Vecton — Privacy Policy
Effective date: 2026-08-03 Last updated: 2026-08-03
This Privacy Policy explains what information Vecton (“Vecton”, “we”, “us”) collects, why, and what we do with it. Vecton is a local-first desktop application for supervising AI coding agents. By design, your code and most of your work never leave your machine. This policy describes the limited data that does reach our cloud when you sign in and use cloud features.
The data controller is Shaked Nachum, trading as “Vecton”, based in Israel, reachable via the contact in Section 12. Vecton is currently operated by Shaked Nachum as an individual; if it is later incorporated or acquired, the successor entity becomes the controller and this policy will be updated with notice (Section 11). Questions: shaked.labs@gmail.com.
1. The short version
- Your code, prompts, diffs, and file contents are never sent to us. They stay in local databases on your device.
- You can use Vecton fully offline, with no account. Choosing “Continue offline” means we collect nothing.
- When you sign in, we process your account identity and a limited set of project and organization metadata needed to sync across your devices and teammates.
- We derive product metrics server-side from data you already transmit for the service to work (your account and task status). We do not run a client-side telemetry SDK, and we never aggregate your code, prompts, or keys. This section of the policy is the disclosure that lets us measure the product without a separate consent pop-up.
2. What stays on your device (never collected)
Vecton is local-first, and that is a rule rather than a list: anything Vecton stores on your device — your work, your settings, and records of the choices you make in the app — stays on your device and is never transmitted to us unless Section 3 says otherwise. This holds for features added after this policy was last updated; if a new feature ever sends something to our cloud, it is named in Section 3.
Local data lives in SQLite databases and settings files on your machine
(~/.vecton/… and per-workspace .vecton/state.db). By way of illustration, and
not as an exhaustive inventory, it includes:
- Source code, file contents, and diffs in your projects and git worktrees.
- Agent prompts, conversations, and reasoning exchanged with the coding agents you run.
- Agent output/stream logs, worker process state, and local audit logs.
- Your local kanban tasks, reviews, and review comments.
- Personal (non-organization) API keys and credentials you enter to run agents locally — these stay in your local device registry and are used only to launch agents on your machine.
If you never sign in, none of the categories in Section 3 are collected either — Vecton operates with no server dependency.
3. What we collect when you sign in
3.1 Account & identity
When you sign in with Google (via Supabase Auth), we receive and store the identity information Google returns for the account you choose: your email address, name, profile picture URL, and Google account identifier. This is the canonical identity your Vecton data is associated with. We store it to authenticate you, associate your data with your account, and enable team features.
3.2 Cloud-synced product data
So that your work is available across devices and to teammates you invite, we store the following in our cloud database (Supabase):
- Project metadata: project name, description, ownership, and timestamps. (Not the code — the code stays local.)
- Organizations & memberships: organization name, your role (admin/developer), and co-members’ account identifiers.
- Deployment records: the named deployment-workflow step definitions, the status of each deployment run, and the short textual “proof” or status message the agent reports for each step (plus any error message). This can include agent-generated free text describing what a deployment step did.
- Shared agent configurations: for organization-shared configurations, the driver name and the configuration payload — which may include an API key. The configuration payload is encrypted at rest in a secrets vault (Supabase Vault / pgsodium) and is never stored in plaintext.
3.3 Server-side product analytics
To understand how Vecton is adopted and used, and to improve it, we derive usage metrics entirely server-side from data described in 3.1–3.2 — your account and your synced task status. We compute:
- Activation (e.g. first task run through to a human-approved change),
- Retention (D1 / D7 / D30 by account), and
- Funnel progression (install → login → agent connected → task started → task shipped).
We do this without a client-side telemetry SDK, without a “phone-home” beacon, and without ever aggregating your code, prompts, diffs, or API keys. No separate consent modal is shown; this disclosure is how we tell you what is measured. If you use Vecton offline, you are not included in these metrics.
3.4 Record of your acceptance of these documents
When you accept the Terms of Service and acknowledge this Privacy Policy in the app, we record that you did so. The record contains your account identifier, the version identifier of each document you were shown, and the timestamp of acceptance. It contains no other information about you, and it does not record anything about how you use the product.
We keep this because these documents only bind you if you actually accepted them: without a record of which version you accepted and when, neither of us can establish what was agreed. Each acceptance is stored as a new entry rather than overwriting the previous one, so the history of what you accepted remains intact.
We do not sell your personal data, and we do not use it for advertising.
4. Legal bases for processing (GDPR / UK GDPR)
For users in the EEA/UK, we rely on:
- Performance of a contract — account identity (3.1) and cloud sync (3.2), which are necessary to provide the cloud features you request.
- Performance of a contract, and our legitimate interests — the record of your acceptance (3.4). Recording that you accepted is part of forming the agreement between us; retaining it serves our legitimate interest in being able to establish which version of these documents applies to you, and in establishing or defending legal claims. We have weighed this against your interests: the record is three fields, contains no behavioural data, and is the minimum needed to make the agreement provable. You may object (see Section 8), though we may then be unable to offer you cloud features, since we would have no record that you accepted the terms governing them.
- Legitimate interests — server-side product analytics (3.3), for the legitimate interest of understanding activation and retention in order to validate and improve the product. We have weighed this against your interests: the metrics are derived from data you already transmit to use the service, exclude all code/prompts/keys, and are not used for advertising or sold. You may object (see Section 8).
- Consent — where we ask for it explicitly and you give it. Nothing described in this policy relies on consent; where we introduce processing that does, we will ask for it separately and you will be free to refuse.
5. Sub-processors and third parties
We share data only with service providers that help us run Vecton:
| Provider | Purpose | Data involved |
|---|---|---|
| Supabase | Cloud database, authentication, and secrets vault | Account identity, cloud-synced product data (Section 3), acceptance records (3.4), encrypted configurations |
| OAuth sign-in identity provider | The identity data you authorize at sign-in | |
| Cloud hosting providers | Running the Vecton cloud services | The data described in Section 3, at rest and in transit |
Vecton’s cloud services are hosted in the European Economic Area and the United Kingdom. We name the jurisdictions rather than a specific data-centre region because the jurisdiction is what determines your rights; if we ever move processing outside the EEA/UK we will update this policy and Section 9 before doing so. When you run third-party coding agents or connect to AI providers using your own keys, your interactions with those tools are governed by their terms and privacy policies, not this one.
6. Data retention
- Account & cloud-synced data is retained while your account is active. When you delete your account, we delete or irreversibly anonymize your associated cloud data within 30 days, except where we must retain it to meet a legal obligation.
- Derived analytics metrics are retained in aggregated form for 24 months.
- Acceptance records (3.4) are the one exception to the 30-day deletion above: they are retained while your account exists and for 7 years after account deletion — the general limitation period for contract claims under Israeli law — because the record may be needed to establish, exercise, or defend legal claims (GDPR Art. 17(3)(e)). The retained record is limited to the three fields described in 3.4 and is deleted when that period ends.
- Local acceptance records written on your own device are retained until you delete them, like all other local data.
- Local data on your device is retained until you delete it; you control it entirely.
7. Security
- Row-Level Security (RLS) is enforced on every cloud table, so you can only read data belonging to you or to organizations you are a member of.
- Organization-shared configuration secrets are encrypted at rest in a dedicated secrets vault and decryptable only through access-controlled paths.
- Data in transit is protected with TLS/HTTPS.
- No security measure is perfect; we cannot guarantee absolute security, particularly for code and commands that agents execute on your own machine.
8. Your rights
Depending on your location (e.g. GDPR/UK GDPR, CCPA/CPRA), you may have the right to access, correct, delete, export, or restrict processing of your personal data, and to object to processing based on legitimate interests. To exercise any of these, contact shaked.labs@gmail.com. Deleting your account removes your associated cloud data as described in Section 6. You will not be discriminated against for exercising these rights.
If you are in the EEA or the UK, you also have the right to lodge a complaint with your local data-protection supervisory authority. If you are in Israel, you may contact the Israeli Privacy Protection Authority (PPA).
9. International transfers
Your data is processed in two places: the European Economic Area and the United Kingdom, where our cloud services are hosted (Section 5), and Israel, where we are based and from which we administer those services.
Transfers between these are covered by adequacy rather than by contractual safeguards: the EEA and the UK recognise each other as providing adequate protection, and the European Commission has recognised Israel as providing an adequate level of protection for personal data. No Standard Contractual Clauses are therefore required for the routes we use today.
If we ever process your data outside the EEA, the UK, or Israel, we will update this section first and put appropriate safeguards — such as Standard Contractual Clauses together with a transfer impact assessment — in place before doing so.
10. Children
Vecton is not directed to, and is not intended for use by, individuals under 18. We do not knowingly collect their personal data.
11. Changes to this policy
We may update this policy as the product evolves. Material changes will be reflected here with a new “Last updated” date and, where appropriate, surfaced in the app.
12. Contact
Shaked Nachum, trading as “Vecton”, Israel Privacy inquiries: shaked.labs@gmail.com