VORKO
LEGAL

VORKO — Privacy Policy

Effective date: 20 September 2026Document version: 4Applies to: the VORKO application and the backend services that support it, including the iOS version distributed through the Apple App Store and TestFlight.

This Privacy Policy explains what information the VORKO application ("VORKO", "the app", "we", "us") collects, why we collect it, who we share it with, how long we keep it, and the rights you have over it. VORKO is a business-to-business (B2B) application for participants in foreign-trade and cross-border logistics (importers, exporters, customs brokers, carriers and laboratories). It is not directed to consumers or to children.

If you do not agree with this Policy, do not use the app.


1. Who is responsible for your data

The app is published and operated by Норицын Никита Игоревич, an individual developer located in the Russian Federation ("the operator", "we", "us"). For privacy questions, data-access requests, account deletion and complaints, contact us at the address in Section 14 (Contact).

The app relies on Telegram as its underlying messaging transport. When you sign in with your Telegram account and exchange messages, that activity is also governed by Telegram's own Privacy Policy (https://telegram.org/privacy). Telegram is an independent service that you use through the app; we do not control it.


2. What we collect

We collect only what is needed to operate your company workspace. We do not run advertising, we do not use third-party analytics or tracking SDKs, and we do not collect an advertising identifier (IDFA). We do not ask you for the App Tracking Transparency permission because we do not track you across other companies' apps or websites.

Data categoryExamplesWhyStored on VORKO servers?
Account & identityTelegram user ID and the phone number tied to your Telegram account; operator-issued access key; company identifier; roleSign-in and access controlYes (identifiers, role)
User contentMessages, photos and files exchanged in work chats; questions, history and optional images sent to VORKO Assistant; with separate consent, text and events from selected private chats for Employee ControlCommunication, assistant answers and optional analysis of work communicationTravels via Telegram; Ask VA journal entries, deal metadata and Employee Control data are kept on our servers within the limits below
Optional contactsNames and phone numbers from your address bookFind which contacts use Telegram (opt-in only)No — passed to Telegram, not stored by VORKO
Trade & settlement recordsDeal amounts, reservation/settlement status, invoices, receipts, transaction historyCoordinate deals, documents and transaction historyYes
DocumentsInvoices, receipts and files you attach to dealsDeal record-keepingYes
Device & technicalApp version, OS version, language, connection/delivery logs, push device tokenDeliver the service and notificationsYes (logs, token)
Authentication and connected channelsSign-in token and personal Telegram session key; credentials for company-connected channelsKeep you signed in and operate connected channelsThe sign-in token is stored on the device and sent to VORKO servers to authorize requests; the server also stores active-session information. On iOS, Keychain is used to protect the sign-in token. The personal Telegram session is maintained on the device; its secret keys are not uploaded to VORKO servers. Company-channel credentials are processed on the server as described below

2.1 Account and identity data

Your Telegram account information used to sign in (your Telegram user ID and the phone number associated with your Telegram account; the Telegram login happens on your device), the access key issued to you by your company operator, your company identifier, and your role.

2.2 Messages and shared content

Messages, photos, files and other content you send or receive in work chats travel through Telegram's infrastructure and are subject to Telegram's Privacy Policy. VORKO servers process the business metadata of your deals (for example which deal a message belongs to) so that the right people in your company see the right information.

Employee Control is a separate optional service for company employees. It is activated for a particular employee only after that employee gives explicit consent, and applies only to private chats that the employee has allowed the company bot to access in Telegram settings. Within that scope VORKO receives message text, direction (incoming or outgoing), time, message edit or deletion events, and attachment type. This subsystem does not download the contents of photos, videos, documents or other attachments.

Allowed text and events are sent to VORKO servers and retained in raw form for no more than 30 days. To produce the daily assessment, they are sent to the configured artificial-intelligence provider in an envelope where direct company, employee and chat identifiers are replaced with pseudonyms. The message text itself may nevertheless contain names, contact details or other personal information entered by conversation participants.

The company owner and appointed company manager receive only the resulting report: scores, findings and recommendations. The Employee Control interface does not give them raw message text or direct access to the employee's chats.

2.3 Contacts (only if you turn it on)

Uploading your address book to Telegram is off by default. Only if you explicitly enable contact synchronisation and grant the iOS Contacts permission do we pass the names and phone numbers from your address book to Telegram so it can find which of your contacts already use Telegram. This includes information about other people who are not VORKO users. VORKO does not store your address book on its own servers. You can turn this off at any time, and you can revoke the Contacts permission in iOS Settings.

2.4 Trade and settlement records

The app displays deal financial information and documents — deal amounts, reservation/settlement status, invoices, receipts and history — for coordination and reference. At some deal stages, the app lets you prepare and send payment information to the other deal participant and attach a receipt; this transfers deal documents and updates deal status rather than making a bank transfer. An importer company owner can reallocate an internal balance between its balance sections and pay the subscription from that internal balance. The app does not request or store bank-card numbers and does not execute bank transfers. Payments for real goods and services take place outside the app through ordinary banking channels.

2.5 Device and technical data

Technical information needed to deliver the service (app version, OS version, language, connection/delivery logs, and a push-notification device token if you allow notifications, used only to deliver app notifications). The sign-in token is stored on the device and sent to VORKO servers to authorize requests; the server also stores active-session information. On iOS, Keychain is used to protect the sign-in token. The personal Telegram session is maintained on the device; its secret keys are not uploaded to VORKO servers.

2.6 Device permissions

The app asks for these iOS permissions only when you use the related feature, and each can be revoked in iOS Settings:

  • Camera — to take photos for chats and documents.
  • Microphone — to record voice messages.
  • Photos — to attach images and to save received images.
  • Contacts — only for the optional contact synchronisation described in Section 2.3 (off by default).
  • Notifications — to alert you about deals, messages and approvals.

2.7 VORKO Assistant (Ask VA)

When you ask VORKO Assistant a question, VORKO processes the question text, the history you send for that conversation, and any images you attach. The server retrieves facts available to you about your company, requests, deals, purchases, files and CRM, and may fetch a linked page or perform a web search when the question calls for it. The question, the selected facts needed for the answer and optional images are sent to the configured external artificial-intelligence provider to generate the answer. The current server route uses OpenRouter for the relevant provider profile; the actual route is selected by server configuration and may change.

Ask VA questions, answers and answer sources are stored on VORKO servers in a conversation journal, including failed exchanges. History is stored on the servers; the current version does not automatically delete it after a fixed period. To request access, correction or deletion, contact support; records needed for company operations, security, disputes or legal obligations may be retained longer.

Ask VA is a separate processing path and does not require Employee Control opt-in. When a question concerns CRM, the assistant may show the current CRM configuration and prepare a change plan. The plan changes nothing by itself: a change is made only after the user reviews it and taps Apply.

2.8 Company-connected channels

The personal Telegram session is maintained on the device; its secret keys are not uploaded to VORKO servers. On iOS, Keychain is used to protect the sign-in token. This does not describe a company's connected WhatsApp companion. A company owner starts a QR link or pairing-code link for the shared number; the server maintains a separate linked-device session, while the QR or code exists only during linking and expires. That session state and transport data are kept in the service's encrypted local storage. Through this channel VORKO processes company messages, statuses, reactions, history and attachments within the service limits. This is company data, not the user's personal Telegram session.


3. Why we use your data (purposes)

We use the data above to: create and maintain your company workspace and your access to it; deliver, route and synchronise messages and deal events to the correct participants; show your trade and settlement records and keep them consistent across the people in your company; answer questions through Ask VA from the data available to you, keep a journal of those exchanges and prepare CRM change plans; with separate consent, perform a daily analysis of allowed work communication and generate scores and recommendations; send you notifications about events that concern you; keep the service secure, prevent abuse, and comply with law.

We do not sell your data, we do not use it for advertising, and we do not profile you for marketing.


4. Who we share data with

We share data only as needed to run the service:

  • Telegram — the app's messaging runs on Telegram's infrastructure, so your messages, shared content and (if you enable it) your synchronised contacts are processed by Telegram under Telegram's Privacy Policy.
  • VORKO backend servers — operated for the service and located in Israel (primary) and the Netherlands (standby). Your workspace and deal data are processed on these servers.
  • The configured artificial-intelligence provider — for Ask VA, it receives the question, supplied history, optional images and selected available company, deal and CRM facts; for Employee Control, it receives allowed text in a pseudonymised envelope to generate analysis and recommendations. The current server source uses OpenRouter for the relevant route; we do not promise a particular model, processing geography or provider training policy.
  • Your company owner and appointed company manager — in Employee Control they receive only the derived report; raw messages are not disclosed to them through this feature.
  • When required by law — we may disclose data if compelled by a valid legal request, or to protect the rights, safety and property of users or the operator.

Where we use service providers to process data for VORKO, we require them by contract or applicable law to protect personal data at least as described in this Policy and to use it only for the purposes described here. We do not share your data with advertising networks, data brokers, or analytics companies.


5. International transfers

VORKO serves companies in several countries, and our servers are located outside your country of residence (Israel and the Netherlands). By using the app you understand that your data is processed on those servers. Where the GDPR applies to you, transfers outside the EU/EEA rely on appropriate safeguards (such as the European Commission's Standard Contractual Clauses or an adequacy decision where available), and we limit processing to what is necessary to provide the service.


6. How long we keep data, and deletion

We keep data only as long as needed for the purposes above:

DataRetention
Account / access recordsWhile your account is active; active sessions and access may be revoked. Company business data is not automatically deleted merely because access is revoked and may be retained for operational, dispute or legal reasons.
Trade records, invoices, receipts, deal history, audit logsWhile the company workspace is active, and up to 7 years where needed for tax, accounting, dispute or legal obligations.
Technical logsNormally up to 90 days, unless needed to investigate abuse, a security incident or a legal request.
Push tokens and active sessionsUntil you disable notifications, log out, or delete your account.
ContactsNot stored on VORKO servers; if you opt in, contact data is passed to Telegram and retained under Telegram's rules.
Raw Employee Control text and eventsNo more than 30 days after receipt. Withdrawal of consent immediately stops new collection; raw events already received are deleted under this limit.
Employee Control reports, consent and chat-scope settings, audit logWhile the relevant company workspace remains active and the data is needed to provide the service, resolve disputes, maintain security or meet legal obligations; afterwards it is deleted or anonymised.
Ask VA journalHistory is stored on the servers; the current version does not automatically delete it after a fixed period. To request access, correction or deletion, contact support; operational, dispute and legally required records may be retained longer.

To request access to, correction of, or deletion of your data, contact us (Section 14). Revoking or closing access revokes active sessions but does not mean that all Ask VA journals, company business records or records required by law are physically deleted automatically. Messages already delivered through Telegram are governed by Telegram's own retention rules, which we do not control.


7. Content rules and reporting abuse (zero tolerance)

VORKO contains chats in which users communicate. We have zero tolerance for objectionable, abusive, illegal or infringing content and for abusive behaviour. Such content and behaviour are prohibited by our Terms of Use and may result in removal of content and termination of access.

In the app you can report a message, a chat or a user that violates the rules, and block or mute another user. We review reports and act on violations, and we aim to acknowledge a report within 24 hours and to act on confirmed violations within 48 hours. To report abuse or objectionable content, use the in-app report action or write to the complaints address in Section 14.

We cannot pre-screen messages that arrive from the underlying Telegram network before they reach you; where technically available for content posted through VORKO, we may apply automated or manual filters, rate limits, attachment restrictions or sensitive-content warnings. We always provide reporting, blocking and a published contact so that abuse can be acted on.


8. Security

The sign-in token is sent to VORKO servers to authorize requests; the server stores active-session information. On iOS, Keychain is used to protect the sign-in token. The personal Telegram session is maintained on the device; its secret keys are not uploaded to VORKO servers. Traffic between the app and our services is protected with standard transport encryption (TLS), and messaging uses Telegram's encrypted protocol. No method of transmission or storage is perfectly secure, but we take reasonable measures to protect your data.


9. No tracking, no advertising

VORKO does not include advertising, third-party analytics, crash-reporting SDKs, or any cross-app/cross-site tracking. We do not use the advertising identifier. Our App Privacy information in the App Store reflects this.


10. Children

VORKO is a B2B tool for trade professionals and is not directed to children. We do not knowingly collect data from children. If you believe a child has provided us data, contact us and we will delete it.


11. Your rights (including GDPR)

Depending on where you live (for example under the GDPR in the EU/EEA), you may have the right to access, correct, delete, restrict or object to the processing of your personal data, and to data portability. Where the GDPR applies, we process data to perform our contract with you, for our legitimate interests in operating and securing the service, to comply with legal obligations, and with your consent where required. Optional Contacts access and participation in Employee Control rely on separate active consent that you can withdraw at any time; withdrawing from Employee Control stops new message collection. A company that uses employee reports is independently responsible for providing any required workplace notice and complying with applicable employment and other rules. To exercise your rights, turn off Employee Control on the Control screen where that setting is available, or contact us (Section 14). We will consider Ask VA journal and company-record requests in light of operational, dispute and legal obligations. You also have the right to lodge a complaint with your local data-protection authority.


12. United States privacy (CCPA/CPRA)

We do not sell personal information and do not share it for cross-context behavioural advertising. California residents may request access, correction or deletion using the contact details below; we will not discriminate against you for exercising these rights.


13. Changes to this Policy

We may update this Policy. When we make a material change we will update the "Effective date" and the "Document version" above, and the app will ask you to review and accept the updated Policy before you continue to use it.


14. Contact

This Policy is published at https://v2.vorko.io/legal/privacy.