Privacy Policy
- Effective date
- July 2026
- Applies to
- Vantr, and everyone using it
This Policy sets out what personal data Vantr collects, the legal basis for each use, who we share it with, how long we keep it, where it is stored, and the rights you can exercise over it.
1.Who we are and what this covers
This Policy explains how Vantr collects, uses, shares and protects personal data when you use the Vantr web application and related services.
For the purposes of the UK and EU General Data Protection Regulation, Vantr is the controller of the personal data described here. Vantr is currently operated as a sole proprietorship; a registered company has not yet been formed, and this section will be updated when one is.
Where you use Vantr to publish to a third-party platform, that platform is an independent controller of the data it receives and holds, governed by its own privacy policy. This Policy does not cover what a platform does with your content once published.
You can reach us about anything in this Policy at support@vantr.app.
2.The personal data we collect
We collect the following categories of personal data:
| Category | What it includes | Where it comes from |
|---|---|---|
| Account data | Email address, display name, password hash or third-party sign-in identifier, workspace name and role. | You, when you register |
| Connected platform data | OAuth access and refresh tokens, platform account ID, username, display name, avatar URL, and granted scopes. | The platform, when you authorise it |
| Content data | Videos, images, captions, hashtags, drafts, scheduled times, and publishing status and errors. | You, as you use the Service |
| Performance data | Views, likes, comments, shares and follower counts retrieved from platforms for posts you published through Vantr. | Connected platforms |
| Business records | Brand deals, contacts, deal values, income and expense entries you choose to record. | You, if you use these features |
| AI usage data | The text you submit to an AI feature, the response returned, and a timestamped record of the request. | You, when you invoke an AI feature |
| Billing data | Subscription plan, status, billing period, and payment-processor customer and subscription identifiers. We do not receive or store full card numbers. | You and Stripe |
| Technical data | IP address, browser and device type, and server and error logs generated when you use the Service. | Automatically |
We do not collect special categories of personal data (such as health, biometric, or political data) and ask that you do not submit them through the Service.
3.Why we use it, and our legal basis
Under the UK and EU GDPR we must have a lawful basis for each use of personal data. Ours are as follows:
| Purpose | Data used | Legal basis |
|---|---|---|
| Provide the Service — authenticate you, store your content, publish to the platforms you select | Account, connected platform, content | Performance of a contract |
| Show analytics for posts you published | Performance, content | Performance of a contract |
| Run the deals and earnings features | Business records | Performance of a contract |
| Provide optional AI features when you invoke them | AI usage, content | Performance of a contract |
| Take payment and manage subscriptions | Billing, account | Performance of a contract; legal obligation for tax records |
| Keep the Service secure, prevent abuse, and debug faults | Technical, account | Legitimate interests — operating a secure and reliable service |
| Enforce our Terms and establish or defend legal claims | Any of the above, as relevant | Legitimate interests; legal obligation |
| Send service messages about your account, billing or material changes | Account, billing | Performance of a contract |
| Send optional product or marketing email | Account | Consent, which you may withdraw at any time |
Where we rely on legitimate interests, we have considered whether those interests are overridden by your rights, and you may object as described in section 8.
We do not sell personal data, and we do not share it for cross-context behavioural advertising, as those terms are defined under California law. We have never done so.
We do not use your personal data for automated decision-making that produces legal or similarly significant effects.
4.AI features and your content
AI features are optional. Nothing is transmitted to an AI provider unless you actively invoke a feature such as caption feedback or rewriting.
When you do, the text you submit is sent to Google (Gemini) to generate a response, and a record of the request is retained in your account history so you can see what was asked and what was returned.
We do not train AI models on your content, and we use our AI provider under paid API terms that prohibit the provider from using submitted data to train or improve its models. We do not send your videos or images to an AI provider — only text you submit to a text-based feature.
If you would rather no content ever reach an AI provider, simply do not use the AI features. Every other part of the Service works without them.
6.International transfers
Vantr and its service providers are located in the United States. If you use the Service from the European Economic Area, the United Kingdom or Switzerland, your personal data is transferred to and processed in the United States.
For those transfers we rely on the European Commission's Standard Contractual Clauses, and the UK International Data Transfer Addendum where applicable, incorporated into our agreements with the providers listed in section 5.
You may request a copy of the relevant transfer mechanism by writing to support@vantr.app.
7.How long we keep it
We keep personal data only as long as we need it for the purpose it was collected:
| Data | Retention period |
|---|---|
| Account and workspace data | For as long as your account is open, then deleted within 30 days of closure. |
| Content, drafts and scheduled posts | Until you delete them, or within 30 days of account closure. |
| Connected platform tokens | Until you disconnect the platform or close your account, then deleted promptly. |
| Performance and analytics data | For as long as the associated post exists in your account. |
| Social listening results | 30 days, then automatically deleted by a scheduled job. |
| Comment data | Comments are refreshed on a rolling 90-day window; records for deleted comments are retained as tombstones so they are not re-imported. |
| AI request history | For as long as your account is open, then deleted with the account. |
| Billing and tax records | Up to 7 years after the transaction, as required by tax and accounting law. |
| Server and security logs | Typically 30 days, longer where needed to investigate a specific incident. |
Deleting content in the Service does not remove anything already published on a third-party platform. You must delete that from the platform itself.
We may retain data longer where necessary to establish, exercise or defend a legal claim, or where the law requires it.
8.Your rights
Depending on where you live, you have some or all of the following rights over your personal data:
- Access — obtain confirmation of whether we process your data and receive a copy of it.
- Rectification — have inaccurate or incomplete data corrected.
- Erasure — have your data deleted where we no longer have grounds to keep it.
- Restriction — ask us to limit how we use your data while a dispute about it is resolved.
- Portability — receive the data you provided to us in a structured, machine-readable format, or have it sent to another controller where technically feasible.
- Objection — object to processing based on legitimate interests, and to direct marketing at any time.
- Withdraw consent — where we rely on consent, withdraw it at any time without affecting processing already carried out.
- Non-discrimination — under California law, we will not deny you service or charge you a different price for exercising your rights.
You can exercise most of these rights directly in the Service: your settings include data export and account deletion. For anything else, write to support@vantr.app. We will respond within one month, and will tell you if we need longer because the request is complex.
We may need to verify your identity before acting on a request. You may use an authorised agent, in which case we will ask for proof of their authority.
If you are unhappy with how we have handled your data you may complain to your local supervisory authority — in the UK, the Information Commissioner's Office; in the EEA, the authority in your country of residence. We would appreciate the chance to resolve it with you first.
9.How we protect it
The measures we actually have in place are:
- Connected platform access and refresh tokens are encrypted with AES-256-GCM before they are written to the database, so a database backup contains only ciphertext.
- Every table enforces row-level security, so a query can only ever return rows belonging to the requesting user's workspace.
- Workspace roles restrict what each member can do, including who may publish, approve, or manage billing.
- All traffic between your browser and the Service is encrypted in transit with TLS.
- Data is stored with established infrastructure providers (Supabase and Vercel) that maintain their own physical and network security controls.
- Passwords are never stored in plain text; authentication is handled by our identity provider.
We want to be straightforward about the limits of that: Vantr has not undergone a third-party security audit and holds no security certification such as SOC 2 or ISO 27001. We do not claim to. No system is perfectly secure, and we cannot guarantee the Service will never be compromised.
If a breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours of becoming aware of it, and will notify you without undue delay where the risk is high.
To report a suspected vulnerability, email support@vantr.app and give us a reasonable chance to fix it before disclosing publicly.
11.Children
The Service is not intended for anyone under 18, and we do not knowingly collect personal data from children.
If you believe a child has provided us with personal data, write to support@vantr.app and we will delete it.
12.Changes to this Policy
We may update this Policy as the Service changes. The effective date at the top records when the current version took effect.
Where a change materially affects how we use your personal data, we will give notice by email or in the Service before it takes effect, and where the law requires it we will ask for your consent.
13.Contact
For any privacy question, to exercise a right, or to request a copy of a data transfer mechanism, write to support@vantr.app.
We have not appointed a Data Protection Officer, as we are not required to under Article 37 of the GDPR. Privacy enquiries are handled by the proprietor of Vantr directly.