Privacy Policy
Effective Date: October 1, 2026 · Version 1.3
Our Privacy Philosophy
Vector Studio is built upon a fundamental principle: we cannot sell, share, or leak your credentials because we never receive them. Vector Studio does not maintain remote user databases, tracking cookies, or third-party telemetry. All encryption and key derivations execute directly within your browser runtime.
01.Information We Do Not Collect
Unlike traditional cloud software and SaaS dashboards, Vector Studio does not ingest or store your confidential operational data. Specifically, we do NOT collect or store:
Your AWS Access Key ID, Secret Access Key, and Session Tokens never leave your device unencrypted.
Your vector indexes, dimensions, queries, and search results are never logged or cached remotely.
Your vault passphrase is known only to you and is held strictly in volatile browser memory.
No advertising trackers, session recording scripts, or third-party profiling analytics.
In-Memory Client Diagnostics Only
Device diagnostics shown in Settings (browser name, rendering engine, screen resolution, and OS architecture via navigator.userAgentData) are calculated 100% locally in-memory for environmental troubleshooting. They are never transmitted to any telemetry server or external third party.
02.Local Storage (IndexedDB, Cookies) & Encryption at Rest
When you configure an AWS connection in Vector Studio, all sensitive data undergoes client-side WebCrypto encryption before touching disk:
- Key Derivation: Your passphrase is fed into the browser-native WebCrypto PBKDF2 function using SHA-256 with 210,000 iterations and a unique cryptographic salt per vault (conforming to modern OWASP recommendations).
- Symmetric Encryption: The resulting key encrypts your connection secrets using AES-256-GCM with a fresh 96-bit initialization vector (IV) per entry.
- IndexedDB Isolation: Only the encrypted ciphertext, salt, and IV are written to the browser's local IndexedDB storage (
vector-studio), strictly sandboxed to your origin. - Local Storage & Masking Preferences: Local storage is used solely for client UI preferences, search query history, consent state, and the sensitive data masking toggle (
vs_mask_sensitive), which automatically masks Account IDs, bucket names, and ARNs with••••••••••••to prevent shoulder-surfing and safe screen sharing. - Encrypted Session Continuity Cookie: To maintain your unlocked session across page reloads without re-prompting on every tab switch, a temporary cookie named
vs_vault_sessionis generated. This cookie is encrypted using a client-device entropy key with strict security parameters (SameSite=Strict; Path=/) and is never read or stored on any server-side database.
03.Stateless API Communication with AWS & Amazon Bedrock
To inspect S3 Vectors and generate embeddings, requests are signed with AWS Signature Version 4 (SigV4). If an API call routes through the Next.js server runtime, it operates as a purely stateless pass-through proxy:
- Credentials and query strings are held in volatile memory only for the duration of the individual HTTP request.
- Bedrock embedding requests (such as Amazon Titan Text Embeddings V2) are forwarded directly to the AWS Bedrock endpoint in your designated region.
- No databases, caches, disk writes, or remote loggers record your keys or vector payload contents.
- Communication between your browser, our proxy, and AWS is strictly secured via TLS 1.3 encryption.
04.Right to Complete Erasure & Universal Purge
You maintain total, unilateral control over all data stored on your device. At any time, you can invoke our universal client storage purge:
- Universal Storage Purge: Available via the Settings panel and the vault unlock gate. Clicking "Delete Passphrase & Wipe Credentials" triggers a complete wipe that drops the IndexedDB database, clears all
localStorageentries, clearssessionStorage, and deletes all cookies (includingvs_vault_session). - Local History Removal: Wiping the vault immediately purges all cached vector search query histories, cached index names, and in-memory WebCrypto keys.
- Selective Removal: You may also delete individual connections or purge specific search records at any time without deleting your master passphrase.
- Browser Data Clearing: Clearing your browser's site data or cookies for this domain achieves an equivalent total purge.
05.Policy Updates, Engineering Attribution & Contact
Vector Studio is an engineering initiative developed by Techity. If we update our architectural practices or security policies, we will publish the changes directly on this page with an updated effective date.
For privacy inquiries, security questions, or disclosures, please visit our Contact Page, review our FAQ, or reach out directly to:
- Security Disclosures: [email protected]
- General Support: [email protected]