Privacy policy
This policy explains how personal data is processed when you use Vorenq, in accordance with the revised Swiss Federal Act on Data Protection (revDSG) and its ordinance (DSV). Where the EU GDPR also applies, we observe it.
1. Controller
The controller responsible for the data processing described here is MomentumQ GmbH, Leutschenbachstrasse 95, 8050 Zürich, Switzerland. Data-protection enquiries: info@vorenq.com.
When your agents process personal data of your customers, employees or contacts, your company is the controller of that data and we act as its processor (terms, section 12). People whose data your workspace processes should address their requests — including a request that a person review an automated decision — to your company; we help you answer them, and workspace owners have a search that finds one person’s data across the workspace.
2. What data we process
- Account data — name, email address and a hashed password; workspace memberships; acknowledgments you give at sign-up or when joining a workspace (such as the AI-use acknowledgment), with their timestamp and the terms version then in force.
- Security data — if you enable two-factor sign-in, an encrypted authenticator secret and hashed recovery codes; a short-lived record that you recently re-entered your password before a sensitive action.
- Session data — a random session identifier in a cookie; our database stores only a digest of it. A session ends after 12 hours without activity and at the latest after 48 hours.
- Usage / log data — IP address, timestamp and browser user-agent; these exist only in our hosting provider’s log stream (for security and troubleshooting) and are deleted there automatically within at most 30 days. To limit abuse, our database also counts requests per IP address and sign-in attempts per email address for a short window (one minute to one day). These counters are stored under a keyed digest, never the address itself, and are deleted at the latest a day after their window ends.
- Workspace settings — the company profile, the email signature (which can contain a person’s name, role and phone number), invitations, and the notification targets you set (email address, WhatsApp number, Threema ID); notifications are delivered through the provider of the channel you choose.
- Billing data — plan, Stripe customer and payment references, the credit ledger and usage per AI model. Card and bank details are held by Stripe, not by us.
- Content you provide — task briefs, messages, files your AI team produces, and the connector credentials you add (stored encrypted; see “Security”).
- Voice recordings — when you dictate, the audio is sent for transcription to a provider listed in section 4 and is not kept afterwards; the transcript lands where you dictated it.
- Customer data you process through Vorenq — when an AI agent acts in a connected tool (e.g. an inbox, accounting or payment system), it processes the data in that tool on your behalf; for that data you are the controller and we act as your processor.
- Product statistics — events such as “task completed” or a finished onboarding step, linked to your user and workspace identifiers but without any content, so we can see how the product is used and improve it. They are kept for 180 days.
- Partner referral — if you arrived through a link from one of our partners (for example a fiduciary), the partner code in that link is stored with the workspace you create, and that partner sees your workspace’s name and creation date in their client list.
Data used by optional workflows
Accounting and company operations. When you use these workflows, we process the company profile, invoices, bank statements, accounting records and supporting documents you provide or authorize agents to read. They can contain customer, supplier, employee and sole-trader data. The service stores workflow instructions, period and entity references, reports, files, approvals and execution evidence to prepare and review your work. Optional weekly observations store the workload, accepted items, baseline and review/correction time, costs, measurement method and recording owner so you can assess results. These are owner-reported observations, not independently verified savings. Company playbooks also store your procedures, standards and scoped permissions, including who approved them and their use.
Campaigns and prospect research. At your direction, agents can research business contacts from public sources and connected tools, assess fit against your campaign brief, and prepare outreach. A campaign pipeline stores contact email, company, source URL, supporting evidence, reported relationship stage, next action, follow-up date and originating run. Connected mailbox content may be read to check prior contact and replies. These assessments and stages can be incorrect; they are not independently verified conversions or decisions about credit, employment or eligibility. You are responsible for the lawful collection and use of contact data, required notices and marketing permissions. A public email address is not consent to receive advertising.
Engineering and data workflows. Authorized repository, helpdesk and Microsoft Fabric operations can process ticket descriptions, comments, source files, commit and pull-request references, CI results, notebook content, query results and job receipts. These may include personal or confidential data embedded in your systems. Share only what is needed, and do not put credentials into briefs or source files supplied to an agent. Relevant context is passed to the AI providers and connected services permitted by your workspace settings, as described below; these features do not authorize additional recipients by themselves.
Retention and objections. Campaign pipeline records are removed with their campaign under its deletion or retention rules. Campaign opt-outs are kept separately as workspace, normalized email and suppression timestamp. They apply to supported Gmail and Outlook campaign sends across this workspace and survive campaign deletion until the workspace is deleted. You must also preserve and honor objections in other channels and systems. Run history, generated files, playbook records and copies in connected services have their own retention and deletion controls, as described below; deleting a campaign does not itself delete a sent message, a repository commit or every related artifact. Data-subject requests can be sent to the contact listed in this policy; where we act for your company, we assist the responsible controller.
Marketing measurement. On our public pages your browser stores, in session storage on your device, the campaign parameters in the link you arrived through (utm_source, utm_medium, utm_campaign), a partner code if the link carried one, the referring website’s host name, the page you landed on and which button you pressed. No cookie is set, and it is gone when you close the tab. If you then send us an access request or sign up, that context travels with the form so we can see which channel works (at sign-up it is kept with the product statistics above). In addition, the first view of a public page in a tab reports the page, the language and the referring host to our server, which keeps only an aggregate count per page and day (for 365 days, with no identifier); to stop strangers inflating those counts, the server counts views per IP address for one hour, under a keyed digest rather than the address. You can prevent all of this by blocking site data for this domain; everything else on the site keeps working.
Access requests. If you ask for access through the form on our website, we store your email address, company, the task you describe, the plan and language you chose and the campaign context above, and send a copy to our own mailbox, in order to answer you and plan your onboarding. We keep the request for 12 months.
3. Purposes and legal bases
We process the data to provide and secure the service and manage your account (performance of our contract with you), to operate, improve and safeguard it against abuse, to measure which channels and features work and to settle partner arrangements (our legitimate interests, weighed against your rights — you may object at any time; see “Your rights”), and to meet legal obligations such as statutory accounting retention. We do not rely on consent for this processing; where we ever ask for your consent, you may withdraw it at any time with effect for the future. Providing the data is voluntary, but without it the service cannot be used.
4. Disclosure to processors and third parties
To run the service we rely on the following processors, who act only on our instructions. Each entry names the state in which the processor handles the data and the basis of that disclosure (see section 5).
- AI model providers (to generate the work): your employees run on the models you assign to them — Anthropic (Claude) by default, or the European versions below in an EU-hosted workspace. The platform also uses providers from this list for supporting tasks, even if you have not assigned work to their models: summarising long tool results and conversation histories, naming chats, planning a brief, checking a task and an outgoing message, reading scanned documents and images, transcribing dictation and reading replies aloud. Those providers receive the content concerned, which can include emails, invoices and other documents your agents read. Your data-residency policy applies to every one of these calls — a provider in a region you have not allowed receives nothing — and you can switch off individual providers in the spend controls. With the setting “only the providers my employees are assigned to” on the Security page, every supporting task stays with the providers of your employees’ models; a supporting feature that none of them can serve is then unavailable. The setting is off by default, only an owner can change it, and it is suggested for professions bound by secrecy; it also covers the manager and turns smart model routing off. Each route counts on its own (Claude through Anthropic does not bring in AWS Bedrock), an assist model an owner picked in Settings counts as assigned, and web search (Tavily) and connected apps such as DeepL are not AI model providers and follow each employee’s tool access. The China-region models (Kimi, Qwen, Z.AI) run only if you first enable the China region on the Security page. Providers marked “coming soon” in the product cannot be enabled yet. The complete list — identical to the sub-processor list on the in-app Security page:
- Claude — Anthropic PBC, USA (FDPIC-recognised SCC; Swiss-US DPF where certified)
- Kimi — Moonshot AI, China (no adequacy, no SCC — only with your Art. 17 DSG basis)
- OpenAI — OpenAI, USA (FDPIC-recognised SCC; Swiss-US DPF where certified)
- Gemini — Google, USA (FDPIC-recognised SCC; Swiss-US DPF where certified)
- Grok — xAI Corp., USA (FDPIC-recognised SCC; Swiss-US DPF where certified)
- Mistral — Mistral AI, EU (adequate level of protection (Annex 1 DSV))
- AWS Bedrock — Amazon Web Services (Bedrock, EU regions), EU and Switzerland (Frankfurt, Zurich, Stockholm, Milan, Spain, Ireland, Paris) (adequate state; SCC for access from the provider's US group)
- Azure Foundry — Microsoft (Azure AI Foundry, EU data zone), EU, may include Switzerland and Norway (adequate state; SCC for access from the provider's US group)
- OpenAI EU — OpenAI (European data residency, eu.api.openai.com), EEA and Switzerland (adequate state; SCC for access from the provider's US group)
- Vertex AI EU — Google Cloud (Vertex AI, EU multi-region), EU (adequate state; SCC for access from the provider's US group)
- Azure Foundry (global) — Microsoft (Azure AI Foundry, global routing), worldwide (FDPIC-recognised SCC; Swiss-US DPF where certified)
- Qwen — Alibaba Cloud (intl: Singapore), Singapore (no adequacy, no SCC — only with your Art. 17 DSG basis)
- Z.AI — Z.AI / Zhipu (Beijing), China (no adequacy, no SCC — only with your Art. 17 DSG basis)
- DeepSeek — DeepSeek (Hangzhou), China (no adequacy, no SCC — only with your Art. 17 DSG basis)
- MiniMax — MiniMax (Shanghai; intl endpoint), China (no adequacy, no SCC — only with your Art. 17 DSG basis)
- Connector providers (only the ones you connect, and only for the actions you authorise): e.g. Bexio, Stripe, Slack, Microsoft 365, Google Workspace, WhatsApp, Threema and others listed on the Integrations page. For Google Workspace connectors (Gmail, Google Calendar, Google Drive), Vorenq’s use of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements — in particular, we do not retain, use or transfer data obtained through Google Workspace APIs to develop, improve or train generalized (non-personalized) AI or machine-learning models, and we do not transfer it for advertising. For the X connectors (posts and advertising), agents act on your X account and X Ads account only after you sign in with X and only for the actions you authorise — for example publishing a post you approved, reading your posts and mentions, or reporting ad-campaign performance; ad campaigns are drafted in paused state, and activating, pausing or re-budgeting a campaign always requires your explicit approval. The data exchanged with X in doing so is processed by X Corp. (USA) under the X privacy policy; we use data received from X’s APIs solely to perform these actions on your behalf and do not use it to train AI or machine-learning models.
- Web search (the web_search tool): Tavily Inc. (USA) receives the search queries an agent formulates while working on your task — such a query can reflect the content of that task. Web search runs only for agents that have the tool; the starter team’s researcher has it from the start, and you can remove it from any agent. (FDPIC-recognised SCC; Swiss-US DPF where certified)
- Embeddings (knowledge-base search): OpenAI (USA) computes text embeddings of the documents you upload — only where your data-residency policy permits US processing; otherwise a local embedder is used. (FDPIC-recognised SCC; Swiss-US DPF where certified)
- Video generation (the optional generate_video tool): where the Seedance engine is configured on our deployment, BytePlus (a ByteDance company) receives the video prompt an agent writes and processes it in Malaysia (Johor). Seedance counts as a China-region vendor, so it is reachable only if you have enabled the China region in your data-residency policy (off by default); otherwise a video is generated on Google Veo (USA) or not at all. (no adequacy, no SCC — only with your Art. 17 DSG basis)
- Voice output (replies read aloud): where configured on our deployment, ElevenLabs, Inc. (USA) receives the text of a reply you have had read aloud, in order to synthesize the speech; your data-residency policy still gates each call. A reply can instead be voiced by Mistral (EU) or OpenAI (USA) from the list above, and every voiced reply names its vendor in the response. (FDPIC-recognised SCC; Swiss-US DPF where certified)
- Voice output: Cartesia AI, Inc. (USA) receives the same data for the same purpose and under the same conditions, where it is the speech vendor configured on our deployment. (FDPIC-recognised SCC; Swiss-US DPF where certified)
- Password check (self-service sign-up, password reset, and changing your password): Have I Been Pwned (operated by Troy Hunt’s Superlative Enterprises Pty Ltd, Australia) receives the first five hexadecimal characters of a SHA-1 of the password you chose, via the k-anonymity range API, so we can refuse a password that already appears in a public breach. Those five characters are shared by hundreds of thousands of possible passwords and cannot be related to you — they are not personal data. The password itself never leaves our server. A local denylist of common passwords still applies if that service is unreachable. (no personal data sent)
- Hosting: Render Services, Inc. (USA) runs the application in its Frankfurt region (Germany). (adequate state; SCC for access from the provider's US group)
- Database: the PostgreSQL database is provided by Neon, Inc. (USA) on Amazon Web Services in Frankfurt (Germany, region eu-central-1). (adequate state; SCC for access from the provider's US group)
- Object storage (the files your agents produce, the documents filed in your workspace, and the nightly database backups described under “Retention”): Cloudflare R2 (Cloudflare, Inc., USA), stored in its EU jurisdiction. (adequate state; SCC for access from the provider's US group)
- Network edge and bot check: Cloudflare, Inc. (USA) fronts the application as CDN and reverse proxy. All traffic between your browser and Vorenq — including the content you send and receive — passes, decrypted for the moment of transmission, through the nearest data centre of its worldwide network; Cloudflare does not keep your workspace content and logs request metadata (IP address, requested URL). Where the bot check is enabled on our deployment, opening the sign-up, sign-in or password-reset page loads Cloudflare’s Turnstile check, which receives your IP address and the browser signals it needs to tell people from bots. How Cloudflare processes that data is described in the Cloudflare Turnstile Privacy Addendum. (FDPIC-recognised SCC; Swiss-US DPF where certified)
- Email delivery (account e-mails — verification, invitations, password resets — and the notifications you configure, e.g. approval or run alerts, which can quote a short summary an agent wrote): Resend, Inc. (USA) receives the recipient’s email address and the message content. (FDPIC-recognised SCC; Swiss-US DPF where certified)
- Payment processing (our own billing, independent of any connector you add): Stripe Payments Europe, Ltd. (Ireland) and Stripe, Inc. (USA) process the account holder’s billing details and payment method for subscriptions and credit top-ups. (FDPIC-recognised SCC; Swiss-US DPF where certified)
- Error monitoring: where error tracking is enabled on our deployment, Sentry (Functional Software, Inc., USA; data stored in its EU region in Germany) receives error reports from our server and from your browser — error type, message and stack trace, with pseudonymous user and workspace identifiers and the page address without its query part. Reports are scrubbed of credentials and never include your documents; an error message can occasionally quote a short fragment of the data being processed. (adequate state; SCC for access from the provider's US group)
- Public Swiss registers (not processors): when an agent looks up a company or searches the gazette, the federal UID register (Federal Statistical Office) and the Swiss Official Gazette of Commerce (SECO) receive the name or UID looked up — for a sole proprietorship that can be a person’s name; an exchange-rate lookup (Federal Office for Customs and Border Security) receives only a date.
- Partners: a partner who referred your workspace (see section 2) sees its name and creation date.
Version and history of this list. Current version: 2026-09-23.
- 2026-09-23: Added two EU-resident model providers for EU-hosted workspaces: OpenAI's European data-residency region (eu.api.openai.com — OpenAI is already listed; this is its separate EU processing region, where prompts are processed and stored in Europe) and Google Cloud Vertex AI's EU multi-region (Gemini and Claude Fable, with ML processing inside EU member states — Google is already listed for the Gemini API). Neither processes anything for a workspace that does not use its models. Same revision: every entry now names the state it processes in and the transfer basis, and the platform processors (Render, Neon, Cloudflare R2 and edge, Resend, Stripe, Sentry) — already named in the privacy policy — are part of the versioned list. Two locations were corrected, not changed: Have I Been Pwned is operated from Australia (it receives a five-character hash prefix, not personal data) and the Seedance video engine processes in Johor, Malaysia.
- 2026-08-13: Added Have I Been Pwned (Troy Hunt). On self-service signup, password reset and in-app password change we send the first five hex characters of a SHA-1 of the chosen password to the k-anonymity range API so a password that already appears in a public breach is refused. The password itself never leaves the server.
- 2026-08-07: First versioned publication. No processor added or removed — the inventory below is the one already in force; this revision only puts a version and a change history on it.
We do not sell personal data. We disclose data to authorities only where legally required.
5. Disclosure abroad
Our application and database run in Frankfurt (Germany) and our files and backups are stored in the EU — states with an adequate level of data protection (Annex 1 DSV). Several processors belong to US groups, and some process data in the USA or worldwide — in particular Anthropic (Claude), which powers the default team, and Cloudflare’s network. For those recipients, and for access from the USA, we rely on the EU Standard Contractual Clauses in the version recognised by the Swiss Federal Data Protection and Information Commissioner (with the Swiss amendments) and, for certified recipients, the Swiss-US Data Privacy Framework. The state and basis for every processor are listed in section 4. Anthropic is contractually bound not to use your content to train its models. Your data-residency policy on the Security page controls which jurisdictions may process your data (EU/US/CN) and is enforced fail-closed — it defaults to the EU and the USA, so no data reaches a China-region provider unless you explicitly enable the China region. The optional China-region providers (Moonshot/Kimi and Z.AI in China, Alibaba Cloud/Qwen in Singapore) are used under their own standard API terms; we have not concluded Standard Contractual Clauses with them and their terms may permit them to use content to improve their services; the same applies to the Seedance video engine of BytePlus (Malaysia), where it is configured on our deployment. Enabling the China region and assigning work to those models is a disclosure abroad to states without an adequacy decision and without additional safeguards — do so only for data for which you, as controller, have a lawful basis under Art. 17 revDSG (in particular the express consent of the persons concerned). A provider that does not offer even the contractual data-protection commitments we require of a sub-processor is not offered at all: DeepSeek, for example, appears as “coming soon” and cannot be selected or enabled.
EU hosting. If you choose EU hosting when you create a workspace — or leave only the EU region ticked on the Security page — your AI processing uses only the European zones of the providers: AWS Bedrock EU (Frankfurt, Zurich, Stockholm, Milan, Spain, Ireland, Paris), Microsoft Azure’s EU Data Zone (which may include Switzerland and Norway), OpenAI’s European region (EEA and Switzerland), Google Cloud Vertex AI EU and Mistral — all in states with an adequate level of protection. Except for Mistral these zones are operated by companies of US groups, so access from the USA cannot be ruled out; the safeguards above cover it. Features with no European provider are unavailable in an EU-hosted workspace: web search, image and video generation, cloud embeddings (a local embedder is used instead) and US voice vendors. EU hosting does not change the platform processors — Cloudflare’s network, Stripe, Resend and Sentry, Render and Neon — nor the connectors you choose. It is offered only where our deployment has a European provider configured.
6. AI-assisted processing and automated decisions
Vorenq uses AI agents that read and act on data automatically; you are interacting with an AI system and the work it produces is AI-generated, which can be incomplete or incorrect — review it before you rely on it. How it works: an employee receives your brief together with the context it needs — your company profile, the relevant passages of your knowledge base, its memory, and what it reads in the tools you connected or on the web — sends it to the AI model that runs it, and proposes or carries out the actions you permitted, for the purpose of doing the work you assigned. Actions that carry real-world consequences — moving money, messaging a customer, writing a financial record, signing — are routed through a guardrail that pauses them for your explicit human approval before they run. That approval requirement is the default; a workspace owner can relax individual pauses or switch the guardrail to a monitor-only mode on the Security page (which warns about the implications) — the payment cap, the block on irreversible deletions and the credential-leak block remain enforced in every mode. Our own processing of your account takes no automated individual decision about you. Where your agents’ work could amount to an automated individual decision about a person outside your company (Art. 21 revDSG), your company is the controller and owes that person the information and a human review (section 1); the approval pause helps you provide it. Vorenq does not rank, filter or reject job applicants and does not evaluate employees: its recruitment workflow summarises applications against the criteria you set and leaves every decision to you.
Transparency: Vorenq is an AI system within the meaning of Regulation (EU) 2024/1689 (EU AI Act), and the product tells you when you interact with an AI agent — the work your agents produce is attributable to them as AI-generated. When your agents write to people outside your company, the platform itself places a notice at the start of the message stating that it was written by an AI agent on behalf of your company — on emails sent through a connected mailbox or e-mail service, postal letters rendered by the platform, messenger and SMS messages, helpdesk and review replies and the other outbound channels that carry text the agent wrote; at the end of a public social-media post — and marks those emails with a machine-readable header (Art. 50(1) and (2) EU AI Act, applicable since 2 August 2026; the Swiss FDPIC likewise holds that people are entitled to know whether they are corresponding with a machine). This notice cannot be switched off. Internal team channels, machine-to-machine endpoints and notifications a provider composes from its own template carry none; where a channel cannot carry it (for example a pre-approved WhatsApp template or a custom connector), the agent is instructed to state it. Images and videos your agents generate carry machine-readable metadata identifying them as AI-generated, and an agent refuses to depict a real, identifiable person unless you confirm that person’s consent. Vorenq itself never trains models on your data. Your prompts and content are sent to the AI model providers described in section 4 solely to generate the response; what a provider may do with them is set by its API terms — Anthropic (Claude) does not use API content to train its models, while Moonshot AI’s (Kimi) standard terms let it use content to improve its services unless restricted by a separate written agreement. Assign work whose content must not be used that way to Claude-powered employees and use the provider setting in section 4. The same applies to every other selectable provider — for example Alibaba Cloud (Qwen), Z.AI or, once offered, DeepSeek: unless this policy states a no-training commitment for a provider, assume its API terms allow such use. In Switzerland there is currently no AI-specific statute: AI-assisted processing of personal data is governed by the revDSG, and Switzerland has signed the Council of Europe Framework Convention on Artificial Intelligence, whose implementation the Federal Council intends to put to consultation — we track it.
7. Retention
We keep personal data only as long as needed for the purposes above. In practice: account data for as long as your account exists — you can delete your account yourself on the Security page, and it is then removed from the live system at once; because the records you created belong to your workspace, your name and email address are replaced there by a neutral placeholder (for example in the workspace audit trail). An account whose email address was never confirmed and that belongs to no workspace is deleted after 7 days. Workspace data is kept until the workspace is deleted — by its owner at any time, or 90 days after its paid subscription ended without renewal (you can export it until then); when your account or workspace is closed or you ask us to delete it, we delete it within 30 days — deleting a workspace removes its active agent, run and connection records from the live system immediately. File erasure and provider revocation continue through the cleanup process below. Request and application logs (IP address, timestamp, user-agent) exist only in our hosting provider’s log stream and are deleted there automatically within at most 30 days — we keep no separate log archive. Sign-in sessions end after 12 hours without activity and at the latest after 48 hours; abuse counters within a day after their window; product statistics after 180 days; aggregate page counts after 365 days; access requests after 12 months. The workspace audit trail keeps the most recent 2,000 human actions and is deleted with the workspace. Where the law requires longer retention — for example accounting records under the Swiss Code of Obligations — we keep those records for the statutory period (generally 10 years) and then delete them.
Deletion cleanup. To finish erasure and withdraw connector access reliably, we retain a restricted cleanup record with workspace/run identifiers, encrypted credential snapshots and the encrypted storage configuration needed for that task. Successful revocation removes the corresponding credentials from the cleanup record; failed erasure or revocation is retried and can require operator intervention. These records are not an active workspace and are not used to run new business tasks. Minimal erasure markers and manual-provider follow-up metadata may remain without credentials or document content. Local deletion does not prove that a provider withdrew access or deleted its own copies. You may need to revoke access directly in that provider’s account. Cleanup remains subject to the purpose and deletion obligations above; retrying is not permission to retain data indefinitely.
Backups. So that we can restore the service after a loss or corruption incident, a complete copy of our database is written every night to our object-storage provider (Cloudflare R2, EU jurisdiction). It covers every table — including account data, workspace content and the encrypted connector credentials — and the 30 most recent nightly copies are kept, each older one being deleted automatically. Deletion of active workspace records is immediate as described above, and we restore from a backup only to recover the service as a whole, never to bring individual deleted records back; a copy made before a deletion does, however, still contain the data until it ages out of that 30-night window.
In addition to cleanup and backups, some records outlive workspace deletion: the accounting records above and an abuse report concerning your workspace: we keep the report together with the evidence snapshot taken when it was filed (the reported content, its checksum, the agent that produced it and the related audit entries) for as long as we need it to handle the case and to establish, exercise or defend legal claims. The party a report is about controls every delete surface in the product, so evidence that vanished with the workspace would make deleting the workspace the universal way to erase it.
Bug reports. When you report a problem with the product from inside the app, we store what you wrote, how urgent you said it is, your name, e-mail address and workspace, and — only if you leave the box ticked — the page you were on (its web address without the query part, so no one-time link travels with it), your language, your browser, your screen size and the last few errors your browser had already logged. We use it to reproduce and fix the problem and to reply to you. It is deleted with your workspace. A report filed before you belong to any workspace is kept under our own platform record instead, where the 500 most recent are retained and older ones are deleted automatically.
8. Security
Connector credentials are encrypted at rest (AES-256-GCM, with a key derived per workspace) and decrypted only server-side at the moment a connector runs; they are never returned to the browser. Passwords are stored only as salted hashes and session identifiers only as digests; two-factor sign-in is available, and sensitive actions require you to re-enter your password. The database and file storage are encrypted at rest by their providers, access is scoped per workspace, and transport is over HTTPS. Every consequential agent action passes the approval guardrail and is recorded in the workspace audit trail. The full list of technical and organisational measures is the annex to section 12 of the terms.
9. Cookies and storage in your browser
We use only strictly necessary first-party cookies and no advertising or tracking cookies, so no consent banner is required:
- vorenq_session — keeps you signed in; ends after 12 hours without activity, at the latest after 48 hours.
- vorenq_stepup — confirms for 15 minutes that you re-entered your password before a sensitive action.
- vorenq_company — which workspace you last opened; kept for one year and removed when you sign out.
- vorenq_terms_ack — which version of our terms you have acknowledged; one year.
- NEXT_LOCALE — your language, until you close the browser. It is set when you choose a language, or when the page language differs from your browser’s; the language can be preselected from the country our network provider derives from your IP address, which is not stored.
- Short-lived state cookies (10 minutes) that secure a connector sign-in.
- Our network provider (Cloudflare) can set a strictly necessary security cookie when it screens automated traffic.
In your browser’s local storage we keep your light/dark theme, interface preferences (which chats you have read, recently used commands, view modes, dismissed hints, your dictation shortcut) and unsent drafts of chat messages — the drafts are deleted when you sign out. Session storage, which ends with the tab, holds a temporary copy of workspace data for faster navigation (also cleared when you sign out or switch workspace), a draft of the onboarding form and the marketing context described in section 2. None of this is shared with third parties. You can block or delete cookies and site data in your browser; without the session cookie you cannot sign in, while the public pages keep working.
10. Your rights
You have the right to information about your data — free of charge, answered within 30 days —, to receive your data in a commonly used electronic format (data portability), and to its correction, deletion, restriction of processing, and to object to processing. Much of this you can do yourself: download an export of your personal data and delete your account on the Security page, correct your name and email address there, and — as a workspace owner — export the workspace on the Data control page. Otherwise contact us at info@vorenq.com; we may ask you to confirm your identity. For data that a company processes about you with Vorenq, contact that company (section 1). You may lodge a complaint with the Swiss Federal Data Protection and Information Commissioner (FDPIC/EDÖB); if you are in the EU/EEA, you may also complain to your national data protection authority.
11. Changes
We may update this policy; the current version always applies. Before a new sub-processor starts processing the data of an existing workspace, we notify its owners by email and on the in-app Security page at least 30 days in advance, stating the date the change takes effect; a newly added AI model provider does not process your workspace’s data before that date unless an owner accepts the updated list earlier (terms, section 12(d), which also sets out your right to object). Last updated: 23 September 2026.