Privacy Policy — VoltPilot
Version: 1.0
Date: 2026-08-22
Canonical language: English — this version governs worldwide, except in
Québec, where the French version governs
§1 — Who processes your data
The controller of the personal data described in this Policy ("we") is the developer and owner of the software, operating under the business name VoltPilot and established in Québec, Canada.
Person responsible for the protection of personal data: the owner of the software, reachable at support@voltpilotpower.com — the single official channel, including for exercising the rights in §10. The postal address is provided through that channel to anyone with a legitimate interest, including a data subject and a data-protection authority.
This Policy covers the VoltPilot desktop application, the licence server and the product website.
§2 — The principle that governs this product
VoltPilot is a desktop application. The work happens on your machine.
Your projects, drawings, calculation records and reports are never sent to us. They are stored locally, on your device. There is no usage telemetry, no behavioural tracking inside the application, and no collection of the content of your files.
What travels to our server is the minimum needed to issue and verify a licence — listed item by item in §3.
§3 — What data we process
3.1 Account
| Data | Source | Note |
|---|---|---|
| Email address | you, at sign-up | it is the account identifier |
| Password | you | stored only as an Argon2id hash; never in clear text, and we cannot recover it |
| Email verification status | system | — |
| Name/company and billing country | you or Paddle | when a purchase is made (§3.5) |
3.2 Record of acceptance of the terms
When you accept the EULA, we record who accepted, which version of the document, the date and time, and the IP address of the acceptance. It is the proof that the contract exists; without it, acceptance would be worth nothing to either party.
3.3 Licence, activation and devices
| Data | Detail |
|---|---|
| Hashes of up to 4 device identifiers | depending on the operating system (on Windows: the system installation identifier, the mainboard identifier, the volume serial number, and an identifier generated on first run). The raw values never leave your machine and are never logged: the application computes a cryptographic digest of each one, per component, and sends only the digest |
| Device name | text you choose (up to 80 characters), so you can recognise the machine in the devices screen. If you do not provide one, nothing is sent in this field |
| Application version | sent on activation and on each revalidation, and also in a request header |
| Activation identifier, issue and revalidation timestamps | required for offline operation |
| Plan, features and licence limits | the snapshot the application consults to unlock features |
Why hashes and not the identifiers? Because a digest allows the same machine to be recognised without us ever knowing your serial number. Recognition requires at least 3 of the 4 components to match — which is why replacing a drive or reinstalling the system normally does not consume an activation.
3.4 Server technical logs
Requests to the licence server produce logs containing the IP address, date and time, the route accessed and the result. They serve security, rate limiting against brute-force attacks, and fault diagnosis.
3.5 Payment
Purchases are processed by Paddle, acting as Merchant of Record.
We do not receive, process or store card data. From Paddle we receive only transaction and subscription identifiers, the plan, the payment status, and the billing country (needed to compute taxes). Paddle is an independent controller as to the data it collects from you in order to bill you; its own privacy policy, presented at the time of payment, also applies.
3.6 Support
If you write to us, we process the content of your message, your email address and anything you attach voluntarily. Attach only what is needed — if a project contains information confidential to your client, send the excerpt, not the whole file.
3.7 Audit log
Sensitive account and licence operations (activation, deactivation, plan change, revocation) are kept in an audit log.
§4 — Optional AI features: what you need to know
VoltPilot offers AI-assisted extraction switched off by default. It works only if you configure it.
4.1 If you configure an external provider (Anthropic or OpenAI), the application uses your own API key and transmits the content you submit — including excerpts of project documents — directly to that provider. We do not intermediate it, receive no copy, and have no control over that processing: the relationship is between you and the provider, under its contract and privacy policy.
4.2 If you configure a local model, nothing leaves the device by that route.
4.3 Assess professional secrecy and your client's confidentiality clauses before enabling an external provider.
§5 — Why we use it, and on what legal basis
| Purpose | Data | Legal basis |
|---|---|---|
| Create and maintain your account | §3.1 | performance of the contract |
| Issue, verify and revoke a licence; enable offline use | §3.3 | performance of the contract |
| Prove acceptance of the terms | §3.2 | legal obligation and legitimate interest |
| Prevent fraud and unauthorised use (multiple accounts, circumvention of activation, clock manipulation) | §3.3, §3.4 | legitimate interest |
| Security and availability of the service | §3.4 | legitimate interest |
| Billing, invoicing and taxes | §3.5 | performance of the contract and legal obligation |
| Support | §3.6 | performance of the contract |
| Operational messages (email verification, expiry notice, payment failure, change of terms) | §3.1 | performance of the contract |
| Audit and defence of legal claims | §3.7 | legal obligation and exercise of rights |
We do not use your data for advertising, behavioural profiling, sale to third parties, or to train machine-learning models.
Email marketing, if any, requires separate consent and can be unsubscribed from in any message.
§6 — Who we share with
Only with those needed for the service to exist:
| Recipient | Role | What it receives |
|---|---|---|
| Paddle | payment (Merchant of Record) | §3.5 |
| Hosting provider (Canada) | licence server infrastructure | data stored on the server |
| Email delivery provider | transactional messages | email address and message content |
| AI providers (Anthropic/OpenAI) | only if you configure it (§4) | what you submit, under your contract with them |
| Authorities | compliance with a valid legal order | strictly what is required |
We may also transfer data in a corporate reorganisation, with the protections of this Policy preserved.
We do not sell personal data.
§7 — Website and cookies
The product website uses strictly necessary cookies for session and security. We do not use advertising cookies. Should we adopt audience measurement, this Policy will be updated beforehand and the measurement will depend on your consent where required.
§8 — International transfer
The licence server is hosted in Canada. If you are in another country, your data is processed outside it. We apply contractual safeguards compatible with applicable law (PIPEDA, Québec Law 25, Brazil's LGPD and, where applicable, the GDPR).
§9 — How long we keep it
| Data | Period |
|---|---|
| Account and licence | as long as the account exists |
| Inactive account with no licence in force | deleted after 24 months without access |
| Record of acceptance of the terms (§3.2) | for the applicable limitation period |
| Tax and payment records | 6 years from the end of the fiscal year concerned, as required by law |
| Server technical logs (§3.4) | a short period, for security and diagnosis only |
| Audit log (§3.7) | preserved — see §10.2 |
§10 — Your rights
10.1 You may request: confirmation of processing, access, correction, deletion, portability, objection to processing based on legitimate interest, withdrawal of consent, and information about sharing. Where the law provides for it, you also have the right not to be subject to a solely automated decision and to request review.
Ask at support@voltpilotpower.com. We answer within the statutory time limits and may ask you to confirm your identity — a request to delete someone else's account is exactly what that step prevents.
10.2 An honest limit on deletion. Deleting your account does not erase the audit log: the event is preserved and the actor is pseudonymised. This exists so that a licence revocation or a payment dispute remains verifiable afterwards. We also keep what tax law requires us to keep.
10.3 You may complain to the competent authority — the Commission d'accès à l'information (Québec), the Office of the Privacy Commissioner (Canada), the ANPD (Brazil), or the authority in your country.
§11 — Security
- Communication with the server over HTTPS.
- Passwords stored as an Argon2id hash; rate limiting on login and on activation.
- The licence is cryptographically signed and verified over the bytes received; private keys are kept outside the application repository.
- On Windows, the licence is stored in
%APPDATA%\VoltPilotprotected by DPAPI and tied to your Windows account: copying the folder to another machine, or to another user, does not work. On an operating system that does not offer that mechanism, the licence file is written without operating-system encryption — this concerns the licence token, never your project files, which in no case are sent to us. - If the application cannot verify the authenticity of a licence, it does not open. That is deliberate protection, not a defect.
No system is infallible. In the event of an incident presenting a real risk, we will notify you and the competent authorities within the statutory time limits.
§12 — Minors
VoltPilot is a professional tool, not directed at minors. We do not knowingly collect data from children or adolescents.
§13 — Changes
We will publish new versions of this Policy, always with the version and date in the header. A significant change is communicated by email or inside the application before it takes effect.
§14 — Contact
VoltPilot — business name of the developer and owner of the software, established in Québec, Canada. Postal address provided on legitimate request, through the same channel. Privacy, exercise of rights, and person responsible for personal data: support@voltpilotpower.com.
Version history
| Version | Date | Change | SHA-256 hash |
|---|---|---|---|
1.0-draft |
2026-08-21 | Initial drafting (X11, pending approval) | — (not frozen) |
1.0 |
2026-08-22 | Approved by the owner; draft banner and pending-site notes removed on publication (W08 of voltpilotpower.com) |
— (recorded at publication) |