Privacy
This notice describes what the VORYN AI website actually does with information you send us. It is written from the system as implemented, not from intention. Where a policy has not yet been set, this notice says so rather than implying one exists.
Last reviewed against the running system on 16 August 2026.
What the contact form collects
The contact form at /contact is the only place on this website where you can submit information to us. Nothing else on the site collects data about you.
- Name
- Required. So we know who we are replying to.
- Email address
- Required. The address we reply to.
- Message
- Required. What you want to discuss, up to 4000 characters.
- Consent acknowledgement
- Required. You must tick the consent box before the form will submit. The form cannot be submitted without it.
- Company
- Optional. Helps us prepare a relevant response.
- Role or title
- Optional. Same purpose.
- Industry
- Optional. Same purpose.
- Business challenge
- Optional. A single choice from a fixed list, so we can route your enquiry to the right area.
- Preferred contact method
- Optional. A single choice from a fixed list — email, phone, video call, or no preference.
What we do not collect
- No analytics, tracking pixels, advertising tags, or session-recording tools are loaded anywhere on this website.
- No third-party scripts run on the public pages. Web fonts are served from this site's own domain, not from an external font provider.
- No cookies are set on the public pages. Cookies are used only on the /admin sign-in area, and only to hold an administrator's authenticated session.
- Your IP address is not stored against your message. It is used only in transient, hashed form as described below.
- The form contains a hidden anti-spam field. If it is filled in, the submission is rejected and nothing is stored.
How a submission is processed
When you submit the form, the information is validated on our server, not only in your browser. If validation fails, nothing is stored and the form returns to you with the fields to correct.
A valid submission is written to a PostgreSQL database hosted by Supabase, which acts as our data-hosting provider. The write happens from our server. Your browser never talks to the database directly.
Abuse protection and hashed request identity
To limit automated abuse of the form, our server derives a short one-way fingerprint from your IP address and browser user-agent string. It is a SHA-256 hash, truncated to 16 characters. The underlying IP address and user-agent are not written to storage.
This fingerprint is used to count recent submissions from the same connection and is recorded on our internal operational events so that a blocked or failed submission can be investigated. It is not attached to your message record, is not used to profile you, and is not shared.
This rate limiting is deliberately lightweight and best-effort. It runs within a single server instance and does not persist across restarts, so it should be understood as basic hygiene rather than strong protection.
Operational and audit events
VORYN keeps a minimal internal event log so that the handling of enquiries and administrator sign-ins remains traceable. Events record what happened and when — for example that a message was received, that a submission was rate-limited, or that an administrator sign-in was requested, succeeded, or failed.
These events carry the hashed fingerprint described above, never your name, email address, or message text. For an administrator sign-in, the event records the administrator's internal account identifier only.
Who can see your message
Access to submitted messages is restricted at the database level, not only in the application. By default the database denies all access. A separate, explicit rule grants read-only access to signed-in accounts that carry an administrator role, which is assigned manually by VORYN and cannot be self-assigned from the website.
The administrative review screen is read-only. There is no interface for editing, replying to, exporting, or deleting messages from within the website, and no automated or AI processing is applied to your message. Enquiries are read by a person.
The administrative area is not indexed by search engines and is not reachable without a valid single-use sign-in link sent to an authorised address.
Why we hold it
We use what you submit to understand your enquiry and respond to it. We do not sell it, rent it, trade it, or share it with third parties for their own purposes.
Our data-hosting provider (Supabase) necessarily processes the data on our behalf in order to store it. We do not send your submission to any other external service.
Your choices
You can ask us what we hold about you, ask us to correct it, or ask us to delete it. Write to hello@vorynaia.com and we will act on the request.
You are never required to use the form. If you would rather not submit anything through this website, email us directly at the same address.
Not yet established
VORYN would rather state this plainly than imply a policy that does not exist. The following are not yet set, and this notice will be updated when the Founder and a qualified legal reviewer have settled them:
- A defined retention period. Submissions are currently kept until a deletion request is acted on or the record is removed manually. No automatic deletion schedule is in force.
- A formal determination of which data-protection regimes apply to VORYN AI, including the Protection of Personal Information Act (POPIA) in South Africa, and the identity of the responsible party for the purposes of any such regime.
- A concluded lawful basis assessment. The consent you give on the form is recorded, but no formal lawful-basis analysis has been published.
- A published data-processing agreement with our hosting provider, and a recorded position on the hosting region and any cross-border transfer of the data.
- A named privacy contact or information officer, and a formal complaints route.
Changes to this notice
This notice was reconciled against the running system on 16 August 2026 as part of the Web Presence v2.2 trust-perimeter review. If the way we handle information changes, this page is updated in the same change as the code that changes it.
Privacy questions
Questions about this notice, or a request about your information, can go to hello@vorynaia.com.