Privacy
Clear boundaries for data.
What Volance collects, what it never collects, and how long it keeps it.
Volance is a product of Oops Games LLC. This page covers both the Volance website and the Volance service you use through the portal and API.
The website
No added tracking.
The Volance website has no added analytics, behavioral collector, or advertising cookies. Its sample scores and request displays are illustrative; they do not measure your visit. Messages you send from the portal's contact and upgrade forms are the ones you deliberately submit.
Our hosting provider (Google Firebase) receives requests and network data, including IP addresses, to serve the site and keep infrastructure logs. That infrastructure activity is separate from Volance product data, where raw addresses are never stored.
Account creation and sign-in happen in the portal at app.volance.com; this website only links to it.
The service
On-site behavior, enabled deliberately.
How collection works. A reviewed collector runs only on pages you choose, capturing timing and integrity signals after your visitors are informed. Scoring happens on your server. Nothing is collected from a page until you deploy it there.
- On-site behavioral signals: client integrity, interaction timing, and movement or scroll patterns on the site where collection is enabled.
- Operator-enabled: nothing is collected from a page until the integrating site deploys the collector there, and the page must inform visitors. Where law or policy requires visitor consent, that consent is the site's to obtain before capture.
- Fingerprint signals are a workspace setting: canvas, font and WebGL-renderer checks are off by default, the API drops them when they are off, and turning them on changes what your own privacy policy has to disclose.
- No cross-site identifiers: no identifiers designed to follow a visitor between unrelated sites.
- Hashed IPs: server-side hashing for product data, rather than retaining raw IP addresses in product records.
- 30-day raw retention: raw saved scores and sessions are purged after 30 days; longer-lived data is aggregate counts only. Saved sessions can be deleted in the portal at any time.
- No raw input content: keyboard signals concern timing only — never typed characters or form values. The API rejects payloads that carry them.
Questions about data handling can be sent through the contact form in the portal. See the terms and the status page, or the fuller service privacy notes in the portal at portal privacy.