Privacy Policy
Last updated: April 2026 · 2026-04-15
This Privacy Policy explains how Vara Lab ("Vara", "we") collects, uses, stores and shares your personal information. It is drafted with reference to the EU GDPR and California CCPA. Specific rights for EU/UK/California residents are in Section 7.
1. Data Controller
The data controller is the Vara operating team (organized in the United Kingdom, or the then-disclosed operating entity). Data protection contact: [email protected] [email protected].
2. Information We Collect
- Account info: email, username, hashed password; for OAuth, public profile from Google / WeChat (name, avatar, OpenID)
- User content: uploaded PDFs, images, run-log attachments; projects, experiments, parameters, steps, notes you create
- Usage data: page views, feature usage, API call counts (for billing and abuse prevention)
- Technical data: IP address, browser User-Agent, device type, timezone (for security and troubleshooting)
- Payment data: handled by our Merchant of Record (Creem.io). We do not store full card numbers, only subscription status, transaction IDs and last 4 digits
3. Purposes & Legal Bases (GDPR Art. 6)
| Purpose | Legal Basis |
|---|---|
| Providing the Service (login, storage, AI parsing) | Contract (Art. 6(1)(b)) |
| Account emails, security alerts | Contract + legitimate interest |
| Abuse prevention, rate limits, audit logs | Legitimate interest (Art. 6(1)(f)) |
| Billing and invoicing | Contract + legal obligation |
| Aggregated / de-identified analytics | Legitimate interest; tracking cookies require consent |
4. Special Protections for Experiment Data
- Admins cannot view your experiment content — only project names and aggregate stats (unless you voluntarily share content in a support request)
- Strict isolation via database-level userId ownership checks on every query
- Never used for model training, by Vara or any third-party provider
- Never sold or shared with advertisers or data brokers
5. Sub-processors
| Service | Purpose | Data |
|---|---|---|
| Vercel | Hosting + Blob storage | All |
| Neon PostgreSQL | Database | Account + experiment |
| MiniMax (China) | Document text parsing | User-submitted text |
| Google Gemini | Image/PDF vision parsing | User-submitted images |
| OpenAI | Fallback AI & Q&A | User-submitted content |
| Resend | Transactional email | Email address |
| Creem.io | Payment & subscription (MoR) | Billing info |
Sub-processors are bound by data processing agreements. For cross-border transfers (e.g. EU user data to the US), we rely on Standard Contractual Clauses (SCCs) or equivalent safeguards. Institutional customers may request a DPA.
6. Retention
- While account is active: retained
- After account deletion: experiment data hard-deleted within 30 days; account metadata kept 180 days for fraud dispute then fully deleted
- Billing records: 7 years per tax law
- Server logs: 90 days
- AI call context: not persisted; cleared after processing
7. Your Rights
Under GDPR / UK GDPR / CCPA and other applicable laws, you have the right to:
- Access — know what we hold about you
- Rectification — correct inaccurate data
- Erasure ("right to be forgotten")
- Restriction and Objection
- Portability — export your data (JSON/Markdown/CSV)
- Withdraw consent (where processing relies on consent)
- Lodge a complaint with your supervisory authority (EU: your national DPA; UK: ICO; California: CPPA)
To exercise these rights, email the data protection contact. We respond within 30 days.
8. Cookies & Tracking
We use only essential cookies (session, locale, CSRF). No ad or cross-site tracking cookies. If product analytics (e.g. PostHog) are introduced, EU users will see a consent banner first.
9. Children
The Service is not directed to users under 18. If we learn we have collected data from a minor, we will delete it promptly.
10. Security Measures
- Site-wide HTTPS/TLS
- bcrypt one-way password hashing
- HttpOnly + Secure session cookies
- Private Vercel Blob with server-side auth
- Authentication and ownership checks on every API
- Rate limiting and anomaly alerts
- Regular database backups
11. Breach Notification
If a data breach is likely to pose a high risk to your rights, we will notify the supervisory authority within 72 hours of discovery, and notify you directly when required.
12. Changes to This Policy
Material changes will be announced in-app and reflected in the date at the top.
13. Contact
Privacy questions, rights requests, or DPA signing: [email protected]