Privacy policy
VectorFAQ Privacy Policy
Effective date: September 4, 2026
This policy explains what information VectorFAQ ("we", "us") collects through the VectorFAQ website and service, how we use it, who we share it with and how, how long we keep it, and how we protect it. It applies to visitors to our website, customers who hold a VectorFAQ account, and the end users who ask questions through an endpoint a customer has published.
- Two roles. For website visitors and account holders, VectorFAQ decides how personal information is handled and is the "controller" of that information. For questions that end users submit through a customer's endpoint, the customer decides why and how that information is processed and we process it on the customer's behalf as their service provider (a "processor"). End users with questions about how a specific endpoint handles their information should contact the organization that published it.
- Information we collect.
- Account information. Your name, email address, and, if you sign up with a password, a salted hash of that password (we never store the password itself). If you sign in with Microsoft or Google, we store the identifier and email address the provider returns to us; we do not receive your provider password.
- Session and login records. A server-side session record for each login, holding a hash of the session token, the browser user-agent string, and timestamps of when the session was created, last used, and expires. We also record when you last logged in and when you accepted our Terms of Service.
- Organization and billing records. Your organization's name, plan, subscription status, and the identifiers Stripe assigns to your customer and subscription records. Payment card details are entered on pages hosted by Stripe and are stored by Stripe, not by us; we never see or store your full card number.
- Customer content. The knowledge you add to your workspace: question and answer pairs, uploaded files and spreadsheets, URLs and the pages we crawl from them, authored documents, instructions, excluded topics, escalation rules, and endpoint configuration such as allowed domains.
- End-user questions and answers. For each question served through an endpoint we store the question text, the answer we returned, the outcome, and the time. We do not ask end users for a name or email address, and we do not store their IP address or any device identifier with the question.
- Forms and messages. What you submit through our book-a-demo form (name, company, email, phone, requested time), affiliate invite requests (name, organization, title, email, and your note), and support tickets filed from the portal (subject, category, description, contact preference, and phone number if you choose phone contact).
- Operational logs. Our servers and hosting infrastructure keep standard request logs, which can include IP addresses, request paths, timestamps, and error details. We also keep an append-only audit trail of actions taken by VectorFAQ staff on customer accounts.
- Cookies and browser storage. We use one essential cookie to keep you signed in and a short-lived cookie that protects the Microsoft and Google sign-in flow from forgery. Both are HTTP-only and are not used for tracking. Your browser's local storage remembers interface choices such as the endpoint you last selected. We do not use analytics cookies, advertising cookies, or any third-party tracking scripts on the website, the portal, or the embeddable widget.
- How we use information. We use the information above to:
- create and secure your account and keep you signed in;
- build search indexes from your customer content and generate answers to end-user questions from it;
- show you reporting on what your endpoint was asked and how it answered, so you can improve your knowledge;
- run your subscription: trials, invoices, plan limits, and usage metering;
- send transactional email such as verification links, password resets, team invitations, and billing notices;
- respond to demo requests, affiliate requests, and support tickets;
- detect abuse, enforce usage limits, investigate security incidents, and keep the service running; and
- comply with legal obligations and enforce our agreements.
- AI processing. To answer questions, we convert your approved content and each incoming question into numerical embeddings and, when no approved answer matches, send the relevant excerpts of your content together with the question to a large language model to draft a grounded answer. This processing runs on Amazon Bedrock inside our own AWS account. Under AWS's Bedrock service terms, inputs and outputs are not stored by AWS for training and are not shared with model providers.
- Who we share information with. We do not sell personal information and we do not share it for targeted advertising. We disclose information only to the following parties:
- Amazon Web Services (AWS), which hosts the entire service: our application servers, database, file storage, content delivery network, outbound email delivery, and the Bedrock AI models described above. All information we hold is stored with AWS in the United States.
- Stripe, our payment processor, which receives your email address, your organization's name, and the payment details you enter when you start a subscription, and returns subscription status and invoice records to us. Stripe's own privacy policy governs its use of that information.
- Microsoft and Google, only if you choose to sign in with them. The provider learns that you are signing in to VectorFAQ and sends us your identifier and email address.
- Your own organization. Administrators and members of your workspace can see the names and email addresses of other members, all customer content, and the end-user questions and answers served by the organization's endpoints.
- Legal and corporate. Authorities, when required by law or a valid legal request, or to protect the rights and safety of VectorFAQ, our customers, or others; and a successor in the event of a merger, acquisition, or sale of assets, subject to this policy.
- How disclosures happen. Information reaches these parties only through encrypted connections, under written terms that limit them to providing their service to us. Payment details go directly from your browser to Stripe's hosted checkout and billing pages and never pass through our servers. Data sent to AWS services stays within our AWS account and its API calls are authenticated with scoped, short-lived credentials rather than shared keys. VectorFAQ staff access customer accounts only to provide support, billing, or security, and every such action is written to the audit trail.
- Security practices. We protect information with measures that include:
- encryption in transit: every connection to the website, portal, widget, and API uses HTTPS;
- encryption at rest for our database and its automated backups, which are retained for seven days;
- password hashing with Argon2id, HTTP-only session cookies backed by server-side, individually revocable sessions, and email verification on signup;
- role-based access control that scopes every member to their organization's projects, with staff actions logged to an append-only audit trail;
- per-endpoint allowed-domain restrictions and a browser content security policy that limit where your endpoint can be embedded, plus rate limiting on public routes;
- least-privilege cloud permissions for each service component, with infrastructure managed as code and reviewed before changes deploy; and
- operational logs kept for about two weeks and then automatically deleted.
- Retention. We keep account information, organization records, and customer content for as long as your account is active. When an account or organization closes, we may delete its content 30 days later, as described in our Terms of Service. End-user questions and answers are kept while the endpoint that served them exists, so that reporting stays complete; deleting an endpoint deletes its question history. Cached answers are cleared whenever the knowledge that produced them changes and expire after seven days regardless. Billing records are retained as long as tax and accounting law requires. Support tickets, demo requests, and affiliate requests are kept while we need them to respond and for our records afterward.
- Your choices and rights. You can update your name and password in account settings and manage your organization's members and content in the portal. You may ask us to access, correct, export, or delete the personal information we hold about you, or to close your account, by contacting us through the Contact options in the footer; we will verify your identity before acting. Depending on where you live, you may also have the right to object to or restrict certain processing and to complain to a data protection authority. We send only transactional email tied to your account and do not send marketing email. End users should direct requests about their questions to the organization that operates the endpoint; we will assist that organization in responding.
- Children. The website and service are intended for business use by adults. We do not knowingly collect personal information from anyone under 18, and customers may not direct endpoints at children.
- International transfers. VectorFAQ operates from the United States and stores information there. If you use the service from outside the United States, your information is transferred to and processed in the United States, where privacy laws may differ from those of your country.
- Changes to this policy. We may update this policy as the service changes. We will post the new version here with a new effective date and, for material changes, notify account holders by email or in the portal before the changes take effect.
- Contact. Questions or requests about this policy can be sent through the Contact options in the site footer.