Vermix
Sign inStart free
Legal/Privacy
Documents

Privacy Policy

Updated 6 September 2026

This is what Vermix collects, why, who it is shared with and how long it is kept. Written from what the app actually does, not from a template.

1. What we collect

Account: e-mail address, password (stored only as an irreversible hash), optional name, experience level.

Your reactor: name, type, start date; readings — substrate and air temperature, moisture, pH, time of reading; feedings — amount, feed type, layer thickness, note.

Diagnosis and the assistant: quiz answers, message history with the VermixAI assistant, your ratings of answers and feedback.

When the app fails: the error report contains the IP address, device model, OS and browser version. It exists to fix the failure and for nothing else.

2. What we do not collect

No behavioural analytics, advertising identifiers, photos or location. The camera, microphone and contacts are not available to the app without your action; speech recognition is done by your phone’s system, not by us.

3. Without an account

For the first 14 days you can work without registering. We set one functional cookie with an anonymous identifier for 14 days, inaccessible to scripts, so that readings and feedings are kept on the server and survive your phone clearing its memory. If you wipe the browser entirely, the identifier goes with the cookie and the data cannot be recovered without an account. Registering ties everything entered as a guest to the account.

Notes, checklists, language and screen state live in the browser’s memory on your device and are not sent to the server.

4. Why we use it

To show the reactor’s state, compute risk, send reminders, answer in the assistant, send service e-mails (address verification, password reset) and fix failures. Your data is not used for advertising, sale or model training.

5. Who we share with

Only processors without which the service cannot run. We do not sell data.

Railway (Amsterdam, EU) — server and database. Cloudflare — app delivery and database backups. Anthropic — assistant answers: your message text, the conversation history and reactor data (type, age, readings) are sent; name and e-mail are not; under the API terms the provider does not use them for training. Resend — e-mail delivery. Sentry — error reports (see above).

6. How long we keep it

Account and reactor data — for as long as the account exists.

Assistant conversations — 12 months, then deleted automatically.

Database backups are made daily and kept for 30 days; a deleted account disappears from backups when that period ends.

Address verification link — 24 hours; password reset link — 60 minutes; sign-in — 7 days; guest cookie — 14 days.

7. Your rights

In Settings you can export all your data in machine-readable form (JSON) and delete your account. Both work without registration too — for guests as well. Deletion is irreversible: reactor, readings, feedings, conversations and feedback are erased at once, and from backups when their retention ends.

You can correct inaccurate data directly in the app. For any question about your data, write to the address below — we answer within 30 days.

8. Cookies

One: the anonymous guest identifier. After signing in — a session token in the browser’s memory. No analytics or advertising cookies.

9. Changes

We will notify you of material changes to this policy by e-mail at least 14 days in advance.

Questions? info@vermix.app