Privacy Policy

Date of Last Revision: July 12, 2026 (UTC) — Updated 8 days ago

Velrix, a trading name of Hypefox AB (org. no. 559570-6416, VAT SE559570641601), with its registered office at Hyllie Boulevard 34, 215 32 Malmö, Sweden, is the controller of the personal data described in this policy. We process personal data in accordance with the EU General Data Protection Regulation (GDPR) and Swedish data protection law. We maintain complete transparency regarding the collection and handling of Your personal information — if You have any specific or technical questions about how We process Your data, please contact Us using the information in Section 13, and We will answer at no cost.

1. User Age Requirement

To use Our services, You must be at least 16 years of age. Velrix does not knowingly collect personal data from children under 16. If You suspect that a User is under this age limit, or if You are a parent or guardian, You have the right to request the removal of any information pertaining to Your child. Please use the contact information provided in Section 13 for assistance with such requests.

2. Personal Data We Collect

Account Information:

  • Username
  • Email Address
  • Hashed Password
  • Email Verification Codes
  • Account Creation Timestamp

Authentication & Session Data:

  • Session Tokens and Cookies
  • Login History and Authentication Attempts
  • Session Duration

Device & Browser Information:

  • IP Address
  • Approximate Geographical Location (derived from IP)
  • Browser Type and Version
  • Operating System
  • User-Agent String
  • Device Type
  • Timezone

Usage & Activity Data:

  • Time of Visit
  • Pages Visited
  • Referring URL
  • Activity Logs
  • API Request Data

Project & File Storage Data:

  • Project Names and Descriptions
  • File Names, Sizes and Types
  • Upload and Modification Timestamps
  • Storage Usage Statistics

Communications: messages You send Us through the contact form or other support channels, and related correspondence.

We collect this data when You register for an account, contact Us, use Our renewal service, access and use Our control panel, or use any other services offered on Our platform.

3. Why We Process Data and Our Legal Bases

  • To provide the Service and perform Our contract with You (GDPR Art. 6(1)(b)) — creating, verifying and managing Your account; facilitating login, authentication and secure access; providing and maintaining Your server, file storage and control panel; enabling Our desktop client and its features; processing service renewals; responding to Your inquiries and providing support; and sending You service emails such as verification codes, renewal and suspension notices, and important security alerts.
  • To comply with legal obligations (Art. 6(1)(c)) — such as retaining records We are required to keep and responding to lawful requests from authorities.
  • For Our legitimate interests (Art. 6(1)(f)) — securing and improving the platform; cybersecurity, including intrusion detection, threat prevention, rate limiting, regional blocking and bot identification; preventing fraud and abuse and enforcing Our Terms of Service; and generating anonymized, aggregated usage statistics (such as most-used services and country distribution) that contain no unique identifiers.
  • With Your consent (Art. 6(1)(a)) — for non-essential cookies and analytics on Our website, and for optional desktop client features. You can withdraw consent at any time without affecting prior processing.

4. Cookies, Analytics and Consent

We use cookies and similar technologies. Consent for non-essential cookies and scripts is managed through Our own consent management platform — You can make or change Your choices at any time via "Your Privacy Choices" in the website footer.

Strictly Necessary: essential cookies that enable login sessions, authentication, security features and core functionality. These do not require consent, and disabling them will prevent You from using Our services.

Analytics (consent-based): We use Microsoft Clarity to understand how Users interact with Our website (navigation patterns, clicks and general usage behavior) and Simple Analytics, a privacy-friendly, cookieless analytics provider that collects anonymous usage metrics. Both are only activated if You consent to analytics. See Microsoft's Privacy Statement and Simple Analytics' Privacy Policy.

Advertising: Our free service is funded by advertising. Banner placements on Our Site are currently served by Us as first-party content and do not set cross-site advertising cookies. If We enable third-party advertising networks, their cookies will only be set subject to Your consent through Our consent platform. We are not responsible for the content of advertisements or the websites they link to — exercise caution and verify the trustworthiness of any site before entering personal information.

5. Security Services and Bot Protection

Cloudflare: We use Cloudflare for security, protection against bots, and performance enhancement, and Cloudflare Turnstile on the control panel to verify human Users. Cloudflare processes connection data, IP addresses and request information as part of these services. See Cloudflare's Privacy Policy.

hCaptcha: During registration and other sensitive operations We may present an hCaptcha challenge (operated by Intuition Machines, Inc.) to distinguish humans from bots. hCaptcha processes technical data such as Your IP address and browser information for this purpose, based on Our legitimate interest in protecting the Service from abuse. See the hCaptcha Privacy Policy.

Cap: As a privacy-friendly alternative, We also use Cap, a proof-of-work challenge served from Our own infrastructure that verifies Your browser without tracking You or storing personal data.

6. Optional Desktop Client Features

When You download and use Our desktop client, You will have the option to enable the following bandwidth-sharing features. Neither is active unless You explicitly consent within the client, and You will receive a prompt to accept the respective terms before they begin operating:

If You enable these features, network and device data is shared with the respective provider according to their terms. You can disable them in the client at any time.

7. Who We Share Your Data With

No Sale of Personal Data: We do not sell, trade, or rent Your personal identification information to third parties. Your username, email address, password, and other personally identifiable information remain confidential.

Infrastructure: Your personal information and files are stored on Our own servers located in Sweden, operated through Our Melonslab infrastructure (also part of Hypefox AB). We maintain direct control over Your core personal data storage and do not rely on external third-party hosting services for storing Your information. For transparency about Our infrastructure practices, see the Melonslab Privacy Policy and the Hypefox Privacy Policy.

Service Providers: We share certain data with the providers described in Sections 4–6 (Cloudflare, Microsoft Clarity, Simple Analytics, hCaptcha, and — only with Your in-client consent — Honeygain and PacketSDK) as necessary to operate Our platform. We share only what is necessary for each service.

Aggregated and Anonymized Data: We may share aggregated statistics that contain no personally identifiable information — such as general visitor trends, popular services and geographical distribution — with business partners, affiliates and advertisers. This data cannot be used to identify individual Users.

Legal Obligations and Protection: We may disclose Your personal information when required by law, legal process or lawful governmental request (see Section 11 of Our Terms of Service), and when necessary to enforce Our Terms, investigate violations, detect and prevent fraud or security issues, or protect the rights, property or safety of Velrix, Our Users, or the public. Where hosted Content involves the abuse of minors, information is forwarded to NCMEC or the appropriate authorities.

Business Transfers: In the event of a merger, acquisition, reorganization, or sale of assets, Your personal information may be transferred as part of that transaction. We will notify You via email and/or a prominent notice on Our website of any such change in ownership or control of Your personal information.

8. International Transfers

Our infrastructure is operated in Sweden. Some providers (such as Cloudflare, Microsoft and hCaptcha) may process data outside the EU/EEA. Where they do, transfers are safeguarded by an adequacy decision of the European Commission or the European Commission's Standard Contractual Clauses.

9. How Long We Keep Your Data

We keep personal data for as long as Your account is active and as long as necessary for the purposes above. If Your free service is not renewed, Your account and all associated data are permanently and irrecoverably deleted 30 days after the missed renewal deadline, as described in Our Terms of Service. Logs and technical data are kept for a limited period for security and troubleshooting. Records We are required to keep by law are retained for the applicable statutory period.

10. Your Rights Under the GDPR

You have the following rights:

  • Right to Be Informed — to receive clear, transparent information about how We collect, use, store, and share Your personal data. This Privacy Policy fulfills that obligation.
  • Right of Access (Art. 15) — to request confirmation of whether We process Your personal data and obtain a copy of that data, including information about its use, sharing, retention period, and source.
  • Right to Rectification (Art. 16) — to request correction of any inaccurate or incomplete personal data We hold about You.
  • Right to Erasure ("Right to be Forgotten") (Art. 17) — to request deletion of Your personal data when it is no longer necessary, when You withdraw consent, when You object to processing, or when it has been unlawfully processed. Upon account deletion, We permanently remove Your data from Our systems, subject to legally required retention.
  • Right to Restrict Processing (Art. 18) — to request that We limit how We process Your personal data while a dispute about it is resolved.
  • Right to Data Portability (Art. 20) — to receive Your personal data in a structured, commonly used, machine-readable format (such as JSON or CSV) and to request that We transfer it to another provider where technically feasible.
  • Right to Object (Art. 21) — to object to processing based on Our legitimate interests, and to direct marketing at any time.
  • Right to Withdraw Consent (Art. 7(3)) — where processing is based on consent (such as analytics cookies or optional desktop client features), You can withdraw it at any time without affecting prior processing.

How to Exercise Your Rights: use the contact information in Section 13. We will respond free of charge and without undue delay, at the latest within one month (extendable by up to two further months for complex or numerous requests, in which case We will tell You why). We may need to verify Your identity before acting on requests involving access to or deletion of personal data. If We refuse a request, We will explain why, and You may appeal or complain to the supervisory authority. We will never discriminate against You for exercising Your privacy rights.

11. Complaints to a Supervisory Authority

If You believe We have not handled Your personal data correctly, You have the right to lodge a complaint with the Swedish Authority for Privacy Protection (Integritetsskyddsmyndigheten, IMY) at imy.se, or with the data protection authority in Your EU/EEA country of residence. UK residents may contact the Information Commissioner's Office (ICO) at ico.org.uk.

12. Security

We apply appropriate technical and organisational measures to protect personal data against unauthorised access, loss or misuse, including:

  • Passwords hashed with strong cryptographic algorithms; SSL/TLS encryption for all data in transit, including API communication between Our main site and control panel
  • Secure session management and encrypted authentication tokens
  • Activity monitoring and logging systems
  • Rate limiting to prevent abuse and unauthorized access
  • Bot detection and regional blocking through Cloudflare
  • Blocking of VPNs, proxies, abusive IP addresses, and disposable email addresses
  • Access controls on stored files so that only You can access Your data
  • Regular security audits and system updates
  • Multi-factor verification during critical operations

Where a personal data breach is likely to result in a risk to Your rights and freedoms, We will notify the Swedish Authority for Privacy Protection (IMY) and, where required, affected individuals, in line with the GDPR. No method of transmission or storage is 100% secure; while We cannot guarantee absolute security, We are committed to protecting Your data using industry-standard practices and to continuously improving Our security infrastructure.

13. Contact and Changes

The data controller is Hypefox AB (org. no. 559570-6416), Hyllie Boulevard 34, 215 32 Malmö, Sweden, trading as Velrix. For any questions, concerns, or requests regarding this Privacy Policy or Your personal data, or to exercise Your data protection rights, please visit our Contact Page for all available contact methods.

We may update this Privacy Policy from time to time to reflect changes in Our practices, technology, or legal requirements. When changes occur, the "Date of Last Revision" at the top of this policy will be updated, and We will make reasonable efforts to inform You of material changes. Your continued use of the Service after changes are posted constitutes Your acceptance of the revised Privacy Policy. This Policy is governed by Swedish law and subject to the courts of Malmö, Sweden.

Get started building today for free!

Deploy your first app or bot in minutes — no credit card required.

© 2026 Hypefox AB
Registered in Malmö, Sweden | Org. nr: 559570-6416