Legal
Privacy Policy
Effective date: 2 June 2026
This Privacy Policy explains how Vesmira (“we”, “us”, “our”) collects, uses, stores, and shares your personal information when you use vesmira.ai and related services (collectively the “Service”). We are based in California, United States. This policy reflects U.S. and California privacy law (including the CCPA/CPRA); if you are in the EEA or UK, the GDPR section below also applies to you.
Please read this policy carefully. If you have any questions, contact us.
1. Who We Are
Vesmira is operated from California, United States. We decide how and why personal information is processed (a “business” under the CCPA; a “controller” under the GDPR). Contact us at contact@vesmira.ai with any privacy questions.
2. Information We Collect
We collect the following categories of information:
Account and authentication data
Your email address, collected when you register or sign in. We use passwordless authentication (magic links and one-time codes) delivered to your email. We do not store passwords.
Content you upload
Documents, URLs, text, and HTML files you submit for rendering are stored in a private cloud storage bucket. Rendered HTML outputs are stored against your account until you delete them. This content may contain personal data if you choose to include it.
Sharing and access control data
Email addresses and domain names you add to the share list of a document, so that we can enforce access restrictions and send share notifications.
API keys (BYOK)
If you supply your own Anthropic or OpenAI API key, we store it encrypted at rest using AES-256-GCM. We display only a short preview (first and last few characters) for identification. We never log or expose the full key value after storage.
Personal Access Tokens
We store a SHA-256 hash of each Personal Access Token you create. The raw token is shown only once at creation and is not recoverable from our systems.
Billing data
If you subscribe to a paid plan, payment is processed by our Merchant of Record, Lemon Squeezy. We do not receive or store your full payment card details. We store your subscription status, plan, and the customer/subscription identifiers Lemon Squeezy returns, so we can grant the right level of access.
Usage data
Render counts per calendar month (to enforce free tier limits), total and unique view counts per document, and template preferences.
Technical and session data
Session tokens issued by our authentication provider (Supabase) following successful sign-in. These are stored in your browser and used to authenticate requests. We also receive standard server access logs (IP addresses, request timestamps, user-agent strings) as part of normal hosting operations.
Email delivery data
When a document is shared with a recipient, we send them a notification email containing the document title and a link. Delivery metadata (sent, bounced) may be retained by our email provider.
3. How We Use Your Information
We use your information for the business purposes below. For users in the EEA/UK, the corresponding GDPR legal basis is shown alongside each purpose.
| Purpose | GDPR legal basis (EEA/UK) |
|---|---|
| Authenticating your account and maintaining your session | Performance of contract (Art. 6(1)(b)) |
| Storing and delivering your documents and share links | Performance of contract (Art. 6(1)(b)) |
| Sending share notification emails to recipients you designate | Legitimate interests (Art. 6(1)(f)) — enabling the sharing feature you have explicitly requested |
| Processing content through AI rendering APIs | Performance of contract (Art. 6(1)(b)) |
| Enforcing free tier usage limits | Performance of contract (Art. 6(1)(b)) |
| Storing encrypted API keys on your behalf | Performance of contract (Art. 6(1)(b)) |
| Detecting and preventing fraud, abuse, and security incidents | Legitimate interests (Art. 6(1)(f)) |
| Complying with legal obligations | Legal obligation (Art. 6(1)(c)) |
4. Third-Party Services and Data Sharing
We share your data with the following sub-processors to provide the Service. We enter appropriate data processing agreements with each.
Supabase (Supabase Inc., US)
Our database, authentication, and file storage provider. Your account data, document metadata, share lists, and rendered HTML files are stored on Supabase infrastructure. Supabase participates in the EU-US Data Privacy Framework and provides standard contractual clauses for international transfers.
Anthropic (Anthropic PBC, US)
When rendering via the platform key or your own Anthropic key, the content you submit for rendering is sent to Anthropic’s API. Anthropic’s API usage is governed by their Privacy Policy. We recommend reviewing Anthropic’s data retention terms before submitting sensitive content.
OpenAI (OpenAI OpCo LLC, US) — optional
If you supply an OpenAI API key, content submitted for rendering using that key is processed by OpenAI. This is governed by OpenAI’s Privacy Policy.
Vercel (Vercel Inc., US)
Our hosting and deployment platform. Standard server logs (IP address, request path, timestamp) are collected by Vercel as part of hosting operations.
Email provider
We use an SMTP email service to deliver authentication codes, magic links, and share notifications. Recipient email addresses and email delivery metadata are processed by this provider.
Lemon Squeezy (Merchant of Record) — paid plans only
If you subscribe, Lemon Squeezy processes your payment and the personal/payment information you provide at checkout, and remits applicable taxes. Their handling is governed by Lemon Squeezy’s Privacy Policy.
We do not sell or “share” your personal information (as those terms are defined under the CCPA/CPRA), and we do not share it with advertisers or for cross-context behavioral advertising.
5. International Transfers
We are based in the United States and our infrastructure providers are primarily in the U.S., so your information is processed there. If you access the Service from the EEA or UK, your information is transferred to the United States; where required, such transfers are covered by an appropriate mechanism — Standard Contractual Clauses, the UK Addendum / International Data Transfer Agreement, or the EU-US / UK-US Data Privacy Framework, as applicable. Contact us for details of the safeguards in place.
6. Data Retention
We retain your personal data as follows:
- Account data: retained for as long as your account is active, then deleted within 30 days of account deletion.
- Documents and rendered files: retained until you delete them or your account is deleted.
- Share lists: deleted when the associated document or your account is deleted.
- API keys (encrypted): retained until you remove them from your account settings.
- Access tokens: hashes retained until revoked or your account is deleted.
- Usage counts: retained for 13 months to support billing and limit enforcement, then deleted.
- Server access logs: retained by our hosting provider for up to 30 days.
- Email delivery logs: retained by our email provider per their own retention policy (typically 30–90 days).
We may retain data longer if required by applicable law or to resolve disputes.
7. Cookies and Local Storage
We use the following browser storage:
- Authentication cookies / local storage: Supabase sets session tokens in your browser to maintain your signed-in state. These are strictly necessary for the Service to function.
- Link session storage:when you verify access to a shared document, a session token is stored in your browser’s local storage for up to 7 days so you don’t need to re-verify on the same device.
We do not use advertising cookies, tracking pixels, or third-party analytics.
8. Your Privacy Rights
Your rights depend on where you live. To exercise any of them, contact us at contact@vesmira.ai (we may need to verify your identity first). We will not discriminate against you for exercising your rights.
California residents (CCPA/CPRA)
- Know / access:request the categories and specific pieces of personal information we’ve collected about you.
- Delete: request deletion of your personal information.
- Correct: request correction of inaccurate personal information.
- Opt out of sale/sharing: we do not sell or share personal information, so there is nothing to opt out of.
- Limit sensitive information: we do not use sensitive personal information for purposes that require a limitation right.
EEA / UK residents (GDPR)
- Access: obtain a copy of the personal data we hold about you.
- Rectification: ask us to correct inaccurate or incomplete data.
- Erasure: ask us to delete your data in certain circumstances.
- Restriction: ask us to restrict how we use your data while a dispute is resolved.
- Portability: receive your personal data in a structured, machine-readable format.
- Object: object to processing based on legitimate interests.
- Automated decisions: we do not make automated decisions with legal or similarly significant effects.
You may also lodge a complaint with your local data protection authority (in the UK, the Information Commissioner’s Office, ico.org.uk).
9. Security
We apply appropriate technical and organisational measures to protect your personal data, including:
- AES-256-GCM encryption for stored API keys.
- SHA-256 hashing for Personal Access Tokens — raw values are never stored.
- All data in transit is encrypted using TLS.
- Row-level security policies on our database ensure users can only access their own data.
- Signed, time-limited URLs for accessing stored files.
- Passwordless authentication — no passwords to compromise.
No method of transmission or storage is 100% secure. If you believe your account has been compromised, please contact us immediately.
10. Children
The Service is not directed at children under 13, and we do not knowingly collect personal information from anyone under 13 (consistent with COPPA). If you believe we have inadvertently collected such information, please contact us and we will delete it promptly.
11. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated by email at least 14 days before they take effect. The effective date at the top of this page will always reflect the most recent version.
12. Contact and Complaints
For any privacy-related question or to exercise your rights, contact us at contact@vesmira.ai. We aim to respond within 30 days (or within one calendar month for GDPR requests).
California residents may also contact the California Privacy Protection Agency (cppa.ca.gov) or the California Attorney General. EEA/UK residents may lodge a complaint with their local data protection authority.