Privacy Policy
Last updated:
This page explains what data Vusul (vusul.app) processes, why, and how. The short version: we collect what running the service requires, we sell nothing, the marketing site runs no third-party trackers, and your data is exportable at any time.
1. Who is responsible
Vusul is operated by Rabi Coşkun as a natural person, without a corporate entity. Contact for all requests: support@vusul.app. Vusul is free right now: nothing is sold, nothing is charged, and no payment data is processed at all. When paid plans open, checkout will run through Paddle as Merchant of Record — and your card details will still never reach us.
2. What we collect
- Account data: name, email, password (never stored in plain text — hashed with argon2id), language and timezone. With Google/GitHub/Apple sign-in, the identifier that provider sends us; with a passkey, only the public key; with 2FA, the encrypted TOTP secret.
- Workspace content: tasks, comments, attachments, wiki pages, time entries, customer records — everything you and your team put into the product. It is yours; section 7 explains our role.
- Technical records: session records (IP address, browser info — so you can see and revoke your own sessions), the audit log, and ordinary server logs.
- Intake channels: if your workspace connects email, forms, Slack, WhatsApp or Telegram, the sender identifier (e.g. a phone number) is recorded on the task; messenger numbers are masked in the interface.
3. Why
To provide the service and perform the contract: run your account, store and sync your content, deliver notifications. Security: manage sessions, prevent abuse, keep an audit trail. Legal obligations: retain what the law requires.
We send no marketing email. Product notifications can be switched off individually in your preferences.
4. Cookies and on-device storage
- tm_refresh — the required session cookie; httpOnly (unreadable to JavaScript), used only to renew your session.
- tm-lang and the theme preference — remember your language and appearance choice.
- An in-browser cache (IndexedDB) — keeps recently viewed data on your own device so the app works offline; it is bound to its owner on sign-out.
All first-party. No third-party analytics, advertising or tracking cookies run anywhere — the marketing site included.
5. Who we share with
We do not sell, rent or share data for advertising. We use a small set of sub-processors to run the service:
- Hosting infrastructure — the servers the application and database run on.
- Email delivery — the provider that sends verification and notification mail.
- Paddle — NOT engaged today. When paid plans open it will handle checkout, invoicing and taxes as seller of record: Paddle would receive your email and billing details, and we would receive the payment status. On free use this step never runs.
The following engage ONLY if your workspace deliberately connects them, and nothing is sent otherwise: an AI provider (with your own API key; content is sent only for actions you trigger), Slack, Microsoft Teams, WhatsApp, Telegram, GitHub, GitLab, Sentry.
6. International transfers
Once paid plans open, billing data on a paid plan will be processed by Paddle (United Kingdom); there are no paid plans today, so that transfer does not happen. If your workspace connects an AI provider or one of the integrations above, the content of those operations goes to that provider’s country (usually the US). These transfers rest on your deliberate activation of the feature; without it they do not happen.
7. Third parties inside your workspace content
You may enter personal data of your own customers or partners into the product (CRM records, service-desk requests). For that data YOU are the controller; we store and process it only on your instructions. Collecting it lawfully is your responsibility.
8. Retention
Account data is kept while your account exists. Deleted tasks sit in a 30-day trash and can be restored; after that they are gone. Account deletion becomes final after a grace period. Backups roll off within the ordinary backup cycle.
9. Security
Passwords are hashed with argon2id; all traffic is TLS-encrypted; session renewal lives in an httpOnly cookie and the access token only in memory; two-factor authentication and passkeys are supported; you can view and revoke your active sessions; administrative actions are audit-logged.
10. Your rights
You can access, correct, delete, object to processing of, and port your data. Portability needs no request: CSV export and the full ZIP backup ship in every plan, inside the product. For anything else write to support@vusul.app; we answer within 30 days. Turkish residents: the KVKK disclosure governs the formal application procedure.
11. Changes
When this policy changes, the date on this page changes with it; significant changes are additionally announced in the app. Earlier versions are available on request.
Questions: support@vusul.app
