VoltOS Privacy Policy

Version 1.1
Effective date: 6 September 2026

  1. Who operates VoltOS

VoltOS is a mobile application for Android and iOS operated by IVI PRO DEVELOPMENT EOOD (ИВИ ПРО ДЕВЕЛОПМЕНТ ЕООД).

Company registration details:

UIC: 208696622

Registered office: 29 Exarch Yosif St., Oborishte District, Floor 1, Apt. 1, Sofia 1000, Bulgaria

Privacy and data requests:

Email: dev@iviprodevelopment.com

Phone: +359 88 911 1035

Public location: Sofia, Bulgaria

  1. Scope

This policy applies to the VoltOS Android and iOS applications and the backend services used by those applications. VoltOS does not currently have a separate public web product.

VoltOS currently supports these interface languages: Bulgarian, English, Spanish, German, French, Italian, Dutch, and Greek.

The selected interface language controls only the language of the user interface. It does not select or change a Site’s country or energy market.

  1. Information processed by VoltOS

Depending on which features a user chooses to use, VoltOS may process the following categories of information.

3.1 Account and authentication information

  • email address;
  • full name;
  • account status and verification status;
  • password hash — VoltOS does not store the account password in plaintext;
  • access and refresh-token data used to maintain authenticated sessions;
  • password-reset token hashes, expiry, usage status, and related timestamps;
  • account creation and update timestamps.

Password-reset responses are designed not to reveal whether an account exists for a particular email address.

Raw refresh tokens and password-reset tokens are not stored in the database.

3.2 Organisation information

  • organisation name and account type;
  • organisation membership and role;
  • the user who created the organisation;
  • creation and update timestamps.

Organisation data may be shared with other authorised members of the same organisation.

Deleting one user’s account does not automatically delete shared organisation data that belongs to or remains necessary for other members.

3.3 Site information

  • Site name and type;
  • address line, city, postal code, and country code;
  • energy-market code and time zone;
  • active status and timestamps.

The Site country and energy market are separate from the user’s selected interface language.

3.4 Meter and energy information

  • meter name, type, source, unit, and status;
  • external provider name and external meter identifier, where applicable;
  • manual cumulative readings, reading time, unit, and source;
  • interval start and end times;
  • energy consumption;
  • estimated cost and currency;
  • tariff name, country, currency, price per kWh, scope, validity period, and active status;
  • record creation and update timestamps.

3.5 Optical character recognition-assisted meter capture

Users may submit a JPEG or PNG meter image to obtain a suggested reading.

VoltOS processes the image with its backend-hosted Tesseract optical character recognition engine.

The result is a capture aid only: the reading is not saved automatically and requires explicit user confirmation through the reading flow.

The current backend processes the uploaded image for the request and does not define a database table for storing the original image.

3.6 Comma-separated values file preview and import

Users may submit a comma-separated values file containing interval consumption data.

VoltOS first parses and validates the file and presents a preview.

Import requires a separate, explicit confirmation.

The current backend processes the original file data for preview and confirmation and does not define a database table for storing the original file.

After successful confirmation, validated interval readings and their calculated energy data may be stored.

3.7 Energy-data providers and consent

Where available for the selected energy market and chosen meter, a user may connect an external energy-data provider.

VoltOS uses a provider-neutral architecture and does not select a provider solely from the interface language.

Provider consent records may contain:

  • the meter reference;
  • provider identifier;
  • external meter identifier;
  • consent status, such as pending, active, rejected, revoked, or expired;
  • provider consent or session reference where required;
  • grant, expiry, revocation, creation, and update timestamps.

Provider credentials for the application programming interface are backend secrets and are not returned to the mobile application.

Consent may be withdrawn through the implemented backend flow where the selected provider supports withdrawal.

No external energy-data provider is currently enabled to retrieve or process real VoltOS user data.

The only implemented external adapter is restricted to n3rgy test-environment endpoints and is used only for staging and testing with test identifiers.

It requires explicit provider consent before energy-data retrieval, and no live provider endpoint is implemented.

Before any external provider is enabled for production use, this Privacy Policy will be updated with the provider’s identity, the data categories processed, consent and withdrawal arrangements, retention, processing locations, subprocessors, and applicable international-transfer safeguards.

3.8 Google Play billing and subscription information

For Android subscriptions purchased through Google Play, VoltOS may process information necessary to verify, attribute, and maintain subscription entitlements.

This may include:

  • Google Play product and base-plan identifiers;
  • purchase token fingerprints or encrypted purchase-token data;
  • purchase and subscription status;
  • renewal, cancellation, expiration, grace-period, account-hold, pause, revocation, or similar lifecycle status;
  • acknowledgement status;
  • subscription start and expiry information;
  • purchase history information made available through Google Play for subscription verification;
  • the VoltOS user and organisation to which a verified purchase is attributed;
  • timestamps and technical records required for duplicate prevention, reconciliation, fraud prevention, and entitlement enforcement.

Google Play purchase responses are treated as authoritative for Google Play subscription verification.

VoltOS does not store payment-card details.

Payment processing for Android subscriptions is performed by Google Play under Google’s own terms and privacy arrangements.

3.9 Trial access and abuse-prevention information

VoltOS may provide a limited Pro trial managed by the VoltOS backend.

New eligible trials are currently intended to last 7 days.

Existing trials that were granted under an earlier duration may retain their originally stored end date.

VoltOS does not use Google Play free-trial offers for this backend-managed trial.

To prevent repeated trial abuse, VoltOS may process limited account, device, application-integrity, and technical information.

This may include:

  • whether a user account has previously consumed trial eligibility;
  • pseudonymous device or application fingerprints derived using cryptographic hashing or keyed HMAC;
  • device-integrity and application-integrity classifications returned by Google Play Integrity;
  • package and application recognition status;
  • limited anti-replay and request-validation information;
  • timestamps associated with prior trial claims;
  • technical risk indicators used to detect repeated or automated abuse.

VoltOS does not intentionally store raw Android device identifiers such as ANDROID_ID for this purpose.

Where a device signal is used, VoltOS is designed to derive a cryptographic representation and discard the raw value.

VoltOS does not use IMEI, device serial number, MAC address, or advertising identifier as a primary permanent trial identity.

A pseudonymous trial-device claim may be retained after account or organisation deletion where reasonably necessary to prevent repeated abuse of trial eligibility.

Internet Protocol addresses may be used as an additional security or abuse-prevention signal, but an Internet Protocol address is not intended to be the sole basis for denying trial eligibility because multiple legitimate users may share the same address through shared Wi-Fi, mobile networks, carrier-grade network address translation, dynamic addressing, or virtual private networks.

3.10 Advertising and consent information

During an active VoltOS backend-managed Pro trial, the Android application may display advertising through Google AdMob / Google Mobile Ads.

Active paid Starter, Pro, and Business subscriptions are intended to remove these trial advertisements.

VoltOS may use Google’s User Messaging Platform and consent-management tools to request, record, and respect advertising privacy choices where required.

Depending on the user’s region, consent choices, device configuration, and applicable law, Google Mobile Ads may process or receive information such as:

  • Internet Protocol address;
  • approximate location derived from Internet Protocol address;
  • application interactions;
  • advertising-related interaction information;
  • diagnostic and performance information;
  • device or other identifiers;
  • consent status and privacy choices;
  • information used for advertising, analytics, fraud prevention, security, and compliance.

VoltOS does not intentionally provide precise GPS location to Google Mobile Ads for advertising.

Where required, users may be offered choices including consent, refusal of consent, and management of privacy options.

If advertising consent is unavailable, refused, or cannot be obtained where required, VoltOS is designed to continue providing the applicable service without making advertising consent a condition for access to a core contractual feature.

The availability and type of advertising may depend on the user’s consent status, applicable law, Google’s advertising rules, and technical availability.

  1. Why information is processed

VoltOS processes information to provide the features selected by the user, including:

  • registration, authentication, session management, and password reset;
  • organisation, Site, and Meter management;
  • manual readings and energy interval generation;
  • optical character recognition-assisted capture;
  • comma-separated values file validation, preview, and import;
  • tariff-backed cost estimates;
  • energy dashboards and summaries;
  • provider connection, consent status, and consent withdrawal;
  • Google Play subscription verification and entitlement management;
  • trial eligibility and abuse prevention;
  • advertising during eligible trial access;
  • advertising consent and privacy-choice management;
  • account deletion, security, troubleshooting, and support.

VoltOS relies on the following legal bases under Article 6 of the General Data Protection Regulation:

  • performance of a contract or steps requested before entering into a contract, under Article 6(1)(b), for registration, authentication, session management, password reset, account and organisation administration, Site and Meter management, manual readings, energy interval generation, optical character recognition-assisted capture, file validation and import, tariff-backed estimates, energy dashboards and summaries, Google Play subscription verification, entitlement management, and account deletion, where this processing is necessary to provide the user-requested VoltOS service;
  • consent, under Article 6(1)(a), where a user voluntarily authorises VoltOS or an external energy-data provider to establish a provider connection or access provider-supplied data, or where consent is required for advertising or related processing. Consent may be withdrawn at any time, without affecting processing carried out lawfully before withdrawal;
  • legitimate interests, under Article 6(1)(f), for maintaining service and information security, preventing misuse and repeated trial abuse, detecting fraud, diagnosing technical faults, troubleshooting, protecting legal claims, maintaining the integrity of subscription entitlements, and improving the reliability of the Service, provided those interests are not overridden by the user’s interests or fundamental rights and freedoms;
  • performance of a contract and, where appropriate, legitimate interests for responding to support requests and administering the relationship with the user;
  • compliance with a legal obligation, under Article 6(1)(c), only where processing is required by an applicable obligation under European Union or national law.

VoltOS will not rely on consent where the processing is necessary to provide a core contractual feature and the user cannot genuinely refuse or withdraw consent.

Where legitimate interests are relied upon, VoltOS will assess the purpose, necessity, and impact on the rights and freedoms of affected individuals.

  1. Hosting and service providers

5.1 Render hosting

Render Services, Inc. hosts the VoltOS production application programming interface and PostgreSQL database.

The production application programming interface and production database are both hosted in Render’s Oregon, United States region.

Render may process customer data on behalf of IVI PRO DEVELOPMENT EOOD and may process its own account and service-usage data under its applicable terms.

Render publishes a Data Processing Addendum and a list of authorised subprocessors.

Render’s published Data Processing Addendum describes the EU–US Data Privacy Framework and Standard Contractual Clauses as applicable international-transfer safeguards.

Under Render’s Data Processing Addendum, Render acts as a processor when it processes VoltOS customer personal data on behalf of and according to the instructions of IVI PRO DEVELOPMENT EOOD.

Render acts as an independent controller for its own account and service-usage data, including data used for customer-relationship administration, billing and compliance, identity verification, security and fraud prevention, and service maintenance and optimisation.

Render publishes its authorised subprocessors and updates that list under the procedure in its Data Processing Addendum.

For transfers from the European Economic Area to the United States, Render’s Data Processing Addendum provides for the EU–US Data Privacy Framework where applicable and otherwise incorporates the European Commission’s Standard Contractual Clauses.

The applicable Standard Contractual Clauses module depends on whether Render acts as processor or independent controller.

The Data Processing Addendum also includes the United Kingdom Addendum and corresponding safeguards for transfers covered by United Kingdom or Swiss data protection law.

5.2 Email delivery

VoltOS uses Brevo to deliver transactional emails, including password-reset messages.

Production delivery uses Brevo’s mail-transfer relay service.

Brevo transactional logs are retained for one month and are then deleted automatically.

Transactional email previews are never stored.

Brevo acts as a data processor for transactional email delivery on behalf of IVI PRO DEVELOPMENT EOOD.

Brevo states that its databases are processed and stored within the European Union, using hosting infrastructure in France, Germany, and Belgium.

Its mail-transfer relays do not store message data and forward it to Brevo’s European data centres.

Brevo’s Data Processing Agreement, incorporated into its Terms of Service, governs its subprocessors and applicable safeguards for international data transfers.

5.3 Google Play billing and Play Integrity

VoltOS uses Google Play services for Android subscription purchases, subscription verification, entitlement lifecycle information, and application/device-integrity verification where enabled.

Google Play may process payment, account, device, application, purchase, subscription, and security information under Google’s own terms and privacy arrangements.

VoltOS may receive limited subscription and integrity information from Google where necessary to:

  • verify purchases;
  • determine subscription entitlement;
  • process renewal, cancellation, expiration, grace-period, account-hold, pause, or revocation status;
  • prevent replay, duplicate attribution, fraud, and trial abuse;
  • confirm that the application is recognised by Google Play;
  • assess application and device integrity.

VoltOS does not receive or store a user’s complete payment-card details from Google Play.

5.4 Google AdMob, Google Mobile Ads, and consent management

VoltOS may use Google AdMob / Google Mobile Ads to display advertising during eligible trial access.

Google’s advertising services may process information such as Internet Protocol address, approximate location derived from Internet Protocol address, application interactions, diagnostic information, and device or other identifiers.

These data may be processed for purposes including:

  • advertising or marketing;
  • analytics;
  • fraud prevention;
  • security;
  • compliance;
  • measurement and delivery of advertising.

Where required by applicable law or Google policy, VoltOS uses Google’s consent-management tools, including the User Messaging Platform, to present privacy choices before eligible advertising requests are made.

Users may be able to consent, refuse consent, or manage advertising privacy options depending on region and applicable requirements.

VoltOS is designed so that a failure to obtain advertising consent does not prevent access to core VoltOS functionality that is otherwise available to the user.

5.5 Services not currently used

VoltOS does not currently use an external crash-reporting service, external artificial-intelligence service, or external optical-character-recognition service.

VoltOS may use Google Mobile Ads and Google Play services as described in this policy.

This Privacy Policy will be updated before other material third-party processing services are enabled.

  1. Application logs

The VoltOS production application programming interface uses Render application logs for operation, monitoring, security, and troubleshooting.

The visible application logs contain:

  • timestamps and log level;
  • request or internal Internet Protocol address and port values;
  • Hypertext Transfer Protocol method, path, and protocol version;
  • Hypertext Transfer Protocol response status.

The production Render workspace is on the Hobby plan.

Under Render’s current documented policy, application logs for this plan are retained for 7 days.

No external third-party log-stream destination is currently configured at workspace level, and preview-instance log forwarding is not enabled.

Separately from application logs, Render processes service metrics and other service-usage metadata.

Render describes this information as including service activity, communication source and destination information, performance and maintenance data, and data used to investigate or prevent misuse.

Documented service metrics for the current Hobby workspace are retained for 7 days.

Render acts as a processor for customer personal data hosted on behalf of IVI PRO DEVELOPMENT EOOD and as an independent controller for its own account and service-usage data.

Render does not publish a fixed retention period for all such service-usage or device and Internet Protocol address metadata.

Its Privacy Policy states that this information is retained according to operational, business, security, and legal needs.

  1. Database recovery and tested backup procedure

The production database, voltos-db, uses Render PostgreSQL Basic-256mb.

Confirmed current recovery capabilities:

  • recovery to a selected point in time is available with a 3-day recovery window;
  • Render database export is available;
  • on 24 July 2026, a production database backup was successfully exported and successfully restored into the separate staging database;
  • after the restore test, the restored production data was removed from staging.

A manual production database export will normally be created once per month.

A restore test will normally be performed at least once every three months using an isolated non-production environment.

Downloaded export files may be stored only in company-controlled encrypted storage and may be accessed only by authorised personnel for backup verification, recovery, or security purposes.

Export files must not be sent through ordinary unencrypted email or stored in publicly accessible locations.

Each downloaded export file will be securely deleted after the relevant restore test is completed, or no later than 30 days after its creation, whichever occurs first.

Temporary restored production data must be removed from the test environment immediately after the restore test is completed.

These operational intervals may be reviewed and strengthened as VoltOS usage, risk, and infrastructure requirements develop.

  1. Data retention

Confirmed retention rules:

  • Render application logs: 7 days under the current Hobby workspace plan;
  • Render PostgreSQL recovery to a selected point in time: 3-day recovery window.

Unless a longer period is required by law or necessary for the establishment, exercise, or defence of legal claims, VoltOS applies the following retention criteria:

  • account and profile data are retained while the account remains active and are normally deleted or anonymised within 30 days after a valid account-deletion request is completed;
  • organisation, Site, Meter, energy-reading, and tariff data are retained while the relevant account, organisation, or Site remains active. After deletion or termination, data linked exclusively to the departing user is normally deleted or anonymised within 30 days. Shared organisation data may be retained where required for remaining authorised members;
  • active authentication sessions and access or refresh codes are retained only until expiry or revocation;
  • password-reset records are retained until they expire or are used and are then deleted during routine cleanup, normally within 30 days;
  • external-provider consent and withdrawal records are retained while the relevant connection is active and for up to three years after withdrawal or termination where reasonably necessary to demonstrate the consent history and related actions;
  • Google Play subscription-verification and entitlement records may be retained while required to administer an active or historical subscription, prevent duplicate attribution or fraud, resolve billing disputes, meet accounting or legal obligations, or establish, exercise, or defend legal claims;
  • trial-eligibility consumption records and pseudonymous device-claim records may be retained after account deletion where reasonably necessary to prevent repeated abuse of trial access. Raw device identifiers are not intended to be retained for this purpose;
  • advertising consent and privacy-choice information may be retained for as long as required to respect the user’s choices, demonstrate compliance, or meet applicable platform and legal requirements;
  • support and privacy-request records are normally retained for up to 24 months after the request is closed, unless a longer period is required for a dispute, legal obligation, or security investigation;
  • Render application logs are retained for 7 days under the current workspace configuration;
  • data within Render PostgreSQL recovery remains recoverable within the current 3-day recovery window;
  • manually downloaded database export files are governed by the separate procedure in Section 7 and are deleted after the relevant restore test or no later than 30 days after creation, whichever occurs first.

Deletion from active systems may not immediately remove data from an already-created recovery copy or export.

Such data will cease to be recoverable when the applicable recovery or export-retention period expires and will not be restored except for legitimate disaster-recovery or security purposes.

Retention periods and criteria will be reviewed when features, legal obligations, risks, or infrastructure arrangements change.

  1. Account deletion and privacy requests

Authenticated users can request irreversible account deletion in VoltOS and must confirm their current password and the irreversible action.

The backend revokes session codes, handles organisation ownership safely, preserves shared organisation data where required for other members, and attempts to withdraw active external meter consents associated with organisations that will be deleted.

Deletion may be blocked when organisation ownership must first be transferred or when required consent withdrawal fails.

Certain limited anti-abuse, billing, fraud-prevention, accounting, legal, or security records may be retained after account deletion where necessary and lawful.

Such retained records are intended to be limited to the minimum information reasonably necessary for the applicable purpose.

Users may also contact dev@iviprodevelopment.com about account deletion or other privacy and data requests.

For identity verification:

  • requests should preferably be sent from the email address associated with the VoltOS account;
  • reasonable additional identifying information may be requested where necessary;
  • VoltOS support will not request passwords, password-reset codes, access codes, refresh codes, keys for an application programming interface, or provider credentials.

Users may submit privacy requests, including requests for access, correction, deletion, restriction, objection, or data portability where applicable, by emailing dev@iviprodevelopment.com.

Requests should preferably be sent from the email address associated with the VoltOS account.

We will respond without undue delay and normally within one month after receiving the request.

Where a request is complex or multiple requests are received, this period may be extended by up to two additional months as permitted by applicable law.

We will inform the requester of any extension and the reasons for it within the initial one-month period.

We may request reasonable additional information when necessary to verify the requester’s identity.

VoltOS support will never request passwords, password-reset codes, access codes, refresh codes, keys for an application programming interface, or provider credentials.

VoltOS does not currently provide a general self-service data-export feature.

A user may request a copy of applicable personal data by email.

After identity verification, the available data will be prepared in a commonly used structured electronic format and delivered using an appropriately secure method.

The scope of each right may depend on the applicable legal basis and statutory limitations.

  1. Security

Confirmed controls include:

  • passwords stored as hashes rather than plaintext;
  • cryptographically signed access codes and file-confirmation codes, and cryptographically generated refresh and password-reset codes;
  • refresh and password-reset codes stored as hashes;
  • password-reset codes expire and are invalidated after successful use;
  • authenticated and organisation-scoped access through the application programming interface;
  • separation checks between organisations for organisation, Site, Meter, file, and consent operations;
  • provider credentials kept in backend environment configuration and excluded from public responses from the application programming interface;
  • explicit confirmation before readings assisted by optical character recognition or file imports are stored;
  • server-side file digest, validation, conflict checks, and atomic import;
  • Google Play purchase verification and replay protections where applicable;
  • cryptographic processing of trial-device signals where enabled;
  • account deletion requires password confirmation.

No system can be guaranteed completely secure.

Users should not send passwords, access codes, refresh codes, keys for an application programming interface, or provider credentials in support requests.

  1. International processing

The primary VoltOS production application programming interface and database are hosted in Oregon, United States.

No external energy-data provider is currently enabled for production use.

For personal data hosted by Render, Render’s Data Processing Addendum provides for the EU–US Data Privacy Framework where applicable and otherwise incorporates the European Commission’s Standard Contractual Clauses.

The applicable Standard Contractual Clauses module depends on whether Render acts as processor or independent controller.

The Data Processing Addendum also includes the United Kingdom Addendum and corresponding safeguards for transfers covered by United Kingdom or Swiss data protection law.

Google services used by VoltOS, including Google Play, Play Integrity, Google AdMob, Google Mobile Ads, and consent-management services, may process data in countries outside the user’s country of residence.

Google applies its own privacy terms, contractual safeguards, and international-transfer mechanisms to processing performed under its responsibility.

Where IVI PRO DEVELOPMENT EOOD is responsible for a restricted international transfer of personal data, appropriate safeguards will be used as required by applicable data protection law.

  1. Children

VoltOS is intended only for persons aged 18 years or older.

The Service is not directed to children or minors, and they may not create or maintain a VoltOS account.

We do not knowingly collect personal data from persons under 18.

If we become aware that a person under 18 has provided personal data through the Service, we will take reasonable steps to delete the data and close the related account, unless retention is required by law.

A parent or legal guardian who believes that a minor has provided personal data to VoltOS may contact us using the details in Section 14.

13. Advertising and Google AdMob

    VoltOS uses Google AdMob, operated by Google, to display advertising in the application.

    When advertising is enabled, the Google Mobile Ads SDK may automatically collect and share certain information with Google for advertising, analytics, measurement, security, fraud prevention, and related purposes.

    Depending on device settings, consent choices, region, and the advertising mode used, this information may include:

    • Internet Protocol (IP) address, which may be used to estimate an approximate location;
    • app interactions, such as app launches, taps, and ad interactions;
    • diagnostic and performance information;
    • device or other identifiers, including the Android advertising identifier where available;
    • information necessary for ad delivery, frequency capping, aggregated reporting, fraud prevention, and measurement.

    Google may use this information to provide personalised ads, non-personalised ads, limited ads, or technical ad delivery depending on the user’s consent choices and applicable law.

    For users in the European Economic Area, United Kingdom, and Switzerland, VoltOS uses Google’s consent-management solution to present applicable privacy choices before advertising data is processed where consent is legally required.

    Users may be offered choices including consent, refusal, and management of advertising preferences. A refusal of personalised advertising does not necessarily mean that no advertising will be shown. Non-personalised or limited ads may still be displayed where permitted.

    Non-personalised ads are not based on a user’s past behaviour, but may still use contextual information, approximate location, device information, cookies, local storage, or mobile identifiers where permitted and required for functions such as frequency capping, aggregated reporting, security, and fraud prevention.

    Advertising consent choices can be changed or withdrawn where the applicable consent-management functionality is available.

    Google acts independently for certain processing carried out through its advertising services. Further information about Google’s handling of information and advertising technologies is available through Google’s privacy and advertising documentation.

    VoltOS does not sell personal data to advertisers.

    14. Changes to this policy

    The current policy is published at:

    Current policy

    Material changes may also be communicated in the application and/or by email where the relevant functionality exists.

    This is not a promise that a notification channel not yet implemented will be used.

    Previous policy versions will be retained internally for audit and history.

    There is currently no commitment to maintain a public archive of previous versions.

    15. Contact

    For privacy or data requests:

    IVI PRO DEVELOPMENT EOOD

    Email: dev@iviprodevelopment.com

    Phone: +359 88 911 1035

    Public location: Sofia, Bulgaria

    Scroll to Top