Privacy Policy

Thank you for using VectorSift (“VectorSift,” “we,” “our,” or “us”). VectorSift is an autonomous data orchestration, automated transformation, and analytics SaaS web application accessible at https://vectorsift.app (the “Site”) and our associated query services, APIs, developer tools, and hosted workspaces (collectively, the “Service”). This Privacy Policy explains how information about you that directly identifies you or makes you identifiable (“personal information”) is collected, used, protected, and handled by VectorSift in connection with our Service.

1. Scope of This Privacy Policy

This Privacy Policy applies to personal information collected through our Site, Service, developer APIs, documentation, and customer support communications.

Account Data vs. Customer Hosted Data:

  • Account and Operational Data: We determine the purposes and means of processing personal information collected during account registration (such as name, email, credentials, and billing details) and technical telemetry.
  • Customer Hosted Data: When you upload, ingest, transform, or analyze datasets, queries, and files within your workspace (“Customer Data”), you retain full ownership and control over that data. We process Customer Data solely on your behalf and under your instructions to provide the Service.

This Privacy Policy does not apply to aggregated, anonymized, or de-identified data that cannot reasonably be used to identify any individual.

2. Information We Collect and Receive

We collect only the information necessary to provide, maintain, and secure the VectorSift platform:

  • Account Information: Full name, email address, username, avatar, and authentication identifiers provided during registration or through authorized single sign-on (Google OAuth or GitHub OAuth).
  • Customer Workspace Content: Datasets, database connection configurations, analytical queries, data transformation pipelines, and report definitions that you upload or configure within your workspaces.
  • Payment & Billing Metadata: Payment transactions, subscription plan choices, and billing identifiers. All payment processing, invoicing, and tax collection are handled directly and securely by our Merchant of Record (Dodo Payments). VectorSift does not store raw credit card numbers on its servers.
  • Technical Telemetry & Usage Data: Internet Protocol (IP) addresses, browser user-agent, operating system details, session tokens, error logs, and performance metrics collected to guarantee platform reliability, enforce rate limits, and prevent fraud.
  • Cookies & Local Storage: Essential session cookies and local storage tokens required for user authentication, session persistence, and theme preferences.

3. How We Process and Use Information

We process personal information under legitimate business bases and contractual necessity:

  • Service Provisioning: Providing core data orchestration features, executing user-directed queries, processing analytical pipelines, and generating exportable reports.
  • Security, Access Control & Fraud Prevention: Enforcing authentication, validating sessions, preventing unauthorized access, blocking automated volumetric attacks, and enforcing rate limits.
  • Billing & Account Management: Calculating metered usage credits, administering subscription tiers, managing workspace seat limits, and providing customer support.
  • Service Improvements: Analyzing aggregated diagnostic trends to optimize platform performance and resolve software defects.

4. How Data Is Securely Stored & Protected

VectorSift employs modern administrative, technical, and physical safeguards to ensure the security and integrity of your data:

  • Encryption in Transit: All communications between your browser or API clients and VectorSift are strictly encrypted using Transport Layer Security (TLS 1.3).
  • Encryption at Rest: All stored datasets, vector representations, query logs, and database records are encrypted at rest using AES-256 cryptographic standards.
  • Multi-Tenant Logical Isolation: Data separation is enforced at the database and application levels, ensuring workspace boundaries are strictly maintained and one user cannot access another user’s data.
  • Credential Security: Authentication credentials and passwords are cryptographically hashed using advanced salted hashing algorithms. Plain-text passwords are never stored or accessible.
  • Rate Limiting & Abuse Protection: Distributed token-bucket rate limiting and automated session verification defend against credential stuffing, brute-force login attempts, and denial-of-service attacks.

5. AI Governance & Data Privacy Covenant

VectorSift provides AI-assisted query generation, schema matching, and anomaly detection. We maintain a strict policy regarding the confidentiality of your proprietary information:

STRICT PUBLIC MODEL NON-TRAINING WARRANTY:

VectorSift does NOT use Customer Data, query definitions, dataset schemas, or mathematical vector representations to train, retrain, fine-tune, or improve public foundational AI models without your explicit written authorization.

Customer retains 100% full ownership, title, and all intellectual property rights in and to all uploaded datasets, queries, and generated analytical outputs.

6. Third-Party Service Providers

To operate a high-performance, globally available SaaS application, VectorSift partners with trusted third-party service providers subject to strict confidentiality and data protection obligations:

Service ProviderPurpose & FunctionData Category
Cloud Compute & HostingApplication hosting, container execution, and cloud object storageEncrypted Customer Data & Telemetry
Database & Auth ProviderManaged database infrastructure and user authentication tokensAccount Profile & Hashed Credentials
Caching & Rate LimitingIn-memory caching, distributed rate limiting, and session verificationSession Identifiers & IP Logs
Dodo PaymentsAuthorized Merchant of Record, subscription billing, and tax remittanceBilling Information & Transaction Records
Telemetry & Error MonitoringReal-time application crash detection and operational telemetryDiagnostic Logs & Error Stack Traces

7. Data Retention & 15-Day Grace Period Purge

We retain personal information for as long as your workspace account remains active and in good standing, or as necessary to fulfill the purposes described in this Privacy Policy.

When an account deletion request is submitted through your workspace settings (under Settings → Security), your account enters an immediate 15-day grace recovery period. During this 15-day window:

  • Your workspaces are deactivated and rendered inaccessible to users.
  • You may cancel the deletion request at any time prior to the conclusion of the 15-day period by contacting support or authenticating to your account.
  • Upon conclusion of the 15th calendar day, our automated background deletion processes permanently and irreversibly erase all database records, vector indices, storage volumes, and credentials associated with your account.

Anonymized telemetry and financial records required by applicable statutory accounting regulations are retained in accordance with legal obligations.

8. Statutory Privacy Rights (GDPR & CCPA/CPRA)

Depending on your location and subject to applicable data protection laws (including GDPR and CCPA/CPRA), you may exercise the following statutory rights regarding your personal information:

  • Right to Access: Request confirmation of whether we process your data and obtain a copy of your personal information.
  • Right to Rectification: Request correction of inaccurate, incomplete, or outdated personal information in your account.
  • Right to Erasure: Request the permanent deletion of your personal data, subject to our 15-day deletion lifecycle and statutory exemptions.
  • Right to Data Portability: Obtain your data in a structured, commonly used, and machine-readable format.
  • Right to Non-Discrimination: We will never discriminate against you, alter service tiers, or deny features because you exercised your statutory privacy rights.

Notice Concerning Sale or Sharing of Personal Information: VectorSift does not sell personal information, nor do we share personal information with third parties for cross-context behavioral advertising.

To exercise any of these statutory rights, please contact us at privacy@vectorsift.app.

9. International Data Transfers

VectorSift operates global cloud infrastructure. Information collected may be stored and processed in the United States or other jurisdictions where our cloud service providers maintain facilities. When transferring personal data from the EEA, UK, or Switzerland to countries lacking an adequate level of data protection under applicable laws, we rely on recognized international transfer mechanisms, including European Commission Standard Contractual Clauses (SCCs), to ensure equivalent protection.

10. Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or our data protection practices, please reach out to us:

VectorSift Privacy Operations

Privacy Inquiries: privacy@vectorsift.app

Customer Support: support@vectorsift.app

Official Website: https://vectorsift.app