Privacy Policy
Effective date: September 4, 2026
We collect what is needed to run Vigil, we do not sell your data, and you can export the current workspace data described below.
1. Data we collect
- Account data — your name and email address, used for sign-in and service messages.
- Workspace content — the sources, notes, decisions, assumptions, wiki, and briefs you create. Processed solely to provide the service to you.
- Billing data — handled by Stripe, our payment processor. We never see or store your full card details; we keep only what Stripe shares with us to manage your subscription (plan, status, invoices).
- Usage data — basic operational logs and AI token usage, kept to enforce plan limits, prevent abuse, and debug problems.
- Share-link access records — when someone opens a brief you shared by link, we record the access so you can see that your link was used.
We do not collect data from third-party trackers, and we do not buy data about you.
2. How we use your data
- To run Vigil for you — compiling your wiki, watching your sources, generating briefs, and answering questions with citations.
- AI processing — relevant excerpts of your content are sent to OpenAI for default product processing. If your Enterprise workspace has an active bring-your-own endpoint, structured workspace product calls use that endpoint instead. The in-product support assistant and hosted web search are separate exceptions and use our shared provider. Hosted search may receive workspace content used to form the search prompt, including assumption text and derived search terms.
- Watching — watched pages are fetched from their public URLs on the schedule you set, on your behalf.
- Plan limits and safety — usage data enforces plan limits and helps us find and fix problems.
- Service messages — we email you about your account, billing, security, and material changes to our terms or this policy.
3. What we never do
- We never sell your personal data or workspace content.
- We do not use your content to train Vigil models. OpenAI processing is governed by the applicable API terms; processing through your own endpoint is governed by your agreement with that provider.
- We never share your content with other customers.
- We never show you ads or let advertisers target you based on your data.
4. Sharing and disclosure
We share data only where the service requires it:
- Service providers — we use a small set of named subprocessors: Stripe (payments — your card details go directly to Stripe and never touch our servers), OpenAI (default AI processing, the support assistant, and hosted web search; an active Enterprise bring-your-own endpoint replaces OpenAI for structured workspace product calls, but not support chat or hosted web search), Amazon Web Services (hosting and databases, United States), and Resend (transactional email delivery). Their handling is governed by our applicable agreements and their service terms. Our web pages also load fonts from Google Fonts, which receives standard request metadata (such as your IP address) but none of your account data or content.
- Share links you create — anyone with the URL of a share link can view the shared brief content. You control creation and revocation of your links.
- Team workspaces — content in a shared workspace is visible to that workspace’s members.
- Legal requirements — we disclose data if the law compels it, and we will tell you unless we are legally barred from doing so.
- Business transfers — if Vigil is acquired or merged, your data moves with the same commitments in this policy.
5. Retention and security
- Your content is retained while your account exists — including after a downgrade or a paused subscription. Pausing deletes nothing.
- If you own a workspace, you can delete that workspace separately from the Billing page after removing its other members and confirming its exact name. Vigil removes that workspace's content from the active application database while keeping your account, session, billing identity, and other workspaces active. We switch you to another workspace you own, or create a fresh empty Personal workspace if it was your last. Identifiable audit and security records (including the deletion event), operational logs, legally required records, de-identified records, provider-side records, and copies in disaster-recovery backups may remain under their applicable retention periods. Workspace deletion does not apply the privacy scrub used for whole-account deletion.
- You can delete your account yourself from the Billing page. After the required checks pass, Vigil removes the account and solely owned workspace data from the active application database. De-identified support or audit records, legally required billing records, provider-side records, operational logs, and copies in disaster-recovery backups may remain under their applicable retention periods. Shared workspace data is not erased for its remaining members.
- Usage events (which features were used, when) are retained for up to 12 months, then automatically deleted.
- Share-link access records are retained under the audit-log retention setting (365 days by default, subject to deployment configuration) and may also disappear when related workspace data is deleted.
- Application and infrastructure logs are kept outside the workspace export and deletion paths. Their current operational retention is available during security review rather than promised as a fixed public period.
- We protect data with encryption in transit, access controls, and the principle of collecting little in the first place. No system is perfectly secure; if a breach affects your data, we will notify you promptly as the law requires.
6. Your privacy rights
- Export — the Export page provides current wiki pages, source metadata and extracted text, claims, links, conflicts, briefs, and answers as Markdown and JSON. It does not include raw uploaded files, revision/audit history, secrets, or provider records.
- Access, correction, deletion — workspace owners can delete one workspace without deleting their account, or delete their whole account, from the Billing page. You can also email privacy@trustvigil.com to request access to, correction of, or deletion of your personal data. We respond within 30 days.
- Objection and portability — depending on where you live (for example under the GDPR or CCPA), you may also have rights to object to certain processing, restrict it, or receive your data in a portable format. The export covers portability; email us for the rest.
- Complaints — you can lodge a complaint with your local data-protection authority at any time.
We do not discriminate against you for exercising any of these rights.
7. International data transfers
Vigil is hosted in the United States. If you use Vigil from elsewhere, your data is transferred to and processed there. Where the law requires safeguards for such transfers (for example, standard contractual clauses for data leaving the European Economic Area or the UK), we put them in place with our service providers.
8. Team and business accounts
- In a team workspace, the workspace owner decides who is invited and administers the workspace. Content you add to a shared workspace is visible to its members.
- The workspace owner is our customer for that workspace. If you joined through an invite link, some requests about workspace data — such as deleting content that belongs to the shared workspace — may need to go through the owner.
- Your personal account data (your name, email, and private workspaces) remains yours and is covered by the rest of this policy as usual.
9. Children’s privacy
Vigil is not directed at children and requires users to be at least 16 years old. We do not knowingly collect data from anyone under 16; if we learn we have, we will delete it.
10. Cookies
Vigil uses a session cookie to keep you signed in, plus a small interface-preference cookie (for example, whether the sidebar is open). No third-party advertising or tracking cookies — which is why you do not see a cookie banner.
11. Changes to this policy
If we materially change this policy, we will notify you by email or in-app notice before the change takes effect. The effective date at the top always tells you when the current version began to apply.
12. Contact
Questions or requests about your data: privacy@trustvigil.com.