1. Introduction
Viorant, Inc. ("Viorant," "we," "us," or "our") builds AI Deployment Infrastructure. This Privacy Policy explains what personal information we collect, why we collect it, who we share it with, and the choices and rights you have.
This policy applies to:
our websites, including viorant.ai, docs.viorant.ai, and career.viorant.ai (the "Sites");
the Viorant Hub desktop application;
our cloud services, including Vio Infra, Helix, Sign, and Sentinel; and
our sales, marketing, support, and recruiting activities.
We refer to all of the above as the "Services."
This policy does not apply to third-party platforms we do not control, including GitHub, Discord, X, and LinkedIn. Your use of those platforms is governed by their own privacy policies.
2. Our Role: Controller and Processor
When we act as a controller. For our Sites, marketing, recruiting, support, account administration, billing, and product telemetry, we decide why and how personal information is processed. This policy describes that processing.
When we act as a processor. When a business customer deploys artifacts, agents, or workloads through our cloud services, content and end-user data flowing through those workloads is processed on that customer's instructions. In that case the customer is the controller and we act as a processor or service provider. Our processing is governed by our Data Processing Addendum, not by this policy. If you are an end user of a customer's application, please direct privacy questions to that customer.
3. Information We Collect
3.1 Information you give us
| What | When |
|---|---|
| Name, email address, password or authentication credential, and account settings | When you create a Viorant account |
| Company name, role, team size, and similar business details | When you request a demo, join a waitlist, or contact sales |
| Billing name, billing address, tax identifiers, and payment card details | When you purchase a paid plan. Card details are collected and stored by Stripe, not by Viorant. We receive only a token, the last four digits, and card brand and expiry |
| The content of your messages, including attachments | When you contact support, complete a contact form, or join our mailing list |
| Resume, work history, education, links, and any information in your application | When you apply for a role through our careers site |
3.2 Information collected automatically from the Sites
When you visit our Sites we and our analytics and advertising partners may collect: IP address, approximate location derived from IP address at the city or region level, browser and device type, operating system, referring and exit pages, pages viewed, links clicked, session duration, and cookie or similar identifiers.
Except for strictly necessary technologies, this collection occurs only after you consent through the banner presented on your first visit. Until you make a choice, our analytics and advertising technologies do not run. See Section 7.
3.3 Information collected from the Viorant Hub
The Hub is local-first. Your prompts, artifacts, policies, and files stay on your machine unless you deploy them or use a feature that explicitly transmits them.
We collect from the Hub:
Account and license information, including your user identifier, plan, and seat assignment.
Telemetry and diagnostics: feature usage counts, session duration, user interface flow events, application version, and platform and operating system version.
Crash and error reports, which may include stack traces and application state at the time of the error.
We do not collect from the Hub by default:
your prompts or model responses, except where you use the Sign feature described in Section 3.4;
your source code or file paths;
your keystrokes; or
the contents of your screen.
We do not have access to API keys you supply for third-party model providers beyond what is necessary to route your requests, and we do not use them for any other purpose.
3.4 Information collected through Sign
Sign is an optional feature. It is used only when you affirmatively choose to sign a prompt or artifact in order to create a verifiable record of authorship and approval.
When you use Sign, we store:
the signed content itself, including the prompt or artifact, which we keep private and do not publish;
a cryptographic hash of that content;
the digital signature;
a pseudonymous signer key identifier; and
a timestamp.
How the public record works. To make the proof durable and tamper-evident, we write the hash, the signature, the pseudonymous signer key identifier, and the timestamp to a distributed ledger, and we make that record publicly accessible through our public APIs and Model Context Protocol endpoints. Your name, email address, and other identifying details are not written to the ledger. The signed content itself is not written to the ledger and is not published.
What this means for deletion. We maintain the link between your signer key and your account in our own systems, separately from the ledger. Records written to the ledger are permanent and cannot be altered or removed. However, if you delete your account, we delete the mapping between your signer key and your identity, after which the ledger record can no longer be attributed to you by us. See Section 13 for how deletion requests are handled.
3.5 Information from third parties
We may receive information about you from our service providers, from advertising and analytics platforms, from publicly available sources, and from your employer or team administrator if you are added to a team account.
4. How We Use Information, and Our Legal Bases
Where the GDPR or UK GDPR applies, we rely on the legal bases indicated below.
| Purpose | Legal basis |
|---|---|
| Create and administer your account, provide the Services, and perform our agreement with you | Performance of a contract |
| Process payments and manage billing | Performance of a contract; compliance with legal obligations |
| Provide the Sign proof-of-record service you request | Performance of a contract |
| Provide support and respond to inquiries | Performance of a contract; legitimate interests in responding to non-customers |
| Product telemetry and diagnostics to maintain, secure, debug, and improve the Services | [Consent, where telemetry is opt-in] OR [Legitimate interests in operating and improving a product our users rely on, balanced against the limited and largely non-sensitive nature of the data] |
| Security, fraud prevention, abuse detection, and enforcement of our terms | Legitimate interests in protecting the Services and our users |
| Website analytics | Consent |
| Advertising, conversion measurement, and campaign attribution | Consent |
| Marketing emails and product announcements | Consent, or legitimate interests where we are contacting an existing customer about similar services and offering an opt-out in every message |
| Recruiting and evaluating job applicants | Steps taken at your request prior to entering a contract; legitimate interests in assessing candidates |
| Comply with law and respond to lawful requests | Compliance with legal obligations; legitimate interests in establishing or defending legal claims |
Where we rely on legitimate interests, you have the right to object. See Section 13.
5. Artificial Intelligence and Your Content
We do not use your prompts, artifacts, source code, or model outputs to train, fine-tune, or otherwise improve any artificial intelligence model, whether our own or a third party's.
Where you route requests through the Hub or our runtimes to a third-party model provider, your content is transmitted to that provider and handled under that provider's terms. Where you use your own API key, your relationship with that provider governs. We do not add your content to any training corpus.
6. Aggregated and De-identified Information
We may create aggregated or de-identified information and use it for any lawful purpose, including benchmarking and publishing statistics about the Services. We maintain such information in de-identified form, do not attempt to reidentify it except as permitted by law, and require the same of recipients.
7. Cookies and Similar Technologies
We use cookies, local storage, pixels, and similar technologies. We group them into three categories:
Strictly necessary. Required to operate the Sites, route traffic, maintain security, protect against abuse, and remember your cookie choices. These are always active and do not require your consent.
Analytics. Measure site usage, page performance, and visitor interactions so we can improve the Sites.
Marketing. Measure advertising performance, conversions, and campaign effectiveness across platforms, and enable advertising on third-party platforms.
On your first visit we present a banner. Analytics and marketing technologies are not set until you allow them through that banner. You can accept all, reject all, or make choices by purpose and by individual partner, and you can change your choices at any time through the "Cookie preferences" link in the footer of every page. Withdrawing consent is as easy as giving it.
Our current partners in each category are listed in Section 9 and in our Cookie Notice.
Do Not Track and Global Privacy Control. Our Sites do not respond to Do Not Track browser signals, because no common standard has been adopted. We do treat a Global Privacy Control signal as a valid request to opt out of the sale and sharing of personal information for the browser and device on which it is received.
8. Advertising, "Sales," and "Sharing"
We do not sell personal information for money.
However, when you allow marketing cookies, our advertising partners receive online identifiers and information about your activity on our Sites in order to measure conversions and deliver advertising. Under the California Consumer Privacy Act and several other US state privacy laws, this activity is treated as a "sale" or as "sharing" for cross-context behavioral advertising, and in other states as targeted advertising.
You have the right to opt out. You can do so by:
rejecting marketing cookies in our banner or the Cookie preferences link;
using our "Do Not Sell or Share My Personal Information" page; or
transmitting a Global Privacy Control signal.
We do not knowingly sell or share the personal information of consumers under 16 years of age.
9. Who We Share Information With
We do not sell your information for money. We disclose personal information to the following categories of recipients.
9.1 Service providers and subprocessors
| Provider | Function | Category |
|---|---|---|
| Google Cloud Platform | Cloud infrastructure and data hosting | Infrastructure |
| Cloudflare | CDN, DNS, network security, and tag management (Zaraz) | Infrastructure |
| Stripe | Payment processing | Application |
| PostHog | Product and website analytics | Analytics |
| Google Analytics | Website analytics | Analytics |
| Plausible | Website analytics | Analytics |
| Meta | Advertising and conversion measurement | Advertising |
| Advertising and conversion measurement | Advertising | |
| GoHighLevel | CRM, waitlist, mailing lists, and contact forms | Marketing |
| Intercom | Customer support and in-product messaging | Support |
A current list is maintained at [https://viorant.ai/subprocessors\]. We will provide notice of changes to subprocessors as described in our Data Processing Addendum.
9.2 Other disclosures
Team administrators. If you use Viorant under a team or enterprise plan, your administrator can access your account information, seat usage, and administrative activity.
Public records. Sign proof-of-record metadata (hash, signature, pseudonymous signer key, and timestamp), as described in Section 3.4.
Legal. Where we believe disclosure is required by law or legal process, or is necessary to protect the rights, property, or safety of Viorant, our users, or others. Where permitted, we will notify you first.
Corporate transactions. In connection with a merger, acquisition, financing, or sale of assets, subject to this policy continuing to govern the information transferred.
With your direction or consent.
10. International Transfers
Viorant is a Delaware corporation, and our operations and infrastructure are located in the United States. If you are located outside the United States, your personal information will be transferred to and processed in the United States and in other countries whose data protection laws may differ from those of your country.
Where we transfer personal information out of the European Economic Area, the United Kingdom, or Switzerland, we rely on:
the European Commission's Standard Contractual Clauses, together with the UK International Data Transfer Addendum and the Swiss adaptations, as applicable;
an adequacy decision, where one applies; or
the EU-US, UK Extension, and Swiss-US Data Privacy Framework, where the recipient is certified.
You may request a copy of the safeguards we use by contacting us at privacy@viorant.ai.
11. How Long We Keep Information
| Information | Retention |
|---|---|
| Account information | For the life of your account, then [30] days after deletion, subject to backups expiring within [90] days |
| Billing and transaction records | [7] years, to meet tax and accounting obligations |
| Telemetry and diagnostics | [24] months in identifiable form, then aggregated or deleted |
| Support communications | [24] months after resolution |
| Marketing contact data | Until you unsubscribe, then [24] months on a suppression list so we do not contact you again |
| Job applicant data | [24] months after the recruiting process closes, or longer with your consent |
| Sign: signer-key-to-identity mapping and signed content | For the life of your account; deleted [12] months after account deletion. The pseudonymous ledger record is permanent but is no longer attributable to you once the mapping is deleted, and cannot be recovered. See Section 3.4 |
| Cookie and advertising identifiers | As set out in our Cookie Notice, generally not longer than [13] months |
12. Security
We maintain administrative, technical, and organizational safeguards designed to protect personal information, including encryption in transit and at rest, access controls on a least-privilege basis, logging and monitoring, vendor security review, and employee confidentiality obligations. No system is completely secure, and we cannot guarantee absolute security.
13. Your Privacy Rights
13.1 Rights available to everyone
You may request access to, correction of, or deletion of your personal information, and you may opt out of marketing communications at any time using the unsubscribe link or by emailing privacy@viorant.ai.
If you delete your account, we delete the link between your Sign signer key and your identity, so that the permanent ledger record can no longer be attributed to you by us. See Section 3.4.
13.2 European Economic Area, United Kingdom, and Switzerland
You have the right to access, rectification, erasure, restriction of processing, data portability, and to object to processing based on legitimate interests, including objecting to direct marketing at any time. Where we rely on consent, you may withdraw it at any time without affecting the lawfulness of processing before withdrawal.
We do not make decisions producing legal or similarly significant effects about you based solely on automated processing.
You have the right to lodge a complaint with your local supervisory authority. In the United Kingdom this is the Information Commissioner's Office.
Our representative in the European Union under Article 27 GDPR is:
Gerard Willeme
20 Rue de l'Epalet, 35170 Bruz, France
privacy@viorant.ai
13.3 United States
Depending on your state of residence, you may have the right to know or access the personal information we collect, to correct it, to delete it, to obtain a portable copy, to opt out of sale, sharing, targeted advertising, and profiling in furtherance of decisions producing legal or similarly significant effects, and to be free from discrimination for exercising your rights.
Categories of personal information collected in the last 12 months: identifiers; customer records including billing information; commercial information; internet or other electronic network activity; approximate geolocation derived from IP address; professional or employment-related information for job applicants and business contacts; and inferences drawn from the foregoing for analytics and marketing.
We collect these categories from the sources described in Section 3, use them for the purposes described in Section 4, and disclose them to the categories of recipients described in Section 9.
Sensitive personal information. We collect account log-in credentials, which California treats as sensitive personal information. We use them only to authenticate you and secure your account, which are purposes for which no right to limit use applies. We do not use or disclose sensitive personal information to infer characteristics about you.
How to exercise your rights. Email privacy@viorant.ai or use our "Do Not Sell or Share My Personal Information" page. We will verify your request by asking you to confirm control of the email address associated with your account or by requesting additional information reasonably necessary to verify your identity. You may use an authorized agent, and we may ask for proof of authorization.
We will respond within 45 days, and may extend by an additional 45 days with notice. California residents may appeal a denial by replying to our response. Residents of Virginia, Colorado, Connecticut, and other states with an appeal right may appeal by emailing privacy@viorant.ai with "Appeal" in the subject line, and we will respond within 45 days. If your appeal is denied you may contact your state attorney general.
13.4 Other jurisdictions
If you are located in a jurisdiction with its own privacy legislation, including Canada, Brazil, Japan, Australia, or South Korea, you may have additional rights. Contact us and we will honor rights available to you under applicable law.
14. Children
The Services are not directed to children. You must be at least 18 years old, or the age of digital consent in your country if higher, to create an account. We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, contact privacy@viorant.ai and we will delete it.
15. Changes to This Policy
We may update this policy. If we make material changes we will post the updated policy with a new effective date and, where required by law or where the change is significant, notify you by email or through the Services before the change takes effect. Prior versions are available on request.
16. Contact Us
Viorant, Inc.
8 The Green STE R
Dover, DE 19901, United States