Privacy Policy
Plain English summary: Vuju AI is built around one core promise — your conversations are private. Your conversation history is stored in your account for your use, not ours. We never access, review, or use it. We do not train on your data. The AI provider we use has zero data retention — your prompts and responses are not stored or logged on their end either. Delete your history whenever you choose — it's permanently gone. We collect only what's needed to run your account and process payment.
Conversation history is stored in your account — never accessed, reviewed, or used by us
Your inputs are never used to train or improve any AI model
Your prompts and responses are never stored, logged, or used to train any model
Site analytics collect no personal data and use no cookies
1. Who We Are
Vuju AI ("Vuju," "we," "us," or "our") is an AI platform operated by Darbet Digital LLC, located at 7901 4th St N #31676, St. Petersburg, FL, 33702, USA. We provide a subscription-based AI chat service with a core commitment to user privacy.
This Privacy Policy applies to all visitors of vuju.com and all subscribers and users of the Service.
2. What We Collect
We collect information in the following categories:
| Category | Examples | Collected? |
|---|---|---|
| Account data | Email address, password hash, account creation date | ✓ Yes |
| Subscription data | Subscription status, billing date, payment status, transaction ID | ✓ Yes |
| Usage data | Usage metrics, error logs | ✓ Yes |
| Conversation history | Your prompts, AI responses, conversation threads | ✓ Your account only — never accessed by us |
| Payment card data | Card number, CVV, full billing address | ✗ Never |
| Browsing behavior | Pages visited, personal identifiers, cross-site tracking | ✗ Never |
| Technical data | IP address (request logs, 24hr rotation), browser user agent | ✓ Briefly |
3. Your Conversations
This is the most important section of this policy.
Your conversation history is stored in your Vuju account so you can reference it later. Here is exactly what we do and do not do with it:
What we never do
- We never access, read, or review your conversation history
- We never use your conversations to train, fine-tune, or evaluate AI models
- We never share your conversation history with any third party
- We do not retain copies of conversations after you delete them
What you can do
- Access your full conversation history at any time from within your account
- Delete individual conversations or your entire history at any time
- When you delete a conversation it is permanently removed — we hold no backup copies
How your prompts are processed
When you send a message, your prompt travels over an encrypted HTTPS connection to our servers and is forwarded to our AI backend via a zero-retention API — meaning the AI provider does not store, log, or train on your prompt or response. The response is streamed back to your browser. We do not retain prompt content beyond the conversation record stored in your account.
4. How We Use Your Data
We use the data we collect to:
- Provide the Service — authenticate your account, maintain your subscription and access
- Process payments — manage your subscription, send receipts, handle billing disputes
- Communicate with you — send transactional emails (account, billing, security alerts), respond to support requests
- Improve reliability — monitor system performance, diagnose technical errors (error logs do not contain conversation content)
- Comply with law — respond to lawful legal process, prevent fraud
We do not use your data for advertising, profiling, behavioral analysis, or any purpose not listed above.
5. Data Sharing
We do not sell your personal data. We do not share your data with third parties for advertising or marketing purposes. We share limited data only with:
Payment Processors
Your email address and subscription status are shared with our payment processor (Stripe) to process your subscription. Stripe handles card data directly — we never see or store your full card details.
Infrastructure Providers
Our web servers run on dedicated infrastructure we control exclusively. AI requests are processed via a zero-retention API — the AI provider contractually does not store, log, or train on your data. No application data is accessible to any infrastructure provider.
Law Enforcement
We may disclose account data (not conversation history — we do not access or retain copies of your conversations) in response to a valid court order, subpoena, or other lawful legal process. We will notify affected users of any disclosure unless prohibited by law.
Business Transfers
In the event of a merger, acquisition, or sale of assets, your account data may be transferred. You will be notified by email and given an opportunity to delete your account before any transfer occurs.
6. Data Retention
- Account data — retained for the life of your account plus 90 days after deletion, then permanently deleted
- Billing records — retained for 7 years as required by U.S. tax law
- Server request logs (IP, timestamp, HTTP status) — rotated every 24 hours, not linked to user accounts
- Conversation history — retained in your account until you delete it; permanently removed upon deletion with no backup copies retained by us
You can request deletion of your account and associated data at any time via our privacy contact form.
7. Security
We take security seriously. Our measures include:
- All data in transit encrypted with TLS 1.2+ (enforced by Cloudflare)
- Passwords stored as bcrypt hashes — never in plaintext
- Servers hardened with firewall protection, intrusion detection, and key-based authentication
- Cloudflare DDoS protection and Bot Fight Mode
- Access to production systems is strictly limited and access-controlled
- Conversation history is accessible only via your authenticated account — we operate no internal systems or processes that access, read, or retrieve it
No system is 100% secure. In the event of a data breach affecting your account data, we will notify you within 72 hours of discovery.
8. Analytics
We use Umami, a self-hosted, open-source analytics platform, to understand how visitors use our website. Umami is:
- Cookieless — no cookies are set on your device
- Anonymous — no personal identifiers are collected
- GDPR compliant — no personal data is processed
- Self-hosted on our own infrastructure — no data goes to Google, Meta, or any third party
Analytics data includes: page views, referral source (aggregated), browser type (aggregated), country (aggregated). No data is ever linked to an individual user or account.
You do not need to opt out of our analytics because they collect no personal data. Your browser's "Do Not Track" signal is respected.
9. Cookies
We use a minimal number of cookies, all strictly necessary for the Service to function:
- Session cookie — keeps you logged in during your browser session. Expires when you close your browser or log out.
- CSRF token — protects against cross-site request forgery. Session-scoped.
We do not use advertising cookies, tracking pixels, or any third-party cookies. Our analytics are cookieless. You cannot meaningfully opt out of the session cookie as it is required to use the Service.
10. Payment Data
We do not store payment card numbers, CVVs, or full billing addresses. This data is handled directly by our payment processors:
- Stripe — PCI-DSS Level 1 certified; their privacy policy governs card data
We retain: your email, subscription tier, subscription status, and transaction IDs (for dispute resolution).
11. Your Rights
You have the following rights regarding your personal data:
- Access — request a copy of the data we hold about you
- Correction — request correction of inaccurate data
- Deletion — request deletion of your account and associated data
- Portability — request your data in a machine-readable format
- Restriction — request that we restrict processing of your data
- Objection — object to processing based on legitimate interests
To exercise any right, contact our privacy team. We will respond within 30 days. We may need to verify your identity before processing your request.
California residents (CCPA): You have the right to know what personal information we collect, to delete it, and to opt out of its sale. We do not sell personal information. For California-specific requests, contact our privacy team with the subject line "CCPA Request."
12. Children's Privacy
The Service is not intended for, and we do not knowingly collect data from, individuals under the age of 18. If we become aware that we have collected personal data from a minor, we will delete it immediately.
If you believe we have collected data from a minor, please contact our privacy team immediately.
13. International Users
Vuju's servers are located in the United States. If you access the Service from outside the United States, your data will be transferred to and processed in the United States, where data protection laws may differ from those in your jurisdiction.
The Service is currently available to users in the United States and Canada only. EU/UK availability is planned for a future phase, at which point we will implement GDPR-compliant data processing agreements.
14. Changes to this Policy
We may update this Privacy Policy from time to time. Material changes will be communicated by email to your registered address and by posting a notice on the Service. The "Last updated" date at the top of this page will always reflect the most recent revision.
Your continued use of the Service after changes take effect constitutes acceptance of the updated policy.
15. Contact
For privacy-related questions, data requests, or concerns:
- Privacy requests: Contact form — Privacy / Data Request
- General support: Contact form — Account Support
- Legal: Contact form — Legal
- Mail: DARBET DIGITAL LLC — Privacy, 7901 4th St N #31676, St. Petersburg, FL, 33702, USA
We aim to respond to all privacy inquiries within 5 business days.