before each support access is not currently required unless your agreement says otherwise.

5.3 Business Transfers

If we are involved in a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction. We will provide notice before your information is transferred and becomes subject to a different privacy policy.

5.4 Legal Requirements

We may disclose your information if required to do so by law or in response to valid requests by public authorities (e.g., court orders, subpoenas, or government agencies).

6. Data Security

We implement appropriate technical and organizational security measures to protect your information against unauthorized access, alteration, disclosure, or destruction. These measures include:

  • Encryption of data in transit and at rest
  • Regular security assessments and audits
  • Access controls and authentication mechanisms
  • Employee training on data protection and security
  • Incident response and breach notification procedures

We will notify you without undue delay and no later than 24 hours after we confirm a security incident affecting your source code, credentials, personal information, repository integrity, tenant isolation, or agent activity. A stricter notification term in your agreement applies. Incidents that originate with an external service provider remain subject to the notification terms in your agreement.

However, no method of transmission over the internet or electronic storage is 100% secure. While we strive to use commercially acceptable means to protect your information, we cannot guarantee its absolute security.

7. Data Retention

We retain personal information only as long as needed to provide the Services, meet legal obligations, resolve disputes, and enforce our agreements. Current default retention periods include:

  • Repository clones and workspaces remain on the session machine for the task. Inactive environments stop after 30 minutes, hibernate after 12 hours, and terminate after 10 days, which deletes their configured volumes. Cleanup before termination is best effort.
  • Session transcripts and model responses are retained for the life of your account.
  • Previous versions of account memory files expire 30 days after replacement.
  • Local test-command logs are removed 10 minutes after completion. Copies saved as session evidence remain with the session record.
  • Optional iOS build files expire after 30 days, and uploaded source files expire after 7 days.
  • Automated database backups and cache snapshots are retained for 7 days. Manual and final snapshots do not currently have an automatic expiry.
  • Network flow logs are retained for 7 days.
  • External error, application, analytics, and support logs follow the applicable service provider's retention terms.

Stopping a session machine or terminating an account does not automatically delete session records, artifacts, memory files, or backups. You may submit a verified deletion request or agree specific deletion timelines with us. We process verified requests according to your agreement and applicable law. Legal, security, backup, and dispute-resolution obligations may require limited continued retention.

8. Your Privacy Rights

Depending on your location, you may have certain rights regarding your personal information:

  • Access: Request a copy of the personal information we hold about you
  • Correction: Request correction of inaccurate or incomplete information
  • Deletion: Request deletion of your personal information
  • Portability: Request transfer of your information to another service
  • Objection: Object to certain processing of your information
  • Restriction: Request restriction of processing in certain circumstances
  • Withdraw Consent: Withdraw consent for processing based on consent

To exercise these rights, please contact us using the information provided in the "Contact Us" section below.

9. Cookies and Tracking Technologies

We use cookies and similar tracking technologies to track activity on our service and store certain information. You can instruct your browser to refuse all cookies or to indicate when a cookie is being sent. However, if you do not accept cookies, you may not be able to use some portions of our service.

Types of cookies we use include:

  • Essential Cookies: Required for the service to function properly
  • Analytics Cookies: Help us understand how users interact with our service
  • Preference Cookies: Remember your settings and preferences
  • Marketing Cookies: Track your activity for advertising purposes (with consent)

10. Third-Party Services and Integrations

Our service may contain links to third-party websites, services, or integrations. We are not responsible for the privacy practices or content of these third parties. We encourage you to review the privacy policies of any third-party services you access through our platform.

When you connect third-party integrations to Vorflux, we will access and process data from those services as necessary to provide our services, in accordance with the permissions you grant.

11. International Data Transfers

Your information may be transferred to and processed in countries other than your country of residence. These countries may have data protection laws that are different from the laws of your country.

When we transfer your information internationally, we ensure appropriate safeguards are in place to protect your information in accordance with this Privacy Policy and applicable laws.

12. Children's Privacy

Our service is not intended for anyone under the age of 18. We do not knowingly collect personal information from anyone under 18. If you become aware that a person under 18 has provided us with personal information, please contact us, and we will take steps to delete it.

13. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. We will notify you of material changes and post the updated Privacy Policy on this page with a new "Last Updated" date.

We encourage you to review this Privacy Policy periodically for any changes. Changes to this Privacy Policy are effective when they are posted on this page.

14. Contact Us

If you have any questions about this Privacy Policy or our data practices, please contact us at:

Vorflux

Email: support@vorflux.com

Website: https://vorflux.ai

15. Specific Regional Rights

15.1 California Privacy Rights (CCPA)

If you are a California resident, you have specific rights under the California Consumer Privacy Act (CCPA), including:

  • The right to know what personal information we collect, use, and disclose
  • The right to request deletion of your personal information
  • The right to opt-out of the sale of your personal information (we do not sell personal information)
  • The right to non-discrimination for exercising your privacy rights

15.2 European Privacy Rights (GDPR)

If you are located in the European Economic Area (EEA), United Kingdom, or Switzerland, you have rights under the General Data Protection Regulation (GDPR), including:

  • The right to access, update, or delete your personal information
  • The right to data portability
  • The right to object to processing
  • The right to restriction of processing
  • The right to withdraw consent at any time
  • The right to lodge a complaint with a supervisory authority

© 2026 Vorflux. All rights reserved.