Privacy Policy
Last updated: 11 September 2026
This Privacy Policy explains how the operator of Vutral handles information when you visit the website, use an online tool, contact us, or connect a third-party AI service. It also explains which data stays in your browser, which data reaches Vutral, and which data goes directly to another service.
Vutral is designed to work without an end-user account. We do not sell personal information, and the public tools currently do not use advertising cookies or third-party analytics. Some technical information is still required to deliver pages, protect the service, and complete the checks you request.
Scope and responsibility
This Policy applies to Vutral's public website, online tools, contact functions, and related services. It does not replace the privacy terms of a website you ask us to inspect or of a third-party service you choose to connect.
For information handled by Vutral, the operator of Vutral determines why and how it is processed. When you use your own Gemini or OpenAI API account, that provider also processes information under its own terms and privacy documentation.
Information we process
- Tool inputs. This may include URLs, domains, text, prompts, article briefs, anchor text, settings, files, or other material you choose to enter.
- Tool results. This may include page content, response codes, redirects, metadata, links, structured data, crawling rules, generated articles, and diagnostic messages.
- Technical request data. Our hosting infrastructure may process IP address, approximate location derived from IP, request time, requested page, browser and device information, referral data, headers, response status, errors, and security signals.
- Communications. If you use a contact form or otherwise contact Vutral, we process the information you provide, such as your name, email address, subject, message, and related correspondence.
Please do not submit confidential information, personal data, authentication credentials, private URLs, or third-party material unless you are authorised to process it and the selected tool is appropriate for that purpose.
How website checking tools handle data
When a tool must inspect a URL, your browser sends that URL and the selected settings to a Vutral endpoint. Vutral's server then requests the target website, may follow redirects, and returns the requested result to your browser. The target website may receive the URL path, request time, Vutral server IP address, selected User-Agent, and standard network headers.
Vutral does not intentionally forward your browser cookies, saved logins, or your personal IP address to the target website. Do not use a public checking tool for a private page that requires authentication or contains confidential information.
Responses from the checking endpoints are marked not to be cached by the application. Inputs and results are not designed to be written to Vutral's content database. They may still be processed transiently in server memory and standard infrastructure logs.
How AI writing features handle data
The Bulk GP Writer connects directly from your browser to the AI provider you select. Your API key, prompt, article brief, writing settings, model selection, and generated output are sent to Gemini or OpenAI using your own provider account. They do not pass through Vutral's application server.
The API key and generated articles are held in the memory of the open browser tab. Vutral does not place them in local storage, cookies, a query string, an environment variable, or its database. Closing or reloading the tab removes the working data from the Vutral interface, so export anything you want to keep.
The selected AI provider may log, retain, review, or use prompts and responses according to your plan, region, account settings, and its current terms. Free and paid tiers can have different data-use rules. Review the provider's policies before sending personal, confidential, regulated, or proprietary content.
Cookies and browser storage
Vutral's public tools currently do not require an end-user account and do not set advertising or third-party analytics cookies. The separate administration area may use an essential authentication cookie for authorised administrators; that cookie is not used to track public visitors.
The tools use local browser storage to remember limited interface preferences, such as whether the tool panel is open and whether a tool last used single or bulk input. These records contain preference values, not API keys, generated articles, or the URLs you submit for checking.
You can remove local storage through your browser settings. Blocking it will not prevent the core tools from working, but interface preferences may reset when you return.
How we use information
- Provide the page, tool, result, export, or response you request.
- Apply request limits, detect abuse, prevent unauthorised access, and protect Vutral, users, target websites, and infrastructure providers.
- Diagnose errors, maintain availability, and improve reliability and usability.
- Respond to questions, rights requests, reports of misuse, and support messages.
- Comply with law, enforce the Terms of Use, and establish or defend legal claims when necessary.
Legal bases where required
Depending on your location and the context, we process information to perform the service or take steps at your request, pursue legitimate interests in operating and securing Vutral, comply with legal obligations, or act with consent where the law requires it. You may withdraw consent for future processing, but that does not affect processing already carried out lawfully.
Request limits and IP addresses
Vutral uses the IP address supplied by the hosting platform as one signal for request limits. The application currently keeps short-lived request timestamps in the memory of the server instance to control traffic. This mechanism is intended to prevent overload, not to build a persistent visitor profile.
Hosting and network providers may independently keep security, diagnostic, and traffic logs according to their own settings and policies. A VPN, proxy, mobile network, or shared connection may cause several people to appear under one IP address or one person to appear under different addresses.
When information is shared
- Infrastructure providers, including hosting, content delivery, database, and security services, where needed to operate Vutral.
- The website or server you ask a tool to inspect, because making the requested check requires a network request to that destination.
- Gemini or OpenAI when you deliberately connect that provider with your own API key.
- Professional advisers, authorities, or other parties where disclosure is reasonably necessary to meet a legal obligation, protect rights and safety, investigate misuse, or complete a business reorganisation.
We do not sell or rent personal information. We do not share it for cross-context behavioural advertising.
Retention
Tool inputs and results that exist only in the browser remain until you clear them, reload, close the tab, or the browser removes them. Interface preferences in local storage remain until you or the browser delete them.
Short-lived rate-limit records expire as their rolling window passes or when the relevant server process ends. Standard infrastructure logs may be retained for a limited period by service providers for security, diagnostics, and operations.
Contact submissions and related correspondence may be retained for as long as reasonably necessary to answer the request, maintain records, prevent misuse, resolve disputes, and comply with law. We may delete or anonymise information earlier when it is no longer needed.
International processing
Vutral and its providers may process information in countries other than your own. Those countries may have different privacy laws. Where required, appropriate contractual, organisational, or legal safeguards should be used for relevant transfers.
Security
We use reasonable technical and organisational measures intended to protect information, including input validation, request controls, restricted administration access, transport encryption provided by HTTPS, and separation between public tools and administration functions.
No online system is completely secure. You are responsible for protecting your API keys, browser, device, accounts, exports, and any sensitive material you choose to process. If you believe a key has been exposed, revoke or rotate it with the provider immediately.
Your choices and rights
Depending on the law where you live, you may have rights to request access, correction, deletion, restriction, objection, or portability of personal information, and to complain to a privacy regulator. Some rights are subject to exceptions, identity verification, and limits where Vutral does not hold the information concerned.
For data sent directly to Gemini or OpenAI, submit the request to that provider because Vutral does not receive or control the provider-account data. For browser storage, you can delete it locally through your browser. For information held by Vutral, contact us through the Contact page and describe your request.
Children
Vutral is not directed to children, and we do not knowingly collect personal information from children. Third-party AI services impose their own age and eligibility rules; Gemini API access currently requires users to be at least 18. If you believe a child has provided personal information to Vutral, contact us so the matter can be reviewed.
Changes to this Policy
We may update this Policy when Vutral, its tools, providers, or legal obligations change. The revised version will be published with a new update date. Material changes may also be highlighted through the website where appropriate.
Contact
For a privacy question, rights request, or concern about how Vutral handles information, contact Vutral through the Contact page. Include enough detail for us to identify the issue, but do not send passwords or API keys.