Privacy Policy

Last updated: 2026-06-12

This Privacy Policy is written in English. Any translation into another language is provided for convenience only. In the event of any inconsistency or conflict between the English version and any translated version, the English version shall prevail and control.

1. Data We Collect

  • Account data: Name, email address (via Clerk authentication)
  • Usage data: Feature usage counts, subscription status
  • Payment data: Processed exclusively by Dodo Payments — we never store card details

Signed-out (Anonymous) Usage: Query content and AI-generated responses are processed in real-time solely to fulfill your request. This data is processed in volatile memory and is not stored or logged on our servers.

Signed-in Usage (Free & Pro): To provide chat history and ensure service quality, query and answer content are processed, de-identified (via PHI masking as a primary safeguard), and linked to your account. This data is retained for a limited period of up to 6 months and is strictly never used to train artificial intelligence models.

Pro Subscription Preferences: For Pro subscribers, we synchronize a 16-character cryptographic hash derived from your workplace, role, and language preferences, alongside your locale, to enable cross-device consistency. The original, raw preference text never leaves your device. This hash is a pseudonymized value (not anonymous) and is treated as personal data linked to your account.

2. No PHI Storage

We do not store patient health information (PHI). Our PHI detection system actively blocks inputs containing identifiable patient data such as national IDs, passport numbers, or medical record numbers. De-identified query logs are retained for audit and service improvement purposes (see §4 below).

3. No AI Training

Your queries and inputs are never used to train AI models, including OpenAI models. We use the OpenAI API with data processing agreements that prohibit training on customer data.

4. Data Retention, Deletion, and User Rights

We retain your signed-in chat history and related audit logs (in their de-identified state) for up to 6 months for the sole purposes of providing you with continuity of service, conducting system security audits, and improving user experience. Data is automatically deleted after 6 months.

You have the right to request the deletion of your account and personal data at any time by contacting us via email at support@an-tho.com. Upon verifying your request, we will permanently erase or de-identify your personal data from our active production systems within 30 days.

Statutory Exception for Financial Records: Please note that pursuant to Article 38 of the Taiwan Business Accounting Act, GDPR Article 6(1)(c), and applicable tax regulations, we are legally obligated to retain transactional, billing, and usage records (including transaction amounts, plan types, and payment processor identifiers) for a minimum of five (5) years solely for financial auditing and tax compliance purposes. During this statutory retention period, such data will be strictly restricted from any operational or marketing use and will be automatically purged once the legal retention period expires.

When you delete your account or chat history, the eligible personal data (excluding the statutory financial records described above) will be immediately and permanently deleted from our active production databases. Residual copies of this data contained within our automated system backups and transaction histories will naturally expire and be completely overwritten within 24 hours.

5. Third-Party Services

We use the following third-party services to operate Vela:

  • OpenAI — AI language model processing
  • Clerk — User authentication
  • Dodo Payments — Payment processing (Merchant of Record)
  • Sentry — Error monitoring and performance tracking (no PII collected)
  • PostHog — De-identified product analytics
  • Neon — Database hosting
  • Fly.io — Application hosting

6. International Data Transfers

Our services are hosted and managed through cloud servers located in Tokyo, Japan (via Fly.io). By using Vela, users in Taiwan and other jurisdictions acknowledge and agree that their personal and pseudonymized data will be transferred to, stored, and processed in Japan. We ensure that our hosting providers maintain industry-standard security measures to protect your data in alignment with applicable data protection laws.

7. Cookies

We use essential cookies for authentication session management (via Clerk). We do not use advertising or tracking cookies.

8. Public Sharing

When you choose to share a query and answer via Vela’s Share feature, the shared content (the query text, the answer, and citations) becomes publicly accessible at a share URL. We do not consider publicly shared content to be personal information, but you remain responsible for ensuring no patient identifiers or personal health information is included before you share. Vela does not actively monitor or pre-screen all publicly shared content.

You retain the ability to revoke any share at any time via Settings → Manage shares. After revocation, the public page will display a “share has been revoked” notice and we will stop serving the original content. However, third-party caches (search engines, social media platforms) may retain previews for some time after revocation; we cannot control these external caches.

We track aggregate view counts on shared pages for service quality and abuse prevention purposes; we do not associate visitor identity with shared page views beyond what is required for rate limiting.

If you delete your account, the link between you and any pages you previously shared is removed (your authorship association is severed), but the shared page itself remains publicly accessible unless you revoke it.

9. Contact

For privacy-related inquiries: support@an-tho.com