01Who we are
Vespera is a platform of services that share one account: Mirror (portfolios and CVs), Souk (online shops) and Anchor (tasks, projects, an assistant and email outreach). This policy explains what personal information those services handle, why, and the choices you have.
It applies to vspera.me and its subdomains, including mirror.vspera.me, souk.vspera.me and anchor.vspera.me, and to sites people publish with them. In this policy, “Vespera”, “we” and “us” mean the operator of the platform; “you” means anyone who uses it.
Questions or requests about your information can be sent to privacy@vspera.me.
02Information we collect
Information you give us
- Account details: your name, email address and password. Passwords are stored only as a secure hash, never in readable form.
- Profile and preferences: language, theme, the look you choose for Anchor, your email signature and similar settings.
- Content you create: portfolios, CVs, projects and images in Mirror; shops, products, pages and orders in Souk; tasks, projects, notes, chats with the assistant, email drafts and outreach lists in Anchor.
- Files you upload, such as images, CVs and documents you attach to emails.
- Messages you send us, for example when you ask for support.
Information created as you use the services
- Assistant memory: short facts Anchor’s assistant keeps so it can help you over time, such as the name you like to be called. You can see and delete every item in Anchor’s settings.
- Security records: sign-ins, password changes, administrative actions and the IP address they came from, kept to protect accounts and investigate abuse.
- Subscription status: which plan you are on. Payments are arranged directly with Vespera and no card details are stored on the platform.
- Technical data: our servers keep standard logs (IP address, browser type, time and address requested) for security and troubleshooting.
Information from Google
If you choose to sign in with Google or connect Gmail, we receive the information described in How we use Google user data.
Information about other people
Some features involve information about people other than you: customers who order from a Souk shop, recipients you import into an Anchor outreach list, and the people whose replies Anchor shows you. You are responsible for having the right to share their information with us. We use it only to provide the feature to you.
03How we use Google user data
Connecting Google is optional. Vespera requests only the permissions a feature needs, asks for them when you choose that feature, and uses the data only to provide that feature to you.
| Permission | When it is requested | What it is used for |
|---|---|---|
Basic profileopenid email profile | When you choose “Continue with Google”. | To create your account or sign you in, using your name, email address and profile picture. |
Send emailgmail.send | When you choose “Connect Gmail” in your Vespera settings. | To send, from your own Gmail address, the emails you write or review in Anchor, only when you press Send. Anchor never sends email on its own initiative. |
Read emailgmail.readonly | Only if you turn on reading: Anchor’s inbox, reply tracking or importing your Gmail signature. | To show your inbox inside Anchor, to detect replies and delivery failures for emails you sent through Anchor, and to copy your existing Gmail signature into your letters. |
What we store
- The access and refresh tokens Google issues, encrypted at rest, so Anchor can act when you ask it to.
- For emails you send through Anchor: the recipient, subject and text you wrote, the date it was sent, and the Gmail message and conversation identifiers.
- For reply tracking: whether a reply or a delivery-failure notice arrived, when, the sender’s address, and a short preview of it (at most 400 characters), so you can see who answered without opening Gmail.
- Your Gmail signature, if you choose to import it.
Other messages in your mailbox are read only at the moment you open Anchor’s inbox or check for replies. They are shown to you and are not stored.
What we never do
- We do not sell Google user data or use it for advertising.
- We do not use Google user data to develop, improve or train generalized artificial intelligence or machine-learning models.
- We do not send the contents of your Gmail messages to any AI model. Letters written with AI in Anchor are based on the instructions, recipient details and portfolio information you provide, not on your mailbox.
- No person at Vespera reads your Gmail data, except with your explicit permission for specific messages (for example, to help with a support request), when necessary for security purposes such as investigating abuse, or to comply with applicable law.
- We do not transfer Google user data to anyone else, except as necessary to provide the features described here, for security, to comply with the law, or as part of a merger or acquisition with adequate notice to you.
Limited Use disclosure
Vespera’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Disconnecting
You can disconnect Gmail at any time in your Vespera settings. Disconnecting revokes Vespera’s access at Google and deletes the stored tokens. You can also remove access from your Google Account at myaccount.google.com/permissions. The email records and reply previews described above are deleted with your account, or earlier on request.
04Email tracking in Anchor
When someone sends an email through Anchor with tracking switched on, the email may contain a tiny invisible image and links that pass briefly through anchor.vspera.me before opening their destination. This lets the sender see whether the email was opened and which links were clicked.
- We record the time of each open or click, which link was clicked, and a general description of the mail app or device (for example “Gmail” or “iPhone”).
- Tracking records do not include the recipient’s IP address, and no cookies are set. Like every request, these pass through the standard server logs described above.
- The records are visible only to the sender and are deleted with the sender’s account.
- Senders can switch tracking off. Recipients can prevent open tracking by not loading images in their email app.
If you received an email sent through Anchor and want the related tracking records removed, contact privacy@vspera.me with the address it was sent to.
05How we use information
- To provide the services: host your portfolio and shop, run Anchor’s tasks and assistant, send the emails you ask it to send, and keep your one account working across all of them.
- To keep them secure: protect accounts, prevent spam and abuse, and investigate incidents.
- To communicate with you: account verification, password resets, security notices and important changes to the services.
- To support you when you contact us.
- To keep them working well: diagnose errors and understand capacity, using technical logs.
- To meet legal obligations.
We process your information because it is necessary to provide the services you asked for, because we have a legitimate interest in keeping them secure and working, because you gave your consent (for example when you connect Gmail, which you can withdraw at any time), or because the law requires it.
06AI features
Several features use AI: writing letters and portfolio text, translating content and Anchor’s assistant. When you use one, the text you submit for that request is sent to an AI model to produce the result. Depending on your settings, that is:
- the model Vespera provides, run by an AI provider on our behalf;
- an AI provider you connected yourself with your own key, whose own terms then also apply; or
- Puter, if you choose it, which runs in your browser under your own Puter account and its terms, including its free daily usage allowance.
We send only what the request needs, and we do not use your content to train AI models. AI output can be wrong: review it before you publish or send it.
08Storage and security
Vespera’s servers and databases are hosted in the European Union (Paris, France). Some providers listed above may process data in other countries. Where they do, we rely on appropriate safeguards such as the European Commission’s standard contractual clauses.
Connections to Vespera are encrypted with TLS. Sensitive credentials such as Google tokens and AI keys are encrypted at rest. Access to production systems is restricted. No method of transmission or storage is completely secure, but we work to protect your information and will notify you and the relevant authorities of a breach where the law requires.
09How long we keep information
- Account and content: for as long as your account exists. When you delete content, it is removed from the service.
- After you delete your account: your personal information is removed from our active systems within 30 days, except where we must keep something to meet a legal obligation, resolve a dispute or prevent abuse.
- Google tokens: deleted as soon as you disconnect Gmail or delete your account.
- Email tracking records and reply previews: kept while the sender’s account exists, and deleted with it.
- Security records and server logs: kept only as long as they are needed to protect accounts and investigate problems.
10Your rights and choices
Depending on where you live, you may have the right to access the personal information we hold about you, correct it, delete it, receive a copy in a portable format, object to or restrict certain processing, and withdraw consent you gave.
- Much of this you can do yourself: edit your profile and content, delete items, clear Anchor’s memory, and disconnect Google in your settings.
- For anything else, including deleting your account or getting a copy of your data, email privacy@vspera.me from the address on your account. We reply within 30 days.
- If you are not satisfied with our answer, you can complain to your local data protection authority.
12Children
Vespera is not intended for children under 16, and we do not knowingly collect their information. If you believe a child has given us personal information, contact us and we will delete it.
13Changes to this policy
We may update this policy as the services change. The effective date at the top always shows the latest version. If a change is significant, we will tell you in the services or by email before it takes effect.
14Contact
For questions about this policy or your information, or to exercise your rights: