what the desk remembers.

Privacy Policy

What Vectra stores, why it stores it, and what happens when you leave. Last revised: September 2026.

1. The short version

Vectra stores what it needs to teach you: your account, the material you upload, and the record of how your learning actually went. It does not sell your data, does not show advertising, and does not use your study material to train foundation models.

2. What we collect and why

Account data — your email and authentication record, handled by Supabase Auth. Used to recognize you and secure your account.

Learning material — the lecture files, notes, and recordings you upload, stored as files (Backblaze B2) and parsed into concepts. Used for exactly one purpose: teaching you that material.

Learning events — recall ratings, answers, re-teach requests, mastery evidence. This is the heart of the product: the adaptive loop decides what to teach next from what you have actually demonstrated. Without this record, the product cannot keep its promise.

Billing data — handled by Polar, our Merchant of Record. Vectra knows your plan and payment status; your card details never touch Vectra.

Operational telemetry — error logs and performance metrics, kept to keep the service working.

3. What the teaching engine does with your events

Your learning events drive a belief state — Vectra's probabilistic estimate of what you understand. That belief state, not engagement metrics, decides everything: which representation teaches you next, when to re-teach, when a prerequisite needs repair, and whether mastery has genuinely been demonstrated.

We deliberately do not reward time-on-app, streaks, or login frequency. The record exists to make the teaching honest, not to keep you scrolling.

4. Sharing

Sub-processors only, each for one job: Supabase (database and authentication), Backblaze (file storage), Polar (payments), and the AI model providers that generate your lessons. We do not sell data, and there is no advertising in Vectra.

You can choose to bring your own model key, in which case generation calls go to the provider you configured.

5. Retention and deletion

Your material and learning history are kept while your account is active — the loop needs them. Delete your account and we delete your profile, uploads, learning events, and belief state within 30 days, except where law requires otherwise (e.g. billing records kept by Polar for tax purposes).

6. Your rights

Access, correction, export, and deletion of your data are all supported. Where GDPR or similar frameworks apply, you have the same rights there — contact support and a human will handle it, not a form black hole.

7. Security

Transport encryption everywhere, credentials encrypted at rest with versioned keys, row-level security on every table so your rows are only ever reachable by you, and rate limiting on the API. No system is perfect; if something goes wrong, we will tell you what happened and what we did about it.

8. Changes

If this policy changes materially, we will tell you in the product before the change applies.