Privacy Policy
Last updated June 29, 2026
This policy explains what Vortic ("we") collects and how we use it. It is a plain-language summary, not a substitute for the binding agreement you accept at sign-up.
What we collect
Account. Your email address and, for OAuth sign-in, the basic profile your provider returns.
Connection credentials. Tokens and secrets for the MCP servers and APIs you connect. These are encrypted at rest and are never placed in model prompts.
Usage. The boxes, tools, and runs you create, plus traces of each call (tool, arguments, results, latency, token counts) so you can audit and debug.
How we use it
To operate the service: route your requests to the models and tools you connect, maintain your workspace, enforce rate limits and security, and show you traces. We do not sell your data or use the contents of your runs to train models.
Subprocessors
We rely on infrastructure providers to run the service, including Vercel (hosting), Supabase (database and authentication), and the model providers you route through (e.g. OpenRouter, OpenAI). Your connected MCP servers receive the requests you direct to them.
Retention & deletion
We keep your data while your account is active. You can delete connections, keys, and boxes at any time, and request deletion of your account and associated data by contacting us.
Security
Credentials are encrypted, tenants are isolated, and API keys are stored only as hashes. No system is perfectly secure; report concerns to the contact below.
Contact
Questions or deletion requests: hello@getvortic.com.
Draft template — review with legal counsel before public launch.