VX CONVERGENCEsign in
Terms of ServicePrivacy Policyhelp
DRAFT · under legal review · not final. The text below is a draft; square-bracket items are placeholders that have not been filled in yet.

VX Convergence Privacy Policy

DRAFT FOR LEGAL REVIEW. NOT FINAL. NOT LEGAL ADVICE. Drafted on 2026-10-03 by an AI agent from the terminal's source code (vxc/vxweb/src/auth.rs, accounts.rs, lib.rs, render/wl.rs, render/shell.rs, render/wheel.rs) and release/phase2n-accounts/OPERATOR-ACCOUNTS.md. It describes what the code does as of the phase2n release (not yet deployed at the time of drafting). It has not been reviewed by a lawyer and must not be published as final. Square-bracket items are placeholders or notes for counsel and the operator; remove every one before publication. Re-check the facts against the code at every release.

Last updated: [DATE]


1. Who we are

This policy explains how [ENTITY NAME] ("we", "us") handles personal information when you use the VX Convergence terminal at terminal.vxconvergence.com and related websites (the "Service"). We are the party responsible for that information. [COUNSEL: contracting entity not yet decided; the operator's parent company may be North South Industries, but that is undecided.]

Contact: [CONTACT EMAIL], [POSTAL ADDRESS], South Dakota, USA.

2. The short version

  • We collect very little: the user name you choose (which may be your email address), a scrambled form of your password, your access tier and dates, sign-in sessions, and a security log of sign-ins that includes your IP address.
  • We use one cookie, for keeping you signed in. No analytics, no advertising, no third-party trackers, and the terminal's pages load no third-party scripts.
  • We do not sell your personal information or share it for advertising.
  • Your watchlist stays in your own browser.

3. What we collect

3.1 Account information

When you redeem an invite and create an account we store, in our account database:

itemwhat it is
user name3 to 64 characters you choose; it may be your email address. Stored in lower case.
passwordnever stored as typed. We store only a one-way hash made with argon2id, a slow password-hashing method designed to resist guessing. We cannot see or recover your password.
tieryour access level (for example beta or paid)
enabled flagwhether the account is active or suspended
createdwhen the account was created
last sign-inwhen you last signed in successfully
access end dateif your access is set to end on a date
welcome flagwhether you have seen the one-time welcome message
notea short internal note we may write (for example who an invite was for)

3.2 Invite and password-reset links

For each invite or password-reset link we store a hash of the link (never the link itself), the tier, when it was created and expires, who created it, whether and when it was used and by which account, whether it was revoked, and a short internal note. Links are single use and expire after 1 to 30 days (reset links 2 days by default).

3.3 Sign-in sessions

When you sign in we create a random session token. We store only a hash of it, with your user name, when the session was created and when it expires (72 hours later). Signing out ends the session.

3.3a Acceptance of the terms

When you create an account, and again whenever we change the Terms, we ask you to confirm that you agree to the Terms of Service and this Privacy Policy. We record your user name, the version of the terms you accepted, the date and time, and your IP address as reported by our web server, and we write a line to the security log. We keep this record for as long as your account exists and for [RETENTION PERIOD] after it ends, because it is our evidence that you accepted the terms.

3.4 Security (audit) log

We keep a security log with one line per account event. Each line records: the time, the event type, the user name involved, the client IP address as reported by our web server, and a short detail. Events recorded are: account setup, successful sign-in, failed sign-in, sign-in blocked (account disabled or access ended), sign-in throttled, sign-out, invite created, redeemed, rejected or revoked, password-reset link issued, password reset, password changed or failed change, account disabled or enabled, tier changed, and sessions ended. No password or token is ever written to this log.

3.5 Sign-in throttle

To stop password guessing, we count failed sign-in attempts per IP address. Ten failures from one address within 15 minutes block that address for the rest of the 15-minute window. These counts are held only in the server's memory, not written to disk, and are lost on restart; a throttled attempt is also recorded in the security log (3.4).

3.6 Web server and hosting logs

[OPERATOR TO CONFIRM BEFORE PUBLISHING: the terminal application itself does not log page requests, but the web server in front of it (nginx) and the hosting provider may keep standard access and error logs that include IP address, date and time, the page requested, response code and browser user agent. State here whether access logging is on, what it records, and how long it is kept, or switch it off.]

3.7 Billing information (paid plans)

During the paid beta we bill by [invoice / hosted payment link]. We keep the billing contact name, email,

[company name, billing address, tax identifiers if provided], amounts, invoice numbers and payment status. Card and bank details are entered on the payment provider's own pages and are processed by that provider; they do not pass through or get stored on our servers. The provider handles them under its own privacy policy: [PROVIDER NAME AND LINK, once chosen].

3.8 Messages you send us

If you email or otherwise contact us, we keep the message and your contact details to respond and to keep a record. [OPERATOR: name the support channel once chosen.]

3.9 What we do not collect

We do not use analytics or advertising services, tracking pixels, fingerprinting, or third-party fonts or scripts in the terminal. The terminal's pages are served with a content security policy that blocks third-party resources. We do not collect payment card numbers, government identifiers, or precise location. We do not record which screens or series you view against your account. [OPERATOR: keep this statement true; revisit before adding analytics, email, server-side watchlists or API keys.]

4. Information stored in your browser

nametypepurposelifetime
vxsesscookiekeeps you signed in; holds a random session token72 hours (Max-Age 259200 seconds), or until you sign out
vxwlbrowser local storageyour watchlist (the series you starred)until you clear it in your browser
vxclosedbrowser local storagewhich groups you collapsed on the wheel screenuntil you clear it in your browser

The terminal sets exactly one cookie, vxsess. It is a strictly necessary first-party cookie, set when you sign in (and when you redeem an invite or change your password) with these attributes: HttpOnly (scripts cannot read it), Secure (sent only over HTTPS), SameSite=Strict (not sent with requests from other sites), Path=/, Max-Age=259200. Signing out replaces it with an empty cookie that expires immediately.

Protection against cross-site request forgery (CSRF) does not use a cookie. Forms that change your account carry a hidden value derived from your session token; it is checked on submission and is not stored anywhere.

The watchlist and collapsed-group settings are kept only in your browser's local storage. The terminal does not store them on our servers, so they do not follow you to another browser or device, and clearing your browser data removes them.

[COUNSEL: confirm that no cookie banner or consent is needed for a single strictly necessary session cookie and functional local storage, in particular if EU/UK users are admitted (ePrivacy rules).]

5. Why we use your information

purposeinformation used[GDPR legal basis: COUNSEL TO CONFIRM IF GDPR APPLIES]
create and run your account, sign you in, apply your tier and access dates3.1 to 3.3, cookieperformance of our contract with you
keep the Service secure: stop password guessing, investigate misuse, enforce the Terms (for example no shared logins)3.4 to 3.6legitimate interests in security and fraud prevention
bill for paid plans and keep financial records3.7contract; legal obligation (tax and accounting records)
answer your messages and send service notices (for example changes to the Terms)3.1, 3.8contract; legitimate interests
comply with law and respond to lawful requestsany, as requiredlegal obligation

We do not use your information for advertising, profiling or automated decisions that have legal or similarly significant effects on you.

6. Who we share it with

We do not sell your personal information and do not share it for cross-context behavioural advertising. We share it only with:

  • Hosting provider: our servers are virtual servers rented from a hosting provider in the United States, which stores the data on our behalf. [OPERATOR: name the provider if counsel advises.]
  • Payment provider (paid plans only): [PROVIDER NAME], as described in 3.7.
  • Email provider (if we email you): [PROVIDER NAME, if any].
  • Professional advisers (lawyers, accountants) under a duty of confidence.
  • Authorities, when the law requires it, or to protect rights, safety or the Service.
  • A successor business, if [ENTITY NAME] is reorganised, merged or sold, subject to this policy.

Data publishers whose data appears in the Service do not receive any information about you.

7. How long we keep it

informationhow long
account recordwhile your account exists. Accounts that are suspended or whose access has ended are not deleted automatically. After you ask us to close your account we delete it within [30] days, except what we must keep for legal, tax or security reasons.
sessions72 hours from sign-in, or until you sign out. Expired session records are removed from the database when new sessions are created.
invite and reset links[OPERATOR/COUNSEL: currently kept indefinitely; propose deleting used, expired or revoked link records after [12] months.]
security log (with IP addresses)[OPERATOR/COUNSEL: there is currently no automatic rotation; the log grows by a few hundred bytes per sign-in. Propose keeping [12] months, then deleting or anonymising IP addresses.]
sign-in throttle countsup to 15 minutes, in memory only
web server logs[OPERATOR TO CONFIRM; see 3.6]
billing recordsas long as tax and accounting law requires, generally [7] years
backupsthe server's nightly backups are kept for up to [14] days. [OPERATOR: the account database is not yet included in off-site backups; an encrypted off-site backup is planned. Update this row when settled.]

8. How we protect it

In plain terms:

  • Encrypted connections. The terminal is served only over HTTPS, and browsers are told to use HTTPS for it in future (HSTS).
  • Passwords are hashed, not stored. We use argon2id. Invite links, reset links and session tokens are also stored only as hashes, so a copy of our database would not reveal them.
  • Minimum password length of 10 characters for new passwords.
  • Short-lived, single-use links. Invite links are single use and expire; a lost link cannot be shown again.
  • Guessing limits. Repeated failed sign-ins from one address are blocked for 15 minutes.
  • Forgery protection. Account-changing forms are checked against a value tied to your session; the session cookie is restricted to our own site.
  • Browser protections. Security headers forbid framing the terminal in other sites, block third-party resources, and stop the browser caching pages.
  • Restricted files. The account database and security log are readable only by the service account on the server.
  • Immediate effect. Suspending an account, ending access or changing a tier takes effect on the next request, and suspension signs the person out at once.

No system is perfectly secure. If we learn of a security breach affecting your personal information, we will notify you and the authorities where the law requires. [COUNSEL: South Dakota's data breach notification law and those of users' home states.]

9. Your choices and rights

You can:

  • see and correct your account information: your user name, tier and access dates are shown at /account, where you can also change your password;
  • ask for a copy of the personal information we hold about you, including your entries in the security log;
  • ask us to delete your account and personal information (we may keep records the law requires, and security-log entries for the retention period in section 7);
  • sign out everywhere by changing your password at /account (this signs out every other session of your account), or by asking us;
  • clear your watchlist at any time by clearing your browser's site data.

Send requests to [CONTACT EMAIL]. We will confirm the request comes from the account holder (for example by asking you to sign in) before acting, and we will answer within [30] days.

[COUNSEL: whether GDPR or UK GDPR applies (only if users in the EU/UK are admitted or targeted), and if so add the rights to object, restrict, data portability, withdraw consent, and to complain to a supervisory authority, plus an Article 27 representative question. Whether the California Consumer Privacy Act or other US state privacy laws apply given our size (likely below thresholds at beta scale, but to confirm), and if so add the required notices. See COUNSEL-QUESTIONS.md Q6.]

10. International users

We are based in the United States and the Service is hosted in the United States. If you use it from elsewhere, your information is processed in the United States, where data protection law may differ from yours. [COUNSEL: transfer mechanism if GDPR applies.]

11. Children

The Service is not directed to children and is for people aged 18 or over. We do not knowingly collect information from anyone under 18. If you believe a minor has an account, contact us and we will delete it.

12. Changes to this policy

We may update this policy. We will post the new version with a new "Last updated" date and, for material changes, tell you in advance by [email / a notice in the terminal].

13. Contact

[ENTITY NAME]

[POSTAL ADDRESS], South Dakota, USA

[CONTACT EMAIL]