← Home

Privacy Policy

Last updated on 25 August 2026

This Privacy Policy forms part of, and should be read together with, the Vorvano Terms of Service. Capitalised terms not defined in this Policy have the meaning given in those Terms.

About this Policy

This Privacy Policy explains the categories of personal information Vorvano LLC (“Vorvano,” “we,” “us,” or “our”), a Wyoming limited liability company with its principal address at 30 N Gould St, Ste R, Sheridan, WY 82801, collects, the sources we collect it from, why we use it, who we share it with, how long we keep it, how we protect it, and the privacy rights you may have. It applies to all Vorvano applications, websites, and related services (the “Service”), whether now existing or hereafter developed and whether obtained through an app store or by direct download. What we actually collect and process depends on which application you use, the features you enable, and the settings you choose, all of which are described in that application's in-app notices, settings, or app-store privacy label and are incorporated into this Policy by reference. The Service is intended for users in the United States only; see the “Where your information is processed” section.

1. Categories of personal information we collect

Depending on the application and how you use it, we may collect the following categories of personal information. Not every category is collected by or applicable to every application — several are collected by none of the applications we currently offer. For what a particular application actually collects, read the “What each application collects” section immediately below, which governs where it differs from this general list.

  • Identifiers and account data: your name, email address, optional phone number, an account identifier, your password (stored only as a salted, memory-hard hash — never in plain text), and the IP address from which you create your account.
  • Consent and verification records: the fact, date, time, and version of the agreements and consents you accepted; your email-verification status; and records of privacy choices you make.
  • User-provided content and inputs: materials and content you submit to or generate through an application and any associated outputs. For AI-enabled applications, this can include text you provide such as document or résumé text, prompts, your spoken answers and their transcripts, and resulting notes, scores, and feedback, which are processed by us and by third-party AI providers to generate outputs.
  • Audio and speech data: for applications with voice features, your microphone input and the resulting transcript. Depending on the feature and your settings, speech recognition may run on your device, or your audio may be transmitted to a third-party speech-to-text provider to produce the transcript. Where session recording is offered, we also create and store on our servers an audio recording of the practice session (a mixed file of your spoken answers and the AI interviewer's synthesized voice), retained and deleted as described in the “Audio, voice & biometrics” and “Retention” sections, which describe this in detail.
  • Usage analytics and inferences: product-usage and interaction analytics, feature and performance metrics, and inferences derived from your use of the Service (for example, practice scores or other AI-generated assessments).
  • Diagnostics and error logs: crash reports, error logs, and technical event data, collected to keep the Service operating and secure.
  • Device and technical profile: non-identifying hardware, operating-system, configuration, and network attributes (such as device type, OS version, app version, and general capability indicators) used to assess compatibility and deliver and secure the Service.
  • Communications: information you provide when you contact us for support, respond to surveys, or otherwise communicate with us, including the contents of those communications.

Data minimization. We seek to collect and process only what is reasonably necessary and proportionate to provide the application and features you request and the purposes described in this Policy. We may de-identify, aggregate, or derive statistics and other non-personal information from any of the above and use and retain it without restriction.

2. What each application collects

The section above lists every category any Vorvano application may collect. This section says which of them each application actually collects, because those are very different lists. Where this section and the general text above differ for a particular application, this section governs for that application.

Daily Tracker (iPhone)

Daily Tracker is a habit tracker. Everything below is stored on your phone and copied to a Vorvano server, against your account, so that it survives losing your phone.

  • Your habit setup. The names of your habits and their steps, your affirmations, your accountability statements, your pledge text, your chosen theme and reading speed, and the display name you type into Settings. The whole setup is sent whenever you change it.
  • Your daily record. Which habits you answered and how, your points, score and streak, and which piece of evidence is attached to which habit. Stored as one document per month.
  • Your journal. Anything you type into the journal, and the machine-generated transcript if you ask the app to turn a recorded entry into text.
  • Photos, videos and voice notes. If a habit asks for proof, or you record a video or voice journal entry, that file is saved on your phone and then uploaded to your account automatically. There is no separate per-capture confirmation: attaching the file is what starts the upload. If an upload cannot complete, the app retries at launch and each time you bring it to the foreground.
  • Your account identifier, which is how the server attributes all of the above to you.

Photos are re-encoded by the app before upload, so the original camera file's metadata, including any location it recorded, is not carried through. A video chosen from your photo library is uploaded without the app processing its metadata, so it may carry the location it was recorded at.

Daily Tracker also keeps its habit records, and every photo, video and voice note, in its own folder on your phone. Those files are deliberately included in your device backup so that restoring a device restores the user’s history. Where iCloud Backup is enabled, those files are therefore included in the iCloud backup; where the device is backed up to a computer instead, they are included there. Your sign-in token is the exception and is not included in any backup.

What Daily Tracker does not do. It contains no advertising, no analytics, no tracking and no third-party code of any kind: it uses only Apple's own frameworks and links no outside libraries. It collects no email address, no phone number, no device or advertising identifier, and no location. It has no AI features, and nothing you put into Daily Tracker is used to train any model — the “Use of your content to improve and train AI” section does not apply to it. Reading a commitment or pledge aloud is recognised entirely on your device: the app refuses to run that feature rather than fall back to a server, no recording is made, and that audio never leaves your phone. Only the fact that you read it, and when, is saved.

Speech, and Apple's part in it — a third-party disclosure. Two matters described here are attributable to Apple rather than to Vorvano, and are identified so that a user is informed where a third party processes their voice. When Daily Tracker first asks for speech permission, iOS shows a standard alert containing Apple's own wording about speech data being sent to Apple; that wording is Apple's boilerplate, cannot be edited, and does not describe what this app does. And if you use the iOS keyboard's dictation key while typing in the journal, that is iOS handling your voice outside this app, under Apple's terms.

Callback (macOS)

Callback runs AI mock interviews. It collects your account data, the document or résumé text and prompts you provide, your spoken answers and their transcripts, the resulting notes, scores and feedback, and product-usage analytics and diagnostics. Its speech may be transcribed by a third-party provider and its interview sessions are recorded and stored as described in the “Audio, voice & biometrics” section. Content from Callback is within the scope of the “Use of your content to improve and train AI” section.

The “Use of your content to improve and train AI” and “Audio, voice & biometrics” sections below — model training, cloud speech transcription and session recording — describe Callback, and any future application this section says they describe. They do not describe Daily Tracker.

Takhtehnar (iPhone)

Takhtehnar is a backgammon game with a coach that scores your moves. Vorvano collects nothing from it. The application makes no network connection of any kind — it contains no networking code, no third-party SDK, no analytics, no crash reporting and no advertising — so no data it holds is ever transmitted to us or to anyone else. Its App Store privacy label is accordingly “Data Not Collected.”

Because nothing is transmitted, the categories in the section above describe nothing that Takhtehnar sends. What follows is instead a description of what the application writes on your own device, given here so that this Policy describes the application you actually have rather than only the parts of it we receive:

  • Your settings. Language, theme, accent colour, board options, sound, haptics, your default opponent level and your match length.
  • Your match history. The moves you played, the dice rolled, the scores, and the opponent level. This is what the Review, Progress and Drills screens read.
  • A local profile, if you make one. A display name and an email address. No password is stored and none is checked — the email is a label on the profile, on the device, and nothing more. It is not an account with Vorvano, it is not registered with us, and no message is ever sent to it.

These are written to UserDefaults and to the application's own container, and are included in your device backup, so where iCloud Backup is enabled they form part of that backup and where the device is backed up to a computer they are included there. That is the only copy of them that exists anywhere other than the device itself, and it is made by Apple at your direction rather than by us.

What the application does with it. Everything is used to run the game: to replay and analyse your own past matches, to build drill positions out of your own mistakes, and to restore your settings. The analysis is performed on the device by neural networks bundled inside the application. Because nothing is sent anywhere, none of it is used for training, profiling, advertising or sharing, and there is no server-side copy for us to disclose, sell, or be compelled to produce.

Permissions. Takhtehnar requests no system permission of any kind: no camera, microphone, location, contacts, photos, notifications or Bluetooth, and no App Tracking Transparency prompt, because there is no tracking to ask about. Its PrivacyInfo.xcprivacy manifest declares tracking false, declares no collected data types, and declares UserDefaults as a required-reason API under reason CA92.1 (accessing the application's own data).

Deleting it. Profile → Delete account removes the profile and every stored match. Settings → History → Clear match history removes the matches and leaves the profile. Deleting the application removes everything. None of these require a request to us, and none of them could, because we hold nothing to delete.

cue

Not yet covered by this section. cue is not released, and this Policy does not yet describe it. When it ships, this subsection will state what it collects, why, and who it goes to, in the same detail as Daily Tracker above. Until then, nothing here should be read as a description of cue. If you are using a pre-release build and want to know what it collects, ask us at support@vorvano.com and we will tell you before you use it.

Future applications

A Vorvano application that is not named in this section is not covered by it. We add a subsection here before an application is released rather than after, so that this page always describes the applications you can actually use. The general categories in the section above do not substitute for a subsection here: they describe what any Vorvano application might collect, not what any particular one does.

3. Cookies, storage, and this website

This section is about vorvano.com itself, which is a different surface from the applications described above and collects far less.

This website sets no cookies, and uses no local storage or session storage. There is no advertising, no tracking pixel, no session identifier, and nothing that follows you between visits or to any other site. Accordingly, no cookie-consent notice is presented on this website, there being no cookie to which consent could apply.

One third party is contacted when you load a page. Our hosting provider offers a cookieless page-view measurement, which is enabled on this site, so your browser loads a small script from that provider and the page view is recorded. It sets no cookie and does not identify you across sites or across visits. As with any request routed through a host, the request itself also discloses your IP address and the page you requested to that provider, which processes it on our behalf. No other third-party script is loaded, and no other host is contacted.

Cookies used at sign-in. When an application hands you to the Vorvano sign-in page, that page runs in a system browser sheet that shares Safari's cookies for our login domain. This is by design: it permits a session established in one Vorvano application to be recognised by another, rather than requiring separate authentication in each. The effect is that a user’s sign-in is linked across Vorvano applications on that device. It does not disclose to Vorvano, or to any other party, browsing activity outside the Vorvano login domain.

Do Not Track and Global Privacy Control. Some browsers transmit a “Do Not Track” signal, and some transmit a Global Privacy Control signal. Vorvano operates no cross-site tracking of any kind: this website sets no cookies, uses no local or session storage, and carries no advertising or tracking pixel, and the applications contain no advertising identifier and no third-party tracking code. There is accordingly no cross-site tracking for either signal to disable. Where a Global Privacy Control signal is treated by applicable law as an opt-out of the sale or sharing of personal information, Vorvano honours it; as stated in the “Sale and sharing” subsection, no such sale or sharing takes place.

4. Sources of personal information

We collect personal information: (a) directly from you when you create an account, submit content, configure settings, or communicate with us; (b) automatically from your device and software as you install, use, and interact with the Service; and (c) from service providers and partners that help us operate, secure, analyze, or deliver the Service (for example, hosting, analytics, AI, speech, and email-delivery providers, and, where applicable, app-store and payment platforms).

6. Use of your content to improve and train AI

This section applies only to applications identified as AI-enabled in the “What each application collects” section. It does not apply to Daily Tracker, whose content is never used to train any model, and it does not apply to Takhtehnar, which transmits nothing at all — there is no content from it for us to train on, and the coach that scores your moves runs on your device rather than on ours.

For those applications: by creating an account, accessing, or using them, you agree that Vorvano and its providers may use the content you submit and generate — including your document and résumé text, prompts, spoken answers and their transcripts, interview and practice content, and the resulting outputs, together with your usage, interaction, and feedback data — to operate, evaluate, develop, secure, and improve the Service, and to develop, train, fine-tune, and improve our and our providers' artificial-intelligence and machine-learning models, systems, and prompts. We may do this as part of providing and improving the Service and without separate notice to you each time.

Where reasonably feasible, we de-identify, aggregate, or minimize content used for model development, and we apply the following limits: we do not use the personal information of minors for model training; we do not sell sensitive personal information, even with consent; we do not use your content to make automated, consequential, or legally significant decisions about you or to furnish a score or determination about you to any third party (your scores and feedback are presented to you, for your own use); and we apply the data-rights and deletion mechanisms described in the “Your privacy rights” and “Retention” sections. De-identified, aggregated, and derived data is not personal information and may be used and retained for any lawful purpose without restriction. Some of our AI providers may also process content under their own terms to provide and, in some cases, improve their services; see the “Service providers” section. If we introduce a dedicated control to opt out of model-training use, your choice through that control will govern going forward.

7. Audio, voice & biometrics

Which applications this describes. Cloud transcription and session recording, described in this section, apply to Callback. They do not apply to Daily Tracker, which pins speech recognition to your device, refuses to run the feature rather than fall back to a server, makes no recording, and never uploads that audio. They do not apply to Takhtehnar either, and cannot: it is a backgammon game that requests no microphone permission, contains no voice feature, and makes no network connection. See the “What each application collects” section.

How speech is processed. Some applications and features transcribe your speech so the AI can respond to what you say, and synthesize a spoken voice for the interviewer. Depending on the feature and your settings, speech recognition may run on your device, or, where cloud transcription is enabled, your microphone audio may be securely transmitted (including in real time) to a third-party speech-to-text provider to produce the transcript, and the text of the interviewer's lines may be sent to a third-party text-to-speech provider to produce the synthesized voice. This is a change from earlier desktop-only versions, which performed all speech recognition on your device; the current Service may transmit your audio to a cloud provider for transcription when that option is in use. Interview-session recordings. For interview-practice sessions, we record the session audio — both your spoken answers and the interviewer's synthesized voice — and store that recording on our servers so that you can review your performance and so our authorized team can review sessions to evaluate, debug, and improve the Service (including the AI, as described in this Policy). A recording indicator is shown during capture. These recordings are encrypted at rest by our object-storage provider as described in the Data security section, access is limited to authorized personnel, and they are retained while your account is active and deleted when you delete your account (subject to short-lived encrypted backups that age out) or sooner on request. Outside interview-practice recording, we use audio only to produce the transcript and deliver the feature you requested, and where speech recognition runs on your device that audio is processed locally. The resulting transcript is handled as User-provided content under this Policy. See the “Service providers” section.

No biometric identifiers; no voiceprints. Except as a specific application expressly discloses in-app (in which case that application's disclosure and consent govern), we do not collect, capture, purchase, receive through trade, store, or otherwise obtain biometric identifiers or biometric information as those terms are defined under the Illinois Biometric Information Privacy Act (740 ILCS 14), the Texas Capture or Use of Biometric Identifier Act (Tex. Bus. & Com. Code § 503.001), the Washington biometric-privacy law (RCW 19.375), or the Washington My Health My Data Act (RCW 19.373). We do not create, extract, or store voiceprints, retina or iris scans, fingerprints, scans of hand or face geometry, vein patterns, or any biometric template from which an identifier can be extracted, and we do not perform speaker recognition, face recognition, or voice- or face-based identity verification. Any audio the Service processes is used to deliver the requested features (such as transcription, feedback, or rendering an animated avatar) and, for interview-practice sessions, is recorded and stored so the session can be reviewed and the Service improved as described in the “Audio, voice & biometrics” section above; in all cases it is not converted into a biometric template, and is not used to identify you. We contractually require any speech-to-text, text-to-speech, or AI provider that processes audio to refrain from creating biometric identifiers or voiceprints from it and from using it to train biometric or identification models. We treat any biometric, genetic, or health data as sensitive and obtain opt-in consent where applicable law requires it.

8. Service providers

To operate, secure, and deliver the Service, we use trusted third-party service providers — including artificial-intelligence and cloud-infrastructure providers — that process personal information on our behalf, only as needed to provide the features you use and under contractual confidentiality and security obligations. The categories of provider on which the Service depends are set out below. Vorvano is operated in the United States and the greater part of it is self-hosted, so the list is short. Every provider that processes personal information on our behalf is contractually required to protect it to a standard at least equal to that stated in this Policy, to process it only on our instructions and only for the purposes described here, and not to use it for its own purposes, to sell it, or to retain it beyond what those purposes require. We do not sell your personal information. Where a state privacy law entitles a resident to the identity of the specific parties to which their personal data has been disclosed, Vorvano maintains that record and provides it on request, as described in the “Your privacy rights” section.

  • Cloud hosting and object-storage providers. Hosting for vorvano.com, hosting for the service that stores account records and application data, and the object storage that holds files uploaded through the applications. Objects held in that storage are encrypted at rest as described in the “Data security” section.
  • A website-analytics provider. The cookieless page-view measurement described in the “Cookies, storage, and this website” section. It sets no cookie and does not identify a visitor across sites.
  • Application-distribution platforms. The app stores through which the applications are distributed and updated.
  • Artificial-intelligence and speech providers, for Callback only. Callback’s interviewer, scoring and transcription are performed by third-party providers acting on our behalf. Daily Tracker uses none of them. Takhtehnar uses none of them and reaches no provider on this list at all, including the hosting and distribution providers, save that Apple distributes it through the App Store.

9. How we share and disclose personal information

We may disclose personal information as follows:

  • Service providers and processors: to the third-party service providers described in the “Service providers” section and other vendors that process personal information on our behalf under contractual confidentiality and security obligations, including AI, speech, hosting, email-delivery, analytics, security, and support providers, and — where applicable — app-store, payment, and content-delivery platforms.
  • Legal, safety, and compliance: to comply with applicable law, regulation, legal process, or enforceable governmental or court request; to enforce our agreements and policies; to detect, prevent, or address fraud, security, or technical issues; and to protect the rights, property, safety, or security of Vorvano, our users, or others.
  • Business transfers: in connection with, or during negotiations of, any merger, acquisition, financing, reorganization, sale of assets, bankruptcy, or other corporate transaction, in which case personal information may be among the assets transferred.
  • With your direction or consent: to other parties when you direct us to do so or otherwise consent.
  • Affiliates: to current and future Vorvano affiliates and related entities for the purposes described in this Policy.

Sale and sharing. We currently do not “sell” or “share” personal information, and do not use personal information for “targeted advertising” or for “profiling” in furtherance of decisions that produce legal or similarly significant effects, as those terms are defined under U.S. state privacy laws. Providing your content to AI and speech providers so they can generate the outputs you request is a service-provider relationship, not a “sale” or “share.” We do not sell sensitive or biometric personal information, and we will not sell sensitive personal information even with consent. If our practices ever change such that we sell or share personal information or conduct targeted advertising, we will update this Policy, provide the clear and conspicuous opt-out controls and notices the law requires, and honor recognized opt-out preference signals (such as the Global Privacy Control). We do not knowingly sell or share, and do not knowingly collect, the personal information of minors; if we learn we have collected such information, we will delete it.

10. Retention

We retain personal information for as long as reasonably necessary to fulfill the purposes described in this Policy — including to provide the Service, maintain and secure your account, develop and improve our products and models, and satisfy our legal, accounting, dispute-resolution, and enforcement needs — after which we delete, de-identify, or aggregate it. Retention periods vary by data type, application, and context. As a general guide: account data is retained while your account is active and for a short period afterward; user-provided content, session recordings, and transcripts are retained as needed to provide the Service and are deleted from our active systems when you delete your account or upon a verified deletion request, subject to the deletion rights described in the “Your privacy rights” section; diagnostic, usage, and error logs are retained for roughly 30 days; and residual copies in routine encrypted backups are purged within roughly 30 to 90 days. You may delete your account and associated synced data at any time using the in-app control; what that erases is set out in the “Deleting your account” section above. Retention of uploaded files is determined per application rather than by a single window across the Service. Where an application sets an expiry period, a file uploaded through it is deleted automatically when that period is reached, including the stored copy in object storage, whether or not the account has been deleted. Where an application sets none, uploaded files are retained until the user deletes them or deletes the account. Daily Tracker sets no expiry period: photographs, video and voice recordings attached as evidence are retained until you remove them or delete your account, because evidence attached to a habit record is of no use if it disappears before the record does. For Callback, session recordings are subject to an expiry period set for that application; the current period is available on request from the address in the Contact section. We may retain limited information as necessary to comply with law, enforce our agreements, resolve disputes, and prevent fraud and abuse. Copies of content already incorporated into trained model weights, backups, or logs that cannot feasibly be extracted or reversed, and de-identified, aggregated, and derived data, may be retained indefinitely.

11. Deleting your account, and what that erases

Each application that lets you create an account also lets you delete it, from inside the application itself — no request to Vorvano is required, and no use of this website is required. In Daily Tracker it is under Settings. In Takhtehnar it is under Profile → Delete account; that profile is local to the device and was never held by us, so what follows in this section describes the applications that sync to a Vorvano account rather than Takhtehnar, for which deletion is simply the removal of files from your own phone.

Scope of deletion. Deleting your account for an application removes, for that application: your account record and the display name on it; everything you created in it, including habit records, schedules, commitments, affirmations and journal entries; transcripts; every photograph, video and voice recording you attached, including the stored copies in our object storage, not merely the database rows that point at them; your device registrations; and your usage and analytics records. Deletion is effected as a removal rather than as a status flag: the records are removed rather than marked deleted, and the service verifies the removal by re-counting every table in the same transaction before it reports success. If that verification fails, the application is told the deletion did not complete and will not tell you your data is gone.

Matters outside the scope of deletion. Your Vorvano sign-in identity itself is shared with the other Vorvano applications you may use, so deleting your account for one application does not delete that identity or the accounts you hold with the others — the deletion of one application should not cause the loss of another that the user has not elected to leave. To remove the identity as well, delete your account in each application you use and then write to us. Residual copies in routine encrypted backups age out as described in the Retention section, and we may keep the minimum a law requires us to keep.

Re-registration. For a short period immediately after a deletion the service refuses to re-create the account — a safeguard against a request already in flight restoring what you just erased. After that you can sign in and start over with a clean, empty account. The data you deleted does not come back.

12. Data security

We implement and maintain reasonable administrative, technical, and physical safeguards designed to protect personal information appropriate to its sensitivity, including: encryption in transit (HTTPS/TLS); passwords stored only as salted, memory-hard hashes; encryption at rest for stored account and contact information; encryption at rest for every file you upload — photographs, video and voice recordings are held in object storage in which all objects and their metadata are encrypted with AES-256 automatically, without configuration and with no option to disable it; signed, expiring, HttpOnly administrative sessions protected by two-factor authentication; rate limiting and abuse controls; input validation and request-size limits; least-privilege access controls; and vendor oversight. We design our security program to align with recognized frameworks such as the NIST Cybersecurity Framework and NIST Privacy Framework and to satisfy applicable data-security laws, including the reasonable-safeguards requirement of the New York SHIELD Act. No method of transmission or storage is completely secure, and we do not and cannot guarantee absolute or perfect security; you use the Service and transmit information at your own risk. If a security breach affecting your personal information occurs, we will notify affected individuals and applicable regulators as and to the extent, and within the timeframes, required by applicable law, including the breach-notification laws of your state of residence (such as the New York SHIELD Act and California Civil Code § 1798.82, among others).

13. Your privacy rights

Which rights you have, and how they apply, depend on your state of residence. To be protective, we generally extend the core rights below to all U.S. users. These rights arise under the laws listed here, as and where they are in effect and apply to us: the California Consumer Privacy Act, as amended by the California Privacy Rights Act (CCPA/CPRA), and the comprehensive consumer-privacy laws of Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA), Utah (UCPA), Texas (TDPSA), Oregon (OCPA), Montana (MCDPA), Delaware (DPDPA), Iowa, Nebraska, New Hampshire, New Jersey, Minnesota (MCDPA), Maryland (MODPA), Tennessee (TIPA), Indiana, Kentucky, and Rhode Island, together with any other comparable state law that is or becomes effective.

  • Right to know / access: to confirm whether we process your personal information and to request the categories and specific pieces of personal information we have collected, the categories of sources, the business or commercial purposes for collecting, using, selling, or sharing it, and the categories of recipients (with a 12-month lookback under California law).
  • Right to delete: to request deletion of personal information, subject to legal exceptions.
  • Right to correct: to request correction of inaccurate personal information we maintain about you (this right is not available in every state, such as Utah and Iowa).
  • Right to data portability: to obtain a copy of certain personal information in a portable and, to the extent technically feasible, readily usable format.
  • Right to opt out of sale, sharing, targeted advertising, and profiling: as described in the “Sale and sharing” section, we do not currently sell or share personal information, conduct targeted advertising, or engage in such profiling, so there is presently nothing to opt out of; if that changes, we will provide the required opt-out controls and notices. We honor recognized opt-out preference and universal-opt-out signals (such as the Global Privacy Control) where required by law.
  • Right to limit use of sensitive personal information: to direct us to limit the use and disclosure of information treated as “sensitive” under applicable law to what the law permits. We process sensitive personal information only with opt-in consent where required, do not use it to infer characteristics about you, and do not sell it.
  • Right to question profiling (Minnesota): Minnesota residents may, in connection with profiling, be informed of the reason a decision was reached, the data used, the right to review and correct that data, and how to obtain a different outcome going forward.
  • Right to a list of third parties (Minnesota, Oregon, Delaware, and other states that provide this right): to request a list of the specific third parties to which we have disclosed personal data.
  • Right to non-discrimination: we will not discriminate or retaliate against you for exercising any of these rights.
  • Right to appeal: if we decline your request, residents of any state whose law provides an appeal right may appeal by replying to our response. We will respond to an appeal within the period the law requires (generally 60 days), and if we deny the appeal we will provide a method to contact the applicable state Attorney General.

How to exercise your rights. You may submit a request by emailing legal@vorvano.com (preferably from the email address associated with your account), or, where available, by using the in-app delete-account and privacy controls. To process certain requests we may need to verify your identity, typically by confirming control of your account email; we may decline or limit a request we cannot reasonably verify. We will acknowledge and respond within the timeframes required by applicable law — for example, under California law we acknowledge within 10 business days and respond within 45 days, extendable by an additional 45 days where permitted, with notice; most other state laws provide a 45-day response window, extendable as allowed. Your first request in a 12-month period is free; we may charge a reasonable fee or decline a request that is excessive, repetitive, or manifestly unfounded, as permitted by law. You may use an authorized agent where the law allows.

California & Nevada. This Policy serves as our California notice at collection. As stated above, we do not sell or share personal information or use it for targeted advertising; California residents may direct us to limit the use of their sensitive personal information and may exercise the other rights above, and we honor the Global Privacy Control. Under California's “Shine the Light” law (Cal. Civ. Code § 1798.83), we do not share personal information with third parties for those third parties' own direct-marketing purposes. California residents have a limited private right of action for certain data breaches under Cal. Civ. Code § 1798.150. Nevada residents may submit a verified request that we not sell certain “covered information” by emailing the address above.

14. Region-specific disclosures

The Service is offered to users in the United States only, so the regimes that apply to it are the state comprehensive-privacy laws rather than the European General Data Protection Regulation. No section of this Policy purports to make representations under the GDPR or the United Kingdom GDPR, and none should be read as doing so.

  • California. This Policy serves as the notice at collection required by the California Consumer Privacy Act as amended by the California Privacy Rights Act. California residents hold the rights to know, delete, correct, and port, the right to limit the use of sensitive personal information, and the right to non-discrimination. Vorvano does not sell or share personal information and does not use it for cross-context behavioural advertising. Under the “Shine the Light” law, no personal information is shared with third parties for those parties’ own direct-marketing purposes.
  • Virginia, Colorado, Connecticut, Utah and Texas. Residents of these states hold the rights to confirm processing and access, to delete, to obtain a portable copy, and to opt out of targeted advertising, sale, and profiling producing legal or similarly significant effects. Vorvano conducts none of those three activities. The right to correct is available in Virginia, Colorado, Connecticut and Texas; it is not conferred by the Utah statute.
  • Other states with comprehensive privacy statutes. Where a state statute confers equivalent rights and applies to Vorvano, those rights are extended to residents of that state on the same terms as set out in the “Your privacy rights” section.
  • Appeals. Where a request is declined and the resident’s state law provides a right of appeal, the appeal may be made by replying to the response. If an appeal is denied, Vorvano will provide the means of submitting a complaint to that state’s Attorney General.

Requests under any of the above are made to the address in the Contact section, and are handled as described in the “Your privacy rights” section.

15. Communications and text messages

If you provide a phone number, we may use it to help verify identity, secure your account, and send transactional or account-related messages. Where providing a phone number is optional, providing it constitutes your prior express consent to receive account, security, and transactional messages at that number. Marketing texts, if any, require your separate prior express written consent under the Telephone Consumer Protection Act (TCPA). Declining to provide an optional phone number does not impair your account or your ability to use the Service. Where you receive texts from us, message and data rates may apply, message frequency varies, and you can opt out by replying STOP (reply HELP for help).

16. Children

Exception for Takhtehnar. Takhtehnar is rated for all ages and may be used by a person of any age, and the adults-only statement below does not apply to it. It is able to carry that exception because it collects nothing: it makes no network connection, so no personal information of any user — child or adult — is ever transmitted to us. COPPA governs the online collection of personal information from children under 13, and no collection occurs. Anything the application saves, including a display name or an email address typed into a local profile, is written to the device and stays there; it is not an account, it is never registered with us, and no message is ever sent to it. The corresponding carve-out in the Terms is in their Eligibility section, and the detail is in the Takhtehnar Application Terms.

For every other application, the Service is intended only for adults (at least 18, or the higher age of majority where you reside) and is not directed to or intended for minors — that is, anyone under 18, and in no event anyone under 13. We do not knowingly collect personal information from anyone under 18, and we never knowingly collect data from a child under 13 within the meaning of the Children's Online Privacy Protection Act (COPPA). We do not use any minor's data to train AI models, for targeted advertising, or for sale. If you are under the applicable minimum age, do not use the Service or provide us any information. If you believe a child under 13 has provided us personal information, or you are a parent or guardian who wishes to request deletion of a minor's information, contact legal@vorvano.com and we will promptly delete it.

17. Where your information is processed (United States)

Vorvano is based in the United States, and the Service is intended for U.S. users only. We and our service providers store and process your personal information in the United States and may process it in other countries where we or our providers operate, subject to appropriate safeguards. We do not undertake to comply with non-U.S. data-protection laws (such as the GDPR or UK GDPR). By using the Service, you understand that your information will be processed in the United States and, where applicable, such other jurisdictions.

18. Changes to this Privacy Policy

We may update this Privacy Policy from time to time. Material changes will be reflected by the effective date shown above, and we will take reasonable steps to provide additional notice where required by law. Your continued use of the Service after an update takes effect means you accept the updated Policy.

19. Contact

Questions, requests, privacy-rights requests, or concerns about this Privacy Policy may be directed to Vorvano LLC, 30 N Gould St, Ste R, Sheridan, WY 82801, or by email to legal@vorvano.com.

On this page