AT A GLANCE
- Your playground draft is saved in your browser.
- Requests pass through Cloudflare to Vansa-owned infrastructure.
- Full API inputs and answers are not stored in the routine usage database.
- Operational metadata and diagnostic records are stored separately.
- Privacy questions and requests: [email protected].
01 Who we are
Vansa.org ("Vansa", "we" or "us") is a non-commercial organisation operating from Lithuania. This policy covers our website, documentation, playground, usage console and API. Vansa.org is responsible for the personal data we use to administer and secure these services.
If your organisation sends personal data to the API on behalf of other people, it is responsible for its own privacy notices and lawful use of that data. Contact us to arrange any required data-processing terms before submitting it. This notice does not replace a data-processing agreement.
02 Information we process
- API content
- The context, questions, answer options and model selection you submit, and the results produced in response. We send the request to the model server to calculate its answers.
- Usage & diagnostics
- Request time and identifier, API-key identifier, model, question and token counts, processing time, status, client IP address and error details. Diagnostic messages can include question identifiers or fragments of submitted content.
- API-key records
- Key names, owner contact details where supplied, administrative notes, access limits, issue and expiry dates, revocation status and usage. We also retain credential information needed to authenticate and administer keys.
- Communications
- Your email address and any information or attachments you choose to send when contacting us about access, support or privacy.
- API waitlist
- Your name, email address, developer or business profile, optional company or project name, intended use and signup date. These details are stored on Vansa-owned infrastructure and are available to the Vansa team through the private administration area.
The public API's routine usage database does not store full request bodies or answers. This is separate from browser drafts and diagnostic logs. A request runs model inference; it does not itself train or update the model.
Use sample or de-identified content in the public playground. Only submit information you have permission to share, and avoid passwords, private API keys and unnecessary personal details in your input.
03 Why we process it
We use the information needed to answer API requests, provide access and respond to support enquiries. Where this involves personal data, we rely on performing our agreement with you or taking steps you request before an agreement.
If you join the waitlist, we use your details to review your request and contact you about API access. Joining does not subscribe you to a general marketing newsletter. You can ask to leave the waitlist at [email protected].
We use usage and diagnostic records to manage capacity, enforce access limits, investigate errors and protect the service against abuse. Our basis is our legitimate interest in operating a reliable and secure service, balanced against your rights. We may also retain or disclose information where a legal obligation requires it.
If we ask for consent for an optional use, you can withdraw it without affecting processing that already took place. Vansa returns model estimates; how an application acts on those estimates is determined by its developer or operator.
04 Browser storage
The playground uses local storage to remember your draft context, questions and editor settings. These drafts have no automatic expiry. Clearing the site's data in your browser removes them.
The playground starts with shared demo access. If you explicitly choose to use your own API key, it is kept only for the current page and is not saved by the playground in browser storage. Personal keys saved by an earlier version are removed when the playground loads; your draft is kept. On a shared device, clear site data when you finish. The shared demo credential does not create a personal account or a private cloud draft.
Vansa's website code does not include advertising or analytics scripts. Infrastructure providers may process technical data needed to deliver and protect traffic. A separate session cookie is used for the administration area.
The usage console uses an essential session cookie to keep you signed in. The API key entered for console sign-in is not saved in browser storage. We store a hashed session identifier, its expiry and the associated API-key identifier. Sessions expire after 12 hours; signing out invalidates the session.
05 Providers & transfers
API requests travel from your device through Cloudflare to Vansa-owned infrastructure, where the API and model run. Cloudflare provides traffic delivery and protection. We do not send API inputs to a third-party AI inference provider.
Providers involved in network delivery and communications may process data needed for those functions. Information may also be disclosed where legally required or necessary to investigate misuse or protect people's rights.
Operating from Lithuania does not mean every network or processing step takes place in Lithuania. Provider infrastructure can involve other countries. Contact [email protected] for current processing-location and transfer information before using Vansa for data with specific residency requirements. Where a restricted international transfer is needed, an applicable legal transfer mechanism must be in place.
Links to external services lead to sites governed by their own privacy notices.
06 Retention & security
Browser drafts remain until you replace them or clear local site data. API-key and operational records are stored separately; revoking or deleting a key does not automatically erase past request records.
The current beta has no fixed automatic deletion schedule for application usage records. Retention must be assessed against the need to administer access, resolve support cases, investigate security incidents and meet legal obligations. Infrastructure logs and backups may follow separate schedules. Contact us to request deletion or details about records connected to your use.
We use access controls, API authentication and HTTPS for the public service. These measures reduce risk, but no system can guarantee complete security. Protect your personal keys and report suspected exposure to [email protected].
07 Your rights
Depending on the applicable law and circumstances, you may request access to your personal data, correction, deletion, restriction or a portable copy, and object to processing based on legitimate interests. Where consent is the basis, you may withdraw it.
Email [email protected] with enough information to identify the records concerned. We may need to verify your identity. Do not send your full API key. For data submitted by another organisation, it may be necessary to direct your request to that organisation.
You can complain to Lithuania's State Data Protection Inspectorate or the competent authority where you live or work. Contacting us first is optional.
The service is intended for adults. If you believe a child has supplied personal data, let us know so we can assess and address it.
08 Changes & contact
We will update this page when our service or data practices change and revise the date above. Where required, we will provide further notice before a material change takes effect.
For questions about this policy or your personal data, contact Vansa.org in Lithuania using the address below.