DRAFT — attorney review required.

Do not rely on this text until a licensed attorney has reviewed and approved it.

Privacy Policy

Version 2 · Last updated: July 5, 2026

The short version

We collect what we need to run your membership — account info, quiz answers, usage, and what you type into the AI tools. AI requests are processed by Anthropic (and Voyage AI for search embeddings) under contracts that prohibit training models on your data. We never sell your data. Payment cards are handled by Stripe; we never see full card numbers. You can export or delete your data anytime.

This recap is for convenience only — the full text below controls.

1. Who We Are

Vantino (vantino.ai) is operated by its founder, Evan Bennett, in the United States. This policy explains what we collect, why, who processes it for us, and the rights you have. Contact for anything privacy-related: hello@vantino.ai.

2. Information We Collect

  • Account information — email address, name, password (hashed; we never see it), and authentication events. If you enable two-factor authentication, we store the data needed to verify it.
  • Quiz responses — your answers to the path quiz, used to match you to a learning path and personalize content.
  • Profile and business context — details you choose to give the Service so tools and AI features can personalize output (e.g., your niche, brand name, goals).
  • AI inputs and outputs — prompts you submit to AI features and the responses generated, retained so you can revisit your history and so we can enforce acceptable use and account for credits.
  • Usage data — lesson progress, tool usage, feature interactions, and credit consumption, used to run and improve the Service.
  • Payment information — processed by Stripe. We receive and store only what we need (plan, status, last-4/brand of card, invoices); full card details never touch our servers.
  • Connected-account data — if you connect a third-party account (for example a social media account for publishing features), we store the tokens and metadata needed to provide that feature, and only access the scopes you granted.
  • One-time services data — for website builds and consulting: order details, files and brand assets you provide, milestone approvals, and deliverable acceptance records (including timestamp, and the IP address and browser user-agent captured at acceptance, which serve as the signature record).
  • Leads — if you give us your email before signing up, we store it to follow up. You can unsubscribe anytime.
  • Support communications — emails you send us.

We do not knowingly collect data from anyone under 18.

3. How We Use Information

  • Provide, personalize, and improve the Service (including matching you to a path).
  • Operate AI features: your prompts and relevant context are sent to our AI processors to generate responses; usage is metered against your credit balance.
  • Process payments, manage subscriptions and one-time orders, and keep legally required transaction records.
  • Send operational email (receipts, account and billing notices, deliverable and acceptance notifications) and — with your consent or as permitted — the weekly drop and product updates. Marketing email always has a working unsubscribe.
  • Protect the Service: rate limiting, abuse and fraud prevention, enforcing acceptable use.
  • Comply with law.

We do not sell your personal information, and we do not share it for cross-context behavioral advertising.

4. AI Processing — the details

  • Processors. AI features are powered by Anthropic (large language models) and Voyage AI (text embeddings for search/retrieval). Both act as our processors: they process your inputs solely to return results to Vantino.
  • No training on your data. Our agreements with these processors prohibit using your content to train their models. We also do not train models on your data ourselves.
  • Isolation. AI requests run under Vantino’s own keys with per-member isolation — your data is never used in another member’s context, and other members can never see your prompts or outputs.
  • Retention at processors. Processors may retain API inputs briefly for abuse detection and reliability per their policies, after which they are deleted. We retain your AI history in your account so you can revisit it; deleting your account deletes it (Section 7).
  • Human review. We do not routinely read your AI conversations. We may review specific content when investigating abuse reports, security incidents, or legal compliance, or when you ask us to for support.

5. Service Providers (Processors)

ProviderWhat it doesWhat it processes
SupabaseDatabase, authentication, storageAccount data, app data
StripePayments, subscriptionsPayment and billing data
ResendTransactional + membership emailEmail address, message content
NetlifyHosting and infrastructureRequest logs (IP, user agent)
AnthropicAI model responsesAI inputs/outputs
Voyage AIEmbeddings for searchText being indexed/searched
BlotatoSocial publishing (only if you use publishing features)Content you publish, connected-account tokens
Analytics providerAggregate product analyticsPseudonymous usage events

Each provider is bound by its own terms and our data-processing arrangements, and gets only the data needed for its function.

6. Cookies and Analytics

We use essential cookies to keep you signed in and secure. We do not use third-party advertising cookies. For product analytics we use privacy-respecting, aggregate measurement; where consent is required, we ask first. You can disable cookies in your browser, but sign-in requires them.

7. Retention and Deletion

We keep account data while your account is active. If you delete your account, we delete your personal data within 30 days, except records we must keep (e.g., payment and tax records, deliverable acceptance records for services orders — kept for the period needed to comply with law and resolve disputes, then deleted). Backups purge on a rolling schedule within 35 additional days.

8. Your Rights

Wherever you live, you can: access the data we hold about you; correct it; delete your account and data; export a copy in a portable format; and unsubscribe from marketing at any time. Residents of California and other U.S. states with privacy laws also have the rights those laws provide — including the right to know, delete, correct, and to not be discriminated against for exercising rights. We do not sell or share personal information as those laws define it, so there is nothing to opt out of. To exercise any right, email hello@vantino.ai; we verify requests via your account email and respond within the legally required window (typically 45 days).

9. Security

Data is encrypted in transit (HTTPS everywhere) and at rest. Authentication is handled by Supabase with row-level security enforcing per-member isolation; admin access is restricted and protected with two-factor authentication. Secrets are held server-side only. No system is perfectly secure; if a breach affects your data, we will notify you as required by law.

10. International Users

We are U.S.-based and the Service is operated from the United States. If you use it from elsewhere, your data is processed in the U.S.

11. Changes

We’ll update this policy as the Service evolves. Material changes are announced by email or in-app notice before they take effect; the version and date above always tell you what’s current.

12. Contact

Privacy questions or requests: hello@vantino.ai
Vantino, United States