Privacy Policy

Last updated 25 August 2026

VortexPrism is operated by Gitspark Technologies LLC. This page explains what we hold about you if you have an account with us, and — separately — what we process on behalf of our customers about the people who use their apps. The two are not the same, and the difference decides who you should ask about your data.

Two different relationships

If you signed up for VortexPrism, we decide how your account data is used, and this policy governs it. Ask us.

If you are an end user of an app built with VortexPrism, the developer of that app decides what is collected about you and why. We hold it on their instruction and do not use it for our own purposes. Your request goes to them; we help them act on it.

What we hold about account holders

  • Your name, email address, and organisation name.
  • How you sign in. If you use Google or Apple, we receive your email and name from them; we never receive your password.
  • Records of administrative actions taken in your organisation, kept as a security log.
  • Support correspondence you send us.

What we process for our customers

A customer’s app sends us data about its own users. What arrives depends on what that developer chose to send, and typically includes:

  • Identity records — email address, phone number, and a hash of the password where the app uses us for sign-in. We never store passwords in a readable form.
  • Product events — the name of an action, when it happened, and any properties the developer attached, along with the IP address, browser or device user agent, and country the request came from.
  • Device tokens, where an app registers for push notifications.
  • Subscription and purchase records retrieved from the stores and payment providers the developer has connected.

How long we keep it

  • Product events and link clicks are deleted automatically two years after they happen. This is enforced by the database, not by a process someone has to remember to run.
  • Identity records, device tokens and consent records are kept until the customer deletes them or closes the project.
  • Administrative audit records are kept indefinitely. They exist to show who changed what, and deleting them would defeat that.
  • Closing an account removes its projects and the data belonging to them.

Who else touches it

We use a small number of providers to run the service:

  • Hetzner — the servers and databases the product runs on.
  • Resend — sending transactional email such as sign-in and verification messages.

Separately, a customer may connect their own accounts with Apple App Store Connect, Google Play, RevenueCat, Stripe, Google Ads or Meta Ads. Where they do, we read data from those services on their behalf. That is their choice and their contract with those providers, not ours.

We do not sell personal data, and we do not use customer data to train models.

Your rights

You can ask for a copy of what we hold about you, ask us to correct it, or ask us to delete it. Email gitspark@gitspark.com and we will respond within 30 days.

Being straight about the current state: erasure requests are handled by us manually. There is no self-serve control for it yet, and an app developer cannot presently delete one of their users from the dashboard. If you need a user erased, write to us and we will do it.

Security

Traffic is encrypted in transit. Passwords are hashed. Credentials for the services a customer connects are encrypted before they are stored and are never shown back in full. Access to production is limited to the people who operate the service.

We do not currently hold a SOC 2 or ISO 27001 certification, and we would rather say so than imply otherwise.

Changes and contact

If this policy changes in a way that matters, we will say so before it takes effect rather than quietly moving the date at the top.

Gitspark Technologies LLC — gitspark@gitspark.com