Privacy Policy
What Vega keeps from your AI work sessions, what it reads them for, what it never learns from, and what you can make us do about it.
1Who we are
Vega operates the service at tryvega.tech, including the website, the capture connectors for Claude, ChatGPT, Claude Code and code editors, and the MCP server that those connectors talk to. In this policy "Vega", "we" and "us" mean that operator, and "you" means the person whose account it is.
Privacy questions, requests about your data, corrections to this document, and security reports: help@tryvega.tech.
2The short version
Vega watches your AI work sessions and turns them into a private record of what you have worked on. That means it holds text you wrote and text a model wrote back to you. Vega does four separate things with it, and keeping them separate is the whole design — sections 3 to 5 are the ones to read if you read nothing else.
- We keep it. Your sessions are stored, and verbatim prompts and replies are stored encrypted where you have turned that on. Encryption is under a key we hold, not one you hold.
- We read it to answer your questions. That reading sends your own content back out to a model provider at the moment you ask, and the answer comes back only to you.
- We do not learn from paid work, ever. Nothing from a paid seat enters anything Vega trains. There is no setting that turns that on.
- Benchmarks would need your permission and would carry no words. Vega runs none today.
- Capture is automatic and silent by design. Once you connect a tool, Vega captures without asking and without announcing it. Only *publishing* to a public profile requires your approval — collection does not.
- Your teammates see your work moments by default if your account belongs to a company. There is no queue where you approve each one first. They do not see your prompts or the model's replies.
- Vega staff can read your session text. No internal page renders verbatim text any more; staff with database access can still read the rows, and we hold the key.
- Almost nothing is deleted on a schedule. Four short clocks exist; your content itself is kept until you delete it or your account.
3The four acts
Most privacy policies collapse everything a company does with your data into one sentence about protecting it. Vega does four different things, they carry four different risks to you, and they get four different rules. A permission for one is never a permission for another.
- Store
- We keep what your session contained, so that your record of your own work is complete. Where verbatim prompts and replies are kept, they are encrypted in our application before the row reaches the database, and no product surface shows them to anyone but you.
- Reason
- We read your stored work at the moment you ask a question of it, to answer that question. The answer goes to you, or — for the surfaces a company account has — to your company, within the limits in section 12. It goes nowhere else and to nobody else.
- Train
- Improving the engine that Vega runs for everybody. Paid content never enters it. Not with permission, not with an exception, not on request.
- Aggregate
- Comparing across customers to produce a benchmark. Only with your explicit opt in, only from structure, never from the words in your work — and never below a floor of three contributors.
One clarification that matters, because it looks like Train and is not. When Vega re-reads your own stored work under a new taxonomy — a better set of work types, a new signal, a corrected scorer — and recomputes your own results from it, that is Reason. Your data, your output, no engine changed for anyone else. It is allowed on every plan and needs no separate permission, and we are naming it here so that a later product change is not read as a broken promise.
What each act does today, as opposed to what it is designed to do. Store: verbatim prompts and replies are kept only for capture categories you have explicitly opted into, and every category ships off — the design point of keeping a full record is not the current default, and where this policy says "stored" without qualification it means the structured record, not the verbatim text. Reason: live, and section 13 describes exactly where the content goes. Train: the training store is a separate database that is not configured, so every training write is currently a no-op and nothing has been written to it. Aggregate: no cross-customer benchmark exists in the product and there is no control that would record your permission for one.
4The two pools
Everything Vega might ever learn from falls into one of two pools, and the difference between them is whether it contains your words.
- The content pool — your words
- The text of your prompts and of the model's replies, and anything derived from them that still carries your phrasing. It is drawn from two sources only: seats on the free tier whose holder has given explicit, separate permission, and public profiles, where you approved each fact for publication. Nothing from a paid seat is in this pool, ever.
- The structure pool — no words, no names
- Facts about the shape of the work rather than its content: which seat, which date, which model, how many tokens, what type of work it was, the score, the nine signals behind the score, how many iterations a piece of work took, and how faithfully the turn was captured. Every tier is in this pool, including the most expensive seat, because none of it contains a word you wrote or a name of any kind.
A seat's pool membership is decided by the seat, not by the item. There is no per-moment content-pool switch, and we are not going to imply one exists.
5The trade
Free pays with data. Paid pays with money. Never both, never neither.
If you use Vega without paying, the deal is that your content — with your explicit, separate permission, recorded and revocable — may help improve the engine everyone uses. If you pay for a seat, your money is the payment, your content is not, and no amount of it is used to improve anything outside your own account. There is no plan where you pay and Vega also learns from your work, and there is no plan where you pay nothing and Vega learns nothing.
What is true today. Vega takes no payments and has no payment integration, so no money has changed hands. Plans are nonetheless real: every seat resolves to one, and the plan decides whether that seat's content may train anything. Existing seats were placed on plans that do not permit content training, and were not moved onto the free trade retroactively. The wall is in the database rather than in a setting: a plan that does not permit content training cannot record a grant for it, and moving a seat onto such a plan writes the withdrawal. A seat whose plan cannot be determined is excluded from every training path, because an unreadable answer resolves to the narrowest one. What has never been tested is the paying half: no seat has yet arrived at a paid plan by paying for it.
6What this policy covers
It covers personal data Vega processes as the party deciding why and how — your account, your captured work, the profile you may publish, and the operation of the service.
It does not cover the AI tools you use. When you talk to Claude, ChatGPT, Cursor or another assistant, that conversation is governed by that provider's terms and privacy policy. Vega is a layer that reads from those sessions; it does not replace the provider's own relationship with you.
7What we collect
Grouped by what it is, not by where it is stored. The technical field-level inventory behind this section covers 610 columns across 52 tables and is maintained internally.
- Account and identity
- Your email address, your account handle, display name, job title and team name if you give them, your chosen appearance and display settings, and the authentication records that let you log in. Access tokens for the connectors are stored as SHA-256 hashes and a short non-secret prefix, never in a form we can replay.
- Session content
- For each captured session: a title, a short structured summary, a redacted excerpt of the text, and a sanitised one-sentence "capsule" describing the shape of the thinking. This is the normal record and it is derived from your prompts and the model's replies.
- Verbatim prompts and replies
- The complete text of a turn, kept only for capture categories you have explicitly opted into, encrypted in our application before storage. Off by default for every category; the personal category is off entirely and cannot be turned on.
- Derived work record
- Work moments, events, contexts and sub-contexts, a graph of nodes and edges linking them, tags, growth scores, archetype and interest signals, coaching output, and session-derived context summaries. All of it is computed from your session content.
- Search vectors (embeddings)
- Numeric vectors built from your text so that Vega can find related work. Every vector Vega builds is now computed inside Vega's own servers — 384 dimensions, no external call, no text leaving the machine. Until 19 August 2026 some were computed by OpenAI at 1,536 dimensions, and until 12 August 2026 one of those was built from the verbatim prompt and reply. Both of those paths are deleted and the vectors they produced have been removed from the database. We treat embeddings as your content, not as anonymous metadata, because text can be partially recovered from them.
- Usage and cost accounting
- How much you used, so that a plan can be priced and so that Vega can show you what your work costs. Today this is a running per-seat total of input tokens, output tokens and turns, with no model, no timestamp and no session attached to it.
- Refusal traces
- When Vega's filter decides a session looked like personal life rather than work, it drops the content and writes one row so the capture is recoverable rather than silently lost: a short redacted preview line and the original capture arguments. Visible to you and to Vega staff with database access; visible on no other surface; deleted after 30 days.
- Company and team data
- If your account belongs to a company: the company, your membership and role, invitations sent to you and by you, verified email domains, the company's prompt-visibility setting, your acknowledgement of it, and the company's own audit log of visibility changes.
- Public profile
- If you choose to publish one: the facts you approved for publication, your handle, and the profile's public URL. Nothing reaches a public profile without your explicit approval.
- Consent records
- Every time you agree to something or take an agreement back: the exact sentence you were shown, the versions of the documents that sentence referred to and a hash of their text, which screen it happened on, your browser's user-agent string, a salted hash of your IP address, and the time. These rows are append-only and are kept permanently — they are the proof you were asked, so they outlive the data they cover.
- Operational and technical data
- Which tool a capture came from and its user-agent string, capture telemetry and health records, records of MCP activity (deleted after 14 days), and your IP address where it is needed for rate limiting on sign-up and connector registration and in the log of Vega staff actions. Our hosting provider and database provider keep their own request and query logs.
- Cookies
- A login session cookie, and four preference cookies that remember your theme, density, accent colour and reduced-motion setting. Nothing else. No analytics, advertising, marketing or session-recording cookies of any kind, first- or third-party.
8Where it comes from
- From you directly — sign-up, settings, your profile, and anything you type into Vega itself.
- From your AI sessions, automatically — through the connector you installed. Vega's tools are deliberately instructed to capture without announcing themselves, so that the assistant does not interrupt your work to ask. This is a real design decision with a real consequence: you will not see a capture happen.
- From other people — a company administrator inviting you, a teammate's actions on shared surfaces, and content about you that appears in someone else's captured session.
- Computed by Vega — everything in the derived work record.
9What is filtered out, and what is not
This section exists because it is the sentence most companies get wrong in their own favour, and because Vega's product materials have made a stronger claim than the code supports.
Three filters exist. Credential shapes are pattern-matched and replaced before storage — provider API keys, personal access tokens, cloud keys, bearer tokens, JWTs, private keys and password-assignment lines. A topical filter drops content that reads as *your own* health, personal finance, family or personal interests, before it becomes a session. And an anonymiser rewrites a work moment to remove company names, people's names, project codenames, geographies and amounts — but it runs only on the path that publishes a profile or writes an anonymised training record, never on the ordinary stored record.
The two filters that do exist are best-effort. The credential matcher is pattern matching tuned to prefer false positives, and it cannot catch a secret that does not look like one. The topical filter is a classifier, so it is wrong sometimes in both directions. Do not paste credentials, and do not treat either filter as a guarantee.
10Content about other people
This section describes the hardest problem in the product and we would rather state it than bury it.
When you paste a client's contract, a colleague's performance note, a candidate's CV or a customer's complaint into an AI session, and Vega captures that session, Vega ends up holding personal data about a person who has never heard of Vega, has no account, and has agreed to nothing. The person consenting is you. The person in the data is not.
Vega's filter is built to drop *your* personal life. As section 9 says, it is not built to detect a third party's personal, medical, legal or confidential information inside something that reads as work, and it does not do so. That content is classified as work and stored.
Two things reduce the exposure, and neither of them is consent from that person, so we will not describe them as if they were: the capsule writer strips proper nouns, organisations, sectors and amounts before anything is used across accounts, and the only content-bearing training record stores an anonymised rewrite rather than the original words.
What that means for you. You are responsible for what you paste into a session Vega can capture. If you handle other people's data professionally — clients, patients, candidates, employees — consider whether your own obligations to them permit a capture layer at all, and use the per-category settings, the pause control and the sensitivity marker accordingly.
11Why we process it, and on what basis
| Act | What we do | Proposed lawful basis (GDPR Art. 6) |
|---|---|---|
| Store | Run your account, capture sessions, build your private work record | Performance of a contract, Art. 6(1)(b) |
| Store | Keep verbatim prompts and replies for a capture category | Consent, Art. 6(1)(a) — withdrawable at any time |
| Reason | Classify, summarise and embed your content using model providers | Performance of a contract, Art. 6(1)(b) |
| Reason | Answer your questions about your own work, at the moment you ask | Performance of a contract, Art. 6(1)(b) |
| Reason | Recompute your own results under a new taxonomy or a corrected scorer | Performance of a contract, Art. 6(1)(b) |
| Reason | Show approved work moments to your teammates on a company account | Legitimate interests, Art. 6(1)(f) — balancing test not yet performed |
| Train | Use the anonymised content-bearing record to improve Vega's engine | Consent, Art. 6(1)(a) — free tier only; see the [COUNSEL] note in section 5 |
| Train | Content-free structural records of how work moved and how it ended | Legitimate interests, Art. 6(1)(f) — no opt-out exists today |
| Aggregate | Cross-customer benchmarks, structure only, floor of three | Consent, Art. 6(1)(a) — not built, and no control exists to record it |
| — | Transactional email: sign-in codes, invitations, connector alerts | Performance of a contract, Art. 6(1)(b) |
| — | Publish a public profile | Consent, Art. 6(1)(a) — you approve each fact |
| — | Security, abuse prevention, rate limiting, staff action logs | Legitimate interests, Art. 6(1)(f) |
| — | Keeping the consent record itself | Legal obligation, Art. 6(1)(c) — Art. 7(1) puts the burden of proof on us |
12Who else sees it
- Your teammates, if your account belongs to a company
- They see your work moments — title, summary, context, when — as soon as those moments exist. There is no approval step for the team view, and Vega does not offer you a way to review a moment before your team sees it. They do not see your prompts or the model's replies, your growth scores, your coaching, or your captures. You can exclude an individual moment from the team, and that exclusion is a guarantee rather than a setting your company can override.
- Your manager
- Aggregate figures only, and only when at least three people contributed to the figure. Below that floor the surface states the reason and shows nothing. Per-person rows show recency, never volume.
- Anyone, if you publish a profile
- Only the facts you approved, at the profile URL. Opting into being visible to recruiters is a private setting: a visitor sees the same page whether it is on or off.
- Our subprocessors
- The companies that host, store, process and deliver for us, and the model provider that Vega's reasoning runs on. Each one, what it receives and where it is, is named on the subprocessor list, which is part of this policy.
- Vega staff
- Staff with the administrator flag can read customer data through internal pages: work moments, capsules, coaching notes and per-person scores, across every seat and every company. Verbatim prompts and replies are no longer rendered on any internal page. Staff with direct database access can still read the rows, and Vega holds the key that decrypts stored raw text. We do this to support and debug the product. Opening the internal capture view is recorded in a content-free staff log before the page renders, and the page refuses to render if the record will not land; that log records that the page was opened, not which rows were read.
- Nobody else
- We do not sell personal data, we do not share it for advertising, we run no advertising or analytics trackers, and we have never disclosed data in response to a legal demand. If we receive one we will tell you unless we are legally prohibited from doing so.
13Model providers, and what reasoning sends where
This is the disclosure most likely to matter to you, so it is separate from the rest and it now covers two different moments, not one.
At capture. Every capture is sent to Anthropic before it is stored — for the personal-life filter, and then for classification, summarising, capsule writing, anonymisation and interest tagging. A daily job sends a decrypted transcript of a session to Anthropic to derive its context. No other company receives anything. Search vectors used to go to OpenAI; since 19 August 2026 they are computed inside Vega's own servers.
At the moment you ask. Vega's Reason act is not local. When you ask Vega a question about your own work, Vega retrieves your own moments, decrypts the verbatim turns behind them where you have stored any, and sends that material — excerpts of your prompts and of the model's replies, along with your moment titles, contexts and open threads — to Anthropic's API to phrase the answer. The excerpts are capped at 600 characters per transcript turn and shorter for a cited moment, the request is scoped to your own seat and no other seat's content can enter it, and the answer comes back to you alone. But the content leaves Vega at query time, under Vega's key, on a relationship you are not party to. The same is true of the coaching surface.
You already talk to one of these providers — that is where the session happens. What you have no reason to expect, and what we are therefore stating plainly, is that Vega sends material from that session back out to a provider's API, both when it is captured and again every time you ask Vega about it.
14Training
We are not going to write "we never train on your data", because Vega is built to, on the free tier, on consent, and the sentence would be false. Here is the actual rule.
- Paid seats are not in the content pool. No content from a paid seat improves the shared engine, with or without permission. There is no opt-in and no exception.
- Company accounts never enter Vega's training set, on any plan, with no way to opt in. A seat whose type cannot be determined is excluded as well. This is the wall that is enforced in code today.
- For free personal seats, the only record containing content is an anonymised rewrite of a session, never your original words, and it is written only if you have given explicit consent for that specific thing. No such consent exists for anyone today: the screen that would ask you is built and is not yet part of settings, so nobody has been asked and the answer is no for every account. When it is there, the switch that turns it off is the same switch that turns it on.
- Three further records are content-free: where a moment sat in its session, which observable events followed it, and which decisions you made about it. They contain no session text. They have no opt-out today, and section 11 flags that.
- Your raw prompts and replies never enter training under any setting. There is no switch for it, and we will not add one without saying so on this page first.
- None of it is running. Vega's training store is a separate database that is not configured, so at the effective date of this policy every training write is a no-op and nothing has been written to it.
Separately: our model providers may retain and use content sent to their APIs according to their own terms. That is section 13 and the subprocessor list, and it is not under our control today.
15Benchmarks
A benchmark compares you to people who are not you. That makes it the one product surface where your data meets someone else's, so it gets its own rules.
- Opt in only. Nothing of yours enters a cross-customer benchmark unless you turned it on, and turning it off is the same control.
- Structure only. The structure pool in section 4 and nothing else. No prompt text, no reply text, no titles, no summaries, no company names, no personal names.
- A floor of three. No figure describing more than one person is produced unless at least three people contributed to it. Below that the surface says why and shows nothing.
16Seeing who can see what about you
The promise Vega is building towards is that at any moment you can see who can see what about you. This is where it stands, split honestly into the part that is built and the part that is not.
What the product shows you today. Your privacy settings carry a "who can see any of this" panel with three live rows: Vega staff, whose access is described and whose reads of the capture view are logged; your team, showing whether your company's prompt visibility is on or off right now; and the public internet, showing whether your profile is live and how many items are on it. Separately, your company's audit log records every change to that visibility setting and any member can open it; your public profile lists every fact you approved; and your export produces your own record and states inside itself what it leaves out.
What the product cannot show you today. It cannot tell you which specific work moments a named teammate has actually opened, because Vega does not log reads of your work by other members. It cannot tell you which rows a Vega staff member read — the staff log records that a page was opened, not what was on it. It cannot show a per-item answer to "who can see this one", only the three category-level rows above. And it can tell a third party who appears inside your captured content nothing at all, because Vega cannot identify them.
What would close it. A per-item visibility inspector — open any moment, see every audience that can reach it and why — backed by a read-side access log that records team and staff reads, with the entry written before the content renders. Until both exist, the sentence "you can always see who can see what" is a description of three category rows, and this section is written so that nobody mistakes it for more.
17Where your data is, and international transfers
Vega's database and its application servers run in Tokyo, Japan — AWS ap-northeast-1 for the database, and our hosting provider's Tokyo region for the application. There is no customer-selectable residency and there is no European or Turkish region.
Our model providers and our email provider process in the United States and other locations. Content therefore leaves Japan again in the ordinary course of operating the service, and — since section 13 — every time you ask Vega a question.
18How long we keep it
Four things are deleted on a clock. Everything else is kept until you delete it or delete your account.
| What | Kept for |
|---|---|
| Undo tombstones for a moment you deleted | 24 hours |
| Partially uploaded encrypted raw slices | 7 days |
| Records of MCP activity | 14 days |
| Refusal traces | 30 days |
| Sessions, work moments, capsules, contexts, the graph, embeddings | Until you delete them or your account |
| Verbatim prompts and replies you opted into | Until you delete them or your account |
| Company audit logs of visibility changes | For the life of the company account |
| Consent records | Indefinitely — they are the proof you were asked |
| Vega staff action logs | Indefinitely — they are the accountability record |
Backups and our providers' own logs persist for their own periods, and content already sent to a model provider is subject to that provider's retention, not ours.
19Deletion, and what it does not reach
You can delete an individual work moment, delete your personal account, or leave a company. Deleting your account destroys your personal seat and the work hanging off it through the database's cascade rules, behind a typed confirmation. It is deliberately designed so that one person closing their account cannot destroy their company's data: company seats are released rather than destroyed.
Four honest limits, all of which we intend to close:
- Graph nodes and edges have no link back to a seat and are not reached by the cascade, so they survive an account deletion.
- Vega's training store has no delete path. Nothing is written to it today, so nothing survives there today, and that must be fixed before anything ever is.
- Your consent records survive deliberately, reduced to an account identifier, the scope, the sentence and the timestamps — no email, no name, no content. They are the evidence that the processing was lawful, so they outlive the data they authorised.
- Content already sent to a model provider is not ours to delete.
20Your rights
If the GDPR applies to you, you have the right to access your data, correct it, have it erased, restrict or object to processing, receive it in a portable form, and withdraw any consent you gave — withdrawal does not undo processing that already happened lawfully. You can complain to your national supervisory authority.
If KVKK applies to you, Article 11 gives you the right to learn whether your data is processed and to what end, to know the third parties it has gone to at home and abroad, to have it corrected, deleted or destroyed and to have those third parties told, to object to a result produced solely by automated analysis, and to claim damages. You can complain to the Turkish Personal Data Protection Authority.
Vega makes no solely automated decision that produces a legal or similarly significant effect on anyone. Vega's scores and coaching are measurements of a sample of your work, shown to you and — in aggregate, above the floor of three — to your company. They are not an assessment we sell to anyone, and they decide nothing on their own.
How to exercise them. Email help@tryvega.tech. We will respond within one month. Deleting a moment, deleting your account and exporting your own record are all self-serve today; the export is one JSON file and it lists inside itself what it leaves out. Say what you want and we will tell you honestly what we can and cannot produce.
21Security
Traffic is encrypted in transit. Our database provider encrypts at rest. Verbatim prompts and replies get an additional layer: they are encrypted with AES-256-GCM inside Vega's application before the row reaches the database, and the server refuses to store them at all rather than store them unencrypted.
That encryption key is Vega's, not yours. There is one key for every account and no rotation path. The product used to say your raw text was encrypted under a key only you hold. That sentence was wrong and has been corrected.
Vega holds no certification and has had no external security audit. The security page sets out what the code actually does, file by file, and lists what is missing.
22Children
Vega is for working adults. It is not directed at children, and we do not knowingly collect data from anyone under 18. If you believe a child has an account, write to help@tryvega.tech and we will delete it.
23Changes
This document carries a version number and an effective date, both shown at the top. A change to what we collect, who receives it, how long we keep it or what we promise raises the major version and we will ask you to accept it again. Smaller corrections raise the minor version.
We keep every published version, so "what did I agree to, and when" has an exact answer rather than an approximate one.
This is version 2.0, and it is a major change. Version 1.1 described a product that stored, read, trained and compared under one undifferentiated set of promises. This version separates those four acts, states which pool your work falls into and why, and says plainly which of it is running and which is not. If you agreed to an earlier version, we will ask you again.