Vanguard AI Vanguard AI Vanguard AI

Legal

Privacy Policy

This policy explains what personal data Vanguard Initiative Co., Ltd. collects when you use Vanguard AI, why we hold it, who else receives it, and how long we keep it. It is written to be read: the tables below are the substance, not an appendix.

Version 1.0 · Last updated 2026-08-31

On this page
  1. 1. Who we are and what this covers
  2. 2. The short version
  3. 3. What we collect
  4. 4. How we use it, and on what basis
  5. 5. How your content reaches AI providers
  6. 6. Who else receives your data
  7. 7. How long we keep it
  8. 8. Your choices and controls
  9. 9. Cookies and local storage
  10. 10. The desktop application
  11. 11. How we protect it
  12. 12. International transfers
  13. 13. Children
  14. 14. Your rights
  15. 15. Changes to this policy
  16. 16. Language
  17. 17. Contact us

On this page

  1. 1. Who we are and what this covers
  2. 2. The short version
  3. 3. What we collect
  4. 4. How we use it, and on what basis
  5. 5. How your content reaches AI providers
  6. 6. Who else receives your data
  7. 7. How long we keep it
  8. 8. Your choices and controls
  9. 9. Cookies and local storage
  10. 10. The desktop application
  11. 11. How we protect it
  12. 12. International transfers
  13. 13. Children
  14. 14. Your rights
  15. 15. Changes to this policy
  16. 16. Language
  17. 17. Contact us

1. Who we are and what this covers

Vanguard Initiative Co., Ltd., registered office REGISTERED_ADDRESS, is the controller of the personal data described here. Contact us about privacy at PRIVACY_EMAIL.

This policy covers https://ai.vanguardinitiative.com, our public API and our desktop application. It does not cover third-party websites we link to, or a website you ask AI CMO to analyse.

If you use Vanguard AI through an Organisation created by someone else, that Organisation controls its own data and its administrators can see activity carried out under it.

2. The short version

QuestionAnswer
Do you sell my data?No. We do not sell personal data or share it for advertising.
Do you train AI models on my content?No. We do not use your content to train models, and the providers we send it to process it to answer your request under their API terms.
Is my uploaded file kept?Not by default. Source media is discarded after processing unless you opt in per upload. The result of the job — the transcript, extracted text or summary — is kept until you delete it.
Who else sees my content?The AI providers that run the model you chose, and the infrastructure providers listed in section 6.
Do you use tracking or advertising cookies?No. We run no analytics, no advertising and no tracking pixels.
Can I delete things?Yes — conversations, jobs, documents, assistant memories and API keys, at any time. Account closure is by request to us.

3. What we collect

Account data. Your email address, your password (stored only as a hash), and optionally your name, an organisation name and a profile picture. If you sign in with Google we receive your Google account identifier, email address, name and profile picture. We also record your role in your Organisation and your plan.

Identity verification data. If you apply to verify your Organisation, we collect whether you are applying as an individual or an organisation, your full name, the registered company name where applicable, a phone number, which identity document you are supplying, and an image of that document — a national identity card, family book or passport — plus a business registration certificate for organisations.

Content you submit. Everything you send to the Services in order to get a result back:

  • Chat messages, prompts, system prompts and file attachments. Attachments are not restricted by file type.
  • Images and PDFs you submit to OCR, which by design may be passports, identity cards, driving licences, bank cards or registration certificates.
  • Audio and video you submit for transcription, and the text you submit for speech synthesis.
  • Documents you add to a Project, and the text extracted from them.
  • Agents, skills and prompts you author.

Voice Live data. While a session is running, your microphone audio and — only if you turn the camera on — still images from your camera. We store the session record and the transcript. If you use the ANNA persona, we also store long-term memories it derives from your conversations, held as short facts, preferences and traits.

AI CMO data. The website address you nominate, content crawled from it, competitor information discovered from it, and performance measurements for its pages.

Usage and billing data. For each call: the service used, credits spent, latency, status and time. Plus your credit balance and ledger, payments, and invoices. We do not receive or store card numbers — payment is settled by bank QR.

Technical data. Cookies as listed in section 9, and the network information any web request carries, including your IP address, which our hosting and proxy providers process to deliver and protect the service. Your browser user-agent is read to pick the right installer on the download page.

Your storage credentials. If you connect your own storage bucket, we store its access key and secret so we can write to it. They are encrypted at rest.

4. How we use it, and on what basis

PurposeData usedBasis
Providing the Services — running your request and returning a resultContent you submit, account dataPerformance of our contract with you
Keeping your history so you can return to itConversations, jobs, transcripts, projectsPerformance of our contract
Billing, credits and invoicingUsage events, ledger, paymentsPerformance of our contract; legal obligation for records
Verifying identity where requiredVerification dataLegal obligation and our legitimate interest in preventing fraud
Security, abuse prevention and enforcing acceptable useUsage data, technical data, content where a report requires reviewOur legitimate interest in a safe service
Support you have asked forAccount data and the records relevant to your questionPerformance of our contract
Improving the ServicesAggregated and statistical usage dataOur legitimate interest
Service messages about your account or these policiesAccount dataPerformance of our contract

We do not use your content to train AI models — not our own, and we do not supply it to providers for their model training. Providers receive it to compute your result under their API terms. We do not sell personal data, and we do not use it for advertising or profiling.

5. How your content reaches AI providers

The Services do not run the models themselves. To answer your request we transmit the relevant Input to the provider that operates the model, receive the Output, and return it to you. Which provider receives it depends on the service and, for chat, on the model you select.

Some chat tools reach further out on your behalf. Web search sends a query derived from your conversation to a search provider, and URL fetching retrieves a page you or the model nominates. Content returned that way is third-party content we do not control.

Voice Live is different, and you should know how. When a session starts, your browser opens a connection to Google’s Gemini Live service using a short-lived token we issue, then streams your microphone audio and any camera images to Google directly. On that leg the media does not pass through our servers. We receive and store the session record and transcript. Google processes the live stream under its own terms.

6. Who else receives your data

We use the following providers. We share only what each needs, and we do not authorise any of them to use your data for their own purposes.

ProviderRoleWhat it receives
Google — GeminiChat, OCR, transcription and speech synthesisThe prompts, documents, images, audio or text for that request
Google — Gemini LiveVoice Live sessionsMicrophone audio and camera images, streamed from your browser
Google — OAuthSign in with GoogleAuthentication exchange; returns your identifier, email, name and picture
Google — PageSpeed InsightsPerformance data for AI CMOThe website address you nominated
YouTube (Google)Music playback inside Voice LiveYour IP address and player interactions, if you play music
OpenAIChat models you selectThe conversation and attachments sent to that model
AnthropicChat models you selectThe conversation and attachments sent to that model
VercelApplication hosting, Singapore regionRequest data, including IP address
CloudflareProxy and protection in front of our APIRequest data, including IP address
Object storage providerStoring files when you opt inThe files you chose to store. If you connect your own bucket, they go there instead
Indochina BankSettling credit top-ups by QRPayment reference and amount
GitHubHosting desktop installersYour IP address when you download the desktop app

We may also disclose data to professional advisers, to an acquirer if the business is sold, or to an authority where the law requires it. If we are legally able to tell you first, we will.

7. How long we keep it

DataRetention
Account recordWhile your account is open
Sign-in session cookie7 days
Google sign-in state cookies10 minutes, single use
Uploaded source media — storage set to "none" (the default)Discarded after processing; never written to storage
Stored media and artifacts — storage set to "platform"Until the expiry you set, capped at 24 hours
Stored files — your own bucketHeld in your bucket under your own rules; we do not delete them
Job records and their results — transcripts, extracted text, summariesUntil you delete the job
Chat conversations, messages and attachmentsUntil you delete them
Voice session records and transcriptsUntil you delete the associated conversation
ANNA long-term memoriesUntil you delete them. Capped at 200 per user; beyond that the least-used are pruned
Agent run event logs7 days
Rate-limit counters1 hour
Usage-cap counters62 days
Usage events used for billingKept as a billing record
Credit ledger, payments and invoicesKept as financial records for as long as the law requires
Identity verification documentsUntil purged after review — KYC_RETENTION_PERIOD. The decision record outlives the files
Back-office audit records of administrator actionsKept as a security record

Choosing storage "none" means the file you uploaded is not retained. The job and its result — for example the transcript of your audio, or the fields read out of your document — are saved to your history so you can open them again, and stay there until you delete them.

8. Your choices and controls

  • Storage, per upload. Choose "none" to have the source discarded after processing, "platform" for a time-limited cache, or your own bucket.
  • Delete your history. Conversations, jobs, projects and project documents can be deleted from the application; deleting a job also deletes any stored source and output file.
  • Delete assistant memories. Settings shows everything ANNA has remembered about you. Remove them one at a time or all at once.
  • Revoke API keys at any time; a revoked key stops working immediately.
  • Camera and microphone are only used while a Voice Live session is active and you have granted the browser permission. Revoke it in your browser at any time.
  • Language cookie and sidebar preference can be cleared through your browser.

To close your account, or to ask us to purge verification documents, write to PRIVACY_EMAIL — these are handled by us rather than self-service today.

9. Cookies and local storage

We use only the cookies needed to make the service work. There is no analytics, advertising or tracking cookie on this site, and no third-party script runs on our pages except where noted below.

NamePurposeDuration
vanguard_ai_sessionKeeps you signed in7 days
vanguard_ai_oauth_stateProtects Google sign-in against cross-site request forgery10 minutes
vanguard_ai_oauth_verifierCompletes the Google sign-in exchange securely10 minutes
vanguard_ai_localeRemembers whether you chose English, Lao or ThaiPersistent until cleared
sidebar_stateRemembers whether the sidebar is collapsed7 days

Your browser also stores a small amount of data locally: your light or dark theme choice, your Voice Live responsiveness setting, and drafts of forms you have not submitted. This stays on your device.

One third party can set cookies. If you play music during a Voice Live session, an embedded YouTube player is loaded and Google may set cookies through it. Nothing else on the site loads a third-party embed. Do not start music playback if you would rather that did not happen.

A separate cookie, vanguard_ai_admin, applies only to our own staff signing in to the back office. It is never set on a customer session.

10. The desktop application

The desktop application behaves like the website, with two differences worth stating plainly.

  • It caches data on your device so it can work offline. The cache includes your account details, credit balance and the contents of your conversations, and is written as plain, unencrypted files in the application’s data folder. Anyone with access to your user account on that device can read it. Use full-disk encryption and a device password.
  • Screen capture. If you use the capture shortcut, the application takes an image of the screen region you select — which may include other applications — and sends it to our OCR service. The recognised text is placed on your clipboard. This happens only when you trigger it, and on macOS requires the screen recording permission you grant to the app.

11. How we protect it

  • Traffic is encrypted in transit.
  • Passwords are stored as hashes; API keys are stored as hashes and shown to you only once.
  • Session cookies are HTTP-only, so page scripts cannot read them.
  • Credentials for a storage bucket you connect are encrypted at rest.
  • Verification documents are never returned to a tenant. A reviewing administrator opens them through a link that expires after five minutes, and administrator actions are recorded in an audit log that captures who acted, from what address, and when.
  • Data is separated by Organisation, and a request is scoped to the Organisation its credential belongs to.

No service can promise perfect security. If a breach affects your personal data and is likely to present a risk to you, we will notify you and any regulator we are required to notify, without undue delay.

12. International transfers

We are based in the Lao People’s Democratic Republic, but the providers in section 6 operate outside it. Our application is hosted in Singapore, and the AI providers process requests in the United States and other countries. Using the Services necessarily involves transferring your content to those countries, which may not offer the same legal protections as your own. Where the law requires a transfer safeguard, we rely on our providers’ standard contractual terms.

13. Children

The Services are not intended for anyone under MIN_AGE, and we do not knowingly collect their personal data. If you believe a child has given us personal data, write to PRIVACY_EMAIL and we will delete it. Do not submit a child’s identity documents or recordings to the Services.

14. Your rights

Depending on where you live, you may have the right to ask us to give you a copy of your personal data, correct it, delete it, restrict or object to how we use it, or provide it in a portable form. You may also withdraw a consent you gave, without affecting what we did before you withdrew it.

Much of this you can do yourself in the application — see section 8. For anything else, write to PRIVACY_EMAIL. We will respond within the time the applicable law allows, and we may need to verify your identity first. If you are unhappy with our response you may complain to your local data protection authority.

15. Changes to this policy

We will update this policy as the Services change. For a material change we will give at least NOTICE_PERIOD_DAYS days’ notice by email or in the application. The version and date at the top always identify the current text.

16. Language

This policy is published in English, Lao and Thai. The English version is the controlling text. The Lao and Thai versions are provided for convenience; where they differ, the English version prevails to the extent permitted by law.

17. Contact us

Privacy questions and rights requests: PRIVACY_EMAIL. General support: SUPPORT_EMAIL.

Vanguard Initiative Co., Ltd., REGISTERED_ADDRESS. Company website: https://www.vanguardinitiative.com.

Vanguard AI Vanguard AI Vanguard AI
Back to home Terms Privacy Docs