Privacy Policy

This policy explains which personal data is processed when you use Vlincta and which services receive it in the currently configured operating state. Services that are not configured or active are deliberately not listed.

Controller

The controller responsible for data processing under the GDPR is the operator named in the Legal notice. The contact details provided there also apply to all privacy-related enquiries.

Principles of processing

We process personal data only where necessary to provide the application (Article 6(1)(b) GDPR) or where we have a legitimate interest in secure and functional operation (Article 6(1)(f) GDPR). Content you enter is not used to train models and is not sold.

Hosting and server logs

The application runs on infrastructure of Scaleway SAS (Paris, France) in the Paris region (fr-par). When you access it, technically necessary connection data, including IP address, time, requested resource and user agent, is processed to deliver the application and maintain its security.

Selecting an EU region does not replace a data processing agreement or a review of subprocessors; the processing described on this page is EU-region processing by the named subprocessors, under the operator's agreements with them.

AI chat and language models

A core function of Vlincta is chat with open-weight language models. Your inputs, including chat messages and the text of documents you attach to a request, are sent to the model provider to generate a response. Attached documents are converted to text for the duration of the request and are not stored.

Open-weight models: Scaleway Generative APIs — processing in the EU (Paris, France). Processing takes place within the EU. Vlincta chooses the model for each request from the models available to your workspace; that choice is made without sending your content anywhere.

Models you connect yourself: if you connect your own credentials for a third-party model provider under Connections, requests routed to that provider are sent to it under your own agreement with that provider. Depending on the provider, this may involve a transfer to a third country (for example the United States), which may include personal data contained in your inputs. Your credentials are stored encrypted and are referenced everywhere else only by an opaque identifier.

Storage of your data

Your workspace, account and connection data, and a usage ledger, are stored in a database operated by Scaleway (Managed Database for PostgreSQL, Paris). The ledger records one entry per model call: which model answered, the tokens used, the cost and the time — never the prompt or the answer.

Whether conversation text is kept on the server is a setting of your workspace (Settings, “Chat history”). By default (“Keep on the server”, for workspaces created from 24 September 2026) conversation titles and messages are stored so a conversation opens on any device; the chat screen says so. A workspace can choose “This browser only” at any time: the server then keeps only a conversation's metadata — when it was created and last used, how many turns it has and which model answered last — and the messages themselves stay in your browser (see Local browser storage). Workspaces created earlier keep the setting they had. Conversations are never used to train models. Switching does not delete what was stored while the other setting was on; you can delete a conversation at any time, which removes it from the server.

Memory is a separate setting of your workspace (Settings, “Memory”). For workspaces created from 25 September 2026 it is on by default: Vlincta keeps short facts you ask it to remember, or that it notes about how you work, so that later conversations can use them — each as one entry, either for you alone or for the whole workspace. Entries are stored in the same database, only while the workspace keeps conversation text on the server, and never used to train models. You can ask in any chat what is remembered or to forget an entry, and list, edit and delete entries with the vlincta memory command; an entry kept for you alone is visible only to you. Workspaces created earlier have memory off until someone turns it on. Turning it off stores nothing new and does not delete what was kept.

A second workspace setting, “Response cache” (on by default), keeps each request and its answer for seven days in a cache operated by Scaleway (Managed Redis, Paris), so that an identical request from the same workspace is answered from the stored answer without calling a model. Nothing is shared between workspaces. Turning the setting off removes the workspace's stored requests and answers at once.

Connected services and Google user data

Under Integrations you can connect third-party services — Slack and Google Calendar, among others — to your workspace, so that the assistant can read from them and act in them when you ask it to. The authorisation runs through Nango (Nango Inc., USA), an OAuth broker that holds and refreshes the grant the service issues (its access and refresh tokens) together with the identifiers of your connection and workspace, under EU standard contractual clauses. Vlincta fetches the token for one call and discards it; Nango never sees a prompt, an answer or anything a service returned. The usage ledger records that a tool was called and whether it succeeded — never what it read or wrote.

Google Calendar. When you connect Google Calendar, Vlincta asks Google for two permissions: to see your calendars and their events (calendar.readonly) and to create and edit events (calendar.events). Vlincta uses this data only to carry out what you ask for in chat: to list the events in a period you name, to tell when a calendar is busy, and to create an event that you have explicitly confirmed, inviting the attendees you named. What is read is shown to you in the conversation and, like any tool result, is passed for that one request to the language model answering it — one of the providers named on this page, admitted under no-training terms, or a model you connected with your own credentials, under your own provider's terms. Calendar data is not stored on the server except as part of a conversation your workspace keeps there (see Storage of your data), is never used for advertising, is never sold, and is not read by people at Vlincta except where security, the law or your explicit consent requires it. Every write — creating an event, posting a message — asks for your confirmation first and shows exactly what will be sent.

Vlincta's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

You can disconnect a service at any time under Integrations; Vlincta then asks the broker to revoke the grant and discards its own reference to it. For Google you can also withdraw Vlincta's access from your Google account's permissions page.

Error reporting and monitoring

Technical error reports are sent to Sentry (EU data region) and request traces to Langfuse (EU cloud) and the operator's own telemetry. By default (Settings, “Retention”: “Metadata only”) these carry which model answered, the tokens, the cost and timing — never a prompt or an answer. Only if the workspace opts into “Content may appear in logs and traces” may prompts and answers appear there, for debugging and evaluation. Credentials are redacted before an error report leaves the application.

Sign-in and accounts

Registration and sign-in are handled by Zitadel (Zitadel Cloud, EU region) as identity provider. When you register or sign in, Zitadel sends us the data authorised for sign-in, generally your email address and name. Passwords are entered on the identity provider's pages only and are never sent to Vlincta. Zitadel acts as an independent controller for its own processing.

After sign-in, Vlincta sets an encrypted session cookie in your browser. It is strictly necessary to keep you signed in, is not used for any other purpose and is removed when you sign out or when it expires.

Profile and organisation details

When you register we ask for your first name and surname. They are passed to Zitadel to create your account and stored in your Vlincta profile, where you can change them under Settings → Profile. Legal basis: Art. 6(1)(b) GDPR, because an account needs a name to address you by.

In the same place you may add a phone number, a date of birth and a postal address. All three are optional; we store only what you enter, use it only to show it back to you, and remove it when you clear the field. Your age is calculated from the date of birth when the page is shown and is not stored. Legal basis: Art. 6(1)(a) GDPR — your choice to provide them, which you withdraw by clearing them. Your profile is visible only to you, including inside an organisation.

An organisation's administrators may record its name, a contact phone number and a postal address. Every member of the organisation can see these details. They describe the organisation, not a member.

Profile and organisation details are stored in the database described under Storage of your data, are never written to logs or traces, and are not used for any other purpose.

Local browser storage (no tracking)

Vlincta stores certain settings and, by default, your conversation text locally in your browser, in localStorage. These are functional values only: your selected colour scheme (vlincta.theme), the sidebar state (vlincta.sidebar.collapsed), whether the introduction has already been viewed (vlincta.intro.seen), and — while your workspace keeps chat history in the browser only — the messages of your conversations (vlincta.chat.bodies.*) so they persist between sessions on this device.

This storage is strictly necessary for the operation of the application that you expressly requested. No cookies or identifiers are set for analytics, tracking or advertising, and none of this data is shared with third parties. Under Section 25(2)(2) TDDDG, no consent is therefore required; for this reason, Vlincta does not display a cookie banner. You can delete this local data at any time through your browser settings.

Your rights

Subject to the statutory requirements, you have the right of access (Article 15), rectification (Article 16), erasure (Article 17), restriction of processing (Article 18), data portability (Article 20) and objection (Article 21 GDPR). To exercise these rights, contact the party named in the Legal notice.

You also have the right to lodge a complaint with a data-protection supervisory authority (Article 77 GDPR).

Changes to this policy

Because the range of functions and services may change, we update this policy where necessary. The services listed in this version reflect the current technical operating state.