Privacy Policy

Effective Date: July 14th, 2026

Last Updated: July 14th, 2026

Vigilis is used by security professionals while they are on shift. VAL captures voice, photos, and location in the course of that work. This policy sets out what we collect, who receives it, how long we keep it, and how to have it deleted.

1. Who This Policy Covers

Vigilis AI ("Vigilis", "we", "our") operates the Vigilis platform — a security management system with an AI voice assistant, VAL. This policy covers two groups of people:

  • Visitors to our website at www.vigilisai.com.
  • Users of the Vigilis platform — security guards, supervisors, and administrators — whose employer or client organization holds a Vigilis account.

If you use Vigilis because your employer does, your organization decides what is collected, who may see it, and how long it is kept. We handle that information on your organization's instructions. A request about your own data is usually best raised with your organization first; section 8 explains what we do when a request comes to us directly.

2. What We Collect

2.1 Account information

Your name, email address, phone number, organization, and role. Sign-in is handled by our authentication provider, Clerk. We never receive or store your password.

2.2 Voice and AI assistant activity

VAL is push-to-talk. It listens while you hold the button down, not continuously. When you speak to VAL we collect the audio of what you said, a written transcript of it, VAL's reply, and a record of any action VAL carried out for you — logging an incident, updating a patrol, looking up a site.

2.3 Operational records

Incident reports, observations, patrol check-ins, shift reports, messages, and the site and procedure documents your organization uploads.

2.4 Photos and location

Photos you take in the app, and the location attached to them. A photo taken on a phone often carries location coordinates embedded inside the image file itself; where it does, we read that location, store it, and record that it came from the photo rather than from the device. We also record your device's location at check-in and during patrols, where your organization has turned that on.

2.5 Technical information

IP address, device and browser characteristics, log files, and error reports. We also compute a hashed fingerprint of your device so we can alert you when your account is used from one we have not seen before.

3. How We Use It

We use the information above to:

  • Run the platform and VAL.
  • Produce the reports, patrol records, and analytics your organization relies on.
  • Secure accounts — detecting unfamiliar sign-ins and preventing abuse.
  • Bill your organization for its subscription.
  • Answer your support requests.
  • Meet our legal obligations.

4. AI Processing

VAL's voice and text assistance are powered by OpenAI. When you speak to VAL, your audio and its transcript are sent to OpenAI so a reply can be generated. When you use VAL's text chat, your messages and the documents relevant to your question are sent the same way.

Two points we want to be exact about:

  • VAL is grounded only in your own organization's documents and procedures. It cannot see another organization's data.
  • We do not use your organization's content to train AI models. Our AI providers' standard API terms state that content submitted through their API is not used to train their models.
  • Our AI providers do hold what is sent to them for a short period — currently up to 30 days — so that they can check for abuse of their systems, after which they delete it. We are working to remove that retention entirely.

5. Who Receives Your Information

We rely on the service providers below. Each receives only what it needs in order to do its job, and none of them may use your information for their own purposes.

  • Clerk — authentication and user accounts.
  • Amazon Web Services — hosting, databases, and file storage, in the United States.
  • Vercel — application hosting and website traffic analytics.
  • OpenAI — VAL's voice and text AI, as described in section 4.
  • Stripe — subscription billing. Card details go to Stripe directly; we never hold them.
  • Statsig — feature management and product analytics. Statsig receives your user ID, email address, organization, and the page you are viewing.
  • Sanity — the content management system behind our public website.

We also disclose information where the law requires it — a court order, a subpoena, or a lawful government request — in connection with a merger, acquisition, or sale of assets, and where it is necessary to protect the rights, property, or safety of any person.

We do not sell your personal information, and we do not share it for cross-context behavioral advertising.

6. Cookies and Analytics

Inside the Vigilis platform — the application you sign in to — we use cookies that are necessary to keep you signed in, and product analytics through Statsig and Vercel to understand which features are actually used.

On our public marketing website we count page views and clicks so that we can see which pages are useful. We do not record your individual visit: we do not use session replay, and we do not capture your mouse movements, scrolling, or keystrokes.

You can block or delete cookies in your browser settings. Blocking the cookies needed for sign-in will stop the platform from working.

7. How Long We Keep It

We keep platform records — voice recordings and transcripts, incident reports, patrol records, photos, and messages — for as long as your organization's account is active. We do not currently apply an automatic expiry to them.

That is a deliberate choice, not an oversight. Security records are routinely needed long after the shift they describe: an incident can become an insurance claim or a lawsuit years later, and a patrol record is only worth anything as evidence if it still exists. If your organization wants a shorter retention period, or wants particular records removed, contact us and we will apply it.

When an organization closes its account, we delete or de-identify its data, except where we are required to keep it.

8. Your Rights

Depending on where you live, you may have the right to:

  • Know what personal information we hold about you, and get a copy of it.
  • Correct it if it is wrong.
  • Have it deleted.
  • Receive it in a portable form.
  • Object to, or ask us to restrict, certain uses of it.
  • If you are in California: opt out of the sale or sharing of your personal information — as section 5 says, we do neither — and not be treated differently for exercising any of these rights.

To make a request, email privacy@vigilisai.com. We will acknowledge it and respond within 45 days.

If you use Vigilis through your employer, your employer controls the account, and we will normally refer your request to them so that they can decide it — whether, for example, an incident report that names you has to be retained. Where the request is ours to act on, we will delete your personal information from our systems, including voice recordings and transcripts, photos, and reports, except where we are required to retain it.

9. How We Protect It

We encrypt your information in transit and at rest. Beyond that:

  • Each organization's data is isolated, so one customer cannot see another's.
  • Staff access is limited to those who need it, and is logged.
  • We monitor for unusual sign-ins and unauthorized access.

No method of transmitting or storing information is completely secure, and we will not claim otherwise.

If you believe you have found a security vulnerability in Vigilis, please report it to security@vigilisai.com.

10. Where Your Information Is Processed

Vigilis is operated from the United States, and your information is stored and processed there. If you use Vigilis from another country, you are sending your information to the United States.

11. Children's Privacy

Vigilis is not intended for anyone under 18, and we do not knowingly collect personal information from anyone under 18.

12. Changes to This Policy

We may update this policy. If a change materially affects how we handle your information, we will tell you by email or in the platform before it takes effect, and we will update the Last Updated date above. Continuing to use Vigilis after that means you accept the updated policy.

13. Contact Us

Vigilis AI

Privacy questions and requests: privacy@vigilisai.com

Security reports: security@vigilisai.com

General support: support@vigilisai.com

Website: www.vigilisai.com