Privacy Policy
Last updated: July 12, 2026
1. Overview
This policy explains what personal data Ventorah (ventorah.com) collects, why, where it goes, and the choices you have. The Service is owned and operated by its individual proprietor, based in India. The short version: we collect what the product needs to function, we don't sell your data, analytics only runs if you opt in, and you can delete everything yourself at any time.
2. Data we collect
- Account data — email address, display name, and a securely hashed password (bcrypt). If you sign in with Google or GitHub we receive your name, email, and avatar from that provider; we never see your provider password.
- Your content — 3D models you upload, simulation configurations and results, projects, comments, and team memberships.
- Billing data — your plan, credit balance, and Stripe customer/subscription identifiers. Card details go directly to Stripe; we never receive or store them.
- API keys you connect (BYOK) — encrypted at rest with AES-256-GCM, never displayed again after saving, and used only to make requests you initiate.
- Messages — anything you send through the contact form.
- Usage analytics (only with your consent) — Google Analytics 4 page-view and interaction events. Analytics cookies are not set unless you accept them in the cookie banner.
3. How we use data
- to provide the Service: run solves, store results, enable collaboration;
- to process payments and maintain credit balances (Stripe);
- to power AI features you invoke (see section 5);
- to respond to messages you send us;
- to understand aggregate site usage — only if you opt in to analytics.
Legal bases under the GDPR: performance of a contract (the Service itself), consent (analytics cookies), and legitimate interest (service security and abuse prevention).
4. Cookies
- vt_session (essential) — keeps you signed in. HttpOnly, secure, expires after your session. The site cannot work without it, so it does not require consent.
- Google Analytics (_ga, _ga_*) (optional) — set only after you choose “Accept analytics” in the cookie banner. Decline and analytics stays off; the site works identically.
To change your choice later, clear this site's cookies/site data in your browser — the banner will ask again on your next visit.
5. AI processing
When you run AI-powered features (AI engine, design studio, aero assistant), your simulation configuration, geometry-derived features, and prompts are sent to Anthropic's Claude API — either under our platform key or, on BYO plans, your own key — solely to generate the response. Learned solver heuristics are stored against your account and are not shared with other customers.
6. Who we share data with
We use a small set of processors to run the Service — we do not sell data:
- Vercel — application hosting and edge network;
- Neon — managed Postgres database (your account and content);
- Stripe — payment processing;
- Anthropic — AI features you invoke;
- Google Analytics — usage analytics, only with consent.
These providers may process data in other countries; transfers rely on their standard contractual safeguards.
7. Retention & deletion
Your data is kept while your account exists. Deleting your account (Dashboard → Settings → delete account) permanently removes your account, models, simulations, comments, memberships, and stored keys. Trial demo runs are never persisted in the first place. Stripe retains transaction records as required by financial regulations.
8. Your rights
Depending on your location (e.g., the GDPR in the EU/UK, or India's Digital Personal Data Protection Act, 2023), you have the right to access, correct, export, restrict, or delete your personal data, and to object to processing. Most of this is self-service: your content is visible in the app, and deletion is one click in Settings. For anything else, contact us via the contact form. You also have the right to complain to your local data-protection authority.
9. Security
All traffic is encrypted in transit (TLS, HSTS). Passwords are hashed with bcrypt; connected API keys are encrypted at rest with AES-256-GCM; sessions use signed HttpOnly cookies. No system is perfectly secure — if we learn of a breach affecting your data we will notify you without undue delay.
10. Children
The Service is not directed at children under 16, and we do not knowingly collect their data.
11. Changes
We will update this policy as the Service evolves and announce material changes on the site before they take effect.
Questions? Use the contact form on the home page.