1. Who we are and what this Policy covers
Vergora is operated by Weizhentian Science and Technology, Inc., a company incorporated in Delaware, United States (“Vergora,” “we,” “us,” or “our”).
Website: https://vergora.ai
Registered address: 2810 N Church St STE 90130, Wilmington, DE 19802, United States
Privacy contact: support@megatron-sh.ai
This Privacy Policy explains how we handle personal data when you visit our website, register or use an account, use our console, APIs, model access, billing or support, or otherwise interact with us. “Personal data” means information that identifies or can reasonably be linked to a person. It may include personal data contained in prompts, files, images, API parameters, support messages, or model outputs.
For our account administration, billing, fraud prevention, website, and direct support activities, Vergora generally determines why and how the relevant personal data is processed. When an organization uses Vergora to process content on its behalf, the roles may differ and the organization may be responsible for its own notice and lawful basis.
For an individual account, Vergora generally acts as the controller or business for account, billing, website, security, and support data. When an organization uses Vergora to process customer content on its behalf, the organization acts as controller or business and Vergora acts as processor or service provider for that content, as described in the applicable Data Processing Addendum (DPA). The DPA applies to commercial or organizational use when presented with, incorporated into, or signed as part of the applicable agreement. Organization administrators may access and manage information associated with their organization account.
2. Information we handle
We handle the following categories when you use the relevant feature. If you do not provide information required for an account, payment, security check, or requested service, we may be unable to provide that feature.
2.1 Account and profile information
This includes name, email address, account identifier, authentication information, language and settings, workspace or organization association, and information you choose to provide. It may also include telephone number, profile image, third-party login data, or multifactor-authentication data when you use those features.
We use this information to register and authenticate users, manage accounts and settings, provide support, communicate service or security notices, and enforce account rules.
2.2 Payment, recharge, usage, and refund information
This may include recharge order number, amount and currency, payment status, payment-method type or limited payment metadata returned by Stripe, billing address where required, usage and balance records, refund requests and status, tax information where applicable, and transaction risk signals.
We use this information to process payments, allocate prepaid balance, calculate usage, issue refunds, reconcile transactions, prevent duplicate payment or reimbursement, address disputes, and meet financial or legal obligations.
Vergora does not ask you to provide your password, API secret, or full card number in a refund or support request. Stripe processes payment-card data; Vergora receives transaction status, payment-method type, and limited payment metadata needed for billing, refunds, fraud prevention, and reconciliation.
2.3 API and service metadata
This may include API-key identifier or masked representation, workspace identifier, request identifier, selected model and version, timestamps, endpoint, usage units, price version, amount reserved and charged, status, latency, error code, network address, and security or audit events.
We use this information to authenticate and process requests, meter and bill usage, operate rate or spending limits, investigate errors and billing questions, protect accounts and the Services, and maintain records of important actions.
2.4 Inputs, outputs, files, and other customer content
Depending on the model and feature, customer content may include prompts, messages, request parameters, documents, images, audio, other uploaded files, and generated output. This content is processed to deliver the requested model service. Support personnel may receive content you intentionally submit in a support case.
2.5 Device, website, and log information
Depending on the implemented website, this may include IP address, browser and operating-system type, access time, referring page, pages or links used, session identifier, cookies, local storage, and security logs.
We use necessary information to maintain sessions, remember settings, protect the website, diagnose errors, and understand service operation. Analytics, advertising, session replay, and marketing technologies must be described only if actually deployed.
2.6 Support and communications
We handle the messages, contact details, transaction references, and attachments that you provide to support. We use them to answer questions, investigate incidents, process valid requests, and maintain an appropriate case record.
3. Legal grounds, where required
Where applicable law requires a legal ground, we rely on:
performance of a contract or steps requested before a contract for accounts, APIs, usage records, payment, and support;
compliance with legal obligations for records or disclosures that are legally required;
legitimate interests, where permitted and not overridden by individual rights, for proportionate security, fraud prevention, service reliability, and legal claims; and
consent where the relevant law requires it, including for optional marketing or non-essential tracking where applicable.
Service and security communications necessary to operate an account are separate from optional marketing. Where processing is based on consent, it may be withdrawn without affecting processing already lawfully performed.
4. How model providers handle content
Where a model is served through an external provider, we transmit the information necessary to complete the request to the approved service provider. The model publisher, infrastructure operator, API intermediary, and party actually receiving the content may be different.
For each launch model, the product or documentation must disclose, or link to information that identifies:
the provider or sufficiently specific provider category;
whether an intermediary receives the request;
the processing location where known and relevant;
whether input or output is retained and for how long;
whether it may be used for training, evaluation, abuse monitoring, or service improvement;
any permitted human review;
applicable model terms and restrictions; and
available data-control options.
Vergora does not use customer prompts or model outputs to train its own models. External model providers may retain or use inputs or outputs for training, evaluation, abuse monitoring, security, or service improvement under their own terms. The applicable model page or linked provider terms describe those practices and available controls. A no-training option does not necessarily mean that the provider performs no storage or security review.
Do not submit passwords, API secrets, payment credentials, or content that the chosen service is not approved to process. You are responsible for having an appropriate legal basis, notice, or permission for personal data about another person that you submit.
5. Cookies and similar technologies
Vergora may use cookies, local storage, or similar technologies that are strictly necessary for sign-in, session security, load balancing, fraud prevention, and saved preferences. Blocking these technologies may prevent essential features from working.
We may also use analytics cookies to understand aggregate site and product usage. Where required, non-essential analytics are activated only after consent and may be disabled through the available cookie control or browser settings. We do not use advertising pixels or cross-context behavioral advertising cookies.
6. How we share or disclose information
We disclose only the information reasonably needed to the following categories of recipients:
model and inference providers that process approved requests;
hosting, database, cache, file-storage, content-delivery, monitoring, and security providers;
authentication and email providers used for account access and service communications;
Stripe and other payment, fraud, tax, or transaction service providers actually used;
customer-support tools and professional advisers under appropriate duties;
public authorities or other parties where disclosure is legally required or reasonably necessary to protect rights, safety, or the Services; and
a buyer, successor, or adviser in a merger, financing, reorganization, insolvency, or transfer of business, subject to appropriate confidentiality, notice, and legal requirements.
We disclose information at your direction or with valid consent where applicable. We do not publicly disclose customer content merely because it was submitted to an API.
Vergora does not sell personal data for money and does not use personal data for cross-context behavioral advertising.
7. International processing
Personal data may be hosted, accessed, or processed in the United States, the European Economic Area, the United Kingdom, or other countries where Vergora and its service providers operate. These countries may have different data-protection laws.
Where applicable law restricts an international transfer, we use a legally recognized mechanism, including an adequacy decision, the European Commission’s Standard Contractual Clauses, the UK International Data Transfer Addendum, or another lawful safeguard, together with supplementary measures where required. Relevant information is available on request.
8. Retention, deletion, and account closure
We retain personal data only for as long as reasonably necessary for the purposes described in this Policy, account administration, billing, fraud prevention, security, disputes, legal claims, and applicable accounting, tax, or other legal obligations.
Account and profile information is kept while the account is active and is deleted or de-identified after closure when it is no longer needed for security, dispute, or legal purposes.
Payment, recharge, refund, tax, and ledger records are kept for the period required by applicable accounting, tax, payment-dispute, anti-fraud, and legal requirements.
Request, usage, error, and audit metadata is kept for the shortest period reasonably needed for billing, troubleshooting, security, and disputes.
Prompt and output content is processed to provide the requested service. Vergora does not use it to train its own models. A provider may retain it under the model-specific rules disclosed for that model.
Images, audio, video, and similar media used for inference are ordinarily processed transiently for routing and delivery, except where retention is needed for security, billing, support, or law. Files intentionally saved through a Files API or account feature remain until you delete them or close the account, subject to backup, provider, and legal-retention cycles.
Support records are kept for as long as reasonably necessary to resolve the case, maintain an appropriate record, and address related disputes or legal duties.
Deleted information may remain in restricted backups until the applicable backup is overwritten. It is not restored to active use except for disaster recovery, security, or legal requirements.
You may request account closure or exercise an applicable deletion right through support@megatron-sh.ai. We may request proportionate verification. We will explain the action taken and any information that must be retained. Information retained for a legal or dispute purpose should be restricted to that purpose.
Account closure does not automatically erase transaction records that must be retained, resolve an outstanding request, or initiate a refund. An expired file link does not by itself establish deletion. Upstream provider deletion and backups must be included in the verified process.
9. Security
We use safeguards designed to protect personal data, including encryption in transit and at rest where appropriate, restricted and role-based access, credential and secret-management controls, log redaction, workspace separation, monitoring, backups, and incident-response procedures. No method of transmission or storage is completely secure.
You should protect your credentials and contact us promptly about suspected unauthorized access. We will investigate incidents and notify affected individuals and authorities where applicable law requires it.
10. Your choices and rights
Depending on your location and applicable law, you may have rights to:
access personal data and receive information about its processing;
correct inaccurate personal data;
delete personal data, subject to lawful exceptions;
obtain a copy or portability where applicable;
object to or restrict certain processing;
withdraw consent where processing relies on consent;
opt out of legally defined sale, sharing, or targeted advertising where applicable; and
complain to a relevant data-protection or consumer authority.
Submit a request to support@megatron-sh.ai. Include enough information to identify your account and request, but do not send passwords, API secrets, or full card details. We may verify your identity and, for an authorized agent, their authority. We will respond within the applicable legal period and explain a lawful refusal, limitation, fee, or extension where permitted.
Available account, credential, and cookie choices may be managed through the product or browser. You may appeal a denied rights request by replying to the decision or emailing support@megatron-sh.ai. We respond within the period required by applicable law.
11. Children
Vergora accounts are intended only for people aged 18 or older. A person under 18 must not create or use an account. If we learn that an underage person has created an account or provided personal data contrary to this requirement, we will investigate and take appropriate action, including deletion where required.
This account rule does not mean that customer API content can never concern a child. Such use must be permitted by applicable law, model terms, and Vergora’s approved use cases.
12. Policy updates
This Policy is effective on September 7, 2026. We may update it for product, provider, legal, or operational changes. We will give additional notice before a material change where required and obtain consent where a new use requires it.
A posted update does not by itself authorize a materially incompatible new use of previously collected data. If you disagree with a change, you may stop using the affected Services and exercise available account or legal rights.
13. Contact
For privacy questions, rights requests, or complaints:
Weizhentian Science and Technology, Inc.
Vergora
2810 N Church St STE 90130
Wilmington, DE 19802, United States