Valori LogoValori

Privacy Policy

Last updated: 2026-09-03

Draft — pending legal review

This document contains placeholders marked [LEGAL INPUT REQUIRED]. It has not been reviewed by counsel and must not be relied upon as the final agreement.

1. Who we are

[LEGAL INPUT REQUIRED: official registered legal entity name] (“Valori”, “we”, “us”) operates Valori Cloud at valori.systems. This policy explains what personal data we process, why, and the choices you have. For privacy questions or requests, contact [LEGAL INPUT REQUIRED: privacy / data-request contact email (e.g. privacy@valori.systems)].

2. Information we collect

  • Account information — name, email address, and organization name, provided by you or by your identity provider (Google or GitHub) when you sign in.
  • Authentication information — session tokens and login events (including timestamps and IP address) used to keep your account secure and detect abuse.
  • Project and API usage — project and collection names, request counts, rate-limit state, and operational metrics used to run the Service and enforce plan limits.
  • Customer Data — the vectors, metadata, and text you store in your projects. We treat this as confidential and process it only to provide the Service; we do not use it to train models or for advertising.
  • Logs — application and server logs, which may include IP addresses, user agents, and request metadata, retained for security and debugging.
  • Billing information — for paid plans, billing contact details and a payment-method reference. Card details are handled by Stripe and are not stored by Valori.
  • Support and feedback — messages you send us and any feedback you submit in-product.

3. How we use personal data

  • To provide, maintain, and secure the Service and your account.
  • To enforce plan limits, rate limits, and our Acceptable Use Policy.
  • To process payments and send billing and transactional communications.
  • To detect, investigate, and prevent fraud, abuse, and security incidents.
  • To respond to support requests and to improve the Service.
  • To comply with legal obligations.

4. Legal bases (EEA/UK users)

Where the UK GDPR or EU GDPR applies, we rely on: performance of a contract (to provide the Service); legitimate interests (security, abuse prevention, product improvement); consent (where specifically requested); and legal obligation (tax and accounting records).

5. Service providers and subprocessors

We share personal data with vendors that process it on our behalf under contract:

  • SupabaseAuthentication and application database
  • StripePayment processing and billing
  • VercelWeb application hosting and CDN
  • [LEGAL INPUT REQUIRED: data-plane / vector-node compute host]Hosting customer vector database instances

We do not sell personal data and do not share it with third parties for their own marketing.

6. International transfers

Personal data may be processed in countries other than where you are located. Where required, transfers of EEA/UK personal data outside the EEA/UK are made under [LEGAL INPUT REQUIRED: international data-transfer mechanism (e.g. EU SCCs)].

7. Data retention

  • Account data: [LEGAL INPUT REQUIRED: account data retention period after deletion request].
  • Logs and IP addresses: [LEGAL INPUT REQUIRED: operational log / IP-address retention period].
  • Billing and invoice records: [LEGAL INPUT REQUIRED: billing record retention period (often set by tax law, e.g. 7 years)].
  • Customer Data: retained while your project exists; deleted on project deletion, subject to routine backup rotation.

8. Security

We use encryption in transit, access controls, row-level security in our database, and a cryptographically verifiable audit chain for stored state. No system is perfectly secure; you are responsible for protecting your credentials and API keys.

9. Your rights

Depending on your location, you may have rights to access, correct, delete, export, or restrict processing of your personal data, and to object to certain processing. To exercise these rights, contact [LEGAL INPUT REQUIRED: privacy / data-request contact email (e.g. privacy@valori.systems)]. You may also lodge a complaint with your local data protection authority. Account deletion and data export requests are handled manually during the beta while self-service tooling is being built.

10. Cookies

We use only strictly necessary cookies. See the Cookie Policy for details.

11. Children

The Service is not directed to children under 16 and we do not knowingly collect their personal data.

12. Changes to this policy

We may update this policy. Material changes will be notified by email or an in-product notice. The “last updated” date above reflects the current version.

13. Contact

[LEGAL INPUT REQUIRED: official registered legal entity name]
[LEGAL INPUT REQUIRED: registered business address]
[LEGAL INPUT REQUIRED: privacy / data-request contact email (e.g. privacy@valori.systems)]