VectorAxis
Legal

Privacy Policy

Last updated: July 1, 2026

VectorAxis is a product of GK Labs Inc. ("GK Labs", "VectorAxis", "we", "us"). This Privacy Policy describes what data we collect through the VectorAxis platform (the "Service"), how we use it, and the choices available to you. It should be read alongside our Terms of Service.

1. Scope

This policy applies to data processed through the VectorAxis dashboard, API, and documentation. It does not cover third-party sites we link to, or the separate privacy practices of LLM providers you connect to your own account (see Section 4).

2. Data We Collect

  • Account & identity data — name, email, and organization/workspace membership, managed via our authentication provider (AWS Cognito).
  • Customer Content — the prompts and messages you send through the chat completions API and the responses returned. In our hosted service, request logs capture operational metadata about each request (see the next item), not the content of your prompts or responses. Customer Content is persisted only when you opt into caching on a request, in which case it is stored in our exact-match or semantic response cache (the latter alongside a vector embedding of the request) so it can be served on a future matching request.
  • Request metadata — model, token counts, cost, latency, cache status, retry/fallback details, and similar operational fields, recorded for every request for observability and analytics.
  • Credentials — BYOK provider credentials are encrypted at rest (AES-256-GCM) and only a truncated hint is ever exposed; platform API keys (va_*) are stored as a one-way SHA-256 hash, never as plaintext.
  • Billing data — subscription, credit balance, and transaction records. Payment card details are handled directly by Stripe; we do not store card numbers.

We do not embed third-party marketing or advertising trackers (e.g. ad pixels, marketing analytics scripts) in the Service.

3. How We Use Data

  • To operate the Service — routing, caching, guardrail checks, and returning responses;
  • To bill for Platform-key usage and manage credit balances via Stripe;
  • To provide the observability, logging, and analytics features you configure;
  • To maintain security, investigate abuse, and prevent fraud; and
  • To comply with legal obligations.

Where we generate aggregated or de-identified statistics (e.g. product usage trends), they are not used to re-identify individual customers.

4. Sub-Processors & Third Parties

  • AWS — authentication (Cognito) and infrastructure hosting, including our PostgreSQL/pgvector data stores.
  • LLM providers (e.g. OpenAI, Anthropic, and other providers you configure) — when a request is routed to one, the Customer Content in that request is sent to and processed by that provider under its own terms and privacy policy, which we do not control.
  • Stripe — payment processing for Platform-key credit top-ups and refunds.

5. Data Retention

Request logs are retained according to your plan's configured retention window; unless your plan specifies a finite window, logs are retained indefinitely until you delete them or close your account. Cached responses expire automatically according to their configured TTL. Encrypted credentials are retained until you delete the associated key. Billing records are retained as required for accounting and legal purposes, including for the duration any credit balance remains outstanding (see Section 7).

6. Security

We encrypt BYOK provider credentials at rest with AES-256-GCM, store platform API keys only as a SHA-256 hash, encrypt data in transit with TLS, and never write credential values (e.g. x-api-key) to request logs. No method of transmission or storage is perfectly secure, and we cannot guarantee absolute security.

7. Your Rights

You may request access to, correction of, export of, or deletion of your personal data by contacting [email protected]. Deleting your account also deletes your workspace data, subject to one exception: we cannot delete an account or organization while it holds an unrefunded Platform-key credit balance — that balance must be fully refunded to you first, as described in our Terms of Service and Platform Policies.

8. International Data Transfers

VectorAxis's infrastructure is split across multiple regions for reliability and performance. Depending on your organization's configuration and the LLM providers you connect, data may be processed in a region or country other than your own. We take steps to ensure appropriate safeguards are applied to any such transfer.

9. Children's Privacy

The Service is not directed at, and we do not knowingly collect personal data from, individuals under 18. If you believe a child has provided us personal data, contact us and we will delete it.

10. Changes to This Policy

We may update this policy from time to time. We will update the "Last updated" date above when we do, and where a change is material we will provide additional notice.

11. Contact

Questions about this policy or requests regarding your data can be sent to [email protected] or by mail to:

GK Labs Inc.
4631 Penhallow Road
Mississauga, Ontario L5V 1E8
Canada