Privacy Policy

Last updated July 24, 2026

The short version

  • Your content is yours. We store it to run the product for you, and for nothing else.
  • We never train AI models on your data.
  • We never mine, analyse, or commercially exploit your business information. It is not an asset of ours.
  • We never sell your data and we never show you ads.
  • AI requests run through your own provider key. What that provider does with your prompt is governed by their policy, not ours — see section 5.
  • Your provider keys are encrypted at rest and never shown again.
  • Do not put banking credentials, card numbers, or government identity numbers into the Service — see section 4.

1. Who we are

VectorBrain ([registered business address]) is the data controller for the personal data described in this policy. For privacy questions or to exercise your rights, contact privacy@vectorbrain.one.

2. What we collect

Account data: your name, email address, and sign-in method (email/password or Google), used to run your account and authenticate you.

Workspace content: what you create and upload — chats, documents, media, wiki entries, business records, prompts, and skills. This is the product working, not data gathering. We hold it so you can use it.

Provider keys: the API keys you connect (such as OpenRouter) are envelope-encrypted at rest, used only to perform work you request, never written to logs, and never returned to your browser after entry.

Billing data: subscription payments are handled by Stripe. We never see or store your card number; we receive only subscription status and plan information. Your AI provider bills you separately and we have no visibility into that account.

Operational data: metrics such as storage consumed, job counts, request timings, and error events, used to run usage meters, keep the Service healthy, and prevent abuse.

3. What we use it for, and our lawful basis

We use the data above to provide the Service, authenticate you, meter plan limits, take payment, diagnose and fix faults, protect against abuse and security threats, and communicate with you about your account. Where the law requires a lawful basis, ours is the performance of our contract with you, our legitimate interest in operating and securing the Service, and compliance with legal obligations.

We do not sell personal data, we do not serve advertising, we do not profile you for marketing, and we do not use your content to train AI models — ours or anyone else's.

4. Information you should never give us

Some information should not be entered into any AI workspace, including this one. The Service is not certified to hold regulated payment, financial, or health data, and content you enter may be transmitted to a third-party AI provider as described in section 5.

Never upload or paste banking or identity credentials.

Please do not enter bank account or routing numbers, full payment card numbers, CVV or security codes, online banking logins, national identity numbers such as a full Social Security number, passport or driver's licence numbers, tax identification numbers, or passwords and API keys for your other services.

The same goes for data carrying its own legal regime: health and medical records, biometric data, information about children, and anything subject to PCI DSS, HIPAA, or equivalent rules.

Refer to accounts and payments descriptively — "the March invoice", "the operating account" — rather than by number. If you realise you have pasted something sensitive, delete it, rotate the credential, and contact privacy@vectorbrain.one so we can help remove it from our systems.

Ordinary business information — plans, drafts, brand material, customer notes, revenue and cost figures — is what the Service is designed to hold, and section 6 sets out how we treat it.

5. AI processing: what leaves our systems, and what we cannot control

When you run an AI task, the content needed for that task — your instruction, and whatever context the task requires, which may include document text or files you attached — is sent to your AI provider using your own key, so the provider can generate a response. This is the core function of the Service and cannot be avoided while using AI features.

At that boundary, our control ends and your provider's policy takes over. We are being explicit about this because it is the part most AI tools leave vague.

The model you choose decides whether your prompts may be used for training.

Model providers have different data policies. Some undertake not to train on your inputs. Others expressly permit it — this is particularly common with free and zero-cost model variants, where permitting training is often part of why they are free. OpenRouter's privacy policy states that it does not control how model providers handle your inputs and outputs, including for use in their model training, and that some providers may use them for training or improvement.

Choose deliberately. Treat a free model as one you are paying for with your data until you have checked its policy.

The controls are real, and they live on your provider account. OpenRouter offers account-level settings for whether your requests may reach providers that train on your data, with separate toggles for paid and for free models:

Because those settings belong to your account, we cannot configure them for you, cannot see what you have selected, and cannot override a provider's policy. OpenRouter also notes that these toggles govern which providers it routes to and do not change OpenRouter's own handling of your prompts. We select the model you asked for and send the request; OpenRouter decides which upstream provider serves it.

What we can tell you plainly: we never train on your content, never retain your prompts for any purpose beyond running and debugging the Service, and never send your content to any AI provider other than to fulfil a task you initiated.

6. Your business information is yours

We want to be unambiguous, because this is the commitment customers most often find missing elsewhere.

We do not use your files, documents, storage, or business information for any purpose of our own. We do not read them for insight. We do not mine or analyse them. We do not aggregate them into datasets, benchmarks, or statistics. We do not use them to train models or to develop features. We do not use them for advertising, profiling, or lead generation. We do not sell, rent, or share them with anyone for those purposes. Storage you occupy is space we are holding on your behalf; the contents are not an asset of ours and we do not treat them as one.

Our staff access workspace content only in narrow, specific circumstances: when you ask us to in order to resolve a support issue; when strictly necessary to investigate a security incident or suspected abuse; or when legally compelled. Such access is limited to what the task requires and is not used for any other purpose.

7. Error reporting and diagnostics

We record operational and error information so we can find faults, fix them, and keep the Service reliable. This is the only "improvement" use we make of anything connected to your activity, and it is deliberately scoped to how the system behaved rather than to what you were writing.

Diagnostic records typically contain the time of an event, which operation failed, error codes and messages returned by our systems or by a provider's API, and identifiers such as a workspace or job id needed to trace the fault. Provider API keys are stripped from error text before it is recorded. We do not copy your documents or your chat content into diagnostic records for analysis, and we do not review those records to learn about your business.

As of the date of this policy we do not use any third-party analytics, advertising, or crash-reporting service, and no behavioural tracking product is embedded in the Service. If that changes, we will update this policy and the list in section 9 before the change takes effect.

8. Where your data lives

Workspace data is stored with Convex, our backend, database, and file storage provider, and the web application is served by Vercel. Every workspace is isolated at the query layer: one customer's data is never reachable from another's workspace, and that boundary is enforced in the backend rather than only in the interface.

9. Service providers we rely on

  • Convex — database, file storage, and backend functions.
  • Vercel — hosting for the web application.
  • Stripe — subscription payments and card processing.
  • Google — sign-in, if you choose Google as your authentication method.
  • Your AI provider (ordinarily OpenRouter, and the model providers behind it) — receives the content needed to run a task, through your own key, under their privacy policy and terms. Because you hold the account, this is a relationship between you and them; see section 5.

10. International transfers

Our providers and your chosen AI provider may process data in countries other than your own, including the United States. Where personal data is transferred out of the UK or EEA, we rely on appropriate safeguards such as the European Commission's standard contractual clauses or an adequacy decision. Note that the geographic location of AI processing depends on the provider and model you select and is determined by your provider's routing rather than by us.

11. Cookies

We use only the cookies needed to keep you signed in and to remember preferences such as your theme. We do not use third-party advertising cookies or cross-site tracking.

12. Security

We use encryption in transit, envelope encryption for provider keys at rest, workspace isolation enforced in the backend, and access controls limiting staff access as described in section 6. No system is perfectly secure, but we treat a breach of your workspace as the most serious failure we could have, and we will notify you and any required regulator without undue delay if one occurs.

13. Retention and deletion

We keep your data while your account is active. If you cancel or delete your account, workspace data is retained for 30 days so you can export it or reactivate, then deleted from active systems in the ordinary course; residual copies may persist briefly in encrypted backups before expiring on their normal cycle. Diagnostic records are kept only as long as they are useful for fault-finding and abuse prevention. Records we must keep for legal or accounting reasons, such as invoices, are retained for the period the law requires. You can request earlier deletion by contacting us.

Content already transmitted to an AI provider is subject to that provider's retention policy; deleting something from VectorBrain cannot retract what a provider has already received.

14. Your rights

You can access, correct, export, or delete your data. Depending on where you live — for example the EU/EEA, the UK, or California — you may have additional statutory rights, including to object to or restrict processing, to data portability, and to withdraw consent. We honour requests under those laws regardless of where you are, and we do not discriminate against you for exercising them.

Write to privacy@vectorbrain.one and we will respond within 30 days. If you are in the EEA or UK and are unsatisfied with our response, you have the right to complain to your local data protection authority.

15. Children

The Service is not intended for anyone under 16, and we do not knowingly collect data from children. If you believe a child has provided us personal data, contact us and we will delete it.

16. Changes to this policy

If we change this policy in a material way — including adding any analytics or error-reporting provider — we will notify you by email or in-app before the change takes effect.

17. Contact

Privacy questions and requests: privacy@vectorbrain.one. General enquiries: hello@vectorbrain.one. VectorBrain, [registered business address].