Legal

Privacy Policy

Effective: May 14, 2026Last updated: May 14, 2026

Privacy Policy

Vrin, Inc. ("Vrin," "we," "us," or "our") operates the website located at https://vrin.cloud and provides the Vrin platform, a retrieval-time reasoning layer for AI agents (collectively, the "Services"). This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website, sign up for an account, or use the Services.

By accessing or using the Services, you agree to this Privacy Policy. If you do not agree, please do not use the Services.

1. Information We Collect

We collect information in three categories: information you provide, information we collect automatically, and information from third parties.

1.1 Information You Provide

  • Account information: When you create an account, we collect your name, email address, password (hashed; we never store plaintext passwords), organization name, and role.
  • Payment information: When you subscribe to a paid plan, our payment processor (Stripe and/or Mercury) collects your payment details. We do not store full credit card numbers on our servers.
  • Customer Content: Documents, text, prompts, queries, configurations, and other content you upload, submit, or process through the Services (collectively, "Customer Content").
  • Communications: Information you provide when you contact us for support, complete a form, or otherwise communicate with us.

1.2 Information Collected Automatically

  • Usage data: Pages visited, features used, queries submitted, API calls made, timestamps, and similar diagnostic data.
  • Device and connection data: IP address, browser type, operating system, device identifiers, and approximate location (city/region level, derived from IP).
  • Cookies and similar technologies: See Section 6 — Cookies.

1.3 Information from Third Parties

  • Authentication providers: If you sign in via a third-party identity provider (e.g., Google, Microsoft, Stytch), we receive basic profile information from that provider as authorized by you.
  • Analytics and marketing partners: We may receive aggregated information from analytics or advertising partners to help us understand how visitors find and use the Services.

2. How We Use Information

We use the information we collect for the following purposes:

  • To provide, maintain, and improve the Services;
  • To process transactions and send related billing communications;
  • To authenticate users and secure accounts;
  • To process Customer Content for the sole purpose of providing the Services you have requested (e.g., ingesting documents, generating retrieval responses, returning structured facts);
  • To respond to inquiries, support requests, and feedback;
  • To send service-related communications (e.g., security alerts, billing notices, product updates);
  • To send marketing communications, subject to your consent and right to opt out;
  • To monitor and analyze trends, usage, and activities in connection with the Services;
  • To detect, prevent, and address technical issues, fraud, and abuse;
  • To comply with legal obligations and enforce our Terms of Use.

We do not use Customer Content to train Vrin's, or any third party's, foundation models or machine learning systems. Customer Content is processed solely to deliver the Services to you.

3. How We Share Information

We do not sell your personal information. We share information only in the limited circumstances described below.

3.1 Service Providers (Subprocessors)

We share information with third-party service providers that perform services on our behalf. These providers are contractually bound to use information only to provide services to us and to protect the confidentiality and security of the information.

Our current subprocessors include:

ProviderPurposeData Categories
Amazon Web Services (AWS)Cloud infrastructure (compute, storage, databases, vector and graph stores, foundation model access via Amazon Bedrock)All categories
OpenAILarge language model inference for query reasoning and synthesisQuery content; not used for OpenAI training (per OpenAI API enterprise terms)
AnthropicLarge language model inference for query reasoning and synthesisQuery content; not used for Anthropic training (per Anthropic API terms)
Stripe / MercuryPayment processingBilling and payment information
StytchAuthentication and identity managementAccount credentials, session data
PostHog / Vercel AnalyticsProduct and website analyticsUsage data, device data
Resend / PostmarkTransactional email deliveryEmail address, message content

A current list of subprocessors is maintained at https://vrin.cloud/legal/subprocessors and is updated as our infrastructure evolves.

For customers using our Enterprise / Bring-Your-Own-Cloud deployment, Customer Content is processed within the customer's own AWS or Azure account and does not transit Vrin's shared infrastructure. In that deployment model, the subprocessors listed above (other than authentication and payment) may not apply.

3.2 Legal and Safety

We may disclose information if required to do so by law or in response to valid legal process (subpoenas, court orders, government requests), or where we believe disclosure is necessary to protect our rights, the rights of our users, or the public, or to prevent fraud, security threats, or illegal activity.

3.3 Business Transfers

If Vrin is involved in a merger, acquisition, financing, reorganization, bankruptcy, or sale of company assets, your information may be transferred or disclosed as part of that transaction. We will notify you (e.g., by email and/or a prominent notice on the Services) of any change in ownership or use of your personal information.

3.4 With Your Consent

We may share information with your consent or at your direction.

4. Your Rights and Choices

4.1 Account Information

You can review, update, or delete your account information at any time through your account settings or by contacting vedant@vrin.cloud.

4.2 Marketing Communications

You can opt out of promotional emails by clicking the "unsubscribe" link in any marketing email or by emailing vedant@vrin.cloud. We will continue to send you transactional and service-related communications.

4.3 Rights Under CCPA / CPRA (California Residents)

If you are a California resident, you have the right to:

  • Know what personal information we collect, use, disclose, and retain;
  • Access the personal information we have about you;
  • Delete your personal information, subject to certain exceptions;
  • Correct inaccurate personal information;
  • Opt out of the sale or sharing of personal information (we do not sell or share personal information for cross-context behavioral advertising as those terms are defined under California law);
  • Limit the use of sensitive personal information (we do not use sensitive personal information for purposes that would trigger this right);
  • Non-discrimination for exercising your rights.

To exercise these rights, email vedant@vrin.cloud. We may need to verify your identity before responding.

4.4 Rights Under GDPR / UK GDPR (EEA, UK, Swiss Residents)

If you are located in the European Economic Area, United Kingdom, or Switzerland, you have the right to:

  • Access your personal data;
  • Rectify inaccurate personal data;
  • Erase your personal data ("right to be forgotten");
  • Restrict or object to processing of your personal data;
  • Data portability;
  • Withdraw consent at any time where processing is based on consent;
  • Lodge a complaint with a supervisory authority.

Our legal bases for processing under GDPR include: (a) performance of a contract with you, (b) compliance with a legal obligation, (c) our legitimate interests in operating and improving the Services, and (d) your consent (where required).

To exercise these rights, email vedant@vrin.cloud.

4.5 Data Transfers

Vrin is based in the United States. If you access the Services from outside the U.S., your information will be transferred to, stored, and processed in the United States. Where required, we rely on appropriate safeguards such as Standard Contractual Clauses for cross-border transfers.

5. Data Retention

We retain personal information for as long as necessary to provide the Services, comply with our legal obligations, resolve disputes, and enforce our agreements. Specifically:

  • Account information is retained for the lifetime of your account, plus up to 90 days after deletion (for backup retention and dispute resolution).
  • Customer Content is retained per your subscription plan and is deleted on account deletion or upon your request, subject to backup rotation cycles (typically 30 days).
  • Billing records are retained for at least 7 years to comply with tax and accounting obligations.
  • Logs and usage data are retained for up to 12 months.

6. Cookies and Similar Technologies

We use cookies and similar technologies (collectively, "cookies") to operate the Services and improve your experience. Cookies are small data files stored on your device.

CategoryPurposeExamples
Strictly necessaryRequired for the Services to function (e.g., authentication, security, load balancing). Cannot be disabled.Session tokens, CSRF tokens
FunctionalRemember your preferences (e.g., language, region, dark/light mode).UI settings cookies
AnalyticsHelp us understand how visitors use the Services.PostHog, Vercel Analytics
MarketingUsed only if you consent. Help us measure marketing effectiveness.Conversion tracking (if enabled)

You can manage cookies through your browser settings or, where applicable, through our cookie banner. Disabling strictly necessary cookies may prevent the Services from functioning.

7. Security

We implement administrative, technical, and physical safeguards designed to protect personal information, including encryption in transit (TLS 1.2+) and at rest, access controls, secrets management via AWS Secrets Manager, audit logging, and regular security review. No method of transmission or storage is 100% secure, and we cannot guarantee absolute security.

If we become aware of a security incident affecting your personal information, we will notify you in accordance with applicable law.

8. Children's Privacy

The Services are not directed to children under 16. We do not knowingly collect personal information from children under 16. If you believe a child has provided us with personal information, please contact vedant@vrin.cloud and we will delete it.

9. Third-Party Links and Services

The Services may contain links to third-party websites or services we do not operate. This Privacy Policy does not apply to those third parties. We encourage you to review the privacy practices of any third party before providing them with information.

10. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. If we make material changes, we will notify you by email (sent to the address associated with your account) or by posting a prominent notice on the Services prior to the change taking effect. The "Last Updated" date at the top reflects the most recent revision.

11. Contact Us

If you have questions about this Privacy Policy or our privacy practices, please contact us:

Vrin, Inc. Attn: Privacy 3217 Roslyn Ct Folsom, CA 95630 United States Email: vedant@vrin.cloud

For users in the EEA, UK, or Switzerland, if we appoint an EU/UK Representative or Data Protection Officer in the future, their contact information will be posted here.