Privacy Policy
Last updated: July 2026
1. Introduction
ManyVector Inc. ("ManyVector," "we," "us," or "our") is committed to protecting the privacy and security of your information. This Privacy Policy describes how we collect, use, disclose, and safeguard personal data when you use our website, platform, and services (collectively, the "Service").
ManyVector is designed from the ground up for data sovereignty. A core principle of our product is that your AI traffic — your prompts, completions, and model outputs — belongs to you. For self-hosted deployments, that data never leaves your infrastructure and ManyVector never sees it. For managed SaaS deployments, we process only what is necessary to operate the Service, and we do not use your AI traffic content for any secondary purpose.
This Privacy Policy applies to all users of the ManyVector website and managed Service. If you are using a self-hosted deployment, this policy applies only to personal data you provide directly to ManyVector (for example, when creating a cloud account or contacting us for support) — your inference data and audit logs remain on your own infrastructure and are outside the scope of this policy.
2. Information We Collect
We collect information that you provide directly to us, information collected automatically when you use the Service, and information from third-party sources where relevant to operating the Service.
Account Information. When you create an account or sign up for a trial, we collect your name, email address, company name, job title, and any other information you choose to provide during registration. This information is used to create and manage your account, communicate with you about the Service, and provide customer support.
Usage Data (SaaS deployments). For managed SaaS deployments, we collect information about how you interact with the admin UI, including pages visited, features used, settings configured, and actions taken within the dashboard. We also collect aggregate platform metrics such as request counts, latency distributions, and error rates to operate and improve the Service. We do not collect or store the content of your AI prompts or model responses as usage data.
Log Data. Like most web services, our servers automatically collect standard log data when you interact with our website and API. This includes IP addresses, browser type and version, operating system, referring URLs, pages viewed, time spent on pages, access timestamps, and HTTP status codes. Log data is used for security monitoring, debugging, and aggregate traffic analysis.
Payment Information. If you subscribe to a paid plan, billing and payment processing are handled by our third-party payment processor. ManyVector does not directly collect, store, or process your full credit card numbers or bank account details. We receive and store limited billing information such as your billing name, address, and the last four digits of your payment method, as provided by the payment processor.
Communications. When you email us, submit a support ticket, participate in user research, or otherwise communicate with ManyVector, we retain those communications and any personal data contained in them. This allows us to respond to your requests, track open issues, and improve our support quality.
3. Information We Do NOT Collect (Self-Hosted)
This section is important for self-hosted customers.
When you deploy ManyVector on your own infrastructure, the software runs entirely within your environment. ManyVector does not collect, receive, or have access to:
Your AI request and response data, including prompts, completions, embeddings, or any other LLM traffic you route through the gateway. Your audit logs, conversation history, or stored completions. Your vector store contents or retrieved context. Your internal user data or end-user identifiers. Any telemetry, usage metrics, or operational data from your self-hosted instance.
The self-hosted binary does not "phone home" to ManyVector servers during normal operation. You are in complete control of your data. The only information ManyVector receives from self-hosted customers is what you voluntarily provide — for example, when registering a cloud account, requesting a license key, or contacting us for support.
4. How We Use Your Information
We use the information we collect for the following purposes:
Providing and Operating the Service. To create and maintain your account, authenticate your identity, deliver the features and functionality you have subscribed to, process transactions, and provide customer support.
Improving the Service. To understand how the Service is used in aggregate, identify areas for improvement, troubleshoot issues, and develop new features. We analyze usage patterns and performance metrics in aggregate and do not use individual Customer Data content for model training or product development.
Communications. To respond to your support requests and questions; to send transactional communications such as account confirmations, invoices, and security alerts; and to send product updates, release notes, and relevant announcements. You may opt out of non-transactional communications at any time by following the unsubscribe link in our emails or contacting us at hello@manyvector.com.
Billing and Account Management. To process payments, manage subscriptions, issue invoices, handle renewals and cancellations, and enforce payment terms.
Security and Fraud Prevention. To detect, investigate, and prevent fraudulent activity, unauthorized access, abuse, and other security incidents. To monitor for violations of our Terms of Service and to protect the integrity of the Service and other users.
5. Data Sharing and Disclosure
We do not sell your personal data. We do not sell, rent, or trade your personal information to third parties for their marketing or other commercial purposes.
We may share your information with third parties only in the following limited circumstances:
Payment Processors. We share billing information with our payment processor(s) to facilitate payment transactions. Our payment processors are contractually required to protect your information and may only use it for the purpose of processing payments on our behalf.
Infrastructure Providers. For managed SaaS deployments, we use cloud infrastructure providers to host the Service. These providers process account and operational data on our behalf under data processing agreements and are not authorized to use your data for their own purposes.
Service Providers. We may engage third-party companies and individuals to perform services on our behalf, such as customer support tooling, error tracking, and email delivery. These providers have access only to the personal data necessary to perform their functions and are bound by confidentiality and data protection obligations.
Legal Requirements. We may disclose your information if required to do so by law, regulation, legal process, or governmental request. Where permitted by law, we will attempt to notify you of such requests before disclosing your information.
Business Transfers. In connection with a merger, acquisition, reorganization, sale of assets, or bankruptcy, your information may be transferred to the successor entity, subject to the same privacy protections described in this policy.
We do not share your AI request content or prompts with any third parties for any reason, including advertising, analytics, or model training.
6. Data Retention
We retain your personal data for as long as your account is active and for a reasonable period thereafter to fulfill the purposes described in this policy, comply with legal obligations, resolve disputes, and enforce our agreements.
Account Data. Account information is retained for the duration of your account and for 30 days after account deletion or subscription termination, during which time you may request data export. After 30 days, account data is deleted or anonymized from our production systems, subject to legal retention requirements.
Log Data. Web server logs and access logs are retained for 90 days for security and debugging purposes, after which they are deleted or anonymized.
Communications. Support communications and email records are retained for 3 years to maintain support history and comply with applicable legal obligations.
Billing Records. Transaction records and invoices are retained for the period required by applicable tax and accounting laws, typically 7 years.
7. Security
We implement industry-standard technical and organizational security measures to protect your personal data against unauthorized access, disclosure, alteration, and destruction. These measures include:
Encryption. All data transmitted between your browser or client and ManyVector services is encrypted using TLS. Data at rest in our managed infrastructure is encrypted using AES-256 or equivalent.
Access Controls. Access to personal data within ManyVector is limited to employees and contractors who need it to perform their job functions. We enforce least-privilege access principles and require multi-factor authentication for internal systems.
Security Monitoring. We monitor our systems for suspicious activity, unauthorized access attempts, and security vulnerabilities. We conduct periodic security assessments and respond promptly to identified risks.
Incident Notification. In the event of a data breach affecting your personal data, we will notify you and applicable regulatory authorities as required by law. We will provide notification without undue delay and include information about the nature of the breach, data affected, and steps we are taking to address it. For security-related concerns or to report a vulnerability, please contact hello@manyvector.com.
8. Your Rights
Depending on your location and applicable law, you may have certain rights regarding your personal data. We honor these rights regardless of jurisdiction to the extent practicable.
Access. You have the right to request a copy of the personal data we hold about you and information about how we use it.
Correction. You have the right to request correction of inaccurate or incomplete personal data. Many account details can be updated directly in your account settings.
Deletion. You have the right to request deletion of your personal data. We will honor deletion requests within 30 days, subject to our legal obligation to retain certain records (such as billing records required by tax law).
Data Portability. You have the right to receive your personal data in a structured, machine-readable format and to transmit that data to another service provider where technically feasible.
Objection and Restriction. You have the right to object to or request restriction of certain processing of your personal data, including processing for direct marketing purposes.
GDPR Rights (EU/EEA Residents). If you are located in the European Union or European Economic Area, you have the rights described above under the General Data Protection Regulation (GDPR), including the right to lodge a complaint with your local data protection authority.
CCPA Rights (California Residents). If you are a California resident, you have rights under the California Consumer Privacy Act (CCPA), including the right to know what personal information is collected, the right to delete personal information, the right to opt out of sale (we do not sell personal data), and the right to non-discrimination for exercising your privacy rights.
To exercise any of these rights, please contact us at hello@manyvector.com. We will respond within 30 days. We may need to verify your identity before fulfilling certain requests.
9. Cookies and Tracking
Our marketing website uses a minimal set of first-party cookies to support core site functionality and measure aggregate traffic. We do not use third-party tracking cookies, advertising cookies, or behavioral profiling cookies. We do not share browsing data with advertising networks or data brokers.
Session Cookies. We use session cookies to maintain your login state within the ManyVector admin interface. These cookies expire when you close your browser or log out.
Preference Cookies. We may use persistent first-party cookies to remember your preferences (such as language or UI settings) across visits. These cookies do not track your activity across other websites.
Analytics. We use privacy-respecting analytics to understand aggregate website traffic (for example, which pages are most visited). Any analytics we use are configured without cross-site tracking and do not fingerprint individual users.
The ManyVector platform software (gateway, workspace) does not set cookies in your infrastructure or end users' browsers. You control your own cookie policies for any applications you build on top of the platform.
10. Children's Privacy
The Service is not directed at or intended for use by children under the age of 16. We do not knowingly collect personal data from children under 16. If you are a parent or guardian and believe your child has provided personal data to ManyVector, please contact us at hello@manyvector.com and we will promptly delete that information.
If you become aware that a child under 16 is using the Service, please notify us immediately. We will take steps to terminate that account and delete associated personal data.
11. International Data Transfers
ManyVector operates globally and may process and store personal data in countries other than your own. By using the Service, you acknowledge that your personal data may be transferred to and processed in countries where data protection laws may differ from those in your jurisdiction.
Where we transfer personal data from the European Economic Area (EEA), United Kingdom, or Switzerland to countries that have not been deemed to provide an adequate level of data protection, we implement appropriate safeguards as required by applicable law. These safeguards may include Standard Contractual Clauses (SCCs) approved by the European Commission or other legally recognized transfer mechanisms.
For self-hosted deployments, your inference data and operational data remain on your own infrastructure in the jurisdiction you choose. ManyVector does not transfer that data.
Enterprise customers with specific data residency requirements should contact us at hello@manyvector.com to discuss deployment options and available contractual protections.
12. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our data practices, the Service, or applicable law. When we make material changes, we will notify you by updating the "Last updated" date at the top of this page and, for significant changes, by sending an email to the address associated with your account.
Changes will be effective as of the updated date noted at the top of this policy. Your continued use of the Service after any changes to this Privacy Policy constitutes your acceptance of the updated policy.
We encourage you to review this Privacy Policy periodically to stay informed about how we protect your information.
13. Contact
If you have questions, concerns, or requests related to this Privacy Policy or our data practices, please contact us at:
ManyVector Inc.
Email: hello@manyvector.com
Enterprise customers requiring a Data Processing Agreement (DPA) for GDPR compliance or a Business Associate Agreement (BAA) for HIPAA compliance should contact us at the same address. We will work with you to execute the appropriate agreements for your compliance requirements.