Privacy Policy
Last updated
This policy explains what Vispull, LLC (“Vispull”, “we”, “us”) collects on its website, vispull.com, and in its application at app.vispull.com (the “Application”), how we use it and the choices you have. Words with capitals, such as Connected Source and Derived Data, mean what they mean in the Terms of Service.
1. What we collect on vispull.com
- Access requests. When you request access, we collect your work email address and, if you give them, your name, your studio or organization, how many people would use Vispull, where your images live, the plan you're interested in and any note you add. With the request we also record the page you arrived on, the page that referred you, any campaign tags in the link you followed (such as
utm_sourceorgclid) and your browser's user-agent string. The request is sent to our inbox by email. - Messages. When you write to us through the contact form, we collect your name if you give it, your email address, the topic and your message.
- Analytics. Vercel Web Analytics and Speed Insights record page views and performance measurements, such as the page, the referring site, browser, device type and country, without cookies. Google Analytics also records page views and events such as a submitted access request; it sets cookies to recognize a returning browser (see section 8).
- Browser storage. The site keeps the link details above in your browser's session storage, which is cleared when you close the tab, so they can be attached to an access request.
2. What we collect in the Application
- Account. Your email address and password, handled by our sign-in provider (we never see your password in plain text), or, if you continue with Google, the email address and basic profile Google shares.
- Connected Sources. For each Google Drive or Dropbox account you connect: its access tokens, stored encrypted; the account's email address or identifier; and your sync choices and chosen folders.
- Image metadata. For each image: file name, folder path, the provider's file identifier, type, size and dates, and information saved in the file, such as the capture date and GPS location.
- Derived Data. What the Application generates from each image: a description; objects, materials, style, mood, technique, room type, probable period and place; colours; visible text; boxes around parts of the image; search vectors; a small blurred placeholder and a fingerprint used to spot duplicates; and the collections it groups images into.
- Uploaded images. Images you upload directly are stored, with resized copies for display. Images in Connected Sources are not stored; the Application fetches them from the provider when you view them.
- Searches and use. The searches and follow-ups you type or speak, as text; the results and replies shown; timings and model costs; the layouts and suggestions you keep or undo, which the Application uses to decide what to offer you; and feedback you send.
- Voice. In Chrome and Edge, voice input is transcribed by the browser's own speech recognition, which may send your audio to the browser's maker under its own terms. In other browsers, speech is transcribed on your device. Vispull receives the text, not the audio. For spoken replies, the reply text is sent to Cartesia, which returns the audio.
- Technical data. Request logs and error traces, and page views recorded by Vercel Web Analytics.
3. How we use it
We use this information to:
- index your images and answer your searches, in writing and aloud;
- keep chosen folders in sync with your Connected Sources;
- keep the Application secure, find and fix errors, and improve it;
- reply to access requests, send invitations and arrange billing; and
- meet legal obligations.
We do not sell personal information, we do not use it for advertising, and Vispull does not train AI models on your images, searches or other content.
4. Providers that process data for us
The Application uses the following providers. Each receives what it needs to do its part, and processes it under its own terms.
| Provider | What for | What it receives |
|---|---|---|
| Supabase | The Application's database, sign-in and file storage | Account details, Connected Source tokens (encrypted), image metadata, Derived Data, uploaded images, search records |
| Google Analytics | Visit statistics for vispull.com | Page views and events, browser and device details, approximate location, and a cookie identifier |
| Modal | Runs the Application's server | Everything the Application's server processes, including images while they are indexed |
| Vercel | Hosts vispull.com and app.vispull.com; Web Analytics and Speed Insights | Page requests, page views and performance measurements |
| OpenRouter | Routes requests to the AI models that describe images and mark their parts (Qwen3-VL), read searches (DeepSeek), and check results, write replies and act on the screen (Google Gemini) | Resized images, searches and follow-ups as text, image descriptions |
| Cohere | Search vectors for images and text, and re-ranking of results | Resized images, searches as text, image descriptions |
| Cartesia | Spoken replies | The text of the reply to be spoken |
| Inngest | Runs the import and indexing jobs | Job details such as image and connection identifiers |
| Pydantic Logfire | Error and performance tracing | Technical details of requests, which can include search text and identifiers |
| Google Drive connection and “Continue with Google” sign-in; Gmail delivers contact-form messages and access requests from vispull.com to our inbox | Requests from the Application for your Drive files and account details; what you wrote in the contact or access-request form | |
| Dropbox | Dropbox connection | Requests from the Application for your Dropbox files and account details |
We may also disclose information if the law requires it, to protect the rights and safety of Vispull, our customers or others, or as part of a merger, acquisition or sale of assets, in which case this policy continues to apply to it.
5. Google user data
When you connect Google Drive, the Application requests the scope https://www.googleapis.com/auth/drive.readonly, plus openid, email and profile. It uses this access to list your folders and the image files that are not in the trash, read the image files you choose to import or keep in sync so it can describe, index and show them to you, and read your account's email address to label the connection. It cannot create, change, move or delete anything in your Drive.
Data received from Google is transferred to the providers in section 4 solely to provide these features. It is not sold, not used for advertising, and not used to train AI models. People at Vispull do not read it unless you ask us to, it is needed for security or to comply with the law, or it is aggregated for internal operations.
Vispull's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. The use of information received from Google Workspace scopes will adhere to the Google User Data Policy, including the Limited Use requirements.
6. How long we keep it
- Account data, image metadata, Derived Data and uploaded images are kept while your account is open.
- Removing an image from your library deletes its metadata and Derived Data, and the stored file if you uploaded it. It does not affect the file in your Connected Source.
- Disconnecting a Connected Source deletes its access tokens. Data already created from it stays until you remove the images or ask us to delete your account.
- To ask us to delete your account, write to us through the contact form at vispull.com/contact. We delete your account and the data we store for it within 30 days, except where the law requires us to keep something.
- Access requests and messages are kept while we handle them and stay in touch with you. Ask us and we will delete yours.
- Logs and traces are kept for the retention period of the provider that holds them.
7. Security
Data travels over encrypted connections. Connected Source tokens are encrypted before they are stored, and the database keeps each account's data apart with row-level security rules tied to the signed-in user. No system is perfectly secure; if you believe your account has been misused, write to us through the contact form at vispull.com/contact.
8. Cookies and browser storage
vispull.com uses Google Analytics cookies (_ga and _ga_366Q3YJQ81) to count visits and see how the site is used. You can block or delete them in your browser's settings, or use Google's Google Analytics opt-out add-on. The site also uses session storage as described in section 1.
The Application at app.vispull.com keeps your sign-in session and a few display preferences, such as its look and voice settings, in your browser's local storage. These are needed for the Application to work and are not used for advertising.
9. Your choices and rights
You can remove images, disconnect sources and change sync settings in the Application. You can also revoke Vispull's access from your Google or Dropbox account settings.
You can ask us to tell you what personal information we hold about you, to correct it, to delete it or to give you a copy, by writing to us through the contact form at vispull.com/contact. We will answer within 30 days. We will not treat you differently for asking. Depending on where you live, including California, you may have further rights under local law, and you may complain to a data protection authority.
10. Children
Vispull is made for professional use and is not directed to children. We do not knowingly collect personal information from anyone under 16.
11. Where data is processed
Vispull is based in the United States. We and our providers may process data in the United States and in other countries where those providers operate.
12. Changes to this policy
We will post any change on this page with a new date. If a change materially affects how we use information we already hold, we will tell account holders by email before it takes effect.
13. Contact
Vispull, LLC, Los Angeles, California. Write to us through the contact form at vispull.com/contact. See also our Terms of Service.