This Privacy Policy explains how Vectra Cloud (“we”, “us”) collects, uses, stores, and shares information when you use our website, dashboard, APIs, and managed AI coding sandboxes (the “Service”). By using the Service, you acknowledge this policy.
1. Data controller / contact
For privacy requests, email hello@vectra.cloud. We aim to respond within a reasonable time.
2. Information we collect
Account and identity
- Email address and password (stored as a secure hash — we do not store plaintext passwords).
- Session cookies / tokens used to keep you signed in.
- Account identifiers and timestamps (created, last login where recorded).
Billing
- Payment status, plan/instance ids, paid-until dates, order references, currency, and amounts associated with your account.
- Card and bank details are processed by Razorpay (or our payment partner). We do not store full card numbers on our servers.
Service configuration
- Instance metadata (name, status, lifecycle events, pairing mode, Telegram bot configuration as you provide it).
- Secrets you supply (for example LLM API keys, bot tokens) so we can write them into your sandbox and run setup. Treat these as sensitive; only paste keys you control.
Technical and usage
- IP address, user agent, approximate location from IP, request logs, and error logs.
- Dashboard and API activity needed for security, abuse prevention, and support.
Sandbox content
- Code, files, agent memory, chat-related data, and processes inside your sandbox are processed to provide the Service. We do not use Your Content to train public foundation models. Third-party AI providers you configure may process prompts under their own policies.
3. How we use information
- Create and secure accounts; authenticate sessions.
- Provision, manage, pause, wake, and destroy sandboxes you request.
- Process payments, prevent fraud, and fulfill access periods.
- Provide support, respond to abuse reports, and enforce our Terms.
- Operate, debug, and improve reliability and security of the Service.
- Send service-related messages (security, billing, material policy changes).
- Comply with law and lawful requests.
4. Legal bases (where applicable)
Depending on your location, we rely on: performance of a contract (providing the Service you request); legitimate interests (security, fraud prevention, product improvement that does not override your rights); consent (where required, e.g. optional marketing); and legal obligation.
5. Sharing
We share data only as needed:
- Infrastructure providers — cloud hosts, database (e.g. MongoDB Atlas), logging, and sandbox compute partners that process data on our instructions.
- Payment processors — Razorpay and banks for checkout, webhooks, and dispute handling.
- You-directed third parties — LLM APIs, Telegram, and other services you configure; their processing is under your and their terms.
- Legal and safety — when required by law, to protect rights, or in connection with a merger/acquisition with appropriate safeguards.
We do not sell your personal information.
6. International transfers
Data may be processed in India and other countries where our providers operate (for example cloud regions). Where required, we use appropriate safeguards for cross-border transfers.
7. Retention
- Account data: while your account is active and for a reasonable period after closure for legal, billing, and security needs.
- Payment records: as required by tax and financial regulations.
- Logs: typically short operational windows unless needed for security investigations.
- Destroyed sandboxes: content is deleted according to provider lifecycle; backups may lag for a short period.
8. Security
We use industry-standard measures such as HTTPS, hashed passwords, access controls, and isolation of customer environments. No method of transmission or storage is 100% secure. You must protect API keys and bot tokens you paste into the Service.
9. Cookies and similar tech
We use essential cookies / local storage for authentication and session management. We do not use advertising trackers as a core part of the product. Browser settings can block cookies; some features may stop working if sessions cannot be stored.
10. Your rights
Depending on applicable law (including Indian IT rules and, where they apply, GDPR-like rights), you may request access, correction, deletion, or export of personal data we hold, or object to certain processing. Contact hello@vectra.cloud. We may need to verify your identity and retain data where law requires.
11. Children
The Service is not directed to children under 18. We do not knowingly collect personal data from children. If you believe a child has registered, contact us to delete the account.
12. Changes
We may update this Privacy Policy. The “Last updated” date at the top will change when we do. Continued use after updates means you accept the revised policy.