Privacy Policy
Effective: August 17, 2026
Who we are
VESQOR MEGA AI is a business-analysis service operated by VESQOR LLC, a Delaware limited liability company (EIN 39-4773373). This policy explains what personal data we collect, how we use it, and the choices you have. By using the Service you agree to the practices described here.
What we collect
- Account identity — email address, display name, and a password hash when you register. Your password is stored only as a salted cryptographic hash (scrypt) and is never readable by us. Used to authenticate you and scope your data to your account.
- Prompts and responses — the inputs you submit and the reports we generate. These are stored in your private, owner-scoped memory to serve you faster answers and enable document recall. They are not shared with other users.
- Documents you upload — stored in object storage (Tigris); only their metadata and derived text chunks live in the database, scoped to your account and chat session.
- Usage metrics — token counts, request counts, and spend. Used for quota enforcement, cost accounting, and abuse prevention.
- Billing data — handled by Stripe. We store only the customer reference, subscription status, and credit balance; we never see or store your card details.
- Technical data — IP address and basic request metadata in server logs, retained for security monitoring and abuse prevention.
How we use it
- To provide the Service: process your prompts, generate reports, and store your history.
- To operate and secure the Service: enforce quotas, prevent abuse, investigate incidents.
- To bill you: process payments and credits through Stripe.
- To improve the Service: aggregated, de-identified analytics. We do not train models on your prompts or reports.
Your personal brain
Each account has a private, per-user knowledge store (the "User Brain") that learns from your interactions: the questions you ask, the reports we generate, and the facts, preferences, and decisions we extract from them. This memory is scoped strictly to your account — no other user can read it, and it is never used to train models. You can view, edit, pin, or delete individual memories at any time in Settings → My Brain, and you can export or delete all of your data at any time.
Compliance screening
When you register, we screen your name and company against public sanctions lists (OFAC, UK, EU, UN) to comply with applicable law. This is a deterministic, automated check; no human reviews your data for this purpose. If a critical match is found, the account is not activated.
How long we keep it
Memory rows are automatically purged after 90 days by a retention job, unless you delete your account earlier. Usage and safety logs are retained up to 13 months for accounting and abuse review. See our Data Retention page for the full enforced policy.
Cookies
The Service uses a session cookie for authentication. No third-party advertising or tracking cookies are set. Billing pages served by Stripe may set their own cookies under Stripe's domain.
Third parties
We share data only with processors required to operate the Service, each bound by contract to use data only to provide the Service:
- Anthropic — AI inference for select models. Prompts and reports may be sent to Anthropic's API to generate your analysis. Anthropic does not use API customer data to train models.
- OpenRouter — AI inference routing. Prompts and reports are sent to OpenRouter's API to generate your analysis. OpenRouter does not use API customer data to train models.
- Stripe — payment processing. We store no card numbers; Stripe handles billing under its own Data Processing Agreement.
- Tigris (Fly.io) — object storage for report bodies and uploaded files, with data processing terms including Standard Contractual Clauses.
- Fly.io — hosting of the application and database.
We do not sell your data, and we do not use your data for advertising.
Your rights (GDPR & CCPA)
- Access — your reports and history are visible in your dashboard at any time.
- Export — download a machine-readable copy of all data we hold about you from your dashboard (“Export your data”).
- Deletion — request account deletion from your dashboard; a scheduled job permanently erases your memory rows, reports, documents, billing history and stored files within 24 hours.
- Correction / objection — contact us at the address below.
To exercise any right, use the self-service tools in your dashboard or email us at info@vesqor.com.
Children
The Service is not directed to children under 13. We do not knowingly collect personal data from children under 13. If you believe a child under 13 has provided us data, contact us and we will delete it.
Security
We implement commercially reasonable technical and organizational measures to protect your data: encrypted tokens and secrets at rest, password hashing, session authentication, and network isolation on our hosting provider. No transmission over the Internet is fully secure; you should not submit sensitive information you are not comfortable sharing.
Changes to this policy
We may update this policy from time to time. We will publish an updated version and effective date on this page. Material changes will be notified in-product or by email.
Contact
Questions about this policy, or to exercise your rights: info@vesqor.com. Security or privacy incidents: info@vesqor.com. For reports of problematic content generated by the Service, use the report function on any result.