legal

Privacy Policy

Last updated: July 21, 2026

This policy covers vendo.run and Vendo Cloud (console.vendo.run), operated by the Vendo team. Short version: we collect what we need to run the service and bill you, we don’t sell it, and you can ask us to delete it.

1. What we collect

  • Account data — your email address and sign-in metadata.
  • Billing data — subscription and payment records via Stripe. Card numbers go to Stripe directly; we never store them.
  • Usage metering — counts of runs, sandbox minutes, and tool calls per project, used for quotas and billing.
  • Site analytics — page views and interactions on vendo.run, measured with PostHog.
  • Customer content — data your end users send through the agent when you run Vendo Cloud in your product. We process it on your behalf and on your instructions; you stay the controller of that data.

2. How we use it

To provide and operate the service, meter and bill usage, answer support requests, prevent abuse, and improve the product using aggregated, de-identified usage patterns. We don’t use customer content to train models.

3. No sale of data

We do not sell your personal information, and we don’t share it with third parties for their own advertising.

4. Processors we rely on

  • Supabase — authentication and application database
  • Stripe — payments and subscription billing
  • Cloudflare — hosting, CDN, and network security
  • Neon — managed Postgres for the data plane
  • Anthropic — model inference for agent runs
  • PostHog — analytics on the marketing site

Each processor receives only what its job requires and is bound by its own data-processing terms.

5. Cookies

The console uses cookies for authentication and session state. The marketing site stores your theme preference locally. We don’t use advertising cookies.

6. Retention

Account and billing data stay for as long as your account is active, plus what tax and accounting rules require. Metering records stay as long as needed for billing and audit. Customer content is deleted when you delete it or close your account.

7. Deletion and your rights

Email founders@vendo.runto access, correct, export, or delete your personal data. If you’re in the EU/EEA or UK, the GDPR gives you these rights plus the right to object to or restrict processing and to complain to your supervisory authority. If you’re a California resident, the CCPA gives you the rights to know, delete, correct, and not be discriminated against for exercising them. We answer within the statutory deadlines.

8. Security

Data is encrypted in transit, access is scoped per organization and project, and production access is restricted to the people who operate the service.

9. Changes

We may update this policy. For material changes we’ll notify you by email or in the console before they take effect.

10. Contact

Privacy questions: founders@vendo.run.