Legal
Privacy Policy
This policy explains what AhuraSense Ltd collects when you use the Vani API and console, why, and what you can do about it. We collect only what is needed to run the service.
Last updated 13 September 2026
What we collect
We collect the following categories of data.
- Account details — email address, username, hashed password, and session tokens.
- Operational telemetry — endpoints called, timestamps, token counts, and error codes.
- Billing metadata — payment method references and invoices, held by our payment provider.
- First-party product analytics — only after you opt in: coarse page categories, page-view/engagement/heartbeat and explicit signup/upgrade intent events, bounded visible duration and (where explicitly supplied) known free-model usage. Prompt text, completions, email, IP address, account IDs, request IDs and raw events are excluded.
- Support correspondence — messages and files you choose to send us.
How we use it
To operate and secure authentication, API keys, and billing. To show usage and cost in your workspace. To understand how the console is used and improve reliability. To send transactional notices and answer support requests.
We do not sell your data. First-party rollups are retained for up to 35 days, then pruned. Anonymous daily HMAC session hashes rotate each UTC day, so the aggregate cannot follow a person across days. Conversion, retention, revenue and unique-user attribution are not available from these rollups.
Retention and security
Customer content is processed in memory and discarded when the request completes. Prompts and system instructions, model outputs, image inputs, and conversation history are never written to storage — we keep no server-side chat logs. Payloads are never used for model training.
Operational telemetry — token counts, timestamps, model IDs, and HTTP status codes — is retained for your account's lifetime plus any legally required period, for billing, fraud prevention, and reliability.
API keys and session tokens are encrypted at rest. Passwords are hashed using an industry-standard algorithm.
Your choices
You can request access to, or export of, your account data. You can request deletion of your account and keys, though billing records may be retained where the law requires it. You can unsubscribe from non-essential email at any time.
To make a request, contact [email protected].
Third parties
We use a PCI-DSS compliant payment processor, an OAuth identity provider for optional single sign-on, and cloud hosting providers engaged under data processing terms. A current list of sub-processors is available on request.
Changes to this policy
We may update this policy as the service changes. Where a change materially affects how we handle your data, we will give notice before it takes effect.
Contact
Privacy questions can go to [email protected].
AhuraSense Ltd, registered in England and Wales, company number 16915427.