Vajra

Privacy Policy

Last updated: July 13, 2026

Draft — pending legal review. This document was prepared as a working draft of Vajra's Privacy Policy and has not yet been reviewed by a qualified lawyer. Don't treat it as final or legally binding until that review is complete.

1. Who this policy covers

This Privacy Policy explains how fastrBuild Intelligence (OPC) Pvt Ltd ("fastrBuild," "we," "us") collects, uses, and shares information when you use Vajra (app.vajra.work). It should be read together with our Terms of Service.

2. Information we collect

  • Account information. Your email address and, if you sign in with Google, the basic profile information Google shares with us.
  • Content you provide. The messages you send in chat, any documents you upload to a Project, skill configurations, and other content you create in the Service.
  • Usage and credit data. Which models and features you use, and the credits consumed by each action, so we can meter usage and show you your balance.
  • Technical data. IP address, browser/device information, and request metadata, used for security, abuse prevention (including the rate-limit and disposable-email protections on signup), and debugging.

3. How we use this information

  • To operate the Service — including routing your prompts to the AI model you selected and returning a response.
  • To generate document embeddings and retrieve relevant passages when you use Projects.
  • To apply the guardrail settings you or your organization configure, including PII masking, before content leaves our systems.
  • To meter and enforce credit usage.
  • To detect and prevent abuse, fraud, and violations of our Terms.
  • To maintain and improve the Service, and to comply with legal obligations.

We do not sell your personal information to third parties, and we do not use your chat content to train our own models.

4. How information is shared with third parties

To generate a response, the relevant portion of your conversation is sent, via OpenRouter, to the AI model provider behind the specific model you chose (for example, Anthropic, OpenAI, or Google, depending on your selection). Those providers process that content under their own privacy terms; we encourage you to review them for the model(s) you use most.

We also use infrastructure providers — including Supabase (database, authentication, and file storage) and Vercel (hosting) — who process data on our behalf under their own data-processing agreements. We do not permit these providers to use your data for any purpose other than providing services to us.

5. PII masking — what it does and doesn't do

If enabled, our guardrails feature applies pattern-based masking to common types of personal data (such as email addresses, phone numbers, and India-specific identifiers like PAN, Aadhaar, and GSTIN numbers) in outbound messages before they're sent to a model provider. This is a best-effort control, not a guarantee — it can only catch information that matches a known pattern, and won't catch personal information described in free text. Don't rely on it as your only safeguard for highly sensitive information.

6. Organization (team) accounts

Vajra supports company/team workspaces. If your account is part of an organization, that organization's admins can see usage metadata about your activity — for example, which models you used, how many credits you consumed, and when you were last active — so they can manage the team's shared credit wallet and guardrail settings. Admins cannot see the content of your chats, uploaded documents, or messages — that stays private to you, the same as it would on a personal account. Your organization can set a guardrail floor (see Section 5) that you can tighten further but not loosen. Vajra is one-account-one-organization: you can belong to at most one team at a time, and organizations do not use shared logins — every member signs in with their own account.

7. Data retention

We retain your account, chat history, and uploaded documents for as long as your account is active, so the Service can function (for example, showing your chat history or letting a Project reference earlier documents). Credit ledger records are retained for accounting and audit purposes even after other data is deleted. If you ask us to delete your account, we suspend it and remove personal content within a reasonable period, except where we're required to retain records by law.

8. Your rights

Depending on your location — including under India's Digital Personal Data Protection Act — you may have the right to access, correct, or request deletion of your personal data, or to withdraw consent for its processing. To make a request, contact us at the address below; we'll respond within a reasonable time.

9. Security

We use industry-standard measures to protect your data, including encryption in transit and database-level row-level-security policies that restrict data access to your own account. No method of transmission or storage is completely secure, and we can't guarantee absolute security.

10. Children's privacy

The Service is not directed to, and we do not knowingly collect personal information from, anyone under 18.

11. Changes and contact

We may update this Privacy Policy from time to time; material changes will be reflected by updating the "Last updated" date above. Questions or requests about this policy can be sent to support@vajra.work.