Volucore.

Your privacy at Volucore

Volucore uses Google sign-in, or an email address and password, through Firebase to identify your account. With Google we receive your Google account identifier, verified email address and display name; we do not receive your Google password. With an email address, Firebase stores your password in hashed form and sends the messages that confirm your address or reset your password; we receive your account identifier, confirmed email address and the name you give.

Checks when an account is created

To keep the Free plan to one account per person, a new account is checked once, when it is created: the network address against public lists of VPN, proxy and hosting networks, and the email domain against public lists of temporary email services, including a look-up of the domain’s mail servers. Email sign-ups also pass Cloudflare Turnstile, which checks the browser without tracking cookies. The raw network address is not stored, and these checks do not apply to accounts that already exist.

Account and download records

We store your account status, monthly download usage, export name and format, and security review records. These records allow your allowance to follow you across devices. Model files are generated for delivery and are not stored as a personal library.

Account settings and security activity

In Account settings you can choose the name we use for you. So you can spot anything unusual, we keep a list of sign-ins and security changes on your account (a password change, signing out of every device, a name change) for 180 days: the time, the browser and system (for example “Chrome on Windows”) and the country your connection appears to come from. The network address is not stored in this list. Your password is handled only by Firebase: changing it happens directly between your browser and Firebase, and Volucore never receives it.

Custom artwork

Name Sign, Neon Sign and LED Letters keep uploaded fonts, SVG files and images on your device. When you export, only the outlines needed for your design are sent to the server to generate the file. They are not stored as a project library.

Payments

Paid plans are sold through Paddle.com, our reseller and merchant of record. Paddle processes your payment details, billing address and tax information under its own privacy notice; we never receive your full card number. We store your Paddle customer and subscription identifiers, plan, billing period, renewal date and subscription status so we can apply your plan.

Patreon

If you link a Patreon account (Account settings), you sign in on Patreon itself and approve a read-only link: we never receive your Patreon password, email address or payment details. Patreon tells us your Patreon account number and the state of your membership of our page: whether it is active, the amount you pledge, whether the last charge was paid and when the next one is due. We keep those few facts, the date you linked and the last notice we received, so your plan can follow your membership; we keep no Patreon access token. Patreon sends us notices about your membership while it is linked. Unlinking releases the link from your account (the record stays, without your account, so the same Patreon account cannot be moved between accounts to multiply downloads). Patreon handles your payment under its own privacy notice.

Shared networks

Where the hosting platform provides a verified visitor IP, we use a keyed hash of it to detect additional registrations from the same network. A matching new account can receive a download hold and an administrator alert. Accounts created while network detection was unavailable receive this check once at a later sign-in. We store the check date so normal network changes do not restart a hold. Shared networks can belong to different people; the administrator can release a hold. Network registration records expire after 30 days. Administrators see related accounts, not a raw IP address.

Measuring visits

We use Google Analytics to count visits and see which pages and tools people use. It sets its own cookies and receives your truncated IP address, the page you are on and your browser type. Advertising personalisation and Google signals are switched off, and the administration workspace is excluded. You can block it with any content blocker or your browser’s Do Not Track setting.

Video

The Neon Sign page shows its video tour from YouTube. Nothing is loaded from YouTube until you press Play; then YouTube (Google) provides the player from its privacy-enhanced domain and may set cookies and count the view under its own policy. You can also watch the video directly on YouTube, or skip it.

Sessions and providers

If you are signed in to Google, Google may offer you a one-tap sign-in card on our pages; it appears only while you are signed out of Volucore, and no account is used until you choose one. Essential cookies keep your server session secure. Firebase may store sign-in state in your browser to refresh your session. Google/Firebase processes authentication, and the hosting provider processes requests and stores account records. We do not enable Google Analytics for this sign-in feature.

Control and review

Sign out to end the current session, or sign out of every device from Account settings. For account questions, correction, deletion requests (you can start one from Account settings) or a review of a network hold, contact the administrator at [email protected]. Administrative changes are recorded for accountability.