Privacy Policy
Last updated: October 9, 2026
Vittil ("we", "us", "our") operates the website vittil.io and the application at app.vittil.io (together, the "Service"). This privacy policy explains what the Service collects, what it does with it, who else holds it, and for how long.
This policy has not been reviewed by legal counsel and may be updated at any time. We encourage you to review it periodically.
Information We Collect
Account Information
When you create an account, we collect your email address and your name. You can sign up with email and password or through Google. Authentication is handled by our authentication provider, which stores your email and a hash of your password; we never see the password itself. If you sign in through Google, Google tells us your email address and name and nothing else.
Device Reports
Your devices send reports to your project with your project key. From each device we collect its device id, its firmware version and build id, and the time of each ping. After a crash we collect the crash report the device kept: the core dump the device wrote at the fault, which holds the registers and the stacks of its tasks, together with the reset reason, the uptime, and the record the component writes beside the dump.
A core dump is the device's memory at the moment of the fault. If your firmware held personal data in memory at that moment, that data may be in the report. We do not look for it, and we do not read the reports except to decode and show them to your project's users.
Build Files
To decode a report, you upload the firmware's ELF file. It contains the firmware's code and symbol names and is stored for your project.
Payment Information
Subscription payments are handled by our payment processor. When you subscribe, your payment card details are collected directly by the processor on its checkout page. We never receive or store your card number. We store only the processor's customer id and subscription id to manage your billing.
Technical Data
Our hosting providers may collect standard technical data such as IP addresses, browser type, and request timestamps through normal web server operation. The Service does not run analytics on you or your devices.
How We Use Your Information
- To receive, decode, and group your devices' crash reports and show them to your project's users
- To process subscription payments and manage your billing
- To communicate with you about your account (for example, a password reset email)
- To prevent abuse and ensure the security of the Service
We do not sell your information and we do not use your devices' reports for anything other than operating the Service for your project.
Third-Party Services
Vittil relies on third-party service providers for hosting, authentication, database and file storage, payment processing, email delivery, and DNS. Each provider processes only the data needed to perform its function, under its own privacy policy. If you choose to sign in with Google, Google processes that sign-in under its own privacy policy.
Cookies and Local Storage
- Session token — Stored in your browser's local storage to keep you logged in between visits.
The Service sets no cookies of its own and uses no advertising, analytics, or tracking cookies.
Data Retention
- Account and project data is retained for as long as your account is active.
- The core dump bytes of a crash report are kept for your plan's retention period (7 days on Free, 90 days on Starter, one year on Pro) and then deleted. The decoded crash (the backtrace, the registers, the reset reason, and the device and firmware it came from) is kept with your project.
- Device pings are kept for 7 days and then deleted; the device's last-seen time and firmware version are kept with your project.
- ELF files are kept with your project so that reports can be decoded again.
- If you delete your account, your project's data will be removed from our database and storage. Some data may persist in encrypted backups for a limited time.
Your Rights
- Access — You can request a copy of the data we hold about you.
- Deletion — You can request that we delete your account, your project, and all associated data by emailing us.
- Correction — You can request corrections to inaccurate information.
To exercise any of these rights, contact us at [email protected].
Data Security
Your devices send their reports over HTTPS, and we use encryption in transit across all services. Data stored in our database, file storage, and payment systems is encrypted at rest. Your project key is stored as a hash and shown to you only once. Access to production data is restricted. However, no method of transmission over the internet is 100% secure, and we cannot guarantee the absolute security of your data.
Children's Privacy
Vittil is not intended for use by individuals under the age of 18. We do not knowingly collect personal information from children.
Changes to This Policy
We may update this privacy policy from time to time. Changes will be reflected with an updated "Last updated" date at the top of this page. Your continued use of the Service after changes are posted constitutes your acceptance of the updated policy.
Contact
If you have questions about this privacy policy, contact us at [email protected].