01Who we are
Vectorless runs the retrieval service at vectorless.store: the dashboard at app.vectorless.store, the API at api.vectorless.store and the MCP server at mcp.vectorless.store. This policy covers what those services collect and what we do with it. It does not cover the open-source engine when you run it yourself; that copy sends us nothing.
Questions go to privacy@vectorless.store.
02What we collect
- Your account. Name, email address and a hashed password. If you sign in with Google or GitHub, we receive your name, your verified email address and your profile picture. We never see your Google or GitHub password.
- What you upload. The documents you add, the structure and section text we extract from them, and page images we render so answers can cite the exact page.
- What you ask. Questions sent to the API, the dashboard or an AI assistant connected over MCP, and the answers and citations returned.
- Usage records. Which operations ran, when, how long they took and whether they succeeded, so we can bill accurately, enforce plan limits and fix failures.
- Billing details. Plan and invoice history. Card details go straight to our payment provider and never reach our servers.
We do not run advertising or third-party analytics trackers, and we do not buy data about you.
03Google and GitHub sign-in
Signing in with Google requests only the openid, email and profile scopes. Signing in with GitHub requests read:user and user:email. We use the result for one purpose: to create your account or sign you in to it. We accept an email address only when the provider confirms it is verified.
Vectorless's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We do not sell this data, use it for advertising, or use it to train AI models, and no person reads it except to keep your account secure or when the law requires it.
04How we use it
- To index your documents and answer questions about them, with citations back to the source.
- To run your account: sign-in, API keys, teams, plan limits and billing.
- To keep the service secure, investigate abuse and fix failures.
- To email you about your account, such as password resets and changes to these terms.
05Your documents are not training data
We do not train or fine-tune any model on your documents, your questions or the answers. The model provider that processes them on our behalf receives them through its commercial API, under terms that bar it from training on them.
06Who processes it for us
We share data only with the providers that run parts of the service, and only what each one needs:
- Google Cloud (United States, us-central1) hosts the service, the database and the files you upload.
- Anthropic receives document text while it is indexed, and receives questions together with the relevant passages to produce answers.
- Polar processes payments for paid plans as merchant of record.
- Google and GitHub authenticate you, if you choose to sign in with them.
If you connect an AI assistant to Vectorless over MCP, that assistant receives the answers it asks for. You choose which assistants to connect and can revoke any of them from the dashboard. We do not sell personal data, and we disclose it to authorities only when the law requires it.
08How long we keep it
- Documents stay until you delete them. Deleting a document removes the uploaded file, its index and its rendered pages. Deleting a store or an organisation does the same for every document in it.
- You can delete your account under Settings → Account. That removes your profile, sign-in methods and API keys, and every document in the organisations you own. If you cannot sign in, email privacy@vectorless.store from the account's address and we complete it within 30 days.
- Usage and audit records outlive a deleted account without the link to it. We keep them for billing and security.
- Operational logs are kept for 30 days.
- Invoices and billing records are kept as long as tax law requires.
09Your rights
You can ask for a copy of your data, ask us to correct or delete it, or object to how we use it. Wherever you live, email privacy@vectorless.store and we reply within 30 days. If you are in the UK or the EU, you can also complain to your data protection authority.
10Security
Traffic is encrypted with TLS, and data is encrypted at rest by Google Cloud. Passwords are stored as hashes. API keys are shown once and stored as hashes. Secrets live in Google Secret Manager, and only the services that need each one can read it. Every organisation's documents are kept apart by account at every query.
11Changes
If we change this policy in a way that affects you, we will email account holders before the change takes effect. The date at the top shows the latest version. See also the terms of service.
Read this with our terms of service.