Vasvel

Pre-launch draft. Production backup retention and applicable international-transfer arrangements require verification before publication.

Privacy Policy

What your library contains, how we use it, and how you stay in control.

Operator and contact

Vasvel is operated by Rauf Maharramov, an individual based in Pittsburgh, Pennsylvania, USA. Contact support@vasvel.com for privacy requests, account help or concerns about your information.

Information we process

  • Account: email, authentication identifiers and preferences. Supabase manages password hashing and sessions.
  • Google sign-in: if you choose Google, we receive your Google account identifier, email address and basic profile information, such as your name and profile picture, to create or authenticate your Vasvel account. We request only identity scopes, not access to Gmail, Google Drive or your contacts. Supabase manages this sign-in connection. We do not use Google sign-in data for advertising or sell it.
  • Your library: selected text, page content, source URLs, titles, available transcripts, notes, images you upload, collections and their memberships. We do not archive original video files.
  • AI features: instructions and questions, summaries, categories, retrieval embeddings, saved working questions, briefs, conversation history and source references.
  • Product activity: opens, revisits, reminders, usage counts and whether a brief is marked used. These support retrieval, usage limits and your activity views.
  • Billing: Stripe customer and subscription identifiers, status, renewal/cancellation information and records needed to manage your plan. Stripe handles payment card details.
  • Support and operation: feedback you submit and technical request/error logs used to operate and protect the service. Hosting providers may process IP addresses and device/request information.

Chrome extension

The extension captures a page, post, selected passage or copied link when you request a save. Website access permissions let it read the requested source and available related images or transcripts. The automatic sign-in script runs on the configured Vasvel website; it does not automatically collect the content of every site you visit. Paste Link & Save reads the clipboard when you choose that action. The extension stores session credentials locally in your browser to keep you signed in and sends requested captures to Vasvel for storage and processing. Treat access to your browser profile as access to your signed-in session.

How we use it

We use this information to authenticate you, preserve and organize your saves, search and retrieve relevant material, generate requested AI output, maintain your workspaces, manage payments, answer support requests and protect the service. Original saved text is kept separately from AI output; AI does not rewrite that original field. If you edit the original yourself, that changes your saved copy.

We do not sell your saved content or make your private library public. Vasvel does not currently use third-party advertising analytics or session replay. Product activity and operational logging are still processing of data; they are described above.

Service providers

  • Supabase: authentication, database and uploaded-image storage.
  • Vercel: hosting and delivery of the web application and server requests.
  • OpenAI: relevant saved content, images or derived visual information, prompts and questions needed for requested AI processing and retrieval embeddings. A request can contain bounded excerpts from multiple relevant saves.
  • Stripe: hosted checkout, payment processing, subscriptions and billing management.
  • Resend: transactional email, research briefs you explicitly opt in to receive (including the question and generated findings), and team notifications for submitted feedback. Authentication email is managed through Supabase's configured email delivery.
  • Cloudflare: website DNS, encrypted backup storage and operational monitoring. Monitoring notifications report service health rather than saved note text.
  • GitHub: code hosting and private automated backup execution. The backup process handles database and stored-file data to create encrypted recovery archives.

Providers process information under their own applicable terms and our service arrangements. Authorized operators may access information where necessary for support, security and service operation. Account access controls restrict one customer from accessing another customer's library; they do not mean no service operator can ever access data.

Chat history and optional ChatGPT connection

Conversations on the AI page are stored in your Vasvel account so you can reopen them. They remain until you delete the conversation or your account. Your account export includes conversation text and source references. Only a bounded recent portion is sent with follow-up questions to control processing costs.

If you connect the Vasvel plugin or Vasvel GPT in ChatGPT, you authorize it to retrieve saved text, titles, source URLs and collections from your Vasvel library when requested. Retrieved content is sent to OpenAI and becomes part of your ChatGPT conversation, governed by your OpenAI account settings and terms. Your ChatGPT features and usage limits apply. A selection link contains a reference, not the saved text, and can only be retrieved through your connected Vasvel account.

If you approve identity permissions, the plugin also shares your account identifier, email address and email verification status with OpenAI to identify your connection. You may separately allow the plugin or GPT to create new text notes when you ask. The connection cannot edit or delete existing notes. You can disconnect it from the AI page; access expires after 90 days. Disconnecting or deleting content in Vasvel does not delete copies already present in ChatGPT. Manage those copies in ChatGPT.

Your choices

Use Settings to change available account preferences, export your library data or permanently delete your account. Export includes saved text and metadata, collections, working questions, saved briefs, usefulness ratings and email schedules; uploaded image binaries are not bundled into the JSON export. Save separate copies of original images you need before deleting the account.

Reminders can be turned off in the application. Collection calendar reminders are optional downloads: once imported, you manage or delete them in your calendar. Where automatic research-brief delivery is available, it is off by default. You can opt in for individual collections, change the schedule, pause it in the workspace or use the unsubscribe link in an email. Delivery uses your brief allowance; unchanged sources and questions do not generate another email. An email already being sent may still arrive after you pause. Security and billing messages serve account operation rather than advertising.

Retention and deletion

We retain your active library while your account exists, including after a paid subscription ends, so you can browse and export it. Deleting your account removes active account records and uploaded images through the application's deletion process and stops active subscriptions. If a required deletion step fails, the application reports an error so the request can be retried.

Historical billing records may remain with Stripe for accounting, dispute and legal requirements. Operational logs and backups have separate provider retention settings; the production schedule must be verified before this policy is published. Deletion from active systems must not be described as instant erasure from every historical backup.

Cookies and security

Authentication cookies keep you signed in. Language and theme preferences remember how you want the application to appear. These features are not advertising tracking. We use account-based access controls and service-provider security features, but cannot promise that any online service is entirely free from security risks. Do not upload information you are not authorized to send to the service or its AI provider.

Privacy requests and location

Email support@vasvel.com to request access, correction or deletion, or to raise another privacy concern. We may need to verify that the request belongs to you. Available rights and response requirements depend on applicable law. Providers may process information outside your country; the operator must verify the applicable contractual safeguards before a broader international launch. This policy does not waive rights you have under local law.

Children and updates

Vasvel is intended for adults aged 18 or older. Contact us if you believe a child has provided personal information. Material changes to this policy will be identified in the application or by email before they take effect. We will not describe a new use of your data as if it had always been part of the service.

Vasvel — Your Personal AI Knowledge Library