volary.ai Privacy Policy
Effective date: 26 February 2026
volary.ai (the “Site”) is owned and operated by Volary Ltd. Volary Ltd is the data controller and can be contacted at: contact@volary.ai
167-169 Great Portland Street, 5th Floor, London W1W 5PF
Purpose
The purpose of this privacy policy (the “Privacy Policy”) is to inform users of our Site of the following:
- The personal data we will collect
- Use of collected data
- Who has access to the data collected
- The rights of Site users; and
- The Site's cookie policy
This Privacy Policy applies in addition to the terms and conditions of our Site.
GDPR
For users in the European Union, we adhere to the Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016, known as the General Data Protection Regulation (the “GDPR”). For users in the United Kingdom, we adhere to the GDPR as enshrined in the Data Protection Act 2018.
We have not appointed a Data Protection Officer as we do not fall within the categories of controllers and processors required to appoint a Data Protection Officer under Article 37 of the GDPR.
Consent
By using our Site users agree that they consent to the conditions set out in this Privacy Policy.
When the legal basis for us processing your personal data is that you have provided your consent to that processing, you may withdraw your consent at any time. If you withdraw your consent, it will not make processing which we completed before you withdrew your consent unlawful.
You can withdraw your consent by contacting us at privacy@volary.ai.
Legal Basis for Processing
We collect and process personal data about users in the EU only when we have a legal basis for doing so under Article 6 of the GDPR.
We rely on the following legal bases to collect and process the personal data of users in the EU:
- Users have provided their consent to the processing of their data for one or more specific purposes.
- We have a legitimate interest (Article 6(1)(f) GDPR) in processing IP addresses for billing verification, fraud prevention, and security investigation to protect our services and our users.
Personal Data We Collect
We only collect data that helps us achieve the purpose set out in this Privacy Policy. We will not collect any additional data beyond the data listed below without notifying you first.
Data Collected Automatically
When you use our Service, we automatically collect the following data:
- IP addresses associated with API requests.
Data Collected in a Non-Automatic Way
We may also collect the following data when you perform certain functions of our Service:
- Historical agent conversation data.
This data may be collected using the following methods:
- By the agent using our services.
How We Use Personal Data
Data collected on our Site will only be used for the purposes specified in this Privacy Policy or indicated on the relevant pages of our Site. We will not use your data beyond what we disclose in this Privacy Policy.
The data we collect when the user performs certain functions may be used for the following purposes:
- To analyze in order to improve future agent performance.
- To verify billing and resolve billing disputes.
- To prevent fraud and investigate security incidents, including compromised API keys.
Who We Share Personal Data With
Employees
We may disclose user data to any member of our organisation who reasonably needs access to user data to achieve the purposes set out in this Privacy Policy.
Third Parties
We may share user data with the following third parties:
- OpenAI
- OpenRouter
We may share the following user data with third parties:
- Historical agent conversation data.
We may share user data with third parties for the following purposes:
- Analysis in order to improve future agent performance.
Third parties will not be able to access user data beyond what is reasonably necessary to achieve the given purpose.
Other Disclosures
We will not sell or share your data with other third parties, except in the following cases:
- If the law requires it;
- If it is required for any legal proceeding;
- To prove or protect our legal rights; and
- To buyers or potential buyers of this company in the event that we seek to sell the company.
If you follow hyperlinks from our Site to another Site, please note that we are not responsible for and have no control over their privacy policies and practices.
How Long We Store Personal Data
User data will be stored until the purpose the data was collected for has been achieved.
You will be notified if your data is kept for longer than this period.
How We Protect Your Personal Data
In order to protect your security, we use state-of-the-art encryption and store all of our data on servers in secure facilities. All data is only accessible to our employees. Our employees are bound by strict confidentiality agreements and a breach of this agreement would result in the employee's termination.
While we take all reasonable precautions to ensure that user data is secure and that users are protected, there always remains the risk of harm. The Internet as a whole can be insecure at times and therefore we are unable to guarantee the security of user data beyond what is reasonably practical.
Your Rights as a User
Under the GDPR, you have the following rights:
- Right to be informed;
- Right of access;
- Right to rectification;
- Right to erasure;
- Right to restrict processing;
- Right to data portability; and
- Right to object.
Children
We do not knowingly collect or use personal data from children under 16 years of age. If we learn that we have collected personal data from a child under 16 years of age, the personal data will be deleted as soon as possible. If a child under 16 years of age has provided us with personal data their parent or guardian may contact our privacy officer.
How to Access, Modify, Delete, or Challenge the Data Collected
If you would like to know if we have collected your personal data, how we have used your personal data, if we have disclosed your personal data and to who we disclosed your personal data, if you would like your data to be deleted or modified in any way, or if you would like to exercise any of your other rights under the GDPR, please contact our privacy officer here:
Peter Ebden
privacy@volary.ai
167-169 Great Portland Street, 5th Floor, London W1W 5PF
Do Not Track Notice
Do Not Track (“DNT”) is a privacy preference that you can set in certain web browsers. We do not track the users of our Site over time and across third party websites and therefore do not respond to browser-initiated DNT signals. We are not responsible for and cannot guarantee how any third parties who interact with our Site and your data will respond to DNT signals.
Cookies and similar technologies
We use web storage (localStorage and IndexedDB) to store and access information on your device. These technologies allow our website to remember information between page loads and visits.
Strictly necessary storage (authentication)
When you sign in, we store authentication tokens in IndexedDB so that:
- you stay signed in as you navigate the site;
- we can recognize your authenticated session and secure access to your account; and
- we can help protect the service against misuse and keep the site functioning reliably.
This information is used only to provide the service and maintain security. It is not used for advertising or cross-site tracking.
How long we keep it: Auth tokens remain on your device until they expire, you sign out, or you clear your browser’s site data.
Functionality storage
We may store limited navigation information in localStorage (for example, the last page or section you viewed) so you can return to where you left off on this device.
How long we keep it: This information stays on your device until you clear it via your browser settings (or until we overwrite it with newer navigation information).
Your choices and how to delete this data
You can remove or control these technologies by:
- signing out (which will end your authenticated session);
- clearing your browser’s site data (which removes localStorage and IndexedDB for this site); and/or
- using your browser settings or extensions to manage site storage.
We recommend not using the Site on a public or shared device. If you do, we recommend signing out and clearing site data after your session.
Modifications
This Privacy Policy may be amended from time to time in order to maintain compliance with the law and to reflect any changes to our data collection process. When we amend this Privacy Policy we will update the “Effective Date” at the top of this Privacy Policy. We recommend that our users periodically review our Privacy Policy to ensure that they are notified of any updates. If necessary, we may notify users by email of changes to this Privacy Policy.
Complaints
If you have any complaints about how we process your personal data, please contact us through the contact methods listed in the Contact Information section so that we can, where possible, resolve the issue. If you feel we have not addressed your concern in a satisfactory manner you may contact a supervisory authority. You also have the right to directly make a complaint to a supervisory authority. You can lodge a complaint with a supervisory authority by contacting the Information Commissioner's Office in the UK.
Contact Information
If you have any questions, concerns or complaints, you can contact our privacy officer, Peter Ebden, at privacy@volary.ai.
