Privacy Policy
How Veilyo collects and processes your personal data (GDPR).
Version 1.0 · in effect today
Data collected and purposes
We collect: your email address and display name (identification and communication); your language and preferences (personalization); the data you create (followed feeds, rules, tags, read states) necessary for the Service to function; your IP address at signup (fraud and abuse prevention, legitimate interest).
Retention periods
Your data is retained as long as your account is active. Collected articles are automatically purged once their retention period expires. When an account is deleted, all associated data and files are permanently erased, subject to legal retention obligations.
Cookies
Only essential cookies are used (a session cookie to keep you signed in). No advertising trackers and no third-party audience measurement.
Authentication
Passwords are hashed (bcrypt) and never stored in plain text. Two-factor authentication (TOTP) is available; where applicable, the associated secret is encrypted at rest. Sign-in via a third-party provider (SSO), when enabled, shares only the information strictly necessary.
Connection data and logging
For security and diagnostic purposes, certain sensitive actions are logged (audit trail): timestamp, action type, IP address. These logs are for internal use only and are never sold or shared for commercial purposes.
We also store the date and time of your last sign-in (only the most recent one, with no history, no IP address and no geolocation). Purpose: account security and activity tracking necessary to operate the service; legal basis: performance of the contract and legitimate interest (security). This data is kept for the lifetime of the account and deleted along with it.
Payments (Stripe)
When billing is active, payments are processed by Stripe. We never store your card data: it is sent directly to Stripe, a PCI-DSS compliant provider. We only retain the subscription and billing references necessary to manage your account.
Statistics
Any usage statistics are aggregated and anonymized to improve the Service. They do not allow you to be individually identified.
Data security
We implement appropriate technical and organizational measures: password hashing, encryption of secrets at rest, account/workspace isolation, logging of sensitive actions, and restricted access.
Your rights (GDPR)
You have the right of access, rectification, erasure, portability, and objection. You can export all of your data in JSON format and permanently delete your account from Settings > Security & account. For any request regarding your data, contact hello@veilyo.com. You may also file a complaint with the CNIL, the French data protection authority.
