Legal
Vulpy Privacy Policy
Effective date: September 3, 2026
This Privacy Policy describes how Vulpy, Inc. (Vulpy, we, us, or our) collects, uses, discloses, and otherwise processes personal information across all Vulpy properties and products, including the vulpy.io website, Vulpy Commerce, and the Vulpy Gateway.
Vulpy, Inc. is a Delaware corporation with its principal business address at 8 The Green, Ste D, Dover, DE 19901, United States. For the processing described in this policy, Vulpy is the controller of personal information we collect directly from you. This policy does not cover third parties or services that we do not control.
1. Information we collect
The information we collect depends on how you interact with Vulpy and may include:
All properties:
- Contact and account information — name, email address, business name, account details, and communications you send to us.
- Subscription and marketing information — email address and preferences you provide when subscribing to product updates, release notes, or other communications.
- Usage, device, and network information — pages viewed, referring URLs, browser and device information, approximate location derived from an IP address, and diagnostics.
- Cookie and similar-technology information — as described in the Cookie Policy.
Vulpy Commerce:
- Commerce administration information — store configurations, product and category information, editorial content, media, settings, and administrator activity.
- Order and payment information — orders, fulfilment information, payment status, billing email, transaction identifiers, and limited card information made available by Stripe (such as the last four digits). Stripe processes payment-card information; Vulpy does not store full payment-card numbers.
- Support and operational information — support messages, security events, and service logs.
Vulpy Gateway:
- Billing and transaction information — payment status, billing email, transaction identifiers, prepaid credit balances, and limited card information made available by Stripe.
- Gateway metadata — model or provider selected, request status, token and usage measurements, cache status, applicable pricing, timestamps, and technical diagnostics needed to route requests, meter usage, secure the Gateway, and resolve operational issues. Vulpy does not retain prompts or model outputs.
- Support and security information — support messages, abuse reports, security events, and service logs.
Demonstration environments are read-only and may be reset or removed. Do not submit real customer data, payment information, production credentials, confidential information, or other sensitive information to a demonstration environment.
2. How we use information
We use personal information to:
- operate, maintain, and secure Vulpy properties;
- create and administer accounts;
- process purchases, route Gateway requests, and apply credits;
- provide support;
- send transactional communications and, where you have subscribed or where otherwise permitted by law, product and marketing communications;
- prevent fraud, abuse, and security incidents;
- measure usage and performance where you consent or where we have a legitimate interest;
- comply with law; and
- establish, exercise, or defend legal claims.
We do not use prompts or model outputs to train models.
3. How we disclose information
We may disclose personal information to service providers that process it on our behalf, including:
- Payment processors — Stripe, for purchase and billing flows. Stripe’s processing is governed by its own privacy notice.
- Hosting and infrastructure providers — to operate and deliver Vulpy properties.
- Email and communications providers — to send transactional and marketing communications.
- Security and logging providers — to detect and respond to incidents.
- Analytics providers — where you have given consent.
- Language-model providers — for Gateway requests, the prompt and related technical information are forwarded to the provider you select or that is configured for your request.
- Support providers — where we use third-party tooling to manage support.
We may also disclose information where we reasonably believe it is necessary to comply with law or legal process; protect the rights, property, or safety of Vulpy, our users, or the public; prevent fraud or abuse; enforce our agreements; or facilitate a merger, acquisition, financing, reorganisation, or sale of assets.
We do not sell personal information for money, and we do not share personal information for cross-context behavioural advertising.
4. Gateway: requests and third-party providers
The Gateway forwards requests to third-party language-model providers. This necessarily involves sending the prompt, model parameters, and related technical information to the selected provider. Vulpy seeks to use providers that do not retain prompt or output content. To Vulpy’s knowledge, no provider trains on prompts or outputs submitted through the Gateway. Provider practices may change and Vulpy does not control third-party providers. Do not submit payment-card data, credentials, secrets, or sensitive personal information in a prompt unless the service expressly requires it and you have determined that doing so is lawful.
5. Analytics and consent
The vulpy.io website uses Google Analytics only after you give consent through the site’s consent controls. Commerce and Gateway analytics are similarly consent-gated where applicable. You may withdraw consent at any time through the same controls. See the Cookie Policy for details.
6. Retention
We retain personal information only as long as reasonably necessary for the purposes described in this policy:
- Gateway metadata (request logs, usage records, billing records) — retained for the period required to resolve billing disputes, meet legal and accounting obligations, and maintain security, typically no longer than 3 years.
- Prompts and model outputs — not retained by Vulpy.
- Account and transaction information — retained for the life of the account and for a reasonable period after closure to meet legal, tax, and accounting obligations.
- Support communications — retained as long as reasonably necessary to resolve the support matter and related issues.
When information is no longer needed, we delete it, anonymise it, or aggregate it. We may retain information for longer where required or permitted by law.
7. Security
We use reasonable technical and organisational measures designed to protect personal information against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access. No method of transmission or storage is completely secure and we cannot guarantee absolute security.
8. International processing
Vulpy is based in the United States. We and our service providers, including underlying Gateway providers, may process personal information in the United States and other countries. Those countries may have data-protection rules different from those in your jurisdiction. Where required, we use appropriate safeguards or lawful transfer mechanisms, including Standard Contractual Clauses for transfers from the EEA or UK.
9. Your privacy choices and rights
Depending on where you live, you may have rights to:
- access personal information we hold about you;
- correct inaccurate personal information;
- request deletion of personal information;
- request portability of personal information;
- object to or restrict certain processing; or
- withdraw consent where processing is based on consent.
To make a request, email privacy@vulpy.io. We may need to verify your identity before responding. We will respond within one month of receiving a verified request, or within any shorter period required by applicable law. We will not discriminate against you for exercising privacy rights available under applicable law.
If you receive marketing email from us, you may opt out by following the unsubscribe instructions in the email or by contacting us at privacy@vulpy.io.
If you are in the EEA, UK, or Switzerland and believe we have not handled your personal information in accordance with applicable law, you have the right to lodge a complaint with a supervisory authority in your jurisdiction.
10. Children
Vulpy properties are not directed to children under 13 (or a higher age where required by local law), and we do not knowingly collect personal information from children below that age. If you believe a child has provided personal information to us, contact us at privacy@vulpy.io and we will take appropriate steps to delete it.
11. Changes and contact
We may update this Privacy Policy from time to time. When we do, we will post the updated version and revise the effective date. For material changes, we will provide advance notice where required by law.
For privacy questions or requests, contact privacy@vulpy.io.
Postal address: Vulpy, Inc., 8 The Green, Ste D, Dover, DE 19901, United States.