Privacy Policy
Last updated: July 10, 2026
This policy explains what VALCRAN OS collects, how account and cloud features use data, which third-party providers process data, what stays local in guest mode, and how to exercise your privacy rights.
- Local guest mode does not create a backend account.
- VALCRAN does not sell personal information or use project content for third-party ads.
- Raw card numbers and CVC codes are handled by Stripe, not stored by VALCRAN OS.
- A named list of subprocessors is included below.
1. Scope
This Privacy Policy applies to VALCRAN OS, VALCRAN AI, VALCRAN Cloud, collaboration, account, billing, managed-domain, deployment, publishing, and support features operated by VALCRAN, LLC, a Florida limited liability company ("VALCRAN"), which is the data controller for personal information processed through these features.
This policy does not replace separate privacy notices or terms from third-party providers that power selected features.
2. Information You Provide
Account information may include your name, handle, email address, optional phone number, password credentials, OAuth profile information (for example, from Google, Firebase, or Apple sign-in), verification codes, profile image, preferences, subscription tier, and account status.
Billing information may include billing address, payment method identifiers, Stripe customer and subscription identifiers, invoices, credits, purchases, payment failures, and refund or dispute records. VALCRAN does not store raw card numbers or CVC codes.
Managed-domain information may include the registrant, administrative, and technical contact details required by ICANN and the applicable registry (such as name, email, optional phone, and address), DNS records you create, and domain purchase and renewal history. Some of this registration data may appear in WHOIS or registry systems as required by domain policy.
Support and communications may include messages you send to VALCRAN, crash details you choose to provide, and correspondence about billing, security, cloud, managed domains, or account issues.
3. Project, AI, and Product Data
When you use account-backed AI features, VALCRAN routes prompts, selected context, files, terminal output, runtime evidence, and generated output only as needed to return the response, protect the service, and operate billing and usage limits.
VALCRAN does not store prompt text, selected code, file contents, terminal output, or AI outputs in internal usage records by default. Usage records are limited to operational metadata such as account ID, model family, request counts, token or cost estimates, timestamps, and feature source.
If you enable AI Improvement Data, VALCRAN may store redacted and capped prompts, selected project context, terminal or runtime evidence, AI outputs, model and tool metadata, and feedback for improving VALCRAN AI, debugging, safety, and reliability. This feature is optional, off by default, requires confirming the account is not used by a child under 13, and stores samples for up to 90 days unless deleted sooner.
If you additionally enable Full Code Context, VALCRAN may store redacted code snippets and locally computed embeddings used for indexing and model training. This separate tier is off by default, requires the AI Improvement Data consent and age confirmation, runs an on-device redaction and secret-scan pass before any content leaves your device (files such as .env and detected secrets are never sent), and stores samples for up to 90 days unless deleted sooner. Enabling Privacy Mode disables all of this and keeps the account in a zero-retention posture.
Some user-directed features may store content you explicitly choose to save, publish, deploy, share, send in collaboration, provide to support, place in prompt/profile/project memory, or schedule as a background task.
Local files remain on your device unless you choose a feature that sends data to VALCRAN or a third-party provider, such as AI assistance, cloud deployment, publishing, collaboration, billing, support, or account sync.
VALCRAN disables supported server-side AI response caches and strips prompt-bearing metadata from internal usage history. Upstream model provider handling remains governed by the applicable provider terms and enterprise settings.
4. Guest Mode
Guest mode is local-only by default. VALCRAN does not create an authenticated account for guest use, and backend-gated features remain unavailable until you sign in.
If you leave guest mode by signing in, deploying, publishing, sharing, using cloud services, or using account-backed AI features, the data needed for those selected features may be sent to VALCRAN and relevant providers.
5. Cookies and Local Storage
When you sign in to account features, VALCRAN sets a strictly necessary session cookie (named "valcran_session") to keep you authenticated. This cookie is HTTP-only, marked Secure on HTTPS connections, and uses a SameSite policy (Lax by default) to help protect against cross-site request forgery. It is required for signed-in features to work.
VALCRAN OS also stores data locally on your device using browser or application local storage — for example, session summaries, preferences, and on-device memory used by product features. This data stays on your device unless you use a feature that sends it to VALCRAN or a provider.
VALCRAN does not use advertising cookies, third-party tracking pixels, or cross-site advertising trackers.
6. Telemetry, Diagnostics, and Logs
VALCRAN may process security logs, authentication events, billing events, deployment status, usage limits, crash data, reduced runtime telemetry, and performance diagnostics to operate, secure, debug, and improve the service.
Where VALCRAN offers telemetry controls, opt-in learning or runtime telemetry is limited to the selected purpose. Reduced runtime telemetry is pruned on a short retention schedule where implemented, including approximately 30 days for the runtime telemetry backend path.
7. Quick Search and Real-Time Data
If you use Quick Search or related real-time features, the query and necessary parameters are sent to third-party providers to return results. These providers currently include Brave Search (web results and related images), Google Maps Platform (places, addresses, and venue details), and Finnhub (company quotes and financial profiles).
Those providers process your query under their own terms and privacy practices. Avoid including sensitive personal information in search queries.
8. How VALCRAN Uses Information
VALCRAN uses information to authenticate users, provide AI assistance, operate local and cloud features, process payments, manage credits and subscriptions, deploy projects, register and manage domains, support collaboration, prevent abuse, secure accounts, send transactional emails and verification messages, provide support, comply with law, and improve product reliability.
VALCRAN does not sell personal information and does not use your account data or project content for third-party advertising.
9. Service Providers and Sharing
VALCRAN shares information with service providers (also called subprocessors) only as needed for the feature you use. These include payment processing, authentication, email and SMS delivery, cloud hosting and storage, databases, domain registration and DNS, AI model providers, and real-time search. A named list appears in the Subprocessors section below.
VALCRAN may also disclose information when required by law, to respond to lawful requests, to protect users or the service, to prevent fraud or abuse, to enforce these terms, to complete a business transaction such as a merger or acquisition, or with your direction and consent.
10. Subprocessors
The providers below process personal or user data on VALCRAN's behalf to deliver the indicated features. Each provider processes data under its own terms and security practices, primarily in the United States.
Stripe — payment and subscription processing — billing details, payment method identifiers, contact data.
Amazon Web Services (AWS) — cloud hosting, storage, compute, database, and logging — account data, project and deployment data, logs.
Cloudflare — domain registrar, DNS, CDN, and security — domain registrant/WHOIS data, DNS records, request metadata.
Anthropic — AI model provider — prompts and selected context for AI requests you initiate.
OpenAI — AI model provider — prompts and selected context for AI requests you initiate.
xAI — AI model provider — prompts and selected context for AI requests you initiate.
Google and Firebase — Google sign-in and authentication — authentication tokens and basic profile data.
Apple — Sign in with Apple — authentication tokens and basic profile data.
Twilio — SMS delivery — phone number and verification codes for phone verification.
Resend — transactional email delivery — email address and message content for account, billing, and security notices.
Brave Search — web search — your Quick Search queries.
Finnhub — financial data — company or ticker queries from Quick Search.
Google Maps Platform — places and mapping — location and place queries from Quick Search.
This list may change as the product evolves; the current version is reflected in this policy.
11. International Data Transfers
VALCRAN and its providers are primarily located in the United States. If you access VALCRAN OS from outside the United States, your information may be transferred to, stored in, and processed in the United States and other countries where VALCRAN or its providers operate, which may have different data-protection laws than your country.
Where required, transfers of personal data from the EEA, UK, or Switzerland rely on appropriate safeguards, such as the European Commission's Standard Contractual Clauses or the providers' equivalent mechanisms.
12. Retention
VALCRAN keeps information for as long as needed to provide the service, maintain account and billing records, resolve disputes, enforce agreements, satisfy legal obligations, protect security, and operate backups.
You may request deletion of account information. Some records may be retained where required for billing, tax, fraud prevention, security, dispute resolution, legal compliance, or backup integrity.
13. Your Choices and Rights
You can update account details, adjust supported privacy preferences, cancel subscriptions, remove saved payment methods where supported, and contact VALCRAN to request access, correction, deletion, export, or restriction of personal information.
California and other U.S. state privacy laws (such as the CCPA/CPRA) may give you rights to know, access, correct, delete, obtain a portable copy, and opt out of the "sale" or "sharing" of personal information and certain profiling. VALCRAN does not sell or share personal information for cross-context behavioral advertising, so there is no such activity to opt out of. EEA, UK, and similar laws may give you rights to access, correction, deletion, objection, restriction, portability, and withdrawal of consent, and a right to lodge a complaint with your supervisory authority.
To exercise these rights, contact support@valcran.com. You may use an authorized agent where permitted by law. We will not discriminate against you for exercising your rights, and we will verify requests before acting on them.
14. Security
VALCRAN uses administrative, technical, and organizational safeguards designed to protect information, including hashed passwords (bcrypt), encryption in transit, HTTP-only secure session cookies, secure payment handling through Stripe, and server-side account controls. No system can be guaranteed perfectly secure.
Report suspected security issues to security@valcran.com.
15. Children
VALCRAN OS is not directed to children under 13, and VALCRAN does not knowingly collect personal information from children under 13. AI Improvement Data is not available for accounts used by children under 13. If you believe a child provided personal information, contact support@valcran.com and we will take appropriate steps to delete it.
16. Changes to This Policy
VALCRAN may update this Privacy Policy as the product and legal requirements evolve. We will post the new version in the product and update the "Last Updated" date, and we will provide additional notice of material changes where required. Continued use after an update means you accept the updated policy.
17. Contact
VALCRAN, LLC (Florida), 36750 U.S. Hwy. 19 N., Unit 2845, Palm Harbor, FL 34684. For privacy requests, account questions, or general support, contact support@valcran.com. For billing issues, contact billing@valcran.com. For security reports, contact security@valcran.com.