Vesta
PricingBlogHelpLog inStart free

Privacy policy

Last updated: 5 October 2026

1. Data controller

The data controller is NOVAMARKET DI CANNAVO' MICHAEL, Via Roma 213, 95030 Mascalucia (CT), Italia, P. IVA 06173360873, REA CT-474343. For any privacy question or to exercise your rights write to [email protected]. This notice is provided under Articles 13 and 14 of Regulation (EU) 2016/679 ("GDPR").

2. What data we process

• Account data: email, password (stored only in hashed form), display name, language, sign-up and last sign-in dates. • Plan and credits: chosen plan, credits used, subscription status and, if you buy, receipt data (amount, date, Stripe customer ID). Card details are handled only by Stripe. • Your material: texts, documents, flashcards, quizzes, maps and the content you upload (PDFs, images, YouTube links). • Technical data: IP address and server security logs, kept briefly. • Support: if you write to us through the chat or by email, your name, your email and the content of the conversation. • Waitlist: if you join before launch, only your email. We do not ask for special categories of data (health, religion, etc.): please do not put them in your material.

3. Why we process it and on what basis

• Providing the Service (account, saving material, AI generation, credits): performance of a contract (Art. 6(1)(b) GDPR). • Payments, receipts and tax obligations: performance of the contract and legal obligation (Art. 6(1)(b) and 6(1)(c)). • Customer support (chat and email): performance of the contract and legitimate interest in answering your requests (Art. 6(1)(b) and 6(1)(f)). • Security, abuse prevention and usage limits: legitimate interest (Art. 6(1)(f)). • Waitlist and launch notice: consent (Art. 6(1)(a)), which you can withdraw at any time. We do no advertising profiling, we do not sell data, and we do not use your material to train AI models. We make no automated decisions with legal effects on you.

4. Artificial intelligence

When you use an AI Feature, the necessary text (your request and the material to process) is sent to OpenRouter, which forwards it to the AI provider (Google) to generate the answer. The text is used only to produce the result. Support assistant. In the support chat an AI assistant replies first. If you are signed in, to answer your questions it can read some of your account data: plan, remaining credits, subscription status, dates and titles of recent documents. It does not see your password, card details or the content of your material. The text of the conversation is processed by AI model providers (including DeepSeek) through OpenRouter. You can ask at any time to talk to a person on the team. PDFs and images are read on our server in the EU and are not kept after text extraction. For YouTube videos we send YouTube only the video ID to fetch the transcript.

5. Who we share data with

We only use providers needed for the Service, appointed as processors (Art. 28 GDPR): • Contabo GmbH (Germany, EU): servers and database where accounts and material are stored; data stays in EU data centres. • Cloudflare, Inc. (USA): content delivery and site protection; it sees the IP address and requests, not the content of the material we store for you. • OpenRouter Inc. (USA): routing of AI requests, including those of the support assistant. • DeepSeek (AI models reached through OpenRouter): processing of the text of conversations with the support assistant. • Purelymail (USA): receiving emails sent to [email protected]. • Google (USA / EU): processing of AI requests and, if you choose it, sign-in with your Google account. • YouTube / Google: only the video ID, for the transcript. • Resend, Inc. (USA): sending service emails (account confirmation, password reset, receipts) and support replies. • Libredesk (support software that we run ourselves on our server in the EU): storing support chats and emails, with no other providers. • Stripe Payments Europe, Ltd (Ireland): payments and receipts for the Plus and Pro plans; card details go straight to Stripe and never pass through our servers. Data may be disclosed to authorities only when required by law.

6. Transfers outside the EU

Accounts and material are stored in the EU. Some providers (Cloudflare, OpenRouter, DeepSeek, Google, Purelymail, Resend, Stripe) may process data in the United States, under the EU-US Data Privacy Framework or the European Commission's Standard Contractual Clauses (Art. 46 GDPR). We send the AI provider only the request text; conversations with the support assistant may also include the account data described above, but never your password or card details.

7. How long we keep it

• Account and material: as long as you have the account. When you delete it they are erased immediately; backup copies are overwritten within 30 days. • Billing data: 10 years, as required by tax law. • Server security logs: up to 30 days. • Support conversations (chat and email): 24 months after the last message, then deleted. • Waitlist: until launch and the invitation is sent, or until you ask to be removed.

8. Your rights

You have the right to access, rectify and erase your data, restrict processing, receive it in a portable format, and object to processing based on legitimate interest (Arts. 15–22 GDPR). You can withdraw consent at any time. Directly in the app, under Plan → Your data: • "Download my data": a JSON file with your account, profile, plan and all your material. • "Delete account": permanently deletes the account and all material. For other rights write to [email protected]: we reply within 30 days. You also have the right to lodge a complaint with the Italian Data Protection Authority (www.garanteprivacy.it) or the authority of your EU country.

9. Cookies and browser storage

We only use technical tools strictly necessary for the Service, which do not require consent: • vesta_locale (cookie): remembers your language. • Supabase session cookies (sb-…): keep you signed in. • Cloudflare technical security cookies (e.g. __cf_bm): protect the site from automated access. The payment page is hosted by Stripe, which uses its own technical and anti-fraud cookies. • Browser storage (localStorage / IndexedDB): reading preferences, flashcard review state, current plan and in-progress generation drafts. This data stays on your device. We use no profiling, analytics or advertising cookies. That is why we do not show a cookie banner.

10. Security

Connections are encrypted (HTTPS), passwords are stored only hashed, and each user can access only their own data thanks to database-level security rules. If a data breach may put you at risk, we notify the supervisory authority within 72 hours and, where required, you as well.

11. Children

In Italy you can sign up on your own from age 14. Under 14, a parent's or guardian's consent is required. If you are a parent and believe your child signed up without consent, write to us and we will delete the account.

12. Changes

If we change this notice we update the date at the top; for material changes we notify you by email or in the app.