Privacy Policy

The Vilkax Privacy Policy is the canonical contract on what we collect, why, how long we keep it, and your rights under the EU GDPR, the CCPA, and the other local data-protection laws that apply.

Who we are (data controller)

The controller of your personal data is Vilkaks UAB (registered company ID 308049358), a company registered in Lithuania with its registered office in Klaipėda and an operating hub in Barcelona, Spain. You can reach us through our contact form; to reach our data-protection contact, select the privacy topic. As an EU-established controller, our lead supervisory authority is the Lithuanian State Data Protection Inspectorate (Valstybinė duomenų apsaugos inspekcija, VDAI).

What we collect

What we do NOT collect

Vilkax Mail (connected mailboxes)

Vilkax Mail is optional. Nothing in this section applies unless you have explicitly connected a mailbox. It is an email client built for security: it shows you your mail, checks every message for fraud, and can help you draft a reply.

What we ask for, and when

What you actually granted is what we record - not what we asked for. If you approve reading but decline sending, Vilkax has no send capability for that mailbox.

What we keep - and what we cannot keep

Your messages are fetched from your provider, checked inside a single request, shown to you, and then gone. They are never written to our database. This is not a policy we promise to follow: our database has no field capable of holding a subject line, a sender, a message body, or an attachment.

Exactly two things are stored:

Commitments

Disconnecting

Unlinking a mailbox revokes the access at Google or Microsoft first, while we can still do so, then erases our stored tokens and every verdict for that mailbox. Where a provider offers no revocation endpoint, we say so and link you to the page where you can finish the job yourself, rather than implying it is done. Deleting your Vilkax account removes all of it regardless.

You can also revoke Vilkax's access directly at any time, without us: Google account permissions or Microsoft privacy settings.

About the people who email you

Checking your mail necessarily means processing what other people wrote to you. We rely on our legitimate interest in protecting you from fraud, and we limit the intrusion in the only way that genuinely counts: nothing about your correspondent survives the check except an unreadable hash and a rating.

Your rights

Children and families

Vilkax is built to protect families, and that starts with how we treat younger users. Under the GDPR (Art. 8), a child can consent to an online service themselves from a national threshold age that varies between 13 and 16 across EU member states. Vilkax is established in Lithuania, where that age is 14: you can create a Vilkax account yourself if you are 14 or older. Below the age that applies to you, we ask that a parent or guardian consents to your use of Vilkax - account creation includes an explicit confirmation of exactly that, and we keep a timestamped record of it.

Automated decisions and profiling (EU AI Act Art. 50 & GDPR Art. 22)

Vilkax uses AI and machine-learning models to generate risk scores, anomaly flags, and threat classifications for users and their accounts. These scores may affect which features are available to you (alert priority, protective tier gates, or escalation routing). No automated decision produces a legal effect or similarly significant impact without the right to human review. Our legal basis for this profiling is Art. 6(1)(b) GDPR (performance of a contract: the core protection service you signed up for) and Art. 6(1)(f) GDPR (legitimate interest in detecting and preventing fraud and account-level threats).

Your rights regarding automated decisions: you can request an explanation of any specific risk score or automated action affecting your account through our contact form. You can also request human review of any decision you consider to have produced an unjust outcome. Every automated decision is logged with its inputs (see the "Explanation" right above).

Sensitive data, and data about other people

Some of what Vilkax handles falls into categories the GDPR treats as needing extra protection. We would rather set that out plainly than leave it implied.

Your right to object

Where we rely on legitimate interest - which is the basis for checking what other people send you, and for security and abuse prevention - you have the right to object to that processing at any time, on grounds relating to your particular situation. If you object, we stop unless we can show compelling legitimate grounds that override your interests, rights and freedoms, or that we need the processing to establish, exercise or defend legal claims. To object, use our contact form and tell us what you object to; we will answer within one month.

Changes to this policy

We update this policy when what we do changes, or when the law does. For a change that materially affects how we use your data or narrows your rights, we will tell you by email and in the app at least 30 days before it takes effect, and where the law requires your consent for the new use, we will ask for it rather than assume it. Smaller corrections take effect on publication. Every version is kept with the date it applied and a hash of its text, so you can obtain the exact version that governed you at any point.

If you are in the United States

We give US residents the same core rights we give everyone: to know what we hold, to get a copy, to correct it, and to have it deleted - all from Settings, or through our contact form. Two points specific to US law. We do not sell your personal information, and we do not share it for cross-context behavioural advertising, as those terms are used in California and the other state privacy laws - we have no advertising business at all, so there is nothing to opt out of, and we honour Global Privacy Control regardless. And we do not use your data to discriminate against you in price or service for exercising any of these rights.

Who else sees your data

We do not sell your data and we have no ads business. We do share it with the service providers who help us run Vilkax - hosting, payments, transactional email, reputation lookups, and AI inference. Every one of them is named, with what it is used for and the region it operates in, on our sub-processor page, which we keep current and which is the same register our business customers get under their Data Processing Agreement. We give 30 days' notice before adding or replacing one.

We may also disclose data where the law requires it, to establish or defend legal claims, or to protect someone's vital interests - and to a successor if the business is acquired, in which case we will tell you.

Transfers outside the EEA. Some of those providers operate outside the European Economic Area - the sub-processor page marks which, and states the safeguard relied on for each (an adequacy decision, or the EU Standard Contractual Clauses). You can ask us for a copy of the safeguard for any specific provider through our contact form.

Where data lives

Account data is stored in a primary region. Edge caches hold only public, anonymous data (marketing pages, public state aggregates). Which provider holds what, and in which region, is published on our sub-processor page - the same register that forms part of our Data Processing Agreement.

Contact

Privacy questions: contact our privacy team.
To reach our data protection officer, contact us and select the privacy topic.
Security disclosures: /.well-known/security.txt

Last updated: 2026-08-29 · Version v9 (added "Network risk context (VPN, proxy or hosting network)" - that when you build a Personal Protection Profile we summarise the reputation of the connection your own request arrives on into coarse flags (VPN / proxy / Tor exit, hosting network, recent abuse reports, a low / elevated / high band, and the country), that it is used only to model how easily someone else could blend in with your sessions, that using a VPN is never treated as wrongdoing and carries the smallest weight of any factor, that your IP address is never stored, and that the same network_scan consent key gates it - without that consent no connection context is derived at all); v8 (added "Browser extension" - that link safety is off until switched on, that the content of pages you visit is never sent, and what is sent when it is on; added "Microphone" - the two features that use it, that speech dictation is transcribed by the phone’s own Google or Apple recogniser and so leaves the device to that provider, and that Vilkax never receives or stores audio; the wearable stress band and step/sleep disclosures were carrying duplicate translation keys and so rendered as unrelated text in every non-English language - they now carry their own keys and translate correctly); v7 (added "Sensitive data, and data about other people" - the Art. 9 explicit-consent basis for Hearth, how sensitive content inside scanned messages is handled, and the Art. 10 position on verdicts about other people; added "Who else sees your data" naming the recipient categories, linking the public sub-processor register and stating the transfer safeguards, replacing the earlier "available on request" wording; v6 (added the Children and families section - GDPR Art. 8 consent age, parental consent below it, KIN's circle-only consented location sharing, and the parent/guardian contact route; v5 re-based to the EU controller - Vilkaks UAB, registered in Klaipėda, Lithuania, with an operating hub in Barcelona, Spain - lead supervisory authority the Lithuanian VDAI, scoped to the EU GDPR; v4 disclosed the consent-gated Spotify embed; v3 disclosed device / network / app-usage protection signals, their consent gating, retention, and confirmed signal-data erasure on account deletion)