1. Who we are
Teero Inc. operates Voidek, a crawler, scraper, and browser automation defense service. This Privacy Policy explains how we collect, use, retain, disclose, and protect personal information when you visit the website, create an account, install snippets, call APIs, or contact us.
Privacy questions and rights requests can be sent to voidek.dev@gmail.com.
2. Information we collect
We collect information you provide directly, information generated by your use of Voidek, and technical data sent by protected sites so that we can provide security decisions.
- Account data: name, email address, workspace or organization name, login/session metadata, support messages, and preferences.
- Site configuration: site name, domain, site ID, API key metadata, rules, modes, protected routes, install snippets, quotas, and billing plan choices.
- Request telemetry: IP address, user agent, headers, HTTP method, path, referrer, accept-language, cookies or token presence, timestamps, decision, score, bot category, ASN, country, source, latency, and quota charge state.
- Browser and challenge signals: webdriver indicators, language, timezone, screen size, browser capabilities, client hints, local token status, challenge/session identifiers, and similar anti-abuse signals.
- Payment data after billing launches: plan, checkout status, customer ID, subscription ID, invoice ID, payment event metadata, tax or receipt data, and payment provider webhook payloads. We do not intend to store full card numbers.
- Website usage and cookies: necessary session, consent, local storage, security, and performance data described in the Cookie Policy.
3. Why we use information
We use information to operate and secure Voidek, deliver bot-defense decisions, maintain accounts, support customers, improve detection quality, and comply with legal obligations.
- Provide accounts, dashboard, site registration, API keys, install snippets, logs, usage, and support.
- Score requests, detect automation, verify browsers, issue challenge/session tokens, prevent credential probes, and block or log abusive traffic.
- Enforce quotas, rate limits, acceptable use rules, security policies, and Terms of Service.
- Debug outages, measure latency, protect infrastructure, investigate abuse, and maintain audit records.
- Send service notices, security notices, support responses, and billing notices.
- Develop new detection features, reporting, alerts, and reliability improvements using aggregated, sampled, or de-identified data where practical.
4. Legal basis and consent
For Korean users, we separate information needed to perform the service contract from optional processing. Account, security, site configuration, API, and anti-abuse telemetry are generally processed because they are necessary to provide and secure Voidek. Optional marketing or analytics cookies will be handled through consent controls when enabled.
If we later process sensitive information, resident registration numbers, unrelated marketing data, or information requiring separate consent, we will provide a separate notice and consent flow before processing.
5. Cookies and local storage
Voidek uses necessary cookies and local storage for login/session status, demo dashboard state, cookie preferences, API protection tokens, abuse prevention, challenge/session continuity, and site security. Optional analytics or marketing cookies are not required for the current beta.
See the Cookie Policy for categories, examples, retention, and controls.
6. Retention
We keep personal information only as long as needed for the purpose collected, unless a longer period is required by law, dispute handling, security investigation, accounting, or backup integrity. Beta retention may be shorter while the system is tuned.
- Account and workspace data: while the account is active, then a reasonable deletion or archival period after closure.
- Session tokens: until expiry, logout, replacement, or security invalidation.
- Raw request logs: target default is 30 days on Free, 90 days on paid plans, and custom on Pro unless a shorter period is configured.
- Aggregated usage: retained longer for billing, quota, product analytics, security trends, and financial records.
- Security/audit events: retained as needed to investigate abuse, protect the service, and maintain compliance records.
- Payment records after billing launches: retained as required for tax, accounting, chargeback, and legal obligations.
7. Sharing and subprocessors
We do not sell personal information. We share information with service providers that host, deploy, monitor, secure, store, analyze, or process payments for Voidek; with your workspace members; with authorities if legally required; and with advisors or acquirers during corporate transactions.
Current and planned subprocessors are summarized in the DPA. Some providers may process data outside Korea, depending on hosting region, account settings, and provider operations.
8. International processing
Voidek uses global cloud infrastructure and may process account data, request telemetry, logs, support communications, and payment metadata in countries other than where you are located. We use contractual, technical, and organizational safeguards appropriate for the provider and data type.
Before paid launch, the final subprocessor and international transfer details should be reviewed against the production infrastructure and payment provider.
9. Security
We use HTTPS/TLS, API key handling, hashed session storage for production auth, access controls, least-privilege deployment practices, infrastructure isolation, audit logs, and retention controls to protect information. No internet service is perfectly secure.
You are responsible for securing your own credentials, API keys, environment variables, protected-site code, and origin infrastructure.
10. Your rights
Depending on your location, you may request access, correction, deletion, suspension of processing, withdrawal of consent, objection, portability, or information about processing. We may need to verify your identity and authority before acting on a request.
Submit requests to voidek.dev@gmail.com. We will respond within a reasonable period required by applicable law. Some data may be retained where necessary for security, legal, billing, audit, or dispute reasons.
11. Children
Voidek is a B2B security service and is not directed to children. Do not create an account or submit personal information if you are not legally able to use business software services in your jurisdiction.
12. Changes
We may update this Privacy Policy as the product, infrastructure, payment provider, or law changes. Material updates will be posted on the website or sent to the account email when practical.