Legal · Privacy Policy

Privacy Policy

Last updated: 1st of September 2026. Effective upon publication; materials changes shall be communicated as set forth in Section 11 (Modifications) hereof.

§ 1.Information Collected

When the User creates an account on the Service, the Company collects the following categories of information: (a) the User’s email address, (b) the User’s chosen display name, and (c) a salted cryptographic hash of the User’s chosen password. The Company shall not store the User’s password in plaintext and shall not possess the technical means to recover it on the User’s behalf; the User is accordingly encouraged to record the chosen password through means not dependent on the Service.

In the course of the User’s use of the Service, the Company additionally collects operational metadata, including without limitation: (i) login attempts and account-creation activity, including successful and unsuccessful outcomes, (ii) Internet Protocol addresses and the proxy routing headers supplied to the Service, (iii) browser-supplied request information such as user agent, language, referrer path, platform hints, fetch context, requested host and protocol, content negotiation headers, data-saving preference, Do Not Track preference, and Global Privacy Control signal, (iv) the approximate country from which the request originated where the Service’s network provider supplies it, and (v) the timestamps at which the foregoing events occurred. Referrer query strings are discarded so invite codes and similar credentials are not retained. The Company uses this data for the purposes set forth in Section 5 and for the legitimate interest of detecting, preventing, and investigating abuse. The Company does not use canvas fingerprinting, browser probing, or third-party enrichment services for this security log.

Strictly speaking, the foregoing is a description of categories, not a list of items. The User’s confidence in the Service is best supported by a category-level understanding; a line-item understanding would, in our experience, occasion more questions than it resolves.

§ 2.Information Not Collected

The Company does not collect the following categories of information: (a) browsing history outside of vrdl.net, (b) contacts from the User’s address book or social graph, (c) precise geolocation data (the geolocation collected under Section 1 is at country or sub-country resolution), (d) biometric data, (e) the contents of the User’s private communications on third-party platforms, or (f) the contents of the User’s clipboard. The Company is not, and does not aspire to be, in the business of being Facebook. The Company’s storage budget is, at present, sufficient for its actual purpose and not for that of others.

§ 3.Cookies; Local Storage

The Service uses a small number of browser-stored items (collectively, “Cookies”) for the purpose of authenticating the User, remembering the User’s stated preferences, and enabling core features such as chat, follow, and stream subscription. The Company does not deploy advertising Cookies. The Company does not deploy third-party tracking Cookies. The Company does not deploy third-party Cookies of any other kind, except where strictly necessary to deliver functionality the User has affirmatively requested.

The Cookies the Company deploys are functional within the meaning of applicable law and are, in the Company’s professional opinion, the smallest reasonable set of Cookies needed to operate a streaming platform. The Company does not, at this time, integrate chocolate chips, although the matter has been raised internally on more than one occasion.

§ 4.Third-Party Service Providers

The Company engages a limited number of third-party service providers in the operation of the Service, including without limitation (a) a content delivery network for the efficient delivery of streaming video, (b) a payment processor for the handling of subscription transactions, and (c) an authentication provider for the secure issuance and verification of session credentials (collectively, “Processors”). Each Processor has its own privacy practices, which are governed by its own public policy documents. Each Processor receives from the Company only the data reasonably necessary to perform its function, and each Processor is bound by a written data-processing agreement with the Company. The agreement is short.

§ 5.Purposes of Processing

The Company processes the User’s personal information for the following purposes: (a) the operation of the Service, including authentication, authorization, content delivery, and chat; (b) the provision of service-related communications, including password resets and security alerts; (c) the detection, prevention, and investigation of fraud, abuse, and violations of these Terms; (d) the production of aggregate, de-identified analytics, which analytics the Company may from time to time cite in its marketing materials; and (e) compliance with applicable law and with the lawful and properly-served requests of public authorities.

The Company does not, and shall not, use the User’s personal information for advertising purposes. The Company does not, and shall not, sell the User’s personal information to third parties. The Company does not, and shall not, trade such information, barter it, exchange it, or otherwise convey it for value. The Company does not share such information with its accountants, who do not want it, or with its lawyers, who have plenty already.

§ 6.Data Retention

The Company retains the User’s personal information for so long as the User’s account is active or for so long as is necessary to provide the Service. Upon deletion of the User’s account, the Company shall delete or de-identify the User’s personal information within thirty (30) days. Certain information may persist in encrypted backups for an additional period, after which it shall be overwritten in the normal course of operations. The Company does not retain information indefinitely. The Company has better things to store, like cat photos; the database is, at the time of writing, principally used for that purpose.

Authentication security events described in Section 1 are retained for ninety (90) days and are then automatically deleted, except where a particular event must be preserved for an active security investigation or legal obligation. Access to the event log is limited to administrators of the Service.

Notwithstanding the foregoing, the Company may retain information where retention is reasonably necessary to comply with a legal obligation, to resolve a dispute, or to enforce these Terms; retained information in such cases shall be limited to what is strictly necessary for the purpose, and shall be deleted upon the conclusion of that purpose.

§ 7.User Rights; How to Exercise Them

Subject to applicable law, the User has the following rights with respect to the User’s personal information: (a) the right of access, (b) the right to rectification of inaccurate information, (c) the right to erasure, (d) the right to restrict or object to processing, (e) the right to data portability in a structured, commonly used, machine-readable format, and (f) the right to lodge a complaint with a competent supervisory authority.

The User may exercise any of the foregoing rights by contacting the Company at the address set forth on the Company’s home page. The Company shall respond to a properly submitted request within thirty (30) days. The Company may, in the alternative, extend the response period by a further sixty (60) days where the request is complex or where multiple requests have been submitted, and shall notify the User of any such extension. The response, in either case, will be written in plain language and will not contain stock paragraphs.

§ 8.Children

The Service is not directed at children under the age of thirteen (13), and the Company does not knowingly collect personal information from children under thirteen (13). Where the Company becomes aware that personal information has been collected from a child under thirteen (13), the Company shall delete such information as soon as reasonably practicable. Where a parent or guardian believes that personal information has been collected from a child under thirteen (13), the parent or guardian may contact the Company at the address set forth on the home page; the Company shall be prompt, thorough, and apologetic.

§ 9.Security

The Company employs reasonable technical and organizational measures to protect the User’s personal information from unauthorized access, disclosure, alteration, and destruction. Such measures include, without limitation: (a) encryption in transit, (b) encryption at rest, (c) access controls based on the principle of least privilege, (d) logging and monitoring of administrative actions, and (e) periodic internal review of policies and practices.

For the avoidance of doubt: no security measure is perfect, and no security measure can guarantee the absolute security of personal information. The Company does not promise perfection; the Company does promise effort, and effort, properly directed, has historically been found sufficient.

§ 10.International Transfers

The Company is organized in the State of Texas, United States of America. By using the Service, the User understands that the User’s personal information may be transferred to, stored in, and processed in the United States. The laws applicable to such information in the United States may differ from those of the User’s jurisdiction of residence; the User acknowledges that such differences exist and consents to the application of United States law for the purposes of this Policy.

§ 11.Modifications; Severability

The Company may modify this Privacy Policy from time to time. Material modifications shall be communicated through the Service and, where reasonably practicable, by electronic mail to the address on file. The date of the most recent revision shall be indicated at the head of this page. Continued use of the Service following the effective date of any such modification constitutes the User’s acceptance thereof.

If any provision of this Policy is held to be invalid or unenforceable, such provision shall be modified to the minimum extent necessary, and the remaining provisions shall continue in full force and effect. The Company respectfully declines to be bound by interpretations made after the fact.

§ 12.Entire Agreement

This Privacy Policy, together with the Terms of Service, the Cookie Notice (if any), and any operating rules or policies posted on the Service, constitutes the entire agreement between the parties with respect to the subject matter hereof and supersedes all prior or contemporaneous understandings, oral or written. Nothing in this clause shall be construed to limit the User’s rights under applicable law; where this Policy affords less protection than applicable law, applicable law shall prevail.

Execution

+

In witness whereof, the Company affirms that the foregoing is the Company’s policy as of the date and year first set forth above, and shall be construed and enforced in accordance with the laws of the State of Texas without regard to its conflict-of-law principles.

- vrdl.net (the Company). For inquiries under Section 7 (User Rights), please use the means listed on the home page; the inquiry will be acknowledged within seven (7) days and answered within thirty (30) days.

Return to home