Vorenthic
Terms Privacy Alpanzo AI Home
Legal — Privacy Policy

Privacy Policy

This Privacy Policy explains how Vorenthic Labs collects, uses, stores, shares, and protects your personal data when you use our Services.

Effective Date: July 19, 2026
Table of Contents
1. Introduction & Scope 2. Data Controller 3. Personal Data We Collect 4. Legal Basis for Processing (GDPR) 5. How We Use Your Data 6. AI Services & Conversation Data 7. Cookies & Tracking Technologies 8. Data Sharing & Third-Party Processors 9. International Data Transfers 10. Data Retention 11. Security Measures 12. Your Rights 13. Children's Privacy 14. California Privacy Rights (CCPA/CPRA) 15. India-Specific Provisions (DPDP Act) 16. Changes to This Policy 17. Contact & Data Protection Officer
Section 01

Introduction & Scope

Vorenthic Labs ("Company", "we", "us", or "our") is committed to protecting and respecting your privacy. This Privacy Policy describes our practices concerning the personal data we collect from users ("you" or "your") of our websites, applications, APIs, and all related products and services (collectively, the "Services").

This Policy applies to all Services operated under the vorenthic.pages.dev domain and its subdomains, including but not limited to:

  • Alpanzo AI — our flagship conversational AI platform
  • Alpanzo Code Suite — our desktop IDE and developer tooling
  • Vorenthic Accounts — our unified identity and authentication system
  • Vorenthic Landing Pages — our public-facing informational websites

This Policy is designed to comply with the General Data Protection Regulation (EU) 2016/679 ("GDPR"), the UK General Data Protection Regulation ("UK GDPR"), the California Consumer Privacy Act as amended by the California Privacy Rights Act ("CCPA/CPRA"), the Digital Personal Data Protection Act, 2023 (India) ("DPDP Act"), and other applicable data protection laws worldwide.

Our Core Principle: Vorenthic means privacy by architecture, not by policy. We engineer our systems to minimise data collection, maximise local processing, and ensure your intellectual property remains under your control.
Section 02

Data Controller

For the purposes of data protection legislation, the data controller responsible for your personal data is:

Vorenthic Labs
Email: privacy@vorenthic.pages.dev
Website: https://vorenthic.pages.dev

If you are located in the European Economic Area (EEA) or the United Kingdom (UK), Vorenthic Labs acts as the data controller with respect to the personal data processed through the Services. If you have questions about our data practices or wish to exercise your rights, please contact us using the details above or see Section 17.

Section 03

Personal Data We Collect

We collect personal data in the following categories:

3.1 Data You Provide Directly

Category Examples Purpose
Account Data Email address, username, password (hashed) Account creation, authentication, communication
Profile Data Display name, avatar, preferences Personalisation, service customisation
User Content Prompts, queries, uploaded files, conversation history Service delivery, AI response generation
Payment Data Billing address, payment method (processed by third-party processors; we do not store full card numbers) Subscription management, billing
Communication Data Support tickets, feedback, correspondence Customer support, service improvement

3.2 Data Collected Automatically

Category Examples Purpose
Device Data IP address, browser type and version, operating system, device identifiers Security, analytics, service optimisation
Usage Data Pages visited, features used, interaction timestamps, session duration Analytics, service improvement, abuse prevention
Log Data Server logs, error reports, API call metadata Debugging, security monitoring, performance
Cookie Data Session tokens, preference cookies, analytics identifiers Authentication, personalisation, analytics

3.3 Data from Third Parties

We may receive limited personal data from third-party authentication providers (e.g., OAuth providers) if you choose to link a third-party account. We receive only the data you authorise the third-party provider to share, typically limited to your email address and display name.

Section 04

Legal Basis for Processing (GDPR)

If you are located in the EEA or UK, we process your personal data on the following legal bases:

Legal Basis Applicable Processing Activities
Contract Performance
(Art. 6(1)(b) GDPR)
Account registration, service delivery, AI response generation, subscription management, customer support
Legitimate Interests
(Art. 6(1)(f) GDPR)
Security and fraud prevention, service improvement and analytics, abuse detection, infrastructure maintenance
Consent
(Art. 6(1)(a) GDPR)
Non-essential cookies, marketing communications, optional data sharing for research purposes
Legal Obligation
(Art. 6(1)(c) GDPR)
Compliance with legal and regulatory requirements, responding to lawful data access requests
Section 05

How We Use Your Data

We use the personal data we collect for the following purposes:

  1. Service Delivery: To provide, operate, maintain, and improve the Services, including generating AI responses, processing your requests, and managing your Account.
  2. Authentication & Security: To verify your identity, manage session tokens, prevent unauthorised access, detect and mitigate fraud, and protect against malicious activity.
  3. Communication: To send you service-related notices, security alerts, account notifications, and respond to your inquiries and support requests.
  4. Analytics & Improvement: To understand how the Services are used, identify trends, diagnose technical issues, and improve the performance, reliability, and user experience of the Services.
  5. Legal Compliance: To comply with applicable laws, regulations, legal processes, or enforceable governmental requests.
  6. Safety & Abuse Prevention: To enforce our Terms of Service, detect violations of our acceptable use policies, and protect the rights, property, and safety of Vorenthic Labs, our users, and the public.
Section 06

AI Services & Conversation Data

Our AI features process your inputs (prompts, queries, uploaded images and files) to generate responses. We handle this data with particular care:

  • No Model Training: We do not use your individual prompts, conversation histories, or uploaded content to train or fine-tune our foundational AI models. Our AI models are provided by third-party vendors and are not trained on user-specific data collected through our Services.
  • Session-Based Processing: Conversation data is processed in real-time to generate responses. Conversation history within a session is maintained temporarily to provide contextually coherent multi-turn interactions.
  • Temporary Caching: Responses and session data may be temporarily cached in memory for performance optimisation. Cached data is automatically purged at the end of each session or within twenty-four (24) hours, whichever is shorter.
  • Content Safety Logging: In limited circumstances, we may log metadata (not content) related to inputs that trigger content safety filters, solely for the purpose of maintaining and improving our safety mechanisms.
  • Third-Party AI Providers: AI responses are generated by third-party model hosting providers. When your prompts are transmitted to these providers, they are processed in accordance with those providers' data processing agreements with us, which prohibit the use of your data for model training.
Important: Do not include sensitive personal data (such as government-issued identification numbers, financial account numbers, medical records, or passwords) in your prompts or conversations with our AI services. While we implement security safeguards, AI-generated responses are not suitable environments for the transmission of sensitive personal data.
Section 07

Cookies & Tracking Technologies

We use cookies and similar technologies to operate and improve the Services. A cookie is a small data file stored on your device that helps us recognise your browser and capture certain information.

Cookie Type Purpose Duration
Essential Cookies Authentication, session management, security verification (e.g., human verification tokens) Session / up to 24 hours
Preference Cookies Storing your display preferences, theme, language selection, and cookie consent state Up to 12 months
Analytics Cookies Understanding usage patterns, page views, and feature adoption (anonymised where possible) Up to 12 months

You can manage your cookie preferences through the cookie consent banner displayed on first visit, or through your browser settings. Disabling essential cookies may impair core functionality of the Services.

We do not use third-party advertising cookies or cross-site tracking pixels. We do not sell your data to advertisers.

Section 08

Data Sharing & Third-Party Processors

We do not sell, rent, or trade your personal data. We share personal data only in the following limited circumstances:

  • Service Providers & Data Processors: We engage trusted third-party service providers who process data on our behalf to deliver the Services. These processors are contractually bound to process data only as instructed by us and to implement appropriate security measures. Our current categories of processors include:
    • Cloud infrastructure and hosting (Cloudflare)
    • AI model hosting and inference (third-party AI providers)
    • Payment processing (for paid subscriptions)
    • Database services (Cloudflare D1)
  • Legal Requirements: We may disclose your personal data if required to do so by law or in response to valid requests by public authorities (e.g., a court order, subpoena, or government investigation).
  • Protection of Rights: We may disclose personal data when we believe in good faith that disclosure is necessary to protect our rights, your safety, the safety of others, or to investigate fraud or respond to a government request.
  • Business Transfers: In the event of a merger, acquisition, reorganisation, bankruptcy, or sale of all or a portion of our assets, your personal data may be transferred to the acquiring entity, subject to the same privacy protections described in this Policy.
Section 09

International Data Transfers

Your personal data may be transferred to and processed in countries other than the country in which you reside. These countries may have data protection laws that differ from those in your jurisdiction. Specifically, our servers and third-party service providers may be located in:

  • The United States
  • The European Economic Area
  • India
  • Other jurisdictions where Cloudflare operates edge infrastructure

When we transfer personal data from the EEA, UK, or Switzerland to countries that have not been deemed to provide an adequate level of data protection, we rely on appropriate safeguards, including:

  • Standard Contractual Clauses (SCCs) approved by the European Commission
  • Data Processing Agreements (DPAs) with our processors that incorporate GDPR-compliant terms
  • Adequacy decisions where available
Section 10

Data Retention

We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, including satisfying legal, accounting, or reporting requirements.

Data Category Retention Period
Account Data Duration of account existence + 30 days after deletion request
Conversation / Session Data Duration of session; purged within 24 hours
Server & Access Logs Up to 90 days
Payment & Billing Records As required by applicable tax and accounting laws (typically 7 years)
Cookie & Consent Records Up to 12 months; refreshed upon re-consent
Support Communications Up to 24 months after resolution

When personal data is no longer required, we securely delete or anonymise it. Anonymised data that cannot be re-identified may be retained indefinitely for analytical purposes.

Section 11

Security Measures

We implement industry-standard technical and organisational measures to protect your personal data against unauthorised access, alteration, disclosure, or destruction. These include:

  • Encryption in Transit: All data transmitted between your device and our servers is encrypted using TLS 1.2 or higher.
  • Encryption at Rest: Sensitive data stored in our databases is encrypted using AES-256 or equivalent encryption standards.
  • Password Hashing: User passwords are hashed using bcrypt with appropriate salt rounds. We never store plaintext passwords.
  • Session Security: Authentication tokens are cryptographically signed and expire after a configurable duration. Session validation occurs on every authenticated request.
  • Access Controls: Internal access to personal data is restricted to authorised personnel on a need-to-know basis, with role-based access controls and audit logging.
  • Infrastructure Security: Our Services are hosted on Cloudflare's global edge network, benefiting from DDoS protection, Web Application Firewall (WAF), and Bot Management capabilities.
No system is 100% secure. While we strive to use commercially acceptable means to protect your personal data, we cannot guarantee absolute security. We encourage you to use strong, unique passwords and to enable available security features on your Account.
Section 12

Your Rights

Depending on your jurisdiction, you may have the following rights regarding your personal data:

Right Description Applicable Jurisdictions
Access Request a copy of the personal data we hold about you GDPR, UK GDPR, CCPA, DPDP
Rectification Request correction of inaccurate or incomplete personal data GDPR, UK GDPR, DPDP
Erasure / Deletion Request deletion of your personal data ("right to be forgotten") GDPR, UK GDPR, CCPA, DPDP
Portability Receive your data in a structured, machine-readable format GDPR, UK GDPR
Restriction Request restriction of processing in certain circumstances GDPR, UK GDPR
Objection Object to processing based on legitimate interests GDPR, UK GDPR
Withdraw Consent Withdraw previously given consent at any time GDPR, UK GDPR, DPDP
Non-Discrimination Exercise your rights without receiving discriminatory treatment CCPA/CPRA
Grievance Redressal Lodge a complaint with us or the Data Protection Board DPDP

To exercise any of these rights, please contact us at privacy@vorenthic.pages.dev. We will respond to your request within the timeframes required by applicable law (typically 30 days for GDPR, 45 days for CCPA). We may request verification of your identity before processing your request.

You also have the right to lodge a complaint with your local data protection supervisory authority. A list of EU supervisory authorities is available at edpb.europa.eu.

Section 13

Children's Privacy

Our Services are not directed to children under the age of thirteen (13). We do not knowingly collect personal data from children under 13. If you are a parent or guardian and believe your child has provided us with personal data without your consent, please contact us at privacy@vorenthic.pages.dev, and we will take steps to delete such data from our systems.

For users in the EEA, we comply with the age requirements set by applicable Member State law. In jurisdictions where a higher age threshold applies (e.g., 16 in Germany), we apply that higher threshold.

Section 14

California Privacy Rights (CCPA/CPRA)

If you are a California resident, you have the following additional rights under the California Consumer Privacy Act (as amended by the California Privacy Rights Act):

  • Right to Know: You have the right to request disclosure of the categories and specific pieces of personal information we have collected about you, the categories of sources, the business purpose for collection, and the categories of third parties with whom we share it.
  • Right to Delete: You have the right to request deletion of your personal information, subject to certain exceptions.
  • Right to Correct: You have the right to request correction of inaccurate personal information.
  • Right to Opt-Out of Sale/Sharing: We do not sell or share (as defined under CCPA/CPRA) your personal information for cross-context behavioural advertising. Therefore, there is no need to opt out.
  • Right to Non-Discrimination: We will not discriminate against you for exercising any of your CCPA/CPRA rights.

To make a verifiable consumer request, please contact us at privacy@vorenthic.pages.dev. You may designate an authorised agent to make a request on your behalf.

Do Not Track: Some browsers transmit "Do Not Track" (DNT) signals. As there is no industry consensus on how to respond to DNT signals, we do not currently respond to them. However, we do not engage in cross-site tracking of our users.

Section 15

India-Specific Provisions (DPDP Act)

If you are located in India, the following provisions apply in addition to (and, where conflicting, take precedence over) the general provisions of this Policy, in accordance with the Digital Personal Data Protection Act, 2023:

  • Consent: We process your personal data based on your free, specific, informed, unconditional, and unambiguous consent, obtained through clear and affirmative action (e.g., accepting our terms, submitting a registration form).
  • Legitimate Uses: We may process your personal data without consent for legitimate uses as defined under the DPDP Act, including voluntary provision of data for a specified purpose and performance of functions under applicable law.
  • Data Principal Rights: As a Data Principal, you have the right to: (a) obtain information about processing; (b) seek correction and erasure; (c) grievance redressal; and (d) nominate another person to exercise your rights.
  • Grievance Officer: Complaints may be directed to our Grievance Officer at privacy@vorenthic.pages.dev. We will acknowledge your complaint within 48 hours and endeavour to resolve it within 30 days.
  • Data Protection Board: If you are unsatisfied with our response, you may approach the Data Protection Board of India as constituted under the DPDP Act.
Section 16

Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technologies, legal requirements, or other factors. When we make material changes, we will:

  1. Update the "Effective Date" at the top of this page.
  2. Post the revised Policy on our website.
  3. Where practicable and required by law, notify you via email or through a prominent notice within the Services.

We encourage you to review this Privacy Policy periodically. Your continued use of the Services after any changes constitutes your acceptance of the updated Policy.

Section 17

Contact & Data Protection Officer

If you have any questions, concerns, or requests regarding this Privacy Policy or our data processing practices, you may contact us at:

Vorenthic Labs — Privacy Team
Email: privacy@vorenthic.pages.dev
Website: https://vorenthic.pages.dev

Grievance Officer (India — DPDP Act)
Email: privacy@vorenthic.pages.dev
Response time: Acknowledgement within 48 hours; resolution within 30 days

For exercising your data subject rights under GDPR, UK GDPR, or CCPA/CPRA, please include "Data Subject Request" in the subject line of your email. We may request identity verification before processing your request.

© 2026 Vorenthic Labs. All rights reserved.
Privacy Policy  ·  Terms of Service  ·  Home