Privacy Policy
Last updated: September 2026
1. What this covers
This policy covers the Vylos desktop app, your Vylos account, and this website (including the waitlist). We collect only what we need to run those, and we don't sell personal data.
2. Your account
When you create an account we store your email address, the name you give us, and — if you sign in with Google or GitHub — the basic profile those services share (name, email, avatar). Passwords are handled by our authentication provider, Supabase, and are never visible to us.
3. Your computer
To limit how many accounts can be used on one computer, the app sends a one-way fingerprint (a SHA-256 hash) of your operating system's install ID when you sign in. The raw ID never leaves your machine, and the hash can't be turned back into it. We store it alongside the accounts that have used that computer.
4. Your code and your lessons
Vylos runs on your machine. Your files, projects and course progress stay on your computer, and exercises are checked locally.
When you use an AI feature — the voice or chat tutor, hover explanations, step-by-step hints, error explanations — the code, question or audio needed for that request is sent through our servers to Google's Gemini API to generate the answer. We don't use your code to train models, and we don't keep the content of these requests. We do count how many AI requests each account makes per day, to enforce usage limits.
5. The waitlist
Joining the waitlist means giving us your name and email address so we can contact you about early access and launch updates. It's only used for that.
6. This website
This site doesn't run analytics, tracking scripts or advertising cookies. Our hosting provider keeps standard server logs (IP address, browser type, pages requested). The sign-in page stores your session in your browser so it can offer to continue as you next time — see the Cookie Policy for details.
7. Who processes your data
Supabase (accounts, database and our servers' functions), Google (Gemini AI requests), Vercel (website hosting) and GitHub (app downloads and updates). Each only uses the data to provide that service to us.
8. Your choices
You can ask us to delete your account at any time; deleting it removes your profile, your AI usage counts and your device records. You can also ask to be removed from the waitlist. Signing out of the app clears the session stored on your computer.
9. Changes to this policy
We'll update this policy as Vylos changes, and tell account holders about significant changes before they take effect. The date above reflects the last revision.
10. Contact
Questions about this policy can be raised through the channels linked in the footer.