The current private pilot
Privacy notice
Updated 8 October 2026
Who operates Vyzier
Vyzier is operated by Siddharth Maheshwari in India. For privacy questions or requests, contact maheshwari_siddharth@vyzier.com.
The Professional pilot is private and access requires owner approval. Wisdom Studio editorial access and administrative access are separate permissions.
Intended users
Vyzier is intended for adults aged 18 and over and is not intended for children. Its intended market is global; the current Professional pilot remains private and requires owner approval. A global market does not mean the service is available in every country.
Information processed
- Sign-in and access: Google/Firebase identity and basic profile information, such as your name, email and account identifier, together with verification, sign-in/provider and session information. Access requests, rights and their approval history are processed to control access. The current sign-in flow does not request Gmail or Drive access.
- Professional record: words you submit, accepted readings, saved responses to reflection questions, preferences such as reading depth, and the temporary dialogue state needed by the feature you use. Your original words are the source of human evidence; generated dialogue is not human evidence.
- Editorial information: for authorized Studio editors, imported book files, bibliography and rights information, source passages, labels, approvals, releases and their history. These are separate from participants' Rivers.
- Operational information: timestamps, record and request identifiers, statuses, approved model-route information, access audits and spending/budget records used for service operation, security and paid-call controls. Authentication and infrastructure providers can also process IP addresses and browser information to operate and secure their services.
- Messages to the operator: your contact information and the information you choose to include when you send a privacy or support request.
Please use low-sensitivity professional examples. Do not submit passwords, employer-confidential or regulated information, identifying details about coworkers, medical or legal records, or crisis information. Vyzier is not an emergency service and does not contact emergency services on your behalf.
Purposes
Identity information authenticates your account, displays your sign-in identity and supports owner-managed admission. It is not used as evidence about your character or professional situation.
Your submitted words and relevant saved context support the Professional readings and temporary dialogue you request. Editorial records support book import, source inspection, labels, human review and separately confirmed source releases. Operational records support access control, reliability, auditability and spending limits. Contact messages support handling your request.
Vyzier does not sell personal data or use it for targeted advertising.
AI and service providers
Vyzier uses Google/Firebase for authentication and cloud infrastructure. The current Professional readings and AI label suggestions are configured to use Google Gemini through Vertex AI. Reviewed-source retrieval uses Google's Vertex AI Search and RAG services. Relevant words and context are transmitted when needed for the requested feature; retrieval can send query text derived from your words. This processing is not limited to encrypted database storage and does not mean you have a separate personal account with each AI provider.
For authorized editors, optional AI label suggestions and book advice can send relevant editorial content to the configured AI service. AI advice does not itself approve or publish a source.
The app offers no employer or cross-user access to your River. Administrative tools can show identity and access information needed to manage admission; those tools do not open participants' River words. Service-provider processing is distinct from another participant's access through the app.
Google's published managed-model terms restrict training use without prior permission or instruction. Provider caching and abuse monitoring can have separate retention conditions. Model caching is enabled in the current production project; its precise lifetime and applicable retention conditions are still being confirmed. Vyzier does not promise zero provider retention. Google Cloud data governance (opens in a new tab).
International processing
Vyzier is operated from India, but this is not an India-only processing service. The current River, Control and Studio databases and the Studio book-upload bucket are configured in Mumbai, India. The AI-model and Vertex AI Search endpoints are global; a storage region is not a guarantee of India-only processing. Google states that Firebase Authentication operates from US data centres. Other Firebase services can process data where Google or its agents maintain facilities unless the particular service offers data-location selection. Storage location alone does not establish the location of AI processing, authentication, support or provider logs. Firebase processing locations (opens in a new tab).
Requirements and cross-border safeguards for the markets served remain under review. A global intended market is not a claim of worldwide availability or legal compliance.
Protection
The service uses authenticated, owner-scoped access and encrypted connections. Private River text and specified derived fields have an additional per-owner AES-GCM encryption layer, with keys wrapped by Cloud KMS. Identity, operational metadata and editorial records are outside that additional field layer.
This is not end-to-end encryption: the backend decrypts relevant fields during authorized operations, including processing needed for AI requests. Encryption is not a promise that the operator or service providers can never technically access data. Application logging rules prohibit recording private words, prompts, generated replies, credentials and raw account identifiers.
Storage and deletion controls
Original Professional words and accepted readings are stored so you can return to your record. Signing out, starting a new topic or losing access does not delete that record. Temporary dialogue state is separate from the saved human-word history.
Saved Professional records have no automatic age-based expiry. They are kept until you clear them or your verified deletion request is carried out. This rule does not set retention periods for identity, editorial, operational or service-provider records.
Temporary dialogue continuity becomes unusable after 24 hours. Its stored state is removed when an expired read or an explicit clearing action processes it, or by active database expiry cleanup. The 24-hour use limit is not a guarantee of physical deletion at that exact time or from all provider backups.
Where available, Clear my Professional data reviews and deletes the Professional record covered by the confirmed action. It does not delete the Google/Firebase sign-in identity or separate Wisdom records. Saved Wisdom positions and responses have a separate Delete Wisdom responses control. The app reports deletion completion only after verifying the targeted record is absent; an interrupted action is not automatically a completed deletion.
A completion receipt without your words remains. Hashed daily generation-budget records have an expiry marker and active database expiry cleanup; physical removal is asynchronous. Clearing a record cannot reset spending controls. These controls do not establish immediate deletion from every service-provider record, log or backup.
The production project's default Google Cloud log bucket retains entries for 30 days; its required audit-log bucket retains entries for 400 days. Deleted Studio book-upload objects remain recoverable through the bucket's seven-day soft-delete period. These settings concern logs and editorial files, not an automatic expiry period for your saved Professional record.
For an account-deletion request, questions about retained data, or assistance with an unavailable deletion control, use the privacy contact above. Clearing the Professional record must not be confused with deleting your Google account.
Google states that Firebase Authentication keeps other authentication information until the Firebase customer initiates deletion of the associated user, after which removal from live and backup systems occurs within 180 days. Logged IP addresses have a separate retention period of a few weeks. These are Google's published Authentication terms, not a deletion period for the River, editorial archive or every other provider record. Firebase Hosting separately retains incoming-request IP information for a few months for abuse detection and usage analysis. Firebase retention information (opens in a new tab).
Browser and third-party resources
Google/Firebase authentication uses browser storage to maintain sign-in, including persistent authentication state. The current frontend loads Google-hosted fonts and authentication resources; those requests reach Google's services. Signing out ends the app's sign-in session, not the stored River.
Privacy requests and policy changes
The operator monitors the privacy contact above and handles privacy and account-deletion requests sent to that address.
Contact the operator to ask about access to your data, corrections, deletion, withdrawing from the pilot or a privacy concern. Identity verification may be needed before acting on a request. Do not email passwords, authentication tokens or your complete River to establish ownership.
This notice was updated on 8 October 2026. A notice edit does not itself authorize new processing or replace any required notice or consent.