Data handling
Use secure transport and send only the data required for the task.
Different parts of the Vergora website, console, and API process different data. Before submitting content, make sure that you are allowed to process it and send only what the task requires.
Data categories
| Scenario | Data that may be involved |
|---|---|
| Account and sign-in | Account identifier, verification, and session information |
| API request | Input content, model, parameters, and generated result |
| Usage and troubleshooting | Request ID, time, status, usage, latency, and cost |
| Payment and refund | Order, amount, currency, and transaction status |
| Support | Problem descriptions and attachments that you provide |
Use the Privacy Policy as the source of truth for processing scope, purposes, and rights.
Platform and model processing
Vergora processes data for platform functions such as accounts, authentication, routing, metering, billing, and support. A model request may also be processed by the model service that performs inference. Review both Vergora guidance and the applicable model rules when selecting a model.
Unified access does not mean that every model has the same data region, retention period, or training policy.
Check before sending
- Remove personal and business data that the task does not require.
- Never include passwords, API keys, payment information, or private keys in a prompt.
- Check images and attachments for sensitive information.
- Confirm that you are allowed to submit the content.
- If your business requires a specific region or retention period, do not send production data until those requirements are explicitly confirmed.
Protect credentials and logs
Use HTTPS and store API keys on the server. Prefer Request IDs, status codes, and redacted errors in application logs. Avoid logging complete request headers or sensitive content.
If you suspect API key exposure, stop using the affected key, create a replacement, and review related request records.
Data requests
For data retention, access, correction, export, or deletion processes, use the channel provided in the Privacy Policy. Provide only the information required for identity verification and request handling.