Privacy Policy
This Privacy Policy explains what personal data Velocity ("we", "us") collects, why we collect it, who we share it with, how long we keep it, how we protect it, and the choices and rights you have. It covers both the Velocity website and the Velocity desktop app. By its nature the desktop app runs optimizations locally on your PC; the technical details of those changes stay on your machine unless you choose to sign in.
1 What we collect
We collect only what we need to run Velocity, keep it secure, and improve it. It falls into a few groups:
- Account details. The email address you register, and a password that we store only as a strong, salted hash (argon2id). We never store your password in a form we can read, and we cannot recover it, only reset it.
- Email verification status. Whether your email address has been confirmed, since a verified email is required before you can buy or activate a device.
- Purchase and license records. Which plan you bought, the payment method type (card or crypto), the amount and currency, an order reference from our payment processor, and your current license status. We never see or store full card numbers, card security codes, or cryptocurrency wallet keys.
- Device and activation data. When you activate the desktop app against your account, we store a record of that authorized device: an opaque device token (kept only as a hash), the approximate time it was last seen, and the browser or app user-agent and IP address at the time. This lets you see and sign out your devices and lets us detect a stolen or reused token.
- Technical and security logs. IP address, browser or app user-agent, and timestamps, collected automatically to operate the service, apply rate limits, prevent abuse, and diagnose problems. We do not log passwords, tokens, or full payment details.
- Support messages. If you contact us or submit a data request, the content of your message and the address you send it from.
What stays on your PC. The desktop app runs its optimizations locally. The specific tweaks you apply, your restore points, and your local settings live on your computer, not on our servers. Your offline license is stored on your device, encrypted at rest using your operating system's key store.
2 How we use it
We use the data above to:
- Provide your account and the product. Create and secure your account, verify your email, process your purchase, issue and refresh your license, and let the app activate and stay up to date.
- Send transactional email. Verification links, password resets, receipts, license details, security notices, and account changes. These are necessary to run your account, so they are not optional while you have one.
- Send occasional product email. New features, tips, and important updates. These are optional; you can opt out at any time from a link in any such email or from your account settings.
- Keep the service secure. Detect and prevent fraud, abuse, and unauthorized access; enforce rate limits; and investigate security events such as a reused device token.
- Improve Velocity. Understand, in aggregate, which steps of signup and checkout work and which do not, so we can make them clearer, and fix bugs.
- Meet legal obligations. Keep the tax, accounting, and records we are required to keep, and respond to lawful requests.
We do not sell your personal data, and we do not use it to build advertising profiles or serve you targeted ads.
3 Legal bases
Where data protection law (such as the GDPR) applies, we rely on the following legal bases to process your data:
- Contract. To create your account, deliver the product, and provide support, we process the data needed to perform our agreement with you.
- Legitimate interests. To keep the service secure, prevent abuse, and improve the product in aggregate, balanced against your rights and expectations.
- Consent. For optional product email, which you can withdraw at any time.
- Legal obligation. To keep financial records and respond to lawful requests.
4 Accounts and device activation
Running the desktop app does not require an account. You only sign in when you want to unlock a paid plan on a device. Activation uses a standard, audited browser sign-in flow (OAuth 2.0 Authorization Code with PKCE): you approve the app in your browser, and the app receives a one-time authorization, never your password.
After activation, your plan is confirmed by a short, cryptographically signed license that the app verifies on your own device, with no ongoing connection required. The app checks in periodically when online to keep the license current and to honor changes such as an upgrade or a refund. You can sign a device out at any time from the app or your account, which revokes it.
5 Payments
Payments are handled entirely by our payment processors on their own secure, PCI-compliant systems. Card details are entered on the processor's checkout and never pass through or get stored on our servers. For cryptocurrency payments, we never handle your wallet or keys.
We receive only what we need to fulfil and support your order: a payment reference, the plan, the amount and currency, and the payment status. We use this to grant your license, issue receipts, and handle refunds and disputes. If you receive a refund or a chargeback, the associated license is revoked and your plan returns to Free.
6 Cookies and local storage
We keep cookies to the minimum needed to run the site securely. When you sign in, we set a single secure, httpOnly session cookie that keeps you logged in; JavaScript on the page cannot read it, and it is not used for advertising. Your short-lived access token is held only in memory and is never written to browser storage. We do not use third-party advertising or cross-site tracking cookies.
You can block or clear cookies in your browser at any time, though signing in and staying signed in may stop working. In the desktop app, your license is stored locally on your device, encrypted at rest using your operating system's protected key store, and is never written in plain text.
7 Third parties
We rely on a few trusted providers (sub-processors) to run Velocity. Each one processes only the data it needs for its job, under its own terms and security commitments:
- Stripe processes card payments and holds your card data on its own systems.
- NOWPayments processes cryptocurrency payments.
- Our transactional email provider delivers verification, receipt, license, and security emails on our behalf.
- Cloudflare provides content delivery, TLS, and protection against attacks and abuse, and may process IP addresses for security.
- Our hosting provider runs the servers and database that store your account.
We do not sell your personal data. We share it with these providers only so they can perform their part of the service, and we require them to protect it. We may also disclose data if required by law or to protect the rights, safety, and security of our users and the service.
8 How we protect data
Security is built into the product, not bolted on. Among the measures we use:
- Encryption in transit. All traffic between your device and our servers uses HTTPS/TLS.
- Strong password hashing. Passwords are stored only as argon2id hashes with a per-user salt. We cannot read or recover them.
- Hashed secrets. Session, activation, and device tokens are stored only as hashes and compared in constant time. Activation codes are single-use and short-lived; device sessions rotate and are revoked automatically if a token is reused, which flags possible theft.
- Least data, least access. We collect the minimum we need, keep secrets in server-side configuration only, and never expose payment or signing secrets to the browser or the app.
- Abuse protection. Rate limiting, input validation, and monitoring guard the sign-in, checkout, and activation endpoints.
No system is perfectly secure, but we work to protect your data and to respond quickly if something goes wrong.
9 Data retention
We keep account and purchase records for as long as your account is active, and for a limited period afterward to meet legal, tax, and accounting needs (for example, up to 24 months for financial records). Security and access logs are kept for a shorter window (for example, around 90 days) unless needed longer to investigate an incident. Device sessions are removed when they expire or when you sign the device out. Single-use verification and activation codes are discarded shortly after they are used or expire.
When you delete your account, we delete or anonymize your personal data, except for the limited records we are required to keep by law. When data is no longer needed, we delete it or anonymize it so it can no longer be tied to you.
10 International transfers
Velocity and its providers may process and store data in countries other than your own. Where we transfer personal data across borders, we rely on appropriate safeguards, such as providers certified under recognized frameworks or standard contractual clauses, so that your data keeps a comparable level of protection wherever it is processed.
11 Your rights
You have control over your data. Depending on where you live, you can ask us to:
- Access a copy of the personal data we hold about you.
- Correct data that is wrong or out of date. You can change most of it directly in your account settings.
- Export your data in a portable, machine-readable format.
- Delete your account and associated data, subject to records we are required to keep by law.
- Object to or restrict certain processing, and withdraw consent for optional product email at any time.
- Complain to your local data protection authority if you believe we have mishandled your data.
To make a request, use the form below or email us. We aim to respond within 30 days, and we may need to verify your identity first.
12 Children
Velocity is not directed to children under 13 (or the minimum age in your country, if it is higher). We do not knowingly collect data from them. If you believe a child has given us personal data, contact us and we will remove it.
13 Changes
We may update this policy as the product and the backend evolve. When we do, we will update the "Last updated" date at the top of this page. For significant changes, we will give notice by email or inside the app before they take effect.
14 Contact
Questions about this policy or your data, or want to exercise any of your rights? Email us at [email protected], or use the request form in section 11 above. For general help with your account or the app, contact [email protected]. You can also reach the team through our Discord.
We aim to respond to privacy requests within 30 days. We may need to verify your identity before acting on a request, to protect your account and data from unauthorized access.
