VULNERABILITY VINES AI — PRIVACY POLICY Rocheston Publication and effective date: October 9, 2026 1. WHO WE ARE Vulnerability Vines AI ("Vines") is operated by Rocheston ("Rocheston," "we," "us," or "our"). This Privacy Policy explains how personal information is collected, used, disclosed, retained, and deleted when you use the Vines iOS app, https://vines.rosebird.org, the connected AinaCode service at https://code.rosebird.org, and their account, security-analysis, reporting, billing, and support features covered by this policy (the "Services"). Privacy contact: info@rocheston.com This policy applies whether you access the Services through the iOS app, a page displayed inside the app, or a desktop or mobile browser. Account, scan, and analysis information is processed by online services and does not remain exclusively on your device. Rocheston is responsible for the personal information it processes for its own account-management, service-operation, billing, and security purposes. Where we process information solely on behalf of an organizational customer, the customer's instructions and any applicable data-processing agreement also govern that processing. This policy does not replace an agreement required by applicable data-protection law. 2. INFORMATION WE COLLECT We collect information from you, the sign-in provider you choose, the systems you instruct the Services to test, and your interactions with the Services. The information involved depends on the features you use. Account and sign-in information. Google or Apple supplies information needed to authenticate and identify your account, which can include a provider-specific identifier, name, email address, and email-verification status. Google may supply a profile image where included in the profile information you authorize. We also process authorization responses and session information needed to complete sign-in and maintain access. Scan and analysis information. This includes target URLs, domains, IP addresses, scan settings, technical responses from target systems, vulnerability findings, supporting evidence, severity assessments, and reports. Depending on the requested test, evidence can include response headers or content, service and configuration details, diagnostic output, and other technical observations. If you use an authenticated scanning feature, we process the credentials, cookies, or access information you supply for that task. Submitted content. This includes source code, files, questions, prompts, and other material you choose to submit through supported analysis or upload features, together with the resulting analysis and recommendations. Technical and service information. When you connect to the Services, technical information can include your IP address, browser and operating-system information, request timestamps, session identifiers, scan status, errors, and security events. We process this information to deliver requests, maintain sessions, troubleshoot failures, and protect the Services. Transaction information. For paid plans, we process subscription and payment records relevant to your account, such as your plan, customer and transaction identifiers, payment status, amounts, currency, renewal status, and billing or invoice information supplied through the payment process. Communications. If you contact us, we collect the information you provide, including your contact details, message, attachments, and the information needed to respond to your request. Scan evidence, uploaded content, and support messages can contain personal or confidential information about other people. A URL, response body, source-code comment, or log entry may contain an identifier or secret. Only submit material and test systems you are authorized to use. Avoid including unnecessary personal information, passwords, private keys, or access tokens. Supply testing credentials only through the feature intended to receive them. Do not assume that sensitive material is automatically removed from evidence or analysis requests. 3. GOOGLE AND APPLE SIGN-IN You can sign in using Google or Apple. We use the information provided through your selected sign-in method to recognize you, create or maintain your Vines account, authenticate access, and associate your subscription, activity, and reports with your account. If you use Sign in with Apple and select Hide My Email, Apple supplies a private relay email address instead of your personal email address. We can use that relay address for account communications while forwarding remains enabled. Some profile information is provided only when you first authorize the connection. Rocheston does not receive your Google or Apple account password through these sign-in methods. Signing in does not, by itself, give Rocheston access to your email messages, contacts, or unrelated account content. You can manage or revoke the Vines connection through your Google or Apple account settings. Revocation may prevent future sign-in but does not by itself delete an existing Vines account or information already held by Rocheston. To delete your Vines account, use Profile as explained in section 10. Google and Apple separately process information to provide their own identity and account services under their respective privacy policies: Google: https://policies.google.com/privacy Apple: https://www.apple.com/legal/privacy/ 4. OPENAI AND AI-ASSISTED ANALYSIS Vines sends scan data to OpenAI to analyze potential vulnerabilities and generate findings, explanations, and remediation recommendations. OpenAI is a third-party AI provider. This processing occurs outside your device. Analysis inputs include the scan findings and supporting technical material submitted for analysis. Depending on the feature and the material being analyzed, this can include target identifiers, technical observations, response content, diagnostic information, source code, uploaded content, questions, and relevant context. Personal information or confidential material contained in those inputs may also be transmitted. The fact that material concerns a security scan does not make it anonymous. The purpose of this disclosure is to provide the requested analysis and associated explanations. AI output may contain errors or reproduce information included in the input. Review both the source material and the results before relying on, exporting, or sharing them. Sharing personal information with a third-party AI provider requires the applicable notice and explicit permission. This Privacy Policy is a disclosure, not a substitute for that permission. You may decline to submit information for AI analysis. To withdraw previously given consent for future AI processing, contact info@rocheston.com and stop submitting new AI-analysis requests. We will handle the withdrawal without undue delay. Processing already completed cannot be reversed, and records already created remain subject to the retention and deletion provisions below. Features that need the withdrawn information or permission may no longer be available. OpenAI's published API policy states that API inputs and outputs are not used for model training by default unless the API customer opts in. OpenAI may retain information for abuse monitoring or feature-specific storage, subject to the service, settings, contractual terms, and legal exceptions that apply. These published defaults are not a promise that Vines has zero-retention settings or that every provider-held copy is deleted immediately. This policy does not authorize a separate use of your personal information for general-purpose model training without an applicable lawful basis and any required additional notice and consent. OpenAI's information about API data controls is available at: https://developers.openai.com/api/docs/guides/your-data 5. PAYMENTS AND SUBSCRIPTIONS Website payments are processed through Stripe. If you proceed to Stripe checkout, Stripe collects the payment and billing information you enter and processes technical and transaction information needed to complete the payment, prevent fraud, and meet its legal obligations. We receive transaction and subscription information needed to provide your plan, maintain billing records, and resolve payment issues. Payment details entered on Stripe's hosted checkout are submitted to Stripe. If a purchase is offered and completed through Apple's payment system, Apple processes that payment under its own terms and privacy policy. We process the purchase or subscription information provided to us to verify access and manage the corresponding service entitlement. Payment providers may retain certain records independently for accounting, fraud prevention, dispute resolution, and legal compliance. Their separate processing is governed by their privacy notices. Opening checkout in an external browser does not make the transaction anonymous. Stripe's privacy policy: https://stripe.com/privacy 6. COOKIES, WEB STORAGE, AND DEVICE PERMISSIONS The website and web content displayed in the iOS app use cookies or similar storage to support authentication, sessions, preferences, and service functionality. Some information may remain on your device between visits. Clearing or blocking this storage may sign you out or prevent protected features from working. Optional processing that requires consent is subject to that consent. Agreeing to this Privacy Policy is not a blanket authorization for optional tracking or unrelated advertising uses. Where an activity falls within Apple's tracking-permission requirements, the applicable system permission is required before that activity begins. If you choose a supported file, photo, or camera upload feature, the app uses the corresponding device controls and requests permission where required. Content you select and submit is sent to the service used by that feature. You can manage device permissions in iOS Settings. Revoking device permission does not automatically delete content already submitted. If you download or share a report, a copy may be stored in Files, another app, or a location you select. Copies you export or send to other recipients are outside the Vines account-deletion process. 7. HOW AND WHY WE USE INFORMATION We use the information relevant to each activity to: * Authenticate users, maintain accounts, and provide access to account features. * Carry out scans and code analysis requested by you. * Generate, display, store, and deliver findings and reports associated with your use of the Services. * Obtain OpenAI analysis as described in section 4. * Process subscriptions, verify payment status, maintain service entitlements, and respond to billing requests. * Maintain sessions, troubleshoot errors, and keep the Services functioning. * Respond to support, privacy, security, and account-deletion requests. * Communicate service, account, billing, and security notices. * Prevent fraud, investigate suspected misuse, and protect accounts, systems, and affected parties. * Comply with applicable legal obligations and establish, exercise, or defend legal claims. Where data-protection law requires a legal basis, we rely on the basis applicable to the particular purpose: performance of our agreement with you for requested account, scanning, reporting, and subscription services; legitimate interests in maintaining reliable services, resolving support issues, preventing fraud, and securing our systems, where those interests are not overridden by your rights; compliance with legal obligations for required records and lawful requests; and consent where consent is required, including relevant AI disclosures and optional device permissions. Where an organizational customer instructs us to process other people's information on its behalf, that customer's lawful instructions and the applicable data-processing arrangements govern that processing. We do not treat your service agreement as the legal basis for every use of another person's data. You may withdraw consent without affecting the lawfulness of earlier processing. We will not treat publication of this policy or continued use alone as consent where a separate affirmative choice is required. If necessary information is not provided, we may be unable to deliver the corresponding feature or transaction. 8. DISCLOSURE OF INFORMATION; NO SALE OF USER DATA Rocheston does not sell user data to anyone. We disclose information as needed for the purposes described in this policy to: * Google and Apple for your chosen sign-in process. * OpenAI for the analysis described in section 4. * Stripe, and Apple when applicable, for payment and subscription processing. * Providers supporting the relevant hosting, data storage, infrastructure, communications, and service-security functions. * Recipients you select or authorize when you export, share, or otherwise direct disclosure of information. * Professional advisers, authorities, or other parties when disclosure is legally required or lawfully necessary to address a specific dispute, investigation, security incident, or threat to rights or safety. Providers processing information on our behalf are required to use it only for authorized purposes, maintain confidentiality, and provide protection consistent with this policy and applicable requirements. Our requirements for third parties receiving app user data include the same or equal protection required by this policy and Apple's applicable rules. A provider's separate role, such as providing its own identity service or meeting its own payment-law obligations, is explained in the relevant sections above. The no-sale commitment does not mean that providers never receive personal information. Information disclosed for sign-in, analysis, hosting, or payment remains subject to the applicable privacy requirements. If a merger, reorganization, or transfer of the Services requires personal information to be transferred, it must remain subject to applicable protections and the disclosed purposes. We will provide notice where required. A business transfer does not itself authorize unrelated new uses of personal information. 9. RETENTION AND DELETION CRITERIA We retain personal information only for as long as needed for the purposes described in this policy, subject to applicable legal obligations and legitimate, specific retention needs. Retention depends on the type of information, the feature used, account and deletion status, unresolved requests or disputes, and the legal requirements applicable to the record. Account and profile information is retained to maintain your account and access to the Services. After account deletion, only information needed for the limited exceptions described below may remain. Authentication and session information is retained for the period needed to complete sign-in, maintain an authorized session or connection, and address relevant security events. Its useful life is determined by expiry, revocation, replacement, or the end of the purpose for which it is needed. Scan inputs, working files, source code, and evidence are retained as needed to perform the requested task, generate its results, support available report or history features, and resolve relevant processing failures. Material no longer needed for those purposes is subject to deletion, including through account-deletion handling. Reports, findings, and analysis conversations are retained as needed to provide the account features through which they are available, unless deleted earlier or retained under a specific lawful exception. They are not retained indefinitely merely because they might be useful in the future. Technical, security, and diagnostic records are retained for the period reasonably needed to investigate relevant events, prevent recurring abuse, resolve faults, and establish the facts of an actual incident or dispute. The nature and resolution of the event determine any additional retention need. Support correspondence and privacy-request records are retained as needed to resolve the request and document its handling. Billing and transaction records are retained for applicable accounting, tax, payment-dispute, and legal recordkeeping periods. Limited information may remain after deletion where required by law or necessary and legally permitted to address fraud, security incidents, unresolved transactions, or actual legal claims. Such information must be limited to the purpose that justifies retention and is deleted when that justification ends. Backup copies may remain until they expire or are overwritten through the applicable backup cycle. Residual copies are not available for routine account use. If a backup is restored, applicable deletion requests must be reapplied. Account deletion does not promise instantaneous erasure from every backup or from a provider's independently required records. OpenAI and payment providers may retain information under the arrangements described in sections 4 and 5. Where a provider processes deletable personal information on our behalf, we will take the steps required under the applicable arrangement and law to give effect to your deletion request. 10. DELETE YOUR VINES ACCOUNT You can initiate account deletion inside the app: 1. Sign in to Vines. 2. Open Profile. 3. Select the account-deletion option. 4. Complete the confirmation steps shown. This is a request to delete your Vines account and its associated personal information, subject to the limited retention exceptions described in section 9. You do not need to contact support merely to initiate deletion through Profile. We handle deletion requests without undue delay and within the time required by applicable law. If additional verification or a legally permitted extension is needed, we will explain it. You can ask info@rocheston.com for the status of your request. To avoid initiating unwanted activity, stop submitting new jobs and cancel pending or recurring scans before deleting your account where the relevant controls are available. Contact us if you need help stopping a job. Deleting your Vines account does not delete your Google or Apple account. Uninstalling the app, signing out, or revoking a sign-in connection does not by itself request deletion of your Vines account. Exported reports and copies already held by recipients you selected are outside our account-deletion process. For paid plans, also check your subscription's renewal status and use the billing controls for the provider that manages it. Apple-managed subscriptions can be managed in your Apple subscription settings. Contact info@rocheston.com for help with a Rocheston-managed subscription or if billing controls are inaccessible. Uninstalling the app does not cancel a subscription. We do not require you to keep an unwanted account merely because a billing record must be retained. If you cannot access Profile, email info@rocheston.com to request deletion. We may need to verify that you are the account holder. Do not send your password, private keys, or authentication tokens. 11. YOUR PRIVACY RIGHTS AND CHOICES Depending on your location and the law applicable to the processing, you may have rights to access or obtain a copy of personal information, correct inaccuracies, request deletion, receive eligible information in a portable format, restrict processing, object to particular processing, or withdraw consent. You may also have the right to complain to the privacy regulator responsible for your jurisdiction. To exercise a right, email info@rocheston.com with enough information to identify your account and understand your request. Use Profile for account deletion when available. We will respond within applicable legal deadlines and may request proportionate verification to protect your information against unauthorized disclosure or deletion. Where permitted by law, an authorized agent may submit a request with evidence of authority. We may also require verification directly from the account holder. If we decline a request, we will explain the reason and any available review or appeal process. You may request review by replying to our decision or emailing info@rocheston.com with the subject "Privacy Appeal." Where applicable, you may also complain to a regulator. We will not unlawfully discriminate against you for exercising your privacy rights. The lawful conditions and exceptions applicable to a right still apply, including protection of other people's information and records we must retain. You can also manage sign-in connections through Google or Apple and device permissions through iOS Settings. These choices have the different effects explained above. Withdrawing a permission can affect the feature that depends on it without removing your other rights. 12. SECURITY Connections to the Vines website use HTTPS. We apply administrative, technical, and organizational safeguards appropriate to the personal information and processing involved. Our requirements include limiting access to legitimate service purposes and protecting information handled by service providers. No online service, transmission method, or storage system can guarantee absolute security. This does not remove our applicable security or incident-notification obligations. Protect your sign-in account, use only authorized targets, and avoid placing secrets or unnecessary personal information in scans and uploads. Report suspected compromise or unauthorized disclosure to info@rocheston.com. 13. INTERNATIONAL PROCESSING The Services use online infrastructure and third-party providers. Information may be processed outside the country where you live, and privacy laws in another country may differ from those in your country. This policy does not promise that all processing or storage occurs in a particular country. Where cross-border transfers are regulated, we are required to use a lawful transfer mechanism and any necessary supplementary safeguards. Depending on the applicable law and destination, this may involve a recognized adequacy decision or approved contractual safeguards. Contact info@rocheston.com to request information about the safeguards applicable to your information. Use of the Services is not treated as blanket consent to every international transfer. 14. CHILDREN AND ORGANIZATIONAL USE The Services are intended for users aged 18 and older, consistent with the Vines Terms of Service. They are not directed to children. If you believe a child has supplied personal information through the Services, contact info@rocheston.com. We will investigate and remove information collected contrary to the applicable age requirement or law, subject to any legal obligation to preserve a limited record. If you use the Services for an employer or client, supply only information you are authorized to process. The organization may have its own privacy duties and rules governing reports it receives from you. Where we process information on its behalf, we may need to refer a request concerning that information to the responsible organization and assist it as required. This does not limit rights relating to information for which Rocheston is independently responsible. 15. AUTOMATED ANALYSIS AND THIRD-PARTY CONTENT Vines uses automated and AI-assisted processes to assess technical security information. Findings and severity scores concern the systems and material being analyzed and require appropriate human review. They are not intended to determine a person's eligibility for employment, credit, insurance, healthcare, or other significant personal opportunities. External websites, services, and recipients you choose may have their own privacy practices. This policy governs Rocheston's handling of information and does not replace another provider's privacy notice. Rocheston remains responsible for the duties that apply to its own processing and disclosures. 16. CHANGES TO THIS POLICY We may update this policy to reflect changes in the Services, providers, information practices, or legal requirements. The date at the top identifies the current version. We will provide notice of material changes and obtain additional consent where required before the relevant new processing begins. A revised policy does not retroactively authorize an undisclosed use of personal information or remove rights provided by law. 17. CONTACT ROCHESTON For privacy questions, access or correction requests, consent withdrawal, deletion assistance, or privacy complaints: Rocheston Email: info@rocheston.com Website: https://vines.rosebird.org Privacy Policy: https://vines.rosebird.org/privacy.html Account deletion: Sign in to Vines and open Profile.