Privacy
This page describes what the software actually does. If anything here disagrees with the service, this page is wrong and should be corrected.
What is stored
| Data | Why |
|---|---|
| Your account identifier, display name and email address, from your Vampelium account | To know whose ticket is whose and how to reach you. The identifier is the one vampelium.com issues, and it is never sent to your browser or anybody else's — a page that carried it would let anyone match your account here to the same account on another Vampelium service. Your email address is refreshed each time you sign in, because a stale address on a support ticket is how a reply reaches the wrong person. Your display name is not: if you set one in Settings here, it stays as you set it, and your Vampelium name is only used when you have not chosen one |
| Your tickets: subject, category, status and every message on them | They are the conversation |
| If you opened a ticket without signing in: the email address you chose to give, if any, and a one-way hash of your access code | There is no account to attach the ticket to, so the code is what proves the ticket is yours. Only the hash is stored — we cannot read your code back, which is also why we cannot recover it for you if it is lost. The email address is optional, nothing is ever sent to it, and it exists only so a person answering you has another way to reach you |
| Which of your tickets you have already read | To show you what is new since you last looked. It is one timestamp per ticket, and it is deleted with the ticket |
| Files you attach | To show us what you are seeing |
| A count of tickets, messages and uploads per hour | To stop one account making the service unusable for everyone. Deleted after two hours |
What is deliberately not stored
- Your password. Sign-in happens at vampelium.com and Support is never shown it.
- No analytics, no advertising identifiers, no third-party scripts. The page loads code from this origin and nowhere else.
- No remote images. Everything shown is served from here, so nobody learns when you read a ticket by watching their image server.
Photographs lose their location
A screenshot or photo from a phone usually carries EXIF metadata, and that routinely includes the exact coordinates where it was taken. Every image attached here is decoded and re-encoded before it is stored, which removes that metadata along with the camera details and the timestamp. The original file is never kept. If the re-encoder is unavailable the upload is refused rather than stored unprocessed.
Files that are not images — logs, crash dumps, documents — are stored as you sent them, because there is nothing to safely rewrite. They are served back only as downloads, never rendered.
Who can read your ticket
You, and Vampelium support staff. Nobody else.
Support staff can also write internal notes on a ticket — working notes between agents, which you do not see. We would rather tell you they exist than let you discover it. A note never appears in your view of the ticket, never moves the ticket in your list, and is not included in the data export, because it is not yours to read.
What you write is not sold, shared in bulk, or used to train anything.
Taking a copy
Settings → Your data gives you a JSON file with your tickets and every message on them that you can read. The attached files themselves are not inside it; each entry names the address it can be fetched from while your account exists. Nothing is behind a request form and nothing waits for a person to approve it.
Getting rid of it
Settings → Delete this account removes your tickets and the files on them. Replies you sent on somebody else's ticket stay, without your name — removing them would tear holes in a conversation that is not only yours.
The removal is not instant, and we would rather say so than round it up. The account stops working the moment you ask; the files are then deleted in batches over the following minutes, and the account row goes last, once nothing is left that points at a file. Doing it in the other order would leave your attachments in storage with nothing left that knows they are yours. Until the removal starts you can still stop it; once it has, you cannot, and the page says so rather than offering a button that would not work.
Signing out somewhere you no longer are
Settings → Signed-in devices ends every session, this one included. A sign-in lasts seven days, and without this there would be nothing you could do about a session left open on a machine you no longer have.
Who else sees it
Cloudflare, because the service runs on their platform and your tickets are stored there. Nobody else.