هذه الوثيقة متاحة حاليًا باللغة الإنجليزية فقط.

Privacy Policy

Last updated: 2026-09-29

1. Who is responsible for your data

SOUMARI LTD, a private limited company registered in England and Wales (company number 17448813), registered office 128 City Road, London EC1V 2NX, United Kingdom is the controller of the personal data described here. Contact for anything about your data, including complaints: info@soumari.net. We acknowledge complaints within 30 days.

2. What we collect

Account data: email address, optional display name, language, marketing preference, and your password (stored only as a hash by our authentication provider) or your Google sign-in identifier.

Project data: the messages and images you send, the files and code generated for your projects, build history, previews, screenshots taken to check your app, and the sites you publish.

Billing data: your plan, credit balance and history, purchases, and the billing address and VAT number you enter at checkout. Card details are handled by Stripe; we never see or store your full card number.

Connected accounts: if you connect Supabase, the access tokens for it (stored encrypted) and which of your Supabase projects you linked.

Technical data: IP address, browser and device information, and logs needed to run and secure the service.

3. Why we use it and our legal basis

To provide Vylith and take payment (performance of our contract with you, UK/EU GDPR Art. 6(1)(b)).

To keep the service secure, screen requests, review published sites and prevent abuse and fraud (our legitimate interests, Art. 6(1)(f)).

To keep tax and accounting records (legal obligation, Art. 6(1)(c)).

To send product news only if you opt in (consent, Art. 6(1)(a)); you can switch it off at any time in Settings.

We do not sell your data, show ads, or use your projects to train AI models.

You need to give an email address to open an account, and billing details to pay. Without them we cannot provide Vylith.

Automated checks: requests are screened automatically, and every site is checked by an automated AI review before it is published. A site the review refuses is not published. You can ask for a person to look at any such decision by writing to us.

4. Who processes data for us

Supabase: sign-in and our database (hosted in the EU, Frankfurt).

Amazon Web Services: our application servers (EU, Frankfurt) and the AI models that power the agent through Amazon Bedrock in EU regions. Your prompts and project content are sent to these models to generate your app. Under Amazon Bedrock's terms they are not shared with the model makers and are not used to train models.

E2B: the isolated build environments and live previews (USA).

Cloudflare: DNS, content delivery and hosting of the sites you publish.

Vercel: hosting of our marketing website at vylith.shop.

Stripe: payments, tax calculation and invoices.

Google: optional "Sign in with Google".

Pexels: stock photos for your sites. We only send search words, never your personal data.

Each provider only processes data on our instructions under a data processing agreement. Where data leaves the UK or EU (for example to the USA), it is protected by the UK International Data Transfer Addendum or EU Standard Contractual Clauses, or by the UK-US data bridge and the EU-US Data Privacy Framework where the provider is certified. You can ask us for a copy of these safeguards.

We may also share data with the police, regulators, courts and child-protection bodies where the law requires it, and with our professional advisers (such as accountants) under confidentiality.

5. How long we keep it

Account and project data: until you delete the project or your account. Deleting your account removes it from our live systems straight away; copies in our providers' backups expire on their normal backup cycle.

Published sites: until you take them offline or delete the project or your account.

Payment and invoice records: kept by Stripe and in our accounting records for 6 years, as UK tax law requires, even after you delete your account.

Moderation records (refused requests, reports and take-downs): deleted with your account, unless we must keep them longer to meet a legal obligation or to deal with a report to the authorities.

Technical server logs: kept for up to 90 days.

6. Your rights

You can access, correct, download and delete your data, restrict or object to how we use it, withdraw consent, and ask for a person to review an automated decision. Data export and account deletion are built into Settings; for anything else, email us and we will answer within one month.

You can complain to the UK Information Commissioner's Office (ico.org.uk) or, in the EU, to the data protection authority where you live. We would appreciate the chance to sort it out first.

7. Cookies

We only use cookies that are needed to run Vylith. See the Cookie Policy.

8. Children

Vylith is for people aged 18 and over. We do not knowingly collect data from children; if you believe a child has an account, tell us and we will delete it.

9. Changes

We will tell you about material changes to this policy by email or in the app before they apply.