Privacy Policy
Last updated: 2026-06-06
1. Who we are
This is the Privacy Policy for the website at voxtide.gg (the "Site"). The data controller is:
Voxtide LLC522 W. Riverside Ave., Suite N, Spokane, WA 99201
[email protected]
We are committed to processing your personal data lawfully and transparently. This policy describes what we collect, why, who we share it with, and what rights you have.
2. What this Site does
The Site is currently a pre-launch information page. The only personal data it collects from you directly is the email address you submit to be notified when our product launches. The Site does not yet host the Voxtide product itself.
3. What data we collect and why
| Data | Purpose | Source |
|---|---|---|
| Email address you submit | Send you a confirmation email and, once confirmed, one launch announcement | You |
| IP address | Apply per-IP rate limiting to the signup form to prevent abuse. We store only a salted, irreversible hash of the IP alongside a successful signup for security audit — never the raw address | Your browser, automatically |
| Approximate country | Understand which regions our early audience comes from. Derived from your IP at our CDN (Cloudflare) and stored as a 2-letter country code — we do not store the underlying location data or city | Derived at our CDN from your IP |
| Confirmation token + status, signup timestamp | Operate the double-opt-in flow and prove consent was given | Generated server-side |
| Aggregate page-view + form-submission events (via PostHog) | Understand whether the page is reaching people and converting | Your visit, recorded server-side (no browser tracker) |
We do not collect: your name, your precise location, your device fingerprint, advertising identifiers, cross-site tracking data, or any special category data. We do not run ads on the Site and we do not share data with ad networks.
Legal bases for processing (EU/EEA users)
For users in the EU/EEA, where GDPR applies, we rely on the following legal bases for the processing described above:
- Email address — your consent, given when you submit the form and confirm the email. You can withdraw it at any time (see Section 8).
- IP address (rate limiting and abuse prevention) — our legitimate interest in protecting the Site from automated abuse.
- Approximate country — our legitimate interest in understanding the geographic reach of our early audience. It is derived server-side from your IP and stored only as a coarse country code; no cookies or client-side tracking are involved.
- Confirmation token, status, and signup timestamp — the same consent as your email, together with our legitimate interest in operating and evidencing the double-opt-in flow.
- Aggregate analytics (PostHog) — your consent where ePrivacy rules require it, otherwise our legitimate interest in understanding the Site's reach and conversion.
4. Who we share data with
We use a small number of third-party processors to operate the Site. Each is bound by a Data Processing Agreement.
| Processor | Role | Data they see | Location |
|---|---|---|---|
| Fly.io | Hosting + database | Everything stored on the Site (your email, IP at submission time, server logs) | United States |
| Resend | Sending the confirmation and launch emails | Your email address, send/delivery metadata | United States |
| PostHog | Anonymous product analytics on the Site | Page-view + event data keyed to a random session identifier | United States |
We do not sell your data and do not share it for advertising purposes. We may disclose data if required to do so by law, valid legal process, or to protect our rights.
5. International data transfers
Where personal data is transferred outside the European Economic Area, we rely on the European Commission's Standard Contractual Clauses (Art. 46(2)(c) GDPR) with each processor, supplemented where necessary by additional technical and contractual measures. Specific transfer details are available on request to [email protected].
6. How long we keep your data
- Email addresses on the pre-launch list: retained until our product launches, plus up to twelve (12) months after launch, after which addresses that have not engaged are deleted. You can request earlier deletion at any time (see Section 8).
- Unconfirmed signups: confirmation tokens expire after seven (7) days; unconfirmed entries are deleted thirty (30) days after submission.
- Transient rate-limiting counters: raw IP addresses used to count requests are held only in memory and discarded within minutes.
- Hashed IP and country stored with a signup: kept for the life of the associated signup record (see the email-address retention above) and removed when that record is deleted.
- Aggregate analytics data: retained no longer than twenty-four (24) months.
- Records of consent: retained for as long as we hold your email, plus the duration of any applicable limitation period thereafter, to demonstrate that valid consent was obtained.
7. Cookies and similar technologies
The Site itself sets no advertising or tracking cookies. Our product analytics are captured server-side. The Site does set one essential, first-party cookie: a signed session cookie holding a random identifier we use to deduplicate analytics counts and to operate the signup flow. It is not used for advertising or cross-site tracking.
You can clear any storage the Site has set via your browser's site-data controls.
8. Your rights
If we hold personal data about you, GDPR gives you the following rights:
- Access — request a copy of the personal data we hold about you
- Rectification — ask us to correct inaccurate data
- Erasure — ask us to delete your data
- Restriction — ask us to limit how we process your data
- Portability — ask for your data in a machine-readable format
- Object — object to processing based on legitimate interest
- Withdraw consent — withdraw any consent you have given, at any time, without affecting the lawfulness of processing before withdrawal
- Complain — lodge a complaint with your local data protection supervisory authority
To exercise any of these rights, email [email protected]. We will respond within one (1) month. The simplest way to withdraw consent for email is to click the unsubscribe link in any marketing email we send.
9. Security
We use TLS for all traffic to the Site, store credentials in environment-injected secrets, run hosting on Fly.io's managed platform, and apply rate limits and abuse protections to public endpoints. No system is perfectly secure; if we ever experience a data breach affecting your data, we will notify you and the relevant supervisory authority as required by applicable law.
10. Children
The Site is not directed at children, and we do not knowingly collect personal data from anyone under the age of 13 (or the local digital-consent age, if higher). If you believe a child has submitted their email through the Site, please contact [email protected] and we will delete it.
11. Changes to this policy
We may update this policy from time to time. When we do, we will update the "Last updated" date above and, for material changes, take reasonable steps to notify people on the launch list before the changes take effect.
12. Contact
Privacy questions, data requests, or complaints:
You also have the right to lodge a complaint with the data protection supervisory authority in your country of residence.
← Back to Voxtide