Privacy Policy

Privacy Policy

VecViz LLC (the "Company", "VecViz", "we" or "us")

This Privacy Policy covers the VecViz website located at vecviz.com, the VecViz web dashboards located at app.vecviz.com, the VecViz API and MCP (Model Context Protocol) tool endpoints, and the services located therein (collectively, the "Service").

Last updated on August 27, 2026.

This Privacy Policy describes:

  • What information we collect via the Service.
  • What information third parties collect or process in connection with your use of the Service.
  • How we use the information.
  • With whom we may share your information.
  • What choices are available to you regarding collection, use and distribution of the information.
  • What types of security procedures are in place to protect the loss, misuse or alteration of information under our control.
  • How you can correct any inaccuracies in the information.

This policy describes how VecViz treats your information, not how other organizations treat your information. If you are using VecViz in a workplace or on a device or account issued to you by your employer or another organization, that organization likely has its own policies regarding storage, access, modification, deletion, and retention of communications and content which may apply to your use of VecViz. Please check with your employer, team owner or administrator about the policies it has in place. Similarly, if you access VecViz through a third-party AI assistant, agent platform, or self-hosted software, that third party's own privacy practices apply to your use of its product, as described in "Third-Party AI Assistants, Agents, and Client Software" below.

How the Service Works

VecViz provides quantitative investment analytics through several connected surfaces: the marketing and content pages at vecviz.com; the web dashboards at app.vecviz.com; a REST API; MCP tools designed to be used inside AI assistants and agent frameworks; and compatibility with self-hosted third-party client software (such as an open-source analytics workspace you run on your own infrastructure). Access to paid features is controlled by an API key. Free trial keys may be issued without any registration. Understanding this architecture helps explain what data we do, and deliberately do not, collect on each surface.

Collection and Use of Information

Subscription and Billing Information

When you purchase a subscription, checkout and payment are handled by Stripe, Inc., our payment processor. Stripe collects your name, email address, and payment card or bank details directly; VecViz does not receive, store, or process your full payment card number. From Stripe we receive your email address, a Stripe customer identifier, your subscription product and status, and partial payment metadata (such as card brand and last four digits) sufficient to administer your subscription. Stripe's processing of your payment information is governed by Stripe's own privacy policy.

We use subscription information to issue and deliver your API key, operate and meter the Service, maintain quality of the Service, provide support, send important notices (such as communications about changes to our terms, conditions, and policies, or to your subscription status), and for loss prevention and anti-fraud purposes. Because these notices are important to your use of the Service, you may not opt out of receiving them while you maintain a subscription. We may also use this information for internal purposes such as auditing, data analysis, and research to improve the Service.

API Keys and Free Trial Keys

Your API key is a credential. Treat it like a password: do not share it or enter it anywhere other than the Service and the authorized configuration surfaces of the software you use to access the Service (for example, the connector settings of your AI assistant, or the backend configuration of self-hosted client software). We store keys in hashed or otherwise protected form.

Free trial keys can be generated instantly without providing an email address, name, or any other personal information, by humans or by automated agents. When a trial key is generated, we record the date and time, a one-way cryptographic hash of the requesting IP address (we do not store the raw IP address with the key), and the requesting software's user-agent string. We use this information solely for rate limiting, abuse prevention, and aggregate statistics about trial usage. Trial keys expire automatically.

Usage and Metering Data

When any key (trial or paid) is used against the API, the MCP tools, the web dashboards, or compatible client software, we log usage data associated with that key: which endpoints or tools were called, the parameters necessary to serve and meter the request (such as ticker symbols queried), timestamps, request outcomes, and quota consumption. We use this data to operate and meter the Service, enforce plan limits, bill correctly, prevent abuse, provide support, and understand which analytics are most useful so we can improve the Service. Usage data is associated with your key and, for subscribers, therefore with your subscription. We do not sell usage data associated with an identifiable subscriber.

Note what we do not receive: when you use VecViz inside an AI assistant or agent, we receive only the tool calls made to our servers. We do not receive your conversation, your prompts, your other messages, or any other content you exchange with that assistant.

What we do not do with your queries. We recognize that the securities you research can signal your research focus or trading intent, and we treat individual query histories accordingly. We do not monitor or mine individual users' queries to inform any trading or investment decision by VecViz or its principals; we do not use your query history to front-run, replicate, or evaluate your research; and we do not share individual query histories with any third party except with service providers as necessary to operate the Service or as required by law. Access to individual usage records is limited to what service operation, billing, abuse prevention, and support require. VecViz's published analytics, reports, and model portfolios are generated from market data and our models, not from user query behavior.

Aggregated query data. We do not currently sell, license, or otherwise commercialize any data product derived from user queries (such as query-volume, popularity, or trending-ticker feeds), whether identified, anonymized, or aggregated. If we ever introduce such a product, it would use only aggregated and de-identified data that cannot reasonably be linked to any user or key, and we will update this Privacy Policy and provide prominent notice before doing so.

Retention of usage data. Operational server and application logs containing request details (including IP addresses) are retained for up to 90 days for operations, debugging, security, and abuse prevention, and are then deleted or anonymized. Metered usage records associated with a key (including tools called and tickers queried) are retained while the key is active and for up to 12 months after it expires or is terminated, to support billing, quota enforcement, dispute resolution, and abuse prevention, after which they are deleted or aggregated into Anonymized Data.

Usage limits, not surprise bills. Plans are enforced with hard usage quotas. When a key exhausts its quota, further requests are declined until the quota resets or the plan is changed; they do not accrue charges. Automated agents using your key draw down the same quotas, so a misbehaving or looping agent cannot generate unbounded charges, though it can exhaust your quota.

Log Files and Non-Personal Information

Like most standard internet services, we use log files with respect to the Service. This includes internet protocol (IP) addresses, browser type, internet service provider (ISP), referring/exit pages, platform type, date/time stamps, and page or endpoint activity, used to analyze trends, administer the Service, track usage in the aggregate, and gather broad demographic information for aggregate use.

We also collect and derive data in a form that does not, on its own, permit direct association with any specific individual or business (collectively, "Anonymized Data"), including aggregated usage statistics. We may collect, use, transfer, license and disclose non-personal information and Anonymized Data for any purpose, except that data derived from user queries is subject to the additional limits described in "Usage and Metering Data" above. Aggregated data is considered non-personal information and Anonymized Data for the purposes of this Privacy Policy. If we combine non-personal information or Anonymized Data with information which permits direct association with a specific individual or business ("Personal Information"), the combined information will be treated as Personal Information for as long as it remains combined.

Unless a user otherwise affirmatively opts in, we shall not use, provide or sell any Personal Information of such user for any reason other than as necessary to provide the Service and as described in this Privacy Policy.

Upon termination or expiration of the Service with any user, we shall delete or anonymize the Personal Information of such user (other than Anonymized Data, which we may retain and use as set forth above), except that we may retain copies for purposes of compliance with applicable law, tax, accounting, and dispute resolution, which shall remain subject to the confidentiality requirements hereunder (which shall survive termination or expiration).

Cookies

The web dashboards use a session cookie to keep you signed in after you enter your API key. This cookie is essential to the operation of the dashboards, is signed, and does not contain your API key itself. The marketing site may use cookies and similar technologies for basic site operation and aggregate analytics. Most web browsers automatically accept cookies, but you can usually modify your browser settings to decline non-essential cookies. Some of our service providers (such as our payment processor, on its own pages) use their own cookies, over which we have no access or control.

Third-Party AI Assistants, Agents, and Client Software

The Service is designed to be used inside software that VecViz does not operate, including AI assistants and chat products, AI agent frameworks and orchestration tools, MCP-compatible clients, directories and registries through which you may discover or connect to the Service, and self-hosted analytics software that you run on your own infrastructure.

When you use your API key inside any such third-party or self-hosted software:

  • That software, and the company or persons operating it, may collect, retain, process, train on, or otherwise use your prompts, queries, conversations, the analytics returned by the Service, and any inferences drawn from your usage (for example, which securities you research and when), in accordance with its own terms and privacy policy, not this one.
  • VecViz does not control, and is not responsible or liable for, the privacy, security, data retention, model training, or other practices of any third-party AI assistant, agent, platform, directory, or client software, or of any self-hosted deployment operated by you or a third party, including anything such software or its operator learns about you through your use of the Service within it.
  • It is your responsibility to review the privacy policy and settings of any assistant, agent, or client software before using your key within it, including any settings governing whether your conversations are retained or used for model training.
  • If you configure an autonomous agent to use your key, you are responsible for that agent's actions with your key, including the queries it makes, which will be metered and logged as your usage.

For clarity, the same applies to links: the Service may contain links to other websites or third-party products or services. We are not responsible for the privacy practices of such other websites or third parties, and we encourage users to read the privacy statements of every website and product that collects information from them.

Sharing

Legal Disclosure

Though we make every effort to preserve user privacy, we may need to disclose personal information when required by law wherein we have a good-faith belief that such action is necessary to comply with a current judicial proceeding, a court order or legal process served. We may also disclose information about you if we determine that for purposes of national security, law enforcement, or other issues of public importance, disclosure is necessary or appropriate, or that disclosure is reasonably necessary to enforce our terms and conditions or protect our operations or users.

Service Providers and Third-Party Intermediaries

We use third-party providers to operate the Service, including payment processing (Stripe), cloud hosting and infrastructure, email delivery, and analytics. We provide those companies only the information they need to deliver their services. They are required to maintain the confidentiality of user information and are prohibited from using that information for any other purpose. We do not sell personally identifiable information.

Business Transitions

In the event the Company goes through a business transition, such as a merger, being acquired by another company, or selling a portion of its assets, users' personal information will, in most instances, be part of the assets transferred. Users will be notified at least 30 days prior to a change of ownership or control of their personal information, giving them the opportunity to request deletion of their information before any transfer. If, as a result of the business transition, users' personally identifiable information will be used in a manner different from that stated at the time of collection, they will be given choice consistent with our Notification of Changes section.

Security

Protection of our users' information is important to us. Information transmitted to the Service is encrypted in transit using Transport Layer Security (TLS). API keys are stored in hashed or otherwise protected form, and personal data is stored on systems with limited access. No method of transmission or storage is completely secure; you play a role too, in particular by keeping your API key confidential. If you believe your key has been compromised, contact us at admin@vecviz.com and we will rotate it. If users have any questions about our security measures, they can send an email to admin@vecviz.com.

Correcting, Updating, Deleting and Deactivating Personal Information

If a user's personally identifiable information changes, or if a user no longer desires the Service, we provide a way to correct, update or delete/deactivate personally identifiable information. Subscription and billing details can be managed through the Stripe billing portal linked in your receipt; anything else can be handled by emailing us at admin@vecviz.com. Depending on your jurisdiction, you may have rights under laws such as the EU and UK General Data Protection Regulation (GDPR) or the California Consumer Privacy Act (CCPA), including rights to access, correct, delete, restrict the processing of, or receive a portable copy of your personal information, and to not be discriminated against for exercising those rights. Requests can be made to the same address and we will respond as required by applicable law. We do not sell personal information as "sell" is defined under the CCPA.

Notification of Changes

If we decide to change our privacy policy, we will post those changes to this Privacy Policy and other places we deem appropriate so our users are always aware of what information we collect, how we use it, and under what circumstances, if any, we disclose it. We will use information in accordance with the Privacy Policy under which the information was collected. If we are going to use users' Personal Information in a manner materially different from that stated at the time of collection, we will notify users via email where we have one; users will have a choice as to whether or not we use their Personal Information in this different manner. Trial key holders, from whom we deliberately collect no contact information, should review this Privacy Policy periodically; continued use of a trial key after changes are posted constitutes acceptance of the updated policy.

Children

The Service is intended for users 18 years of age and older. We do not knowingly collect, use or disclose personal information from anyone under 18, or the equivalent minimum age in the relevant jurisdiction. If we learn that we have collected the personal information of a child under that age, we will take steps to delete the information as soon as possible. Persons under that age are not permitted to subscribe to or use the Service.

International Users

The Service is operated from the United States, and the information you provide may be transferred to, stored in, or accessed from the United States and other jurisdictions as described in this Privacy Policy, which may have data protection laws different from those of your jurisdiction.

Contact Information

If users have any questions or suggestions regarding our privacy policy, please contact us at admin@vecviz.com.