Short version: we collect only what we need to run Vectos, we don't sell your data, we don't use it to train AI models, and you can ask us to delete it any time at support@vectos.app.
Account: name, email, and a hashed password. If you sign in with Google, we also receive your profile photo and Google ID.
Usage: API requests, credit usage, prompts you submit, errors, used to operate the service and fix bugs.
Payments: handled entirely by Stripe. We never see or store your card details.
Cookies: one secure HTTP-only session cookie to keep you signed in. No advertising or tracking cookies.
We do not sell personal data. We do not train AI models on your data or your generated assets.
When you generate an asset, your prompt is sent to Google's Gemini API (Vertex AI) which returns the result. Google handles this data under their Cloud Data Processing Addendum. Prompts may be cached for up to an hour to keep responses fast and reduce cost.
Data is stored on AWS (us-east-1): Postgres for structured data, S3 for assets. Encrypted at rest and in transit.
Your data stays while your account is active. If you delete your account, we delete your personal data within 30 days, except where we're legally required to keep something (e.g. tax records for payments).
You can ask us to export or delete your data, or correct something that's wrong. Email support@vectos.app and we'll respond within 30 days.
Vectos isn't intended for people under 16. If you think we've accidentally collected data from someone under 16, email us and we'll delete it.
If this policy changes materially, we'll email you or post a notice in the app. Continued use after a change means you accept the new version.