Privacy policy
This policy explains how personal data is processed when you use vorenq, in accordance with the revised Swiss Federal Act on Data Protection (revDSG). Where the EU GDPR also applies, we observe it.
1. Controller
The controller responsible for the data processing described here is MomentumQ GmbH, Leutschenbachstrasse 95, 8050 Zürich, Switzerland. Data-protection enquiries: info@vorenq.com.
2. What data we process
- Account data — name, email address and a hashed password; workspace memberships; acknowledgments you give at sign-up or when joining a workspace (such as the AI-use acknowledgment), with their timestamp and the terms version then in force.
- Session data — a server-side session identifier stored in a cookie.
- Usage / log data — IP address, timestamp and browser user-agent; these exist only in our hosting provider’s log stream (for security and troubleshooting) and are deleted there automatically within at most 30 days. Short-lived security-throttle records (e.g. sign-in attempt counters keyed by email address and IP address) are kept in our database until their time window expires.
- Content you provide — task briefs, messages, files your AI team produces, and the connector credentials you add (stored encrypted; see “Security”).
- Customer data you process through vorenq — when an AI agent acts in a connected tool (e.g. an inbox, accounting or payment system), it processes the data in that tool on your behalf; for that data you are the controller and we act as your processor.
Marketing measurement. On our public pages your browser stores, in session storage on your device, the campaign parameters in the link you arrived through (utm_source, utm_medium, utm_campaign), the referring website’s host name, the page you landed on and which button you pressed. Nothing identifies you, no cookie is set, and it is gone when you close the tab. If you then send us an access request or sign up, that context travels with the form so we can see which channel works. You can prevent it by blocking site data for this domain; everything else on the site keeps working.
3. Purposes and legal bases
We process the data to provide and secure the service and manage your account (performance of our contract with you), to operate, improve and safeguard it against abuse (our legitimate interests, weighed against your rights — you may object at any time; see “Your rights”), and to meet legal obligations such as statutory accounting retention. We do not rely on consent for this processing; where we ever ask for your consent, you may withdraw it at any time with effect for the future. Providing the data is voluntary, but without it the service cannot be used.
4. Disclosure to processors and third parties
To run the service we rely on the following categories of processors, who act only on our instructions:
- AI model providers (to generate the work): Anthropic (Claude) powers your team by default; every other provider — including Moonshot AI (Kimi) — processes data only where you enable it or assign work to its models, and the China-region models (Kimi, Qwen, Z.AI) run only if you first enable the China region on the Security page. Providers marked “coming soon” in the product cannot be enabled yet. The complete list — identical to the sub-processor list on the in-app Security page — with each provider’s jurisdiction:
- Claude — Anthropic PBC, USA
- Kimi — Moonshot AI, China
- OpenAI — OpenAI, USA
- Gemini — Google, USA
- Grok — xAI Corp., USA
- Mistral — Mistral AI, EU
- AWS Bedrock — Amazon Web Services (Bedrock, EU regions), EU
- Azure Foundry — Microsoft (Azure AI Foundry, EU data zone), EU
- Azure Foundry (global) — Microsoft (Azure AI Foundry, global routing), USA
- Qwen — Alibaba Cloud (intl: Singapore), China
- Z.AI — Z.AI / Zhipu (Beijing), China
- DeepSeek — DeepSeek (Hangzhou), China
- MiniMax — MiniMax (Shanghai; intl endpoint), China
- Connector providers(only the ones you connect, and only for the actions you authorise): e.g. Bexio, Stripe, Slack, Microsoft 365, Google Workspace, Threema and others listed on the Integrations page. For Google Workspace connectors (Gmail, Google Calendar, Google Drive), vorenq’s use of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements — in particular, we do not retain, use or transfer data obtained through Google Workspace APIs to develop, improve or train generalized (non-personalized) AI or machine-learning models, and we do not transfer it for advertising. For the X connectors (posts and advertising), agents act on your X account and X Ads account only after you sign in with X and only for the actions you authorise — for example publishing a post you approved, reading your posts and mentions, or reporting ad-campaign performance; ad campaigns are drafted in paused state, and activating, pausing or re-budgeting a campaign always requires your explicit approval. The data exchanged with X in doing so is processed by X Corp. (USA) under the X privacy policy; we use data received from X’s APIs solely to perform these actions on your behalf and do not use it to train AI or machine-learning models.
- Web search (the optional web_search tool): Tavily Inc. (USA) receives the search queries an agent formulates while working on your task — such a query can reflect the content of that task. Web search runs only for agents you have given the tool to.
- Embeddings (knowledge-base search): OpenAI (USA) computes text embeddings of the documents you upload — only where your data-residency policy permits US processing; otherwise a local embedder is used.
- Video generation (the optional generate_video tool): where the Seedance engine is configured on our deployment, BytePlus (ByteDance) — Seedance (China) receives the video prompt an agent writes. Seedance counts as a China-region vendor, so it is reachable only if you have enabled the China region in your data-residency policy (off by default); otherwise a video is generated on Google Veo (USA) or not at all.
- Voice output (replies read aloud): where configured on our deployment, ElevenLabs, Inc. (USA) receives the text of a reply you have had read aloud, in order to synthesize the speech; your data-residency policy still gates each call. A reply can instead be voiced by Mistral (EU) or OpenAI (USA) from the list above, and every voiced reply names its vendor in the response.
- Voice output: Cartesia AI, Inc. (USA) receives the same data for the same purpose and under the same conditions, where it is the speech vendor configured on our deployment.
- Payment processing (our own billing, independent of any connector you add): Stripe Payments Europe, Ltd. (Ireland) and Stripe, Inc. (USA) process the account holder’s billing details and payment method for subscriptions and wallet top-ups.
- Email delivery (transactional account email — verification, invitations, password resets — and the operational notification emails you configure, e.g. approval or run alerts): Resend, Inc. (USA) receives the recipient’s email address and the message content.
- Hosting and database: Render (Render Services, Inc.) hosts the application in its Frankfurt region (EU); the PostgreSQL database is provided by Neon (Neon, Inc.) on Amazon Web Services in its Frankfurt region (EU, region eu-central-1).
- Object storage (durable storage of the files your agents produce, and of the nightly database backups described under “Retention”): Cloudflare R2 (Cloudflare, Inc.), stored in the EU jurisdiction.
- Content delivery and edge security: Cloudflare, Inc. (USA) additionally fronts the application as CDN/edge proxy and in doing so processes request metadata (IP address, requested URL) at its global edge. Where the bot check is enabled on our deployment, Cloudflare also operates the invisible Turnstile check on the sign-up, sign-in and password-reset forms and receives the challenge token and the IP address that solved it.
- Error monitoring: where error tracking is enabled on our deployment, Sentry (Functional Software, Inc., USA) receives technical error reports (error type, message, stack trace) when a server error occurs — never your documents or run content.
We do not sell personal data. We disclose data to authorities only where legally required.
5. Disclosure abroad
Some processors are located outside Switzerland — the jurisdiction of each AI model provider is shown in the list in section 4; several connector providers are located in the USA. Our hosting (Render), database (Neon) and object storage (Cloudflare R2) store data in the EU (Frankfurt / EU jurisdiction). For recipients in the USA we rely on the EU Standard Contractual Clauses in the version recognised by the Swiss Federal Data Protection and Information Commissioner (with the Swiss amendments) and, for certified recipients, the Swiss-US Data Privacy Framework; Anthropic (Claude), which powers the default team, is contractually bound not to use your content to train its models. Your data-residency policy on the Security page controls which jurisdictions may process your data (EU/US/CN) and is enforced fail-closed — it defaults to the EU and the USA, so no data reaches a China-region provider unless you explicitly enable the China region. The optional China-region providers (Moonshot/Kimi, Alibaba Cloud/Qwen, Z.AI) are used under their own standard API terms; we have not concluded Standard Contractual Clauses with them and their terms may permit them to use content to improve their services; the same applies to the Seedance video engine of BytePlus (ByteDance), where it is configured on our deployment. Enabling the China region and assigning work to those models is a disclosure abroad to a country without an adequacy decision and without additional safeguards — do so only for data for which you, as controller, have a lawful basis under Art. 17 revDSG (in particular the express consent of the persons concerned). A provider that does not offer even the contractual data-protection commitments we require of a sub-processor is not offered at all: DeepSeek, for example, appears as “coming soon” and cannot be selected or enabled.
6. AI-assisted processing and automated decisions
vorenq uses AI agents that read and act on data automatically; you are interacting with an AI system and the work it produces is AI-generated, which can be incomplete or incorrect — review it before you rely on it. Actions that carry real-world consequences — moving money, messaging a customer, writing a financial record, signing — are routed through a guardrail that pauses them for your explicit human approval before they run. That approval requirement is the default; a workspace owner can relax individual pauses or switch the guardrail to a monitor-only mode on the Security page (which warns about the implications) — the payment cap, the block on irreversible deletions and the credential-leak block remain enforced in every mode. Where processing could amount to an automated individual decision under Art. 21 revDSG, you can request human review via the contact above.
Transparency under the EU AI Act: vorenq is an AI system within the meaning of Regulation (EU) 2024/1689, and the product tells you when you interact with an AI agent — the work your agents produce is attributable to them as AI-generated. When your agents send messages to people outside your company, emails sent through a connected mailbox and postal letters carry a notice of the AI assistance added by the platform itself, and for every other channel (e.g. chat replies) the agents are instructed to identify themselves as AI; a workspace can adjust this disclosure on the Security page. vorenq itself never trains models on your data. Your prompts and content are sent to the selected AI model provider solely to generate the response; what the provider may do with them is set by its API terms — Anthropic (Claude) does not use API content to train its models, while Moonshot AI’s (Kimi) standard terms let it use content to improve its services unless restricted by a separate written agreement. Assign work whose content must not be used that way to Claude-powered employees. The same applies to every other selectable provider — for example Alibaba Cloud (Qwen), Z.AI or, once offered, DeepSeek: unless this policy states a no-training commitment for a provider, assume its API terms allow such use. In Switzerland there is currently no AI-specific statute: AI-assisted processing of personal data is governed by the revDSG, and Switzerland has signed the Council of Europe Framework Convention on Artificial Intelligence — we track its implementation.
7. Retention
We keep personal data only as long as needed for the purposes above. In practice: account and workspace data for as long as your account is active — when it is closed, or you ask us to delete it, we delete it within 30 days; request and application logs (IP address, timestamp, user-agent) exist only in our hosting provider’s log stream and are deleted there automatically within at most 30 days — we keep no separate log archive; sign-in sessions expire after 30 days; task content, files and connector credentials are kept until you delete them — deleting a workspace removes its agents, runs, files and connector credentials from the live system immediately. Where the law requires longer retention — for example accounting records under the Swiss Code of Obligations — we keep those records for the statutory period (generally 10 years) and then delete them.
Backups. So that we can restore the service after a loss or corruption incident, a complete copy of our database is written every night to our object-storage provider (Cloudflare R2, EU jurisdiction). It covers every table — including account data, workspace content and the encrypted connector credentials — and the 30 most recent nightly copies are kept, each older one being deleted automatically. Deletion in the live system is immediate as described above, and we restore from a backup only to recover the service as a whole, never to bring individual deleted records back; a copy made before a deletion does, however, still contain the data until it ages out of that 30-night window.
Two things deliberately outlive the deletion of a workspace. The accounting records above are one. The other is an abuse report concerning your workspace: we keep the report together with the evidence snapshot taken when it was filed (the reported content, its checksum, the agent that produced it and the related audit entries) for as long as we need it to handle the case and to establish, exercise or defend legal claims. The party a report is about controls every delete surface in the product, so evidence that vanished with the workspace would make deleting the workspace the universal way to erase it.
Bug reports. When you report a problem with the product from inside the app, we store what you wrote, how urgent you said it is, your name, e-mail address and workspace, and — only if you leave the box ticked — the page you were on (its web address without the query part, so no one-time link travels with it), your language, your screen size and the last few errors your browser had already logged. We use it to reproduce and fix the problem and to reply to you. It is deleted with your workspace. A report filed before you belong to any workspace is kept under our own platform record instead, where the 500 most recent are retained and older ones are deleted automatically.
8. Security
Connector credentials are encrypted at rest (AES-256-GCM) and decrypted only server-side at the moment a connector runs; they are never returned to the browser. Passwords are stored only as salted hashes. Access is scoped per workspace, and transport is over HTTPS.
9. Cookies
We use only strictly necessary first-party cookies — a session cookie for sign-in, your current-workspace selection, your language choice, a note of which version of our terms you have already acknowledged, and short-lived state cookies that secure connector sign-in flows. Your light/dark theme preference is stored locally in your browser (not a cookie) and never shared. We do not use advertising or third-party tracking cookies, so no consent banner is required.
10. Your rights
You have the right to information about your data (we respond within 30 days), and to its correction, deletion, restriction of processing, data portability, and to object to processing. Contact us at info@vorenq.com. You may lodge a complaint with the Swiss Federal Data Protection and Information Commissioner (FDPIC/EDÖB); if you are in the EU/EEA, you may also complain to your national data protection authority.
11. Changes
We may update this policy; the current version always applies. Last updated: 29 July 2026.