Privacy Policy
Last updated 27 September 2026
This policy explains what information Vensal ("we") collects when you use getvensal.com and the Vensal app at vensal.app, how we use it, and the choices you have.
What we never collect
Vensal does not collect the content of your AI usage — no prompts, no completions, no files you send to a provider. We only read cost and usage figures from your providers' billing and usage reports, and that data does not include what anyone typed.
What we collect
- Account details: your name, work email, and company name when you sign up, and the email addresses of anyone else on your account.
- Provider API keys you connect. These are stored in AWS Secrets Manager; our own database only holds a reference to each key, never the key itself.
- Cost and usage data from your AI providers: dates, dollar amounts, token counts, model and workspace names, and — where a provider reports it — the identifier of the person or API key behind the usage, such as an email address.
- Information you add: people, teams, clients, departments, budgets, and similar details you enter or upload.
- Billing details: payments are processed by Stripe. We keep your plan and Stripe's customer and subscription references; we never see or store your full card number.
- Messages you send us, for example through our contact form.
- Technical information: the cookies needed to keep you signed in, and standard server logs such as IP address and request times.
How we use it
- To run Vensal: importing your spend, allocating it, and showing budgets and forecasts.
- To manage your subscription and billing.
- To send service emails, such as confirming your sign-up.
- To keep the service secure, fix problems, and improve it.
We don't sell your information, and we don't use it for advertising.
Who processes it for us
We use a small number of service providers to run Vensal:
- Supabase — database and sign-in
- Vercel — hosting
- Amazon Web Services — encrypted storage of provider API keys
- Stripe — payments
- Resend — email delivery
- Inngest — running the scheduled daily imports
Your data is processed and stored in the United States.
Cookies
We use only the cookies needed to keep you signed in to the app. We don't use advertising or third-party tracking cookies.
How long we keep it
We keep your data while your account is active. If your trial or subscription ends, your account becomes read-only and is later archived — archived data is kept so you can come back, until you ask us to delete it. When we delete your data, we may keep records we are required to keep, such as billing records and our security and audit logs.
Security
Data is encrypted in transit. Provider keys are held in AWS Secrets Manager. Each customer's data is kept separate in our database by access rules enforced by the database itself, not just by our application code.
Your choices and rights
You can ask us for a copy of your data, to correct it, or to delete it. Depending on where you live, you may have additional rights under laws such as the GDPR or the CCPA. To make a request, contact us at [support email — to be set up].
Children
Vensal is a business service and is not intended for anyone under 18.
Changes to this policy
If we make material changes, we'll update the date above and let account owners know by email or in the app.
Contact
Vensal · [support email — to be set up]