Privacy Policy
Last updated: July 17, 2026
Vercel-Recovery · 't dorp 13C, 5384MA Heesch, Netherlands · KVK 74366580
At vercel-recovery, operated by Vercel-Recovery ('t dorp 13C, 5384MA Heesch, Netherlands, KVK 74366580), we respect your privacy and are committed to protecting the personal and technical data you share with us. This Privacy Policy explains how we collect, process, and safeguard your information.
1. Information We Collect
To provide the code recovery service, we collect and process the following information:
- Account data: When you sign in via Google, GitHub, Apple, or email, we store your profile information (such as email, name, and avatar URL) and authentication identifiers to manage your session and Token balance.
- User-provided Vercel API tokens: To download your source files, you must provide your Vercel API token.
- Deployment metadata: We temporarily read deployment IDs, file names, and project lists associated with your Vercel account to display recovery choices and facilitate downloads.
- Payment data: Purchases are processed by Stripe. We store purchase records (amount, tokens credited, Stripe session ID) but not your card details.
- Usage & support data: We store recovery usage logs (project, file counts, tokens spent), scan and login events tied to using the product, and problem reports you submit (title, description, and linked account if signed in). With optional consent, we also store first-party page-visit events.
- Support chat: Optional on-site assistant that answers from a curated Vercel Recovery knowledge base via a server-side LLM API (currently NVIDIA Build / OpenAI-compatible). Messages you send are processed to generate a reply. Do not paste secrets (API tokens, passwords) into the chat.
2. How We Process and Use Your Data
- Transient token processing: We do not store your Vercel API tokens in our databases. Tokens are sent to our servers only to call the Vercel API during scan and download requests, then discarded from server memory.
- Browser local storage: For your convenience, the Recovery Console may save form fields (including your Vercel token) in your browser's local storage on your device. Cookie preferences are also stored in local storage. You can clear this at any time via your browser settings or by clearing site data.
- Code and file integrity: Recovered source files are fetched from Vercel, compiled into a ZIP archive, and streamed to your browser. We do not inspect or permanently host your source code. ZIP files may be temporarily stored in Vercel Blob storage during download and are deleted after retrieval or expiry.
- Account management: We use your login data to maintain your session, verify your identity, and manage your Token balance. Authentication is handled by Firebase — we do not store plain-text passwords.
- Service analytics: Login and scan events are recorded when you use those features so we can operate billing, support, and the admin dashboard. Separately, with your consent, we record page visits (path, referrer, user agent) and load Google Ads tags. Without consent, visit tracking and Google Ads are not used.
3. Data Retention
- Account data: We retain your account profile data and credit/purchase history as long as your account remains active.
- API tokens: Vercel API tokens are not persisted in our database and are not retained on our servers after a request completes.
- Recovered source code: We do not archive your recovered source code. Transient download buffers and blob storage objects are removed after your download completes or expires.
- Analytics & support: Visit, login, and scan events, and problem reports, are retained as long as needed to operate and support the service, then deleted or anonymized when no longer required.
4. Third-Party Integrations
Our Service interacts with the following third-party platforms:
- Firebase Authentication (Google): Google, GitHub, Apple, and email/password login.
- Vercel REST API: Read deployment directories and fetch file contents.
- Vercel Blob / hosting: Temporary ZIP storage and application hosting on Vercel infrastructure.
- Neon (PostgreSQL): Application database for accounts, purchases, usage logs, and consented analytics events.
- Stripe: Payment processing for Token purchases. We do not collect or store your credit card details.
- Resend: Transactional emails (welcome, purchase receipt, email verification, recovery complete) when you have an email on file.
- NVIDIA / LLM provider (support chat): When you use the support chat, your messages are sent to our configured OpenAI-compatible inference provider (default: NVIDIA hosted API) to generate answers grounded in our knowledge base.
- Google Ads: If you accept optional cookies, we load Google Ads tags to measure advertising performance and purchases. Google may set cookies subject to your consent.
5. Cookies, Local Storage & Similar Technologies
We distinguish between essential and optional technologies:
- Essential — session cookie:
__session(HTTP-only) keeps you signed in after Firebase authentication. - Essential — Firebase Auth: Firebase may use browser storage or cookies required to complete sign-in with Google, GitHub, Apple, or email.
- Essential — payments: Stripe Checkout may set cookies on Stripe-controlled domains when you complete a purchase.
- Essential — local preferences: Recovery Console form fields and your cookie choice are stored in
localStorage/sessionStorageon your device. - Optional — product analytics: With consent, we store first-party page-visit events on our servers for the admin dashboard.
- Optional — Google Ads: With consent, Google Ads / gtag cookies and tags may measure ad clicks and conversions.
You can choose Accept optional or Essential only in the cookie banner. You can change your mind later by clearing site data for this domain in your browser, which resets the banner.
6. Security Measures
We implement standard industry-level security practices. Because you provide API access keys, you are responsible for:
- Using a scoped Vercel API token limited to the necessary projects.
- Revoking the Vercel API token in your Vercel developer dashboard after verifying your download.
Read our token security guide.
7. Your Rights (GDPR / CCPA)
Depending on your location, you may have rights regarding your personal data, including the right to access, correct, or delete account information we hold. To exercise these rights or request account deletion, contact us at privacy@vercel-recovery.com.
Vercel-Recovery · 't dorp 13C, 5384MA Heesch, Netherlands · KVK 74366580