Skip to content
vrot

Legal

Privacy

How Vrot handles information — on this website, and inside the Windows application.

Last updated 10 September 2026Terms of service

This is a general summary provided for transparency. It is not legal advice, and it should be reviewed by a qualified adviser before Vrot begins commercial operation.

Who this policy covers

This policy covers two separate things, and it is worth keeping them apart:

  • The vrot.ai website. The public pages you are reading now. There is nothing to sign in to and no business software is connected here.
  • The Vrot application. The Windows program you install on your own computer, together with the cloud services that support it. This is where connections are made and where business data is handled.

Vrot is a product for businesses. It is not directed at children, and it should not be used by anyone who cannot enter into a contract.

What this website collects

The website has no accounts, so there is no profile of you to build. What it records is a short list of marketing events, used to understand which pages are useful and which are not.

  • Page viewsThe path of the page that was opened, for example /pricing.
  • Integration searchesThat a search happened, whether it returned any results, and how many characters were typed. The words themselves are never recorded.
  • Integration viewsWhich integration page was opened, for example Gmail or Xero.
  • Pricing viewsThat the pricing page was viewed.
  • Download clicksWhich part of the page the button was on, and whether a download was available at the time.
  • Contact clicksWhich part of the page the contact link was on.

Each event is stored with the time it happened. None of them carry a name, an email address, an account, or an identifier that follows you between visits, and none of them are joined together to work out who you are.

At the time of writing, no analytics provider is connected: these events are collected in your browser only. If we connect one, we will choose a provider that does not build advertising profiles, and we will update this page before we do.

Like any website, vrot.ai is served by a hosting provider that keeps standard request logs — an IP address, a browser user agent, a timestamp — for a short period, to deliver pages and to protect the site from abuse.

What this website does not do

  • It does not connect to any business application.
  • It does not store business data of any kind.
  • It never handles the credentials for Gmail, Xero, HubSpot or any other integration. Signing in happens in the application, on the provider’s own page.
  • It does not use advertising trackers, and it does not follow you across other websites.
  • It does not sell, rent or share personal information for advertising.

Browsing this site is browsing a brochure. Nothing you read here reaches into your business.

When you contact us

If you get in touch about Vrot, we receive the message you send and the address you sent it from. We use it to answer you and to keep a record of the conversation, and we keep it for as long as it is useful for support. We do not add you to a marketing list because you asked a question.

The Vrot application

The application runs on your own Windows computer and is supported by cloud services that schedule work and store your configuration.

  • Account details. The information you provide when you set up an account — such as an email address — is used to run your subscription and to contact you about the service.
  • Payment details. Subscriptions are handled inside the application through a payment provider. Card details are handled by that provider, not stored by us.
  • Your configuration. The workers you create, the instructions you give them, their schedules and their permission settings.
  • Activity records. A record of what each worker did and when, so you can review it, approve it or undo it.

Connections, credentials and permissions

A connection is authorised through the provider’s own sign-in. You sign in to Google, Microsoft, Xero or whichever service it is on their page, not inside Vrot, and you choose which permissions to grant.

  • Access tokens and connection credentials are stored encrypted.
  • Vrot works within the permissions you granted, and no further.
  • You can review or withdraw access at any time from the provider’s own security settings, or by removing the connection in the application. Removing a connection removes the stored credentials for it.

Business data and how it is used

Business data is the content a worker touches while it does the job you asked for — a message it reads, a record it updates, a document it drafts. It is processed to carry out that work, and to keep the activity record that lets you check it afterwards.

Carrying out a task can involve sending the relevant content to the AI model that performs it. Only the content needed for the task is sent.

  • Your business data is yours. We do not sell it or share it for advertising.
  • It is not used to build a profile of you or of the people you work with.
  • Access inside Vrot is limited to what is needed to run and support the service.

How information is protected

Information is encrypted in transit, stored credentials are encrypted at rest, and internal access is limited to the people who need it to operate and support the service.

We aim to handle personal data lawfully and carefully, and to apply sensible technical and organisational measures. We do not claim certification under any particular security or privacy scheme, and no system can be guaranteed to be completely secure.

How long information is kept

  • Website events are kept only for as long as they are useful for understanding traffic, and are reviewed in aggregate.
  • Account details and configuration are kept while your account is active.
  • Activity records are kept so you can review recent work, and are removed on a routine cycle after that.
  • Connection credentials are removed when you disconnect the integration or close your account.

Some information may be kept for longer where the law requires it — for example, billing records.

Access, correction and deletion

You can ask for a copy of the personal information we hold about you, ask us to correct it, or ask us to delete it. Email support@vrot.ai and we will respond within a reasonable time and tell you what we can and cannot do.

Depending on where you live, local data protection law may give you further rights. We will work with you on any request made under those rights. This policy does not claim compliance with, or certification under, any particular regime.

Changes to this policy

As Vrot changes, this policy will change with it. The date at the top of the page always reflects the current version. If a change materially affects how personal information is handled, we will make that clear rather than quietly revising the text.

Contact

Questions about this policy, or about anything above, go to support@vrot.ai. A person reads it.