Legal
Privacy Policy
Last updated May 2026
⚠ Placeholder — pending legal review. Not binding in this state.
Who is responsible
Wrenchy SASU (France) operates Volato and is the data controller for your account and billing data. For the error events your application sends, we act as a processor on your behalf — you remain the controller of that data. Full company identity is in the legal notice. Contact: [email protected].
What we collect
Account. Your email and (optionally) name and avatar, password hash or the identifier from your Google/GitHub sign-in, and an optional « how did you hear about us » answer. Workspace names, members and invitation emails.
Billing. Handled by Stripe. We store only your Stripe customer and subscription identifiers, plan, status and billing dates — never your card number.
Error events. What your app sends us: error type and message, stack traces, file paths and line numbers, route/URL and request method, breadcrumbs, environment and release, and device/browser context. We never store HTTP request bodies. If your app attaches user context (id, email, username, IP) or custom data to an event, we store it as received — you control what is sent.
Technical. A session token and limited session metadata (such as IP address and user agent) needed to keep you logged in securely.
Your source code is not collected
The generated integration strips sourcesContent from source maps before upload and our ingest rejects any map that still carries it. We hold file paths and mappings, not your code; the agent reads source from your own repository.
How we use it & legal bases
- Providing the service — capturing, grouping and showing your errors (performance of our contract).
- Billing and fraud prevention (contract and our legitimate interest).
- First-seen email alerts about new errors in your projects (performance of the service).
- Security, debugging and improving Volato (legitimate interest).
We do not sell your data and do not use it for advertising.
Sub-processors
We rely on a small set of providers to run Volato:
- Stripe — payments and tax.
- Resend — sending email alerts.
- Our database & object storage providers — hosting error data and source maps in the EU. [hosting and storage providers to be named]
Where your data lives
Your error data, source maps and database records are stored in the European Union. Some providers (e.g. Stripe) may process limited data outside the EU under appropriate safeguards such as the EU Standard Contractual Clauses.
How long we keep it
Error events are retained for up to 7 days on the Starter beta plan and then automatically deleted. If you cancel or your subscription lapses, events are kept for a 7-day grace period and then purged. Account and workspace data are kept while your account is active and deleted (or anonymised) after closure, except where we must retain records — for example invoices for accounting obligations.
Cookies
We use a single essential cookie to keep you signed in (better-auth.session_token). We run no analytics, advertising or third-party tracking — so there is no consent banner to click through.
Your rights
Under the GDPR you can access, rectify, export, restrict or erase your personal data, and object to certain processing. Email [email protected] to exercise them. You may also lodge a complaint with the French data protection authority (CNIL). For personal data inside error events, requests from individuals are usually directed to the customer who controls that data; we will assist them as their processor.
Security & changes
Access is gated by authentication and workspace-scoped tokens; CLI access is read-only except for marking errors resolved. We may update this policy as the product evolves and will revise the date above; material changes will be communicated.