Vezvezak Privacy Policy
Vezvezak LLC · San Jose, California, United States
The short version
Vezvezak is a shopping assistant. To answer your questions it needs to know what you are looking for and roughly where you are.
- Your precise location never leaves your phone. It is rounded to about 110 metres before anything is sent.
- Most of what you do stays on your device — your basket, favourites, price watches, recent searches, and chat history.
- Your searches, and questions you ask the assistant, are read by an AI model that runs on Cloudflare’s own infrastructure — without your name, account or location.
- We show no ads and sell no data.
The rest of this page is the detail.
1. What stays on your phone
The following is stored on your device and is not sent to us:
- Your profile: display name, first and last name, photo, bio, interests, links, birthday (month and day only — never the year), city, country, phone, and email. Every field is optional, and the whole profile is skippable.
- Your basket, favourites, and saved comparisons
- Your recent searches and recently viewed items
- Your price watches and price history
- Your chat history with the assistant
- Cached search results
- Your app settings
- A local error log, which never leaves the device
- Your Face ID or Touch ID, if you turn it on. iOS performs the match; it tells Vezvezak only yes or no. We never receive your face or your fingerprint, we never store it, and it is never sent anywhere. Your password is not stored on the device either — what Face ID unlocks is the sign-in session the server already issued, held in the device Keychain and released only after a match. If you add or remove a face or a fingerprint, iOS deletes that saved sign-in by itself and you sign in with your password once more.
Deleting the app deletes all of it.
2. What we store on our servers
| What | Why |
|---|---|
| Your email address | To sign you in. Stored in readable form because it is your login identifier. An email address is the only identifier Vezvezak accepts: we send no SMS, so an account registered to a phone number could never be recovered. |
| Your name, if you provide one | To address you |
| A cryptographic hash of your password | So we can verify your password without storing it. PBKDF2-SHA256 with a 600,000-iteration work factor — six chained rounds of 100,000, the platform's per-call maximum — and a unique random salt per account. We never store your actual password and cannot see it. |
| Short-lived codes for confirming your email address, signing in, and resetting your password | Stored hashed — we keep a one-way hash of the code, never the code itself. All three expire after 10 minutes. |
| Whether your email address has been confirmed | A new account confirms its address with a six-digit code before it can be signed into, so that an account can only be created by someone who reads mail at that address. Accounts that existed before we began asking are not asked. An account left unconfirmed is not deleted: it cannot be signed into, and you can confirm it at any time. |
| A device identifier | To credit referrals and to prevent abuse |
| Your subscription tier and search counts | To apply your weekly cap. We store a count of searches, never a monetary balance. |
| If you have a paid plan: when it expires; whether it came from the App Store or from a promotional code; for an App Store purchase, Apple’s original transaction ID and whether it was a real or a test (sandbox) purchase; and, for promotional codes, a one-way hash of each code you redeemed | To know your plan is still current, to tie one App Store subscription to one account, and to let each promotional code be used only once. |
| A record of each live search that counted against your weekly cap, and of each question you asked the assistant: a random identifier, whether it was a nearby search, an online search or an assistant question, and the week it counted in. No search text, no question text and no location. | So one search is counted once, and so your plan’s weekly limits apply. |
| Rate-limiting records: a count and the time it started, filed under a one-way hash of your email address, account, or IP address — never the address itself | To slow down password guessing, code flooding and spam. |
If you write a review, we store the review text, the star rating, the language, the title of the product the review is about (the product's own name — not anything you typed into search), and a hashed form of your IP address. The IP hash is used only to limit abuse and is never shown to anyone.
If you list a business or products as a merchant, we store what you entered. For the business: its name, category and type, address, coordinates, phone number, website, your notes, the services you offer, whether you sell wholesale, the seller type you chose, whether you offer products or services or both, how you sell (in person, online or both), a showcase link if you gave one, the service radius you cover, a luxury certification reference if you gave one, and your answer about paying a commission — if you were ever asked one. We do not ask today, and for a business listed before we began keeping this the field is empty: that means we never asked, which is not the same as a no, and we do not record it as one. For each product: its title, brand, model, barcode (GTIN), category, condition, description and image link, and for each version of it the SKU, attributes (such as size or colour), price and currency, any earlier price, unit, stock and quantity details.
Your business record is yours to see. No part of Vezvezak shows it to a buyer: no request returns a business row to anyone but the account that created it, and your data export contains it in full. Your products are different — they are published to buyers, and every one carries a label saying it was listed by the merchant and is unverified. We do not check them; the label says so.
If you send us feedback, we store what you wrote, which kind you chose (a suggestion, a bug, praise or other) and when. If you submit something for verification, we store which kind of verification it is, the company name if you gave one, whether you told us it is a company, whether you agreed to the product passport, and its status — which stays “pending”, because there is no review process and nothing you send is read.
Your email address is never shown to other users, to merchants, or in any public part of Vezvezak.
Your search text is not stored on our servers. It passes through them on its way to the services that find results for you — see section 4. The one exception is described in section 5: we keep the English search terms the model produced for a search for up to 30 days, filed under a one-way hash and linked to no one.
3. Location
We ask your device for an approximate location, not GPS-grade precision.
Before anything is sent, your phone rounds the coordinates to roughly 110 metres. Your exact position never leaves your device.
That approximate location is sent to Google Places to find nearby shops. It is also sent, on its own and with no search text, to work out which country you are in — that decides which country’s online market we search. It happens once each time you open the app: whichever search comes first sets it off, including an online-only one, and the answer — including “we couldn’t tell” — is reused for the rest of that session, so your location is not sent again to ask the same question. If we can’t tell which country you are in, we don’t search online stores for the rest of that session, and we don’t send your location again to try. See section 4. We do not store the location used for a search.
If you open the map screen, map tiles are loaded from the map provider on your device, centred on the same approximate location.
You can refuse location access. The app still works; it will not show nearby shops.
4. Who receives your data
These companies receive data when you use Vezvezak. Each has its own privacy policy.
| Company | What they receive | When |
|---|---|---|
| Cloudflare | All traffic to our servers — they are our infrastructure provider. They also run the open-source language model described in section 5. It receives the words of each search, the questions you ask the assistant together with a summary of the results on your screen, and — only if the content check is ever switched on — the review or listing text you submitted. | Always |
| Your search text and your approximate location — rounded to about 110 metres before it leaves your phone — to find shops near you. Map tiles when you open the map. No account identifier is sent. | When you search for shops near you, or open the map | |
| Your approximate location on its own, with no search text, so we can tell which country you are in. That decides which country's online market we search; if we can't tell, we don't search online stores. | Once each time you open the app — on your first search, including an online-only one, or when you price a basket or open a compatibility card. The answer — including “we couldn't tell” — is reused for the rest of that session. | |
| SerpApi | The English search terms described in section 5 — or, if those could not be produced for a search written in plain English letters, your search text as typed — plus the country we resolved for you and your app's language, so results come from your own market rather than a default one. No account identifier is sent. | Online search |
| Resend | Resend is the company that sends our email. They receive your email address and a six-digit code, so they can deliver a sign-in, password-reset or email-confirmation message to you. Nothing else — no name, no account identifier, no location, and nothing about what you searched for. Our messages contain no images and no links, so opening one loads nothing and tells nobody that you read it. | When you ask for a one-time code, a password reset, or to confirm your email address |
| Apple | The sound of what you say while voice search is listening, so Apple’s speech recognition can turn it into search text. Depending on your device and language, Apple may process it on your iPhone or on its servers. Vezvezak adds no account identifier to it. | Only after you tap the microphone to search by voice |
| Apple | The transaction ID of a purchase you make or restore, so the App Store can confirm it to us. | Only when you buy or restore a plan |
- Cloudflare — cloudflare.com/privacypolicy
- Google — policies.google.com/privacy
- SerpApi — serpapi.com/privacy-policy
- Resend — resend.com/legal/privacy-policy
- Apple — apple.com/legal/privacy
5. Artificial intelligence
We have built a content check that can use an open-source language model, running on Cloudflare's own infrastructure, to look at a merchant's listing title and description for prohibited goods. It is disabled by an explicit setting, so it does not run for any user today — no review or listing text is sent to any model. That setting, not your plan, is what holds this true: switching it on is a deliberate, recorded change, and no account becoming a paid one can turn it on by itself. Were it switched on, no name, email, phone number, or account identifier would be sent with the text, and Cloudflare states it does not use such content to train any AI model or to improve its services. We will update this page before it is ever switched on.
Understanding your search. Every search you type is sent to an open-source language model that Cloudflare runs on its own infrastructure, so it can work out which product you mean — in whatever language you wrote — and give us English search terms. We search with those terms. Brand names and model numbers must come back exactly as you typed them, or we do not use the answer. If the model cannot tell what product you mean and your search is not written in plain English letters, we do not search at all and tell you so, rather than show results for a guess. No name, email, phone number, account identifier or location is sent with the words, and Cloudflare states it does not use such content to train any AI model or to improve its services. We keep the English terms for up to 30 days, filed under a one-way hash of your words, so the same search is not sent to the model twice; they are not linked to you or to any account.
The assistant. If you have Pro or Max and ask the assistant about a set of results, we send your question and a summary of the results on your screen — product names, prices, sellers and the app’s own checks on them — to the same model. It answers only from that summary; when the answer is not there, it says it cannot answer. No name, email, phone number or location is sent to the model. Nothing from the conversation is stored on our servers — your chat history stays on your device (section 1). We record that a question was asked, to apply your plan’s weekly limit (section 2), and, to limit abuse, a rate-limiting record filed under a one-way hash of your IP address (section 12).
6. Analytics
We collect a small amount of anonymous usage data. There are six kinds of event:
- A search — which language and script it was in, how many results came back, and how many were uncertain
- A shown answer — which engine produced it and how confident it was
- An opened evidence chain — which engine produced the answer behind it
- An added price watch — which engine produced the answer it was set from
- A tapped link to a shop — which shop, and the price shown for that offer
- A referral to buy a product — a short code derived from the product's identity number (its model or SKU), never its name or your query
None of this is tied to you: no account, device, session, or IP is recorded with any event, and it is sent without signing in — there is no field that could link a row back to you. It never includes your search text or your coordinates. The table these events are written to has no column for a person: the list above is its whole shape.
Two things we should say plainly. The app also sends a seventh kind of event — that an action such as adding to your basket completed — and our server discards it: it is not among the events the server accepts, so nothing about it is stored. And because these rows contain nothing that identifies anyone, we do not delete them on a schedule; they are kept as a long-run measure of how often the app says “unsure”.
You can turn this off in the app. Nothing is collected then, and anything still waiting on your device is discarded.
We use no third-party analytics, advertising, attribution, or crash reporting services. No Google Analytics, no Facebook SDK, no ad networks. No crash reporting SDK is installed in the app.
7. Server logs
Our servers do not log the content of your requests. Request logging on our proxy is disabled, and we have automated tests that fail our build if anyone re-enables it.
Requests pass through Cloudflare, which may retain limited technical metadata for a short period as part of operating their network.
8. Payments
Vezvezak processes no payments. There is no checkout, no wallet, and no card handling anywhere in the app. If you buy something you found through Vezvezak, you buy it from that shop, on their site, under their terms.
Pro and Max cannot be bought in the app. They can be granted by a promotional code, at no charge. If paid plans are sold, the App Store bills them — not Vezvezak — and we never see your card details. Section 2 lists what we keep about a plan.
9. What we never do
- We never sell your personal data.
- We use no third-party ad network, and we never show advertising from one.
- We never personalise anything shown to you based on your behaviour. We do not build a profile of you.
- We never sell placement in search results. What ranks first ranks first because our system judged it best, not because anyone paid.
- We never share your data with advertisers or data brokers.
Affiliate links are switched off. No affiliate account is configured, so a shop link you tap is passed through unchanged and the app sends us nothing about it. Our server will not accept a purchase referral or a commission record either: the setting that would allow it is off, and those requests are refused before anything in them is read. That setting, not our app’s behaviour, is what holds this true. Turning it on is a deliberate, recorded change, and we will update this page before it happens.
10. Your rights
You can, at any time:
- See your data — request an export in Settings
- Correct it — edit your profile in Settings
- Delete it — delete your account in Settings (this needs a connection; see section 11)
- Refuse location — the app works without it
If you are in the EU, UK, or California, you have additional rights under GDPR, UK GDPR, and the CCPA — including the right to object, to restrict processing, and to complain to your data protection authority. We honour these rights for everyone, wherever you live.
To exercise any of these, email privacy@vezvezak.com. We respond within 30 days.
11. What deletion actually does
When you delete your account, we remove from our servers:
- Your account, email address, and password hash
- Every review you wrote
- Your business listing and every product you listed, if you are a merchant
- Anything you submitted for verification
- Any feedback you sent
- Your referral code and the invitations you sent
- Your subscription tier, its expiry and purchase record, the promotional codes you redeemed, your search counts, the record of which searches counted, and the record of the assistant questions you asked
- Rate-limiting records filed under a hash of your email address or account
On your device, everything is cleared.
Deleting your account needs a connection. If we can’t confirm the deletion with our servers, nothing is removed — not from our servers and not from your device — and the app tells you, so you can try again.
Four things are not removed, because none of them is connected to you:
- If someone invited you, the record of that invitation, which identifies a device by a hash and not your account.
- Anonymous usage statistics, which never contained any identifier.
- Rate-limiting records filed under a hashed IP address. They are gone within about a day anyway.
- English search terms the model produced for a search (section 5), which are stored with no link to anyone and are gone within 30 days.
One thing about timing: once our servers confirm the deletion, it takes effect immediately. But our infrastructure provider keeps automatic backups, so copies may remain in their recovery system for up to 30 days before they are gone for good.
12. How long we keep things
| What | How long |
|---|---|
| Account details | Until you delete your account |
| An account whose email address was never confirmed | Until you delete it — we do not remove it for you |
| Reviews and listings you wrote | Until you delete your account |
| Your plan and purchase record | Until you delete your account |
| The record of which searches counted | Until your weekly cap refills |
| English search terms produced for a search | Up to 30 days |
| Sign-in, email-confirmation and password-reset codes | 10 minutes |
| The internal token issued after a reset code is confirmed | 15 minutes |
| Rate-limiting records | Up to about a day |
| Anything on your device | Until you delete it or remove the app |
| Your business listing and its products | Until you delete your account |
| Feedback you sent us | Until you delete your account |
| Anything you submitted for verification | Until you delete your account |
| Anonymous usage events (section 6) | Kept — they contain nothing that identifies anyone |
| The location used for a search | We do not keep it |
13. Children
Vezvezak is not for children under 13, and we do not knowingly collect anything from them. If you believe a child has given us information, email privacy@vezvezak.com and we will delete it.
14. Security
- Passwords are hashed with PBKDF2-SHA256 at a 600,000-iteration work factor (six chained 100,000-iteration rounds), unique salt per account
- All traffic is encrypted in transit
- API keys are held server-side and never shipped in the app
- Our build fails automatically if a secret would be included
- The sign-in session is held in the iOS Keychain, marked so that it never leaves this device and never enters a backup or iCloud. If you turn on Face ID or Touch ID, it is additionally sealed to the faces and fingerprints enrolled at that moment, and iOS destroys it if that set changes
- You can set Vezvezak to lock itself whenever you leave the app. There is always a way in with your password; biometrics are never the only way
No system is perfectly secure.
15. International transfers
Vezvezak is operated from the United States. If you use it from elsewhere, the data described above is processed in the US and by our providers' global infrastructure.
16. Changes
If we change this policy we will update the date at the top. For anything material we will tell you in the app before the change takes effect.
17. Contact
Vezvezak LLC
San Jose, California, United States
privacy@vezvezak.com