Privacy Policy
Last updated: 15 September 2026.
This policy explains what data the VR9 Infra service collects, why it collects it, who else processes it, how long it is kept and how you can have it removed. It covers the whole Service, including the data the Service receives from Google APIs when you connect Google Analytics or Search Console. The terms of use are a separate document published on the Terms page.
1. Who operates the Service and how to contact us
Operator. The VR9 Infra service (“Service”) is operated by the VR9 Infra team.
Contact. Write to infra@vr9.pro with any question about this policy, about the data the Service holds about you, or with a request to export or delete that data. This is the address to use for privacy requests, including requests concerning data received from Google APIs. You can write in English or Russian; we answer from the same address.
What the Service is. VR9 Infra is an inventory tool for infrastructure: companies record their servers, sites, services, domains, access records and related events, and the Service monitors availability, ports, TLS certificates and domain registration dates for them. Data belongs to a company, and every user works inside a company they were invited to.
2. Account data
What we store. Your email address, used for sign-in by one-time code, for notifications and for invitations; your interface language; your notification settings; the time of your last sign-in; your role in each company you belong to.
No passwords. The Service has no passwords at all — sign-in is by a one-time code sent to your email. Nothing that could be used as a password is stored.
Consequence. Access to your mailbox means access to the Service. Protecting that mailbox is your responsibility.
3. Data you enter into the Service
Inventory data. Servers, IP addresses, domains, sites, services, tags, events, problems and notes — everything you or your colleagues type into the Service.
People. The email addresses of the people you invite into a company, and the record of who changed what and when.
Access records. An access record stores only a reference to your password manager — a link, an item identifier or a hint — and your notes. The Service is not designed to store passwords, keys or other secrets; anything of that kind put into notes is stored at your own risk.
Your responsibility. By entering data about other people — including the addresses of the people you invite — you confirm that you are entitled to do so.
4. Technical data
Sessions. Your IP address and browser identifier at sign-in and for each active session.
Change log. The author, time and content of every change made inside a company.
Notifications. Browser push subscription data, if you turn push notifications on.
Server logs. Ordinary request and error logs of our servers.
In your browser. Session tokens, the selected language and the selected theme are kept in your browser's local storage. We do not use tracking cookies and we do not run third-party analytics on our own pages.
5. Checks of the infrastructure you add
What the Service checks. For the servers, sites and domains you add, the Service regularly checks availability, the ports you name, TLS certificate validity dates and domain registration dates, and keeps the results and their history.
Where the checks go. To do this, the addresses you enter are sent from our infrastructure to the hosts being checked, to public RDAP registries and to an IP geolocation provider, which returns the country, city and hosting provider for a server IP address.
Your responsibility. By adding a host you confirm that you are entitled to have it checked.
6. Google user data
This is the most detailed section of this policy, because connecting a Google account gives the Service access to data held by Google.
Why the Service asks for access. If you choose to connect Google Analytics or Search Console, VR9 Infra shows daily traffic and search metrics next to the corresponding site in your inventory, so that availability, certificates and traffic are read in one place. Connecting is optional and the rest of the Service works without it. Only a user with the administrator or owner role can connect or disconnect a Google account, and the connection belongs to the company, not to the person.
Scopes we request and why. The Service requests exactly these scopes and nothing else:
https://www.googleapis.com/auth/analytics.readonly— to read the list of Google Analytics 4 properties available to the connected account, so that you can choose which property belongs to which site, and to read daily aggregate metrics for the properties you selected.https://www.googleapis.com/auth/webmasters.readonly— to read the list of Search Console properties available to the connected account, so that you can choose which property belongs to which site, and to read daily aggregate metrics for the properties you selected.openidandemail— to show in the interface which Google account is connected, and to recognise that the same account is already connected so that it cannot be connected twice.
What we store. After you connect an account, the Service stores:
- the refresh token issued by Google, encrypted at rest with AES-256-GCM; the field holding it is excluded from ordinary database queries and is read only by the code that talks to Google;
- the email address of the connected Google account and the list of scopes it granted;
- the permanent identifier of that Google account, issued by Google itself (the
subvalue of its ID token) — it lets the Service recognise that the same account is being connected again, even if its email address has changed, and it is the reason theopenidscope is requested; - the identifiers and display names of the Google Analytics and Search Console properties you selected, and the time zone of each property — the time zone is needed because Google cuts days by it, and without it our chart would not match what you see in Google;
- daily aggregate metrics for each selected property: from Google Analytics 4 — users, new users, sessions, engaged sessions, views and key events; from Search Console — clicks, impressions and average position. One record per property per day.
What we do not collect. The Service requests aggregates by date only. It does not collect and does not store data about the individual visitors of your sites, search queries, landing pages, devices, geography, audiences, cohorts, the user or client identifiers of those visitors, events of individual users, or any content of your site. This is about the people who visit your sites and their identifiers: the identifier of the Google account you connected with is listed above, among the data we store. Nothing beyond the daily totals listed above leaves Google.
Read-only access. Both scopes are read-only. The Service does not create, modify or delete anything in your Google account, in your Analytics properties or in your Search Console properties, and it cannot do so with the access it holds.
How long we keep it. Connecting a Google account is available on the Pro plan. Daily metrics are kept for 365 days on Pro; older records are deleted automatically. If a company moves from Pro to Start, the section closes and, after a short grace period, the history is trimmed to the 30 days kept on Start — so returning to Pro within that period does not cost you the data. The connection record itself — the account address and the list of scopes — is kept while the connection exists.
What we never do with Google data. We do not sell it. We do not transfer or disclose it to third parties, except to the infrastructure providers listed in section 10 that merely host and transmit it on our behalf, and except where disclosure is required by law. We do not use it for advertising, ad targeting, profiling or any purpose unrelated to showing you the metrics of your own sites. We do not use it to train, retrain or improve machine learning or artificial intelligence models, whether ours or anyone else's. Humans do not read it: it is processed automatically, and our staff access it only with your explicit permission, when it is necessary for security or abuse investigation, or when the law requires it.
7. Limited Use disclosure
VR9 Infra's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
8. Revoking Google access and deleting Google data
Disconnect in the Service. In the main menu open the Monitoring section and go to Connections, then disconnect the Google account. The Service sends a revocation request to Google for the refresh token, then deletes the encrypted token from our database and stops all data collection for that account. Both steps happen in that order, so the entry does not stay in the list of third-party access in your Google account.
Revoke on Google's side. You can also remove access at any time on the Third-party apps and services page of your Google account. Access stops immediately; the next time the Service tries to refresh data it receives a refusal from Google, deletes the stored token and marks the connection as needing reconnection.
What happens to metrics already collected. The daily aggregates already collected stay in your company: they are your record of your own sites, and losing a year of history because an account was reconnected would be the wrong default. Collection stops, the charts simply end on the last day collected, and the remaining records are still deleted on the retention schedule of your plan.
Deleting them earlier. If you want the collected metrics removed before that, you do not have to ask us: a user with the administrator or owner role can delete them in the Service. On the Connections page open Match sites, unlink the resource from its site, then choose Release next to it — the collected history of that resource is deleted permanently and the resource becomes free to link again. Deleting the company removes all collected metrics along with the rest of its data. For anything these do not cover, write to infra@vr9.pro from the address of an account in the company and name the company and the sites; we delete the data and confirm when it is done.
9. Payments
Who processes payments. Payments are processed by Dodo Payments as merchant of record.
Card details. We do not receive and do not store card details. We keep the plan, the period, the subscription status and the payment provider's identifiers.
10. Who processes your data
Processors. Our hosting provider; the email delivery service; the payment provider; Google, for connected Google accounts; the IP geolocation provider used for server addresses; and the push service of your browser vendor for push notifications.
Where the data is. Servers may be located outside your country, and by using the Service you agree to such transfer.
What we use the data for. To run the Service, to support you, to prevent abuse, and to improve the Service in aggregate form. We do not sell personal data and do not disclose it to third parties beyond what is described in this policy or required by law.
11. How long we keep data and how it is deleted
While the account exists. Data is kept for as long as your account and your company exist.
Automatic expiry. One-time codes, sessions and invitations expire automatically. Check history and site metrics are kept within the periods set by the Service and your plan.
Deleting a company. Deleting a company — available to its owner — irrevocably removes its data. We keep only the record that the deletion happened and technical logs; backups are cleared within our backup rotation period.
Deleting your account. Write to infra@vr9.pro from the address the account uses. If you own a company, transfer ownership or delete the company first, otherwise its data would be left without an owner.
12. Security
Measures. Encryption in transit; encryption of integration secrets at rest; role-based access inside a company; every request scoped to a single company, so that one company's data cannot be read from another.
Limits. No method of storage or transmission is completely secure, and we do not claim otherwise.
Your part. You are responsible for whom you invite into your company and for the security of your email account, since access to it means access to the Service.
13. Your choices and requests
Access, correction, export, deletion. Write to infra@vr9.pro from the address your account uses and say what you need. We answer every request; if we cannot satisfy one — for example, because the data belongs to a company you do not own — we say so and explain why.
Notifications. Email and push notifications are turned on and off in your profile settings. Messages required to operate the account, such as sign-in codes, are not marketing and cannot be turned off.
Connected accounts. Connecting Google is optional, and disconnecting is described in section 8.
14. Changes to this policy
How changes are published. The updated text is published on this page and the date at the top changes. Continued use of the Service after publication means you accept the updated policy.
Substantial changes. If a change materially expands what we collect or what we do with it, we also notify the account owners by email before it takes effect.
Questions. infra@vr9.pro.