1. Status of this document
This draft describes behavior present in the VEXA application as of August 21, 2026. The legal entity that operates VEXA, its registered address, privacy contact, governing privacy regimes, and representative details have not been supplied in this repository. Those details must be completed and approved by counsel before this policy is published as a production commitment.
2. Information handled by the service
- Account data: name, email address, a password hash for password-based accounts, verification and authentication state, and configured multi-factor or OAuth identifiers.
- Workspace and creative data: prompts, uploaded or generated media, projects, layers, personas, workflow configuration, provider settings, and related metadata.
- Usage and operational data: feature activity, token transactions, job state, security and audit events, and technical request information used to operate and protect the service.
- Payment-related data: when checkout is enabled, Stripe processes payment details. VEXA stores transaction and provider identifiers needed to correlate purchases, refunds, disputes, and token grants; the application does not intentionally store full card numbers.
3. Purposes and legal basis
The application uses information to authenticate users, provide workspace and creative features, send account messages, process configured purchases, maintain token and job records, investigate failures or abuse, and protect the service. Counsel must identify the applicable legal bases, consent requirements, and any jurisdiction-specific notices before launch.
4. AI providers and other service providers
Inputs required for an AI request are sent to the provider selected by the deployment or workspace. Provider availability, data use, retention, training, location, and billing depend on that provider's terms and account settings. Depending on configuration, VEXA may also use payment processing, email, database, hosting, and file-storage providers.
A production subprocessor list, international-transfer mechanism, data-processing agreement path, and provider-by-provider retention review are not present in the repository and require owner and counsel approval before launch.
5. Storage, security, and access
VEXA stores relational records in its configured database and media in its configured storage location. Password-based accounts use bcrypt password hashes. Authentication and OAuth transaction state use HTTP-only cookies, with secure-cookie behavior enabled for production connections. The application includes access checks, audit records, rate limits, and encrypted storage for supported provider credentials. No system can guarantee absolute security; production controls and access policies still require operational verification.
6. Retention and deletion
Retention differs by record type and deployment configuration. The account-deletion flow removes the account's relational data and places stored-user assets into a durable deletion workflow that retries if storage is temporarily unavailable. Some operational, security, payment, dispute, backup, or legal records may need separate retention. Workspace deletion also has a configured recovery period before purge. A complete retention schedule and backup-deletion timetable require operator and counsel approval.
7. User choices and requests
Signed-in users can update profile information, request a structured data export, download supported creative assets, and initiate account deletion through the product. The applicable rights, identity- verification process, response deadlines, appeal route, and privacy-request contact depend on the operator's jurisdiction and must be completed before launch.
8. Cookies and local storage
Core application code uses HTTP-only cookies for authentication and short-lived OAuth transaction state. It also uses browser storage for product preferences such as theme state. A production cookie and tracking scan is required to account for any hosting, analytics, support, or edge services added outside this repository and to determine whether a consent mechanism is required.
9. Children, changes, and contact
Minimum-age rules, notice-of-change procedures, controller identity, and a monitored privacy contact are legal and operational decisions that remain open. This draft must not be treated as counsel-approved or production-ready until those fields and the related external reviews are complete.