VaraLab

Privacy Policy

Last updated: April 2026 · 2026-04-15

This Privacy Policy explains how Vara Lab ("Vara", "we") collects, uses, stores and shares your personal information. It is drafted with reference to the EU GDPR and California CCPA. Specific rights for EU/UK/California residents are in Section 7.

1. Data Controller

The data controller is the Vara operating team (organized in the United Kingdom, or the then-disclosed operating entity). Data protection contact: [email protected] [email protected].

2. Information We Collect

  • Account info: email, username, hashed password; for OAuth, public profile from Google / WeChat (name, avatar, OpenID)
  • User content: uploaded PDFs, images, run-log attachments; projects, experiments, parameters, steps, notes you create
  • Usage data: page views, feature usage, API call counts (for billing and abuse prevention)
  • Technical data: IP address, browser User-Agent, device type, timezone (for security and troubleshooting)
  • Payment data: handled by our Merchant of Record (Creem.io). We do not store full card numbers, only subscription status, transaction IDs and last 4 digits

3. Purposes & Legal Bases (GDPR Art. 6)

PurposeLegal Basis
Providing the Service (login, storage, AI parsing)Contract (Art. 6(1)(b))
Account emails, security alertsContract + legitimate interest
Abuse prevention, rate limits, audit logsLegitimate interest (Art. 6(1)(f))
Billing and invoicingContract + legal obligation
Aggregated / de-identified analyticsLegitimate interest; tracking cookies require consent

4. Special Protections for Experiment Data

  • Admins cannot view your experiment content — only project names and aggregate stats (unless you voluntarily share content in a support request)
  • Strict isolation via database-level userId ownership checks on every query
  • Never used for model training, by Vara or any third-party provider
  • Never sold or shared with advertisers or data brokers

5. Sub-processors

ServicePurposeData
VercelHosting + Blob storageAll
Neon PostgreSQLDatabaseAccount + experiment
MiniMax (China)Document text parsingUser-submitted text
Google GeminiImage/PDF vision parsingUser-submitted images
OpenAIFallback AI & Q&AUser-submitted content
ResendTransactional emailEmail address
Creem.ioPayment & subscription (MoR)Billing info

Sub-processors are bound by data processing agreements. For cross-border transfers (e.g. EU user data to the US), we rely on Standard Contractual Clauses (SCCs) or equivalent safeguards. Institutional customers may request a DPA.

6. Retention

  • While account is active: retained
  • After account deletion: experiment data hard-deleted within 30 days; account metadata kept 180 days for fraud dispute then fully deleted
  • Billing records: 7 years per tax law
  • Server logs: 90 days
  • AI call context: not persisted; cleared after processing

7. Your Rights

Under GDPR / UK GDPR / CCPA and other applicable laws, you have the right to:

  • Access — know what we hold about you
  • Rectification — correct inaccurate data
  • Erasure ("right to be forgotten")
  • Restriction and Objection
  • Portability — export your data (JSON/Markdown/CSV)
  • Withdraw consent (where processing relies on consent)
  • Lodge a complaint with your supervisory authority (EU: your national DPA; UK: ICO; California: CPPA)

To exercise these rights, email the data protection contact. We respond within 30 days.

8. Cookies & Tracking

We use only essential cookies (session, locale, CSRF). No ad or cross-site tracking cookies. If product analytics (e.g. PostHog) are introduced, EU users will see a consent banner first.

9. Children

The Service is not directed to users under 18. If we learn we have collected data from a minor, we will delete it promptly.

10. Security Measures

  • Site-wide HTTPS/TLS
  • bcrypt one-way password hashing
  • HttpOnly + Secure session cookies
  • Private Vercel Blob with server-side auth
  • Authentication and ownership checks on every API
  • Rate limiting and anomaly alerts
  • Regular database backups

11. Breach Notification

If a data breach is likely to pose a high risk to your rights, we will notify the supervisory authority within 72 hours of discovery, and notify you directly when required.

12. Changes to This Policy

Material changes will be announced in-app and reflected in the date at the top.

13. Contact

Privacy questions, rights requests, or DPA signing: [email protected]