Legal
Privacy Policy
What we collect, why we collect it, who we share it with, and the rights you have over it.
1. Overview
This Privacy Policy explains how Vortex Enterprises (a registered trade name; not a separately incorporated company), operating Vortex ("Vortex," "we," "us"), collects, uses, shares, and protects information when you use the Vortex app, website, and Discord bot (together, the "Service"). It's part of, and should be read together with, our Terms of Service. If you don't agree with this policy, don't use the Service.
2. Information We Collect
2.1 Information you give us
- Account information: username, email address, password (stored hashed, never in plain text), and birthdate (used only to verify you meet our minimum age requirement).
- Profile information: avatar, status message, bio, badges, and any other profile fields you choose to fill in.
- Content: messages, images, files, and other content you send or upload in guilds, channels, direct messages, tickets, and reports. Direct messages aren't end-to-end encrypted - like most hosted chat platforms, our systems can access message content to deliver and store it, and authorized staff can access it too, but only for a legitimate purpose such as investigating a report or policy violation, responding to valid legal process, or fulfilling your own data access request (see Section 11).
- Payment information: when you make a purchase, our payment processor (Stripe) collects your card details directly - we receive only limited billing metadata (such as the transaction amount, subscription status, and a Stripe customer reference), not your full card number.
- Support communications: anything you submit in a support ticket, report, or dispute, including messages you send us.
2.2 Information collected automatically
- Device & connection data: IP address, browser/device user agent, and a device fingerprint used for account security, fraud prevention, and enforcing platform and moderation restrictions.
- Session & login data: session identifiers, login timestamps, and login risk signals (for example, a login from an unrecognized device) used to detect suspicious account activity.
- Usage data: feature usage counts (such as message counts), presence/online status, and similar activity data needed to operate features like presence indicators and rate limiting.
- Cookies & local storage: see Section 5.
2.3 Information from third parties
- Discord: if you link a Discord account, we receive your Discord user ID and the minimum profile information needed to complete the link.
- Payment processor: Stripe shares limited transaction and subscription status information with us so we can grant the purchase.
3. How We Use This Information
- To provide the Service - deliver messages, sync presence, process purchases, and operate features you use;
- To secure accounts and the Service - detect and prevent fraud, account takeover, abuse, and platform attacks;
- To moderate content and enforce our Terms and Community Guidelines, including automated safety scanning described in Section 7;
- To communicate with you - account verification, security alerts, billing receipts, support responses, and, if you opt in, product announcements;
- To comply with legal obligations, including responding to valid legal process and mandatory reporting laws (see Section 13); and
- To improve the Service, including diagnosing bugs and understanding feature usage in aggregate.
We do not sell your personal information, and we do not use your private message content to train third-party advertising or AI models.
4. Legal Bases for Processing (EEA / UK Users)
If you're located in the European Economic Area, UK, or another jurisdiction with similar requirements, we rely on the following legal bases under the GDPR / UK GDPR:
- Performance of a contract - processing needed to provide the Service you signed up for (accounts, messaging, purchases);
- Legitimate interests - security, fraud prevention, content moderation, and service improvement, balanced against your rights;
- Legal obligation - responding to lawful requests and mandatory reporting laws such as CSAM reporting; and
- Consent - optional features like push notifications or marketing email, which you can withdraw at any time.
5. Cookies & Similar Technologies
We use cookies and local storage for things that make the Service work: keeping you signed in (session/auth cookies), remembering a trusted device, and basic security checks. We don't use third-party advertising trackers. Because these cookies are necessary for the Service to function, there isn't a separate cookie-consent banner for them; you can control cookies through your browser settings, though disabling them will likely prevent you from staying signed in.
6. Who We Share Information With
We share information only as needed to run the Service, and never sell it. This includes:
| Who | What they receive | Why |
|---|---|---|
| Stripe | Payment details, billing email, purchase amount | Payment processing |
| Image/content delivery provider (ImageKit) | Uploaded images and files | Storing and serving uploaded content |
| OpenAI (Moderation API) | Uploaded images and video frames; the text of direct messages and group chat messages | Automated content moderation screening (sexual content, graphic violence, self-harm, and other policy violations) - see Section 7 |
| Google (Safe Browsing API) | URLs shared in messages | Checking links for malware/phishing before they're shown to other users |
| Email delivery provider (ZeptoMail) | Your email address and message content of transactional emails | Sending verification codes, security alerts, and account emails |
| Discord | Your Discord ID, if you link your account | Account linking and bot features you opt into |
| Law enforcement / NCMEC | Limited account and content data | Legal compliance - see Section 13 |
Other members of a guild or channel you're in can see the messages and content you post there, consistent with that channel's normal visibility - that's the ordinary functioning of a chat platform, not a "sharing" event in the sense used elsewhere in this policy.
7. Automated Content Safety Scanning
Every image or video you upload is automatically run through an automated content moderation system before it can be viewed by anyone else, screening for sexual content, graphic violence, self-harm content, and other material that violates our Community Guidelines. Links shared in messages are checked against Google's Safe Browsing database for malware and phishing. Automated screening is a first line of defense, not an infallible one - flagged content is blocked from view and escalated for staff review, and we also rely on human review and user reports to catch what automated systems miss.
Whenever we become aware of apparent child sexual abuse material (CSAM) on the Service - whether through automated screening, staff review, or a user report - we are legally required under U.S. federal law (18 U.S.C. § 2258A) to report it to the National Center for Missing & Exploited Children's CyberTipline, along with available account information and the content itself. We preserve the associated report and related account data for the period required by law. See our Law Enforcement Guidelines for how this interacts with law enforcement requests.
Direct messages and group chat messages are also automatically screened for safety risks - such as threats, harassment, self-harm, and sexual content involving minors - using a combination of local keyword filtering and OpenAI's Moderation API. Flagged messages are queued for staff review the same way user-submitted reports are. In the small number of cases where a message is flagged with very high confidence for sexual content involving minors or detailed self-harm instructions, we may automatically and temporarily mute the sending account pending staff review. If a message appears to describe self-harm intent, we may also show you an in-app notice with crisis support resources, visible only to you and never stored as part of the chat history.
8. Children's Privacy
Vortex is not directed at children under 13, and we don't knowingly collect personal information from children under 13 beyond what's needed to enforce that age limit. During account setup, we ask for your birthdate for this single purpose. If our records show an account belongs to someone under 13, that account is automatically locked and cannot be used until our records show the minimum age has been reached - we do not knowingly allow a user we believe to be under 13 to access chat, uploads, purchases, or any other feature of the Service in the meantime.
We don't keep a locked underage account's data indefinitely while waiting for a birthday. If an account stays locked for this reason for 6 months, we automatically and permanently delete it, including the email address, birthdate, and device information collected during signup, instead of retaining it until the account holder eventually reaches the minimum age. If the account reaches the minimum age before that 6-month window closes, it unlocks normally instead of being deleted.
If you're a parent or guardian and believe your child under 13 has provided us with personal information beyond a birthdate used for this age check, contact admin@vortexos.net and we'll investigate and delete it as appropriate.
9. How Long We Keep Information
We keep account and content information for as long as your account is active, plus a limited period after deletion to handle fraud disputes, security incidents, and legal obligations. Some categories have shorter, fixed retention windows - for example, email verification codes and password-reset codes expire within minutes, and session records expire automatically once your session ends or its maximum lifetime is reached. An account locked for not meeting our minimum age requirement is permanently deleted after 6 months if it hasn't unlocked by then - see Section 8. Security and audit logs used to detect abuse are retained for a limited period on a rolling basis. Records tied to a CyberTipline report are retained for the period required by law (currently at least one year under the federal REPORT Act). When you delete your account, we delete or anonymize personal information that we're not legally required or permitted to retain.
10. Security
We use technical and organizational measures to protect your information, including password hashing, encrypted connections (HTTPS/TLS), session validation tied to your device, optional multi-factor authentication and passkey (WebAuthn) support, and automated risk scoring on logins. No system is perfectly secure, and we can't guarantee absolute security of information you transmit to us.
11. Your Privacy Rights
11.1 All users
Regardless of where you live, you can access, update, or delete most of your account information directly from your account settings, or by contacting us at admin@vortexos.net or through a support ticket. To request a full copy of your data, open a Data Request ticket from Contact Us. If your request includes direct messages, the export of a DM thread necessarily includes the messages sent by the other participant(s) in that conversation, since they're part of the same exchange - we don't redact the other side of a conversation from your own copy of it.
11.2 California residents (CCPA/CPRA)
If you're a California resident, you have the right to know what personal information we've collected about you, request deletion of it, request correction of inaccurate information, and opt out of any "sale" or "sharing" of personal information (we don't sell or share personal information for cross-context behavioral advertising) or restrict use of sensitive personal information. We won't discriminate against you for exercising these rights. To exercise them, contact us using the details in Section 15; we may need to verify your identity before fulfilling certain requests.
11.3 EEA / UK residents (GDPR)
If you're located in the EEA or UK, you have the right to access, rectify, erase, or restrict processing of your personal information, receive a portable copy of it, object to processing based on legitimate interests, and withdraw consent where processing is based on consent. You also have the right to lodge a complaint with your local data protection authority.
11.4 Other jurisdictions
If you're located in a jurisdiction with its own privacy law (for example, Virginia, Colorado, or other U.S. states with comprehensive privacy statutes), we extend the same categories of rights described above to the extent required by that law. Contact us and we'll respond consistent with applicable law even if a specific process isn't described here.
12. International Data Transfers
Vortex is operated from and stores data primarily in the United States. If you're accessing the Service from outside the United States, your information will be transferred to and processed in the United States, which may not have the same data protection laws as your home country. By using the Service, you consent to this transfer, to the extent consent is the applicable legal basis for doing so.
13. Law Enforcement & Legal Requests
We disclose account information in response to valid legal process (such as a subpoena, court order, or search warrant), where we believe in good faith that disclosure is required to comply with the law, or where necessary to prevent imminent harm to a person. Full detail on the process we require, what legal process is needed for which category of data, and our CSAM reporting obligations is in our Law Enforcement Guidelines. Where legally permitted, we try to notify affected users before disclosing their information.
14. Changes to This Policy
We may update this policy as the Service evolves. Material changes will be reflected in the "Last updated" date above and, where required by law or where the change is significant, announced in-app or by email before they take effect. Continued use of the Service after a change takes effect means you accept the updated policy.
15. Contact
Questions about this policy, or requests to exercise your privacy rights, can be sent to admin@vortexos.net or submitted as a support ticket from Contact Us.