Privacy policy
Last updated August 1, 2026.
VectorHub sits between your AI agents and the systems they call, which means we handle credentials and call records on your behalf. This page explains what we collect, why, and what we do not do with it.
What we collect
Account data. Name, work email, company and billing details for the person or organisation holding the account.
Connection credentials. OAuth tokens, API keys, usernames and passwords, and custom authentication material for the services you connect. These are encrypted with a per-tenant data key wrapped by a managed KMS root key.
Call records. For each tool call through the gateway: timestamp, calling key, connector and tool, input arguments, upstream status, latency and response size. Arguments are subject to the redaction rules you configure, and argument capture can be disabled per connector.
Product telemetry. Aggregated usage of the dashboard and CLI, error reports, and performance metrics. This is used to operate and improve the service.
What we do not do
- We do not sell personal data, and we do not share it with advertisers.
- We do not use your credentials for any purpose other than making the calls your agents request.
- We do not use the contents of your call records to train models.
- We do not return provider credentials to a client. They are decrypted in memory at the gateway and discarded after the outbound request.
Legal bases
We process account data to perform our contract with you, connection credentials on your instruction to provide the service, and product telemetry under our legitimate interest in operating and improving it. Where consent is the applicable basis, you can withdraw it at any time.
Retention
Account data is retained for the life of the account and for a limited period afterwards to meet legal and accounting obligations. Call records are retained according to your plan: 7, 30 or 90 days on standard plans, and a configurable period on enterprise plans. Credentials are destroyed when you delete the connection; old material is destroyed on rotation rather than archived.
Sub-processors
We use a small number of infrastructure sub-processors for hosting, key management, error reporting and billing. The current list is available on request and to enterprise customers as an appendix to the data processing agreement. We provide notice before adding a sub-processor that handles customer data.
International transfers
Credential stores and call records are regional. EU and US regions are available on standard plans, with custom residency for enterprise deployments. Data keys are never replicated across a residency boundary. Where transfers occur, they rely on standard contractual clauses.
Your rights
Depending on where you are, you may have the right to access, correct, export or delete your personal data, to object to or restrict processing, and to lodge a complaint with a supervisory authority. Write to us and we will action it: identity verification may be required first.
Security
Credentials are encrypted at rest with per-tenant data keys, transport is TLS 1.3 only, connector execution is sandboxed per tenant with egress allowlists, and credential material is excluded at the serialiser so it never reaches a log. See the security page for the full model, including what it does not defend against.
Changes
We will post material changes here and notify account holders by email before they take effect.
Contact
Questions about this policy, or a data subject request, go to the address on our contact page.