Privacy Policy
Effective date: 2026-10-11
Who we are
Vonvon is an identity platform operated by Dupuu (“we”, “us”). This policy explains how personal data is handled when you visit vonvon.id, or when you sign in to, create or manage an account through a Vonvon sign-in page.
Vonvon is also used by organizations and applications to sign in their own users. When you sign in to an application or organization that uses Vonvon, that organization decides why and how your data is used and we process it on its behalf. Please also read that organization’s privacy policy.
Information we collect
Depending on how you use Vonvon, we process the following categories of information.
- Account details: email addresses, a phone number if you add one, username, name, display name, profile picture address, language and time zone, and your organization memberships and roles.
- Credentials: a salted Argon2id hash of your password (never the password itself), the public part of your passkeys (the private key never leaves your device), encrypted authenticator app secrets, and hashed backup codes, one-time codes and sign-in links.
- Connected accounts: if you choose to sign in with a social provider such as Google or Apple, we receive the profile details that provider releases to us, such as an identifier, email address, name and picture. Provider tokens are stored encrypted.
- Sessions and devices: for each sign-in we keep your IP address, browser user agent, device name, an approximate location label, sign-in methods used and timestamps, so you can review and end your sessions.
- Security records: an append-only audit log of security-relevant events such as sign-ins, password and factor changes and administrative actions, with the acting account, the target, the time and the IP address.
- Consent records: where an organization asks you to accept terms or marketing preferences, the choice, its time and the IP address it came from.
- Messages: the email, SMS or WhatsApp messages we send to deliver codes, links and invitations.
- Abuse prevention data: counters keyed to IP addresses and accounts used for rate limiting, and the result of Cloudflare Turnstile checks on sign-in forms.
- Usage data on hosted sign-in and account pages: page and event information, browser and device characteristics and an approximate location derived from your IP address, collected through Google Analytics.
- Technical logs: short-lived operational logs from our Cloudflare Workers. We keep credentials, cookies and request bodies out of these logs.
The public Vonvon website at vonvon.id (the home page and this policy) sets no cookies and uses no analytics or advertising trackers. Cloudflare still processes your IP address to deliver the pages.
Cookies and similar technologies
Hosted sign-in and account pages use first-party cookies that are strictly necessary to keep you signed in and to complete multi-step sign-in. Their names begin with __Host-vonvon and they are not readable by other sites. Your language and display preferences are kept in your browser’s local storage.
Those pages also load Google Analytics, which may set its own cookies to measure usage, and Cloudflare Turnstile, which may use browser storage to tell people from bots. You can block or delete these through your browser settings.
How and why we use information
- To provide sign-in, account management and access control (performance of a contract, or our legitimate interest in running the service on behalf of the organization you sign in to).
- To protect accounts and the service against fraud, abuse and attacks, including rate limiting and breach checks (legitimate interests).
- To send service messages such as verification codes, sign-in links and invitations (contract, legitimate interests).
- To measure and improve the hosted pages (legitimate interests, or consent where the law requires it).
- To meet legal obligations and to establish, exercise or defend legal claims (legal obligation, legitimate interests).
Where we rely on consent, you can withdraw it at any time without affecting earlier processing. We do not sell personal data and we do not use it for advertising.
Sharing and service providers
We share personal data only as needed to run Vonvon.
- The organization or application you sign in to, whose administrators can see the account details, memberships, sessions and audit events of their members.
- Cloudflare, which hosts and delivers Vonvon and provides Workers, storage, queues, email sending, bot protection and network security.
- A managed PostgreSQL database provider that stores account and configuration data.
- Google, for analytics on hosted pages and for sign-in if you choose Google, and Apple if you choose to sign in with Apple.
- SMS and WhatsApp delivery providers, such as Twilio or Vonage, only when an organization enables phone codes.
- Have I Been Pwned, which receives only the first five characters of a SHA-1 hash of a password to check it against known breaches.
- An error-monitoring service, which receives technical error reports without request bodies, cookies or user data.
We may also disclose information when the law requires it or to protect rights, safety and security.
International transfers
Vonvon runs on Cloudflare’s global network, so your information may be processed in countries other than your own. Where the law requires it, we rely on safeguards recognised by law, such as standard contractual clauses or an adequacy decision, for transfers out of the European Economic Area, the United Kingdom or Switzerland.
Retention
- Account data is kept while your account is active.
- Session records are removed after the session ends or expires. One-time codes and sign-in links expire within minutes, and expired ones are cleaned up automatically.
- Privacy export files are available for 48 hours and are then deleted.
- When your deletion request completes, we erase your credentials, profile details, memberships and identity links, and keep only a minimal placeholder record of the account.
- The audit log is append-only so that tampering can be detected. Its entries are not rewritten or deleted when an account is erased; they may keep a pseudonymous account identifier and an IP address, and the erased account is shown as deleted.
- Operational logs are kept for a short period, measured in days.
Your rights
Depending on where you live, you may have the right to access, correct, delete and port your personal data, to restrict or object to its processing, to withdraw consent, and to complain to your data protection authority.
Signed-in users can use the account pages to review their sessions, download a copy of their data (a privacy export) and request deletion. A deletion request waits 30 days, during which you can cancel it, and then runs automatically. Deletion is refused while it would leave an organization without an owner or a Vonvon instance without a manager; transfer that role first.
If you use Vonvon through an organization or application, send requests to that organization too, because it decides how your data is used. You can also write to us at hello@dupuu.com and we will respond within the time required by law.
Security
Passwords are hashed with Argon2id and a server-side secret, signing and encryption keys are stored encrypted, traffic is protected with TLS, and each tenant’s data is isolated at the application layer. No system is perfectly secure; if a breach affects your personal data, we will notify you and the authorities as the law requires.
Children
Vonvon is not directed to children under 16, and we do not knowingly collect their personal data. If you believe a child has given us personal data, contact us and we will delete it.
Changes to this policy
We may update this policy. The effective date above shows the latest version, and we will make material changes visible on this page.
Contact
Dupuu operates Vonvon. For privacy questions or requests, email hello@dupuu.com.
