Skip to main content

Legal

Privacy policy

Version 1 · Effective 2026-10-02

This policy explains how Vresk handles your personal information. A shorter overview is Your data in the docs; where the two differ, this policy applies.

Who we are

Baran Labs LLC runs Vresk and is responsible for the personal information it handles. This policy says what we collect, why, who processes it for us, how long we keep it, and what you can do about it.

Our Privacy Officer is accountable for how we handle personal information. You can reach them at contact@baranlabs.com, or by post at Baran Labs LLC, Attn: Privacy Officer, 1070 Montgomery Rd, Unit 256, Altamonte Springs, FL 32714, United States.

The short version

  • We store what you give Vresk so it can work for you, in the United States.
  • To answer you, we send your conversation to the companies that run the models. They are named below.
  • We don't sell your personal information, we don't show you ads, and we don't use your conversations or files to train AI models.
  • You can see where your data goes, export a copy of it, and delete it, from Your data.

What we collect

  • Your account: your email address, your sign-in details, and when you confirmed you are 18 or older. If you sign in with Google, the name, email address, profile picture and Google account ID Google shares with us.
  • As a guest: a guest account, kept signed in by a cookie in your browser.
  • What you create: your messages and the answers to them, files you upload, notes, memories (if memory is on) and the summary Vresk writes from them, projects, instructions, scheduled tasks, links you share, and the settings of services you connect.
  • Cost records: what each request cost us in dollars and which model answered. This is how your allowance is measured.
  • Usage records: when you send a message, and which steps in Vresk you have reached, such as your first message or creating an account, with the time. They don't include what you wrote.
  • Safety-check records: the result of each safety check and, when a check flags something, an excerpt of up to 2,000 characters of the text it judged.
  • Technical records: request logs with your IP address and browser details, kept by our hosting provider; error reports, which don't include your account; records of refused requests, such as failed sign-ins, stored as scrambled codes of the email address or IP address that change every day; and a log of sign-ins and account changes kept by our database provider's sign-in service, with the email address and IP address.
  • The waitlist: if you join it, your email address and how you found us, such as the link you came from.
  • Payments: the billing details Stripe collects at checkout, which are your name, email and billing address. Your card is handled by Stripe, and we never see the full number. We also keep copies of Stripe's payment notifications.
  • Anything you send us yourself, such as an email to support.

How we use it

  • to run Vresk: to answer you, save your work and show it back to you;
  • to keep Vresk safe: safety checks, stopping abuse and protecting accounts;
  • to measure your allowance and, if you pay, to bill you;
  • to send the emails you need, such as sign-in and account emails, and the notifications you turn on;
  • to understand how Vresk is used, such as how many people come back;
  • to find and fix problems;
  • to follow the law.

We don't sell or rent your personal information, we don't share it for advertising, and we don't use your conversations or files to train AI models.

Who processes it for us

These are the companies that receive information from Vresk today. The list shows the services switched on right now, and it changes when they do.

Supabase
Runs our database, sign-in and file storage.
What it receives: Everything we store for you: your account, conversations, files, notes and settings.
What its terms say: Stores what we store for as long as we keep it. Deleted data can remain in its encrypted backups for a limited period.
Our agreement with it: Its standard data processing agreement, which applies to us under its terms.
Where: United States.
Vercel
Hosts the Vresk website and app, and runs code a model writes in an isolated machine with no network access.
What it receives: Every request your browser makes to Vresk, including your IP address, and the code a model writes when it runs a calculation.
What its terms say: Keeps request logs, which can include your IP address and the page you asked for, for up to 30 days.
Our agreement with it: Its standard data processing agreement, which applies to us under its terms.
Where: United States.
Resend
Sends our email: sign-in and account emails, and the notifications you ask for.
What it receives: Your email address and the email we are sending you.
What its terms say: Stores the emails it sends and their recipients for a limited period.
Our agreement with it: Its standard data processing agreement, which applies to us under its terms.
Where: United States.
DeepInfra
Runs most of the models that answer you, the safety check on every message and answer, image making and editing, and the search index for your notes, files and memories.
What it receives: What each answer needs: your messages, attached images, and any notes, memories, instructions or files (whole, or excerpts of them) included for that answer, and anything Vresk reads for you to answer (web pages, public data sources and apps you connect); the text of each message and answer, and anything Vresk reads for you to answer (web pages, public data sources and apps you connect), for the safety check; image requests; and, to build the search index, the full text of each note and uploaded file when you save or upload it, and each memory when it is saved.
What its terms say: Its terms (last modified 2026-08-17, §7(b)) say: “Provider will not retain, store, or log any Customer Data submitted to or generated by the Services beyond the period strictly necessary to process and return the applicable request, after which such Customer Data is deleted from Provider's systems in the ordinary course of operations”. The exceptions they list are “(i) Customer Data that Provider retains at Customer's written request, or with Customer's prior written authorization, to diagnose or resolve a support or Service issue, which Provider will delete within thirty (30) days after the issue is resolved; (ii) non-content operational metadata, such as request counts, timestamps, latency, and billing data, that does not include Customer Data submitted to or generated by the Services; and (iii) records Provider is required to retain to comply with applicable laws or to detect, investigate, or respond to fraud, security incidents, or abuse of the Services.” Its privacy policy (last modified 2026-08-15) says: “We will not store, sell, or train using this data unless we have your explicit consent.” We have not given that consent.
Our agreement with it: Its published terms only. We have no signed agreement with it.
Where: The United States: its privacy policy says data may be “transferred, stored, and processed outside of your jurisdiction, specifically in the United States”.
Fireworks AI
Runs some of the models you can choose.
What it receives: What each answer needs: your messages, attached images, and any notes, memories, instructions or files (whole, or excerpts of them) included for that answer, and anything Vresk reads for you to answer (web pages, public data sources and apps you connect).
What its terms say: Its terms (last updated 2026-07-10, §3.6) say: “We will not use your Content to train our own models or to improve the Service. We will not retain any Content for longer than is necessary to provide the Service to you.” And: “we will not, unless otherwise required by Applicable Law (or to provide the Service or support to you): (i) log your Content for human review; or (ii) retain your Content, beyond the time it takes to generate Output and deliver that Output to you.” They also keep “the right to use safety screening tools on the Content as we deem appropriate”.
Our agreement with it: A data processing agreement that is part of its terms.
Where: Its data processing terms (v3.2, §6.1) say it “may Process Covered Data anywhere that Company, its Affiliates or its Sub-processors maintain facilities”. The sub-processors they list process data in the United States, Japan, the United Kingdom, Germany and Iceland, and one, a content delivery network, at the “[c]losest data center to End User”.
OpenAI
A backup safety check on images you upload or ask us to edit, used when our main check is unavailable or gives no clear answer.
What it receives: The image, with its location data already removed.
What its terms say: Its published documentation says its moderation service does not keep or train on what it screens.
Our agreement with it: Its published terms only. We have no signed agreement with it.
Where: United States.
Brave
Runs the web searches Vresk makes for you.
What it receives: The words of your message as a search query, and for research the questions the model writes from it. Nothing about your account.
What its terms say: Its published notice for the search service says it keeps search query logs for up to 90 days.
Our agreement with it: Its published terms only. We have no signed agreement with it.
Where: Not stated in the terms we reviewed.
U.S. Securities and Exchange Commission (EDGAR)
A public source of company filings that research can look up.
What it receives: The names of the companies a research request needs. Nothing about your account.
What its terms say: A public government service.
Our agreement with it: None. It is a public service or one you choose, used under its own terms.
Where: United States.
Stripe
Takes payments for Plus and runs the page where you manage your subscription.
What it receives: Your account's email address and ID when you start a checkout. You give your card and billing details to Stripe directly, and Stripe sends us payment notifications that include your name, email and billing address.
What its terms say: Keeps its own records of your payments under its own terms, including where the law requires it to.
Our agreement with it: A data processing agreement that is part of its terms.
Where: United States and the other countries where Stripe operates.
Google
Lets you sign in with your Google account, if you choose to.
What it receives: Nothing from us. When you choose Google, Google tells us your name, email address, profile picture and Google account ID, and Google knows you signed in to Vresk.
What its terms say: Handles your Google account under Google's own terms and privacy policy.
Our agreement with it: None. It is a public service or one you choose, used under its own terms.
Where: Google's worldwide systems.
Cloudflare
Runs the check that tells people from bots when you start as a guest, on the sign-in page, and on the waitlist.
What it receives: Your IP address and signals from your browser, during the check. No account identifier from us.
What its terms say: Uses the signals for the check, and also, under its own terms, to improve its bot detection.
Our agreement with it: A data processing agreement that is part of its terms.
Where: Cloudflare's worldwide network.
Your browser's push service
Delivers notifications you turn on, through the service run by the company that makes your browser.
What it receives: An encrypted notification it cannot read, and when it was sent.
What its terms say: Sees delivery details only; the notification itself is encrypted for your device.
Our agreement with it: None. It is a public service or one you choose, used under its own terms.
Where: Your browser maker's servers.

We send your conversations only to the companies above that run the models, never to the companies that made them. The exception is OpenAI's safety checks described below: OpenAI, which made one of the models we offer, receives images you upload and pictures we made that you ask us to edit, when our main check is unavailable or gives no clear answer.

Where a company's entry says we rely on its published terms only, we have no signed agreement with it, and what we say about it is what its own published terms say.

This company processed information for us before and no longer does. It is named because what it received may still exist:

  • Together AI. It ran some of the models that answer you, starting 2026-09-02, and received what each answer needed: your messages, attached images, and any notes, memories, instructions or files (whole, or excerpts of them), and anything Vresk read for you to answer (web pages, public data sources and apps you connect). Up to 2026-09-28, when we switched them off, our account used two of its defaults. Its documentation (its “Privacy and security” page, as we read it on 2026-10-02) says: “By default, Together stores the prompts you send and the responses models return, and may use them for product improvements.” And: “Allow passthrough models: on by default. Allows models that forward prompts and responses to third-party providers”. Of passthrough models, the same page says data “is handled under that provider's own data policy”. Of stored data it tells its customers, which here means us: “This data is not shared with third parties, and you can delete it at any time.” Its privacy policy (updated 2025-12-17, §2.5) says: “Your information, including Personal Data, is processed at the Company's operating offices and in any other places where the parties involved in the processing are located.” We stopped sending it your information on 2026-10-01.

Services you choose, and your browser

If you connect another service to Vresk, such as a notes or project tool, the model sends that service what it needs to do what you asked, under that service's own terms. You can disconnect it at any time. Guests can't connect services.

Some features load files into your browser from public file hosts: dictation and read-aloud download their speech models from jsDelivr and Hugging Face, and some interactive answers load their tools from jsDelivr and esm.sh. Those hosts see your IP address when your browser downloads from them. The audio you dictate never leaves your device, and read-aloud turns an answer into speech on your device.

When Vresk searches the web for you, the words of your message go to Brave as a search query, with phrases like “search for” taken out, and for research the questions the model writes from your message go too. Nothing about your account goes with them. Brave's published notice says it keeps search query logs for up to 90 days.

When research reads a page it found, our servers fetch the page. The site sees our servers, not you, and the request carries no cookies and nothing about you.

Search words are also kept briefly in a shared cache that is not linked to your account.

Research that needs figures may also look up public data from the U.S. Securities and Exchange Commission (EDGAR), sending only the names of the companies or data series it needs.

Conversations that don't use web search or research send no search words anywhere.

Safety checks

Every message you send and every answer goes through an automatic safety check, before and after the model answers, and images you upload are checked too. The check runs on DeepInfra. If that check is unavailable or gives no clear answer, images you upload, and pictures we made that you ask us to edit, are checked by OpenAI's moderation service instead.

We keep a record of each check's result. When a check flags something, we also keep an excerpt of up to 2,000 characters of the text it judged. The excerpt is deleted after 90 days, and the record of the result stays until you delete your account.

How long we keep it

Conversations
Kept until you delete them. A deleted conversation leaves your history at once and is permanently removed 30 days later. The pictures in documents Vresk designed in it are not removed with it: they stay until you delete all your data or delete your account.
Conversations untouched for 720 days (about two years) are removed automatically, unless you have chosen to keep things until you delete them yourself.
Files you upload
Files you upload are not removed automatically. They stay until you delete all your data or delete your account, and that includes files you uploaded into a conversation you later deleted. An automatic cleanup of old uploads is planned, and we will update this policy before it runs.
Notes, memories and projects
Kept until you delete them, delete all your data, or delete your account.
When memory is on, Vresk also writes a summary from your memories. When it rewrites the summary, including after you delete a memory, it keeps the earlier version, so an earlier summary can still contain something you have since deleted. Earlier versions are included in your data download and are removed when you delete all your data or delete your account.
Guest accounts
Guest accounts are kept until you delete them or ask us to. An automatic removal of guest accounts with no new chat message for 30 days is built but not switched on yet.
Cost, usage and safety-check records
Kept until you delete your account. The excerpt a safety check keeps is deleted after 90 days.
Error reports
Deleted after 30 days.
Records of refused requests
Deleted after 365 days.
Your waitlist email address
Kept until you ask us to remove it. Nothing removes it automatically yet.
Payment records
Our copies of Stripe's payment notifications are not deleted when you delete your account, and nothing removes them automatically yet. Stripe keeps its own records under its terms.
Request logs
Kept by our hosting provider for up to 30 days.
Sign-in log
Kept by our database provider's sign-in service; it is not deleted with your account, and nothing removes it automatically yet.
Backups
Deleted information can remain in our database provider's encrypted backups for a limited period before they are replaced.

You can choose, on Your data, to keep your conversations and files until you delete them yourself. A conversation you delete is still removed: that part is never optional.

Your choices and rights

  • See where your data goes, export a copy of it, and delete it, from Your data.
  • Delete all your data: removes your conversations, files, notes, memories and projects, and keeps your account, your instructions and settings, and the services you connected.
  • Delete your account: removes your account and everything in it.
  • Turn memory off, change your notifications, and disconnect services you connected.
  • Withdraw your consent to the waitlist email by writing to support@vresk.ai.

You can also ask us what personal information we hold about you, and ask us to correct or delete it, by writing to support@vresk.ai. We answer within 30 days, and we won't treat you differently for asking.

If you are not satisfied with our answer, you can complain to the Office of the Privacy Commissioner of Canada if you are in Canada, or to the privacy regulator or attorney general of your state if you are in the United States.

What deletion covers

Delete all your data removes your conversations and messages, files, notes, memories, projects, shared links, scheduled tasks and notifications. Your account, instructions and settings, connected services, plan, cost records, usage records and safety-check records stay.

Delete your account removes everything in your account, including your cost, usage and safety-check records, and then the account itself.

A few records stay after you delete your account:

  • copies of Stripe's payment notifications, and Stripe's own records;
  • copies of the emails we sent you, kept by our email provider for a limited period;
  • what Together AI may still hold from requests it ran for us up to 2026-09-28, when we switched its storage off (see “Who processes it for us”); deleting your Vresk account does not remove it;
  • your waitlist email address, if you joined the waitlist;
  • records our team keeps when we look up or change an account to help you, such as extending a guest pass;
  • records of refused requests, such as failed sign-ins, stored as scrambled codes, for up to 365 days;
  • request logs kept by our hosting provider, for up to 30 days;
  • the log of sign-ins and account changes kept by our database provider's sign-in service;
  • copies in encrypted backups, for a limited period.

If we are ever legally required to preserve specific material, for example in connection with a child-safety report, we will keep only that material for as long as the law requires.

If you pay for Plus and it is still set to renew, cancel it first with Manage billing on your plan page. We won't delete an account that is still being billed.

If a deletion stops partway, run it again, and it picks up where it stopped.

Cookies and browser storage

Vresk keeps only what it needs to work, and to remember choices you make, in your browser:

Your sign-in session, including a guest session (cookie)
Kept until you sign out or the session expires.
Whether the sidebar is open (cookie)
Kept 7 days.
A marker that you are resetting your password (cookie)
Kept 15 minutes.
Messages you have started but not sent (local storage)
Kept until you send them or delete your data; signing out does not clear them.
Layout, display and voice settings, tips you have dismissed, and the models you picked recently (local storage)
Kept until you clear them in your browser.
A random ID the landing page sends with a waitlist sign-up (local storage)
Kept until you clear it in your browser.
The speech model files dictation and read-aloud download (browser cache)
Kept until you clear them in your browser.

We don't use analytics or advertising cookies, so there is no cookie banner to accept.

Vresk doesn't track you across other websites, and we don't let advertising or analytics companies do so through Vresk. Some companies see your visit directly: Google, if you sign in with it, Cloudflare, during the bot check and the public file hosts your browser downloads from. They handle what they see under their own terms. Because we don't track you across websites, a browser's Do Not Track signal doesn't change anything we do.

How we protect it

Connections to Vresk are encrypted. Our database rules keep each account's data separate, and changes go through our servers. Location data is removed from images you upload before they are stored.

No system is perfectly secure, so we can't promise that your information will never be accessed without permission.

If something goes wrong

If a breach of security involving your personal information creates a real risk of significant harm to you, we will tell you, and report it to the regulators the law requires, as soon as we can.

Children

Vresk is for people 18 or older. We don't knowingly collect personal information from anyone under 18. If we learn that an account belongs to someone under 18, we will close it and delete its data. If you think a minor is using Vresk, tell us at support@vresk.ai.

Where your information is

We store your information in the United States. The companies that process it for us are listed above with what we know about where they process it. Information in the United States may be accessible to authorities there under US law.

Changes to this policy

This is version 1 of this policy, in effect from 2026-10-02. If we change it in a way that matters to you, we will tell you before the change takes effect: by email if you have an account, and on our changelog. The list of companies above, and the lines about payments, analytics and guest accounts, always describe the services switched on today.

Contact

Write to our Privacy Officer at contact@baranlabs.com, or by post at Baran Labs LLC, Attn: Privacy Officer, 1070 Montgomery Rd, Unit 256, Altamonte Springs, FL 32714, United States.