Vanzim

Privacy Policy

Last updated: July 22, 2026

This policy explains what information Vanzim collects, why, and what you can do about it. We've written it in plain language on purpose.

Who this applies to

Vanzim has two kinds of people connected to it:

  • Our customers, the businesses who sign up for a Vanzim account.
  • Your customers' end users, the people who interact with our customers' AI systems. If you're an end user of a company that uses Vanzim, that company is responsible for telling you how your data is handled. Vanzim processes that data on their behalf, we don't have a direct relationship with you.

What we collect from our customers

  • Account information: your email address and authentication details, handled through our authentication provider.
  • Payment information: if you subscribe to a paid plan, your payment is processed entirely by our payment provider, Paddle. We never see or store your card details ourselves.
  • AWS credentials: if you connect your own AWS bucket, we store the access key and secret key you provide, encrypted at rest. We never display these back to you once saved, and you can rotate or revoke them at any time from your dashboard.
  • API keys: we store a cryptographic hash of your API key, never the key itself in readable form.

What we collect when your AI logs conversations

This is the part we want to be completely clear about, since it's the core of what Vanzim does.

  • When your system sends us a conversation to log, we process the raw text just long enough to remove personal information (like emails, phone numbers, and, if you've enabled it, ages and dates) and generate a cryptographic hash of it.
  • The scrubbed content is then written directly into your own AWS S3 bucket, a bucket you control, using credentials you provided.
  • We do not keep a copy of the conversation content ourselves. Our own database stores only the cryptographic hash and basic metadata (like which AI model was used and how long the request took), never the actual conversation text.
  • If our secret-scanning feature detects something that looks like a leaked credential or API key in the text, we block that specific request rather than storing or forwarding it.

Where your data is hosted

Our own database infrastructure is hosted in the EU (Frankfurt). Our edge processing runs on Cloudflare's global network. Your actual scrubbed conversation content lives in the AWS bucket you configured, wherever you've chosen to host it.

Who we share information with

  • AWS, but only your own AWS account, using your own credentials.
  • Paddle, our payment processor, who handles your billing information directly.
  • Cloudflare and Supabase, the infrastructure providers we use to run our own service.

We do not sell your data. We do not use your data to train any models.

Your rights and choices

  • You can view, rotate, or revoke your API key at any time from your dashboard.
  • You can request deletion of your account and associated data by emailing contact@vanzim.com. We'll process deletion requests within a reasonable time.
  • If you're in the EU or another jurisdiction with data protection rights, you may have additional rights to access, correct, or delete your personal information, reach out to us at the same email and we'll help.

Security

Credentials are encrypted at rest. API keys are stored as cryptographic hashes, not plain text. We use standard encryption in transit (TLS) for all connections to our service. No system is perfectly secure, and we can't guarantee absolute security, but we've built our architecture specifically to minimize what we hold in the first place, we can't leak what we never stored.

Changes to this policy

We'll update the date at the top of this page if we make material changes, and where appropriate, we'll notify account holders directly.

Contact us

Questions about this policy, or about your data specifically: contact@vanzim.com