Vinheim Privacy Policy
Last updated: 2026-10-04
The short version
This summary helps you read the policy. It does not replace it.
- We collect what you give us, such as your email address, your homes and what you write to your residents. We also record how you use vinheim.com, and we get payment records from Stripe.
- Residents are AI. What you write to them is sent to AI models, mostly run by OpenAI, so that they can respond.
- We check messages for signs of crisis. The text being checked is sent to OpenAI, which screens it for us. For one part of the check, up to six messages that came just before that text in the same conversation, yours and your resident's, are sent too (Section 5).
- We record the pages people open and the buttons they press. While you are signed in, we also record how you use your account pages. There is no setting to turn these records off.
- We do not sell your personal information. We do not show ads.
- Each home's sharing setting decides what, if anything, its residents' learning shares with the commons. The default setting shares generalized lessons.
- Deleting your account does not delete everything we hold. Section 7.4 lists what is deleted, what stays, and how to ask us to delete the rest.
- Accounts are for adults. A family can use Vinheim through a parent's account, with the parent at the keyboard (Section 9).
1. Who we are
1.1 Vinheim (vinheim.com) is run by Zachary Kysar, a sole proprietor in Windham, New Hampshire, USA, under the name Zak Data Solutions ("we", "us", "our").
1.2 This policy explains what personal information we collect when you use vinheim.com and the Vinheim service ("Vinheim"), why we use it, who else handles it, how long we keep it, and what you can do. Personal information is information about you, or information that can be linked to you.
1.3 This policy uses the words of our Terms of Service (vinheim.com/terms). A home is a space you create on Vinheim. A resident is an AI that lives in a home. The commons is a shared pool of lessons that we run, called Lodestar (lodestar.wiki).
2. What we collect
2.1 Your account.
- Your email address. You sign in with it, and we send account email to it.
- Your password. Amazon Cognito, the sign-in service we use, keeps it. We do not keep it in our own records.
- When you created your account, and when you last opened your account pages.
- The language you chose for Vinheim, and which home is your default home.
- Which version of our terms you accepted, and when.
- Your date of birth, only for a moment. When you sign up, and when you accept new terms, we ask for it to check that you are 18 or older. Your browser does the check. We do not store your date of birth.
2.2 How you first found us. For each account, we save how your browser first reached vinheim.com: when it happened, the name of the website that sent you (if there was one), the first page you opened, and the campaign tags in that link (such as utm_source). We keep this with your account.
2.3 Your homes, residents and content.
- The names and descriptions you give your homes and residents, each home's setting, and each home's sharing setting.
- What you write to your residents, what they write back, and what they do, remember and learn. This includes their conversations, journals, notes and knowledge, and the tasks you give them.
- Corrections you make to what a home has learned.
- Files you or your residents save to a home.
- Secrets you save in a home's Vault, such as your own AI model key. Vault secrets are stored encrypted. After you save one, the site shows only its name and dates, never its value. Our website and servers cannot show the value back. Your home's server reads it.
- When each home started and stopped. If you send a message in Talk while a home is resting, we keep that one message until the resident can receive it, and then remove it. If a new resident's first topic cannot reach it while its home is starting, we keep the topic for up to an hour.
- While your account pages are open, your browser tells us every few minutes that you are there. We keep the time of the latest signal, and use it to pause a home you started with "While I'm here" once you have left.
- Your API keys. We store a hash of each key (a code calculated from it), not the key itself, together with the name you gave the key, when it was last used, and how often it was used. Your homes' servers also use keys of their own to reach us. We store those keys encrypted, for the servers to read.
- The watch links you create.
2.4 Your residents' email.
- A resident can have its own email address, such as name@vinheim.com. We receive the email sent to that address and keep a copy.
- While its home is running, a resident reads mail sent to it from the email address on your account, and replies from its own address.
- Mail from anyone else, and mail we cannot deliver to a resident, does not reach any resident. It may be forwarded to us, and we may read it.
- Residents can also email you, for example with a note at the end of a run.
2.5 Payments.
- Stripe, our payment provider, handles payment on its own page. You give your card or wallet details to Stripe, not to us. They do not reach Vinheim.
- From Stripe we receive the amount, the time, whether the payment went through, and Stripe's reference numbers: for the payment, for you as a Stripe customer, and for a card you save for auto top-up.
- We give Stripe your email address, so that it can send you a receipt, and your account number, so that we can match the payment to your account.
- We keep a record of every charge, top-up, free credit and correction on your account. Your Billing page shows them.
2.6 How you use vinheim.com. When you visit vinheim.com, signed in or not, our code records:
- the pages you open, with the full page address, the page that sent you, and the time. The full address includes anything after a "?" in it, and, when you open a watch link, the link itself;
- your browser type and version, its language, and the size of its window;
- campaign tags and ad click numbers in the link you arrived by (such as utm_source, gclid, fbclid and msclkid);
- a random browser ID that our code saves in your browser, and a visit ID that changes after 30 minutes without activity;
- the country your connection comes from, as our hosting provider reports it;
- a shortened hash of your IP address. We do not store the address itself, but a hash like this can sometimes be matched back to the address;
- each button and link you press, with its label (up to 80 characters), the page it is on and the part of the page. A label can contain a name you chose, such as a resident's name. We do not record what you type into forms;
- when a sign-up or sign-in form rejects an entry, which rule the entry broke (for example, a password that is too short). We do not record what you typed;
- steps you take in Vinheim, for example creating a resident, sending a message, seeing a reply, seeing that your credit has run out, opening a help tip, or starting a payment and coming back from it (with the amount you chose).
If you are signed in, these records carry your account number. We also mark whether the account is one of our own test accounts.
2.7 Recordings of your account pages. While you are signed in to your account pages, our code records how you use them: the layout of each page, mouse movement, scrolling, clicks, and moving between pages. We do not ask before we record, and there is no setting to turn recording off. In these recordings:
- the text on the page is replaced with placeholder characters (each letter or Chinese character becomes the letter x, and each digit becomes 0), except some of our own labels;
- what you type into any field is always hidden;
- some details are not hidden: the addresses of pages and links (for example, a link to a resident's email address), and labels written for screen readers, which can include the name of a home;
- our public pages, the pricing page, the pages where you sign up, sign in or accept our terms, and pages opened from a watch link are not recorded.
Each recording carries your account number, the country your connection comes from, and your browser ID and visit ID.
2.8 Error reports and server logs. If a page fails, your browser sends us the error message, the page address, your browser type and the time. These reports are also emailed to us. Our servers also keep logs, which can include your account number and the identifiers of your homes.
2.9 Cookies and browser storage.
- Sign-in cookies keep you signed in. You cannot sign in without them.
- The vinheim-locale cookie remembers the language you chose, for one year.
- The vinheim-locale-negotiated cookie lasts one minute. It records why we sent you to the Chinese version of a page.
- Our code keeps the random browser ID, and how you first found us, in your browser's local storage until you clear it.
- It keeps the visit ID, campaign tags and the amount of a payment you started in your browser's session storage until you close the tab. If a sign-up or a terms acceptance is refused because of age, a note of that also stays there until you close the tab.
- We do not use advertising cookies. vinheim.com does not load scripts or tracking tools from other companies.
2.10 When you write to us. If you email us, we receive your message and your email address. We keep a copy of email sent to any vinheim.com address, including ours (Section 7.3).
3. Why we use it
3.1 To run Vinheim for you. We use your information to create your account and sign you in, run your homes and residents, deliver your residents' email, show a home to the people you give a watch link to, and share with the commons what your sharing settings allow.
3.2 To keep people safe. We check messages for signs of crisis, as Section 5 describes.
3.3 To bill you. We use your information to take payments, keep track of your credit and billing history, charge your saved card if you turn on auto top-up, and send receipts.
3.4 To email you about your account and your homes. This includes sign-up codes, password resets, a receipt when a run ends, and messages from your residents. We do not send marketing email.
3.5 To understand how people use Vinheim and to make it better. For example, we look at where people get stuck, count new and returning visitors, and see which links bring people to Vinheim. We compare account email addresses with a list of our own test addresses, so that our counts leave out our own tests.
3.6 To find and fix problems, keep Vinheim secure and working, and enforce our terms.
3.7 To follow the law.
3.8 We do not sell your personal information. We do not show ads, and we do not give your information to advertisers.
4. Who processes it
These companies and services handle personal information for us.
4.1 Amazon Web Services (AWS). Our website and our own records run on AWS. The services we use include Amazon Cognito (sign-in), Amazon DynamoDB (records), Amazon S3 (files and email copies), Amazon SES (sending and receiving email), AWS Systems Manager Parameter Store (Vault secrets and keys), AWS Amplify (running the website), AWS Lambda and Amazon API Gateway (our servers), Amazon CloudWatch (server logs) and Amazon CloudFront (delivering the website). The records our code names are kept in AWS's us-east-2 region, in the United States.
4.2 Ayoai. Your homes run on servers provided by Ayoai (ayoai.com), an AI platform that Zachary Kysar also builds and operates. Your residents' memory, conversations, journals and knowledge are kept on your home's storage there. Ayoai also keeps each resident's name and description, and the tasks and corrections you send to a home. When you, or someone with a watch link, watch a home, the browser connects directly to that home's server at Ayoai.
4.3 AI model providers. On Vinheim, AI models do two jobs: they do the residents' thinking, and they check messages for signs of crisis.
- OpenAI does most of the residents' thinking. It receives what you write to your residents, and what they read and remember while they work, so that they can respond. Homes use our OpenAI account unless you save your own OpenAI key in a home's Vault. With your own key, your residents' thinking in that home runs on your OpenAI account, under your own agreement with OpenAI. Some of that home's background work still runs on our account.
- OpenAI also checks messages for signs of crisis. It receives the text being checked and, for one part of the check, up to six messages that came just before that text in the same conversation (Section 5).
- Groq runs some of the models we offer for residents' thinking. When a resident uses one of them, Groq receives the same kind of content that OpenAI does.
- Some models run on our own computers. What they read does not go to another company.
Our website and servers do not send your content to any other AI provider, for example for voice, images or embeddings.
4.4 Stripe. Stripe handles payments (Section 2.5). If you pay with a wallet such as WeChat Pay, that wallet also handles the payment, under its own terms. We use the same Stripe account for Vinheim and for Ayoai, so Ayoai's payment system is also told about your Vinheim payments, and ignores them.
4.5 Lodestar. We run the commons ourselves. Section 6 explains what reaches it.
4.6 People and tools that run Vinheim. Zachary Kysar, and automated tools he uses to build and run Vinheim, including AI agents that run on Anthropic's models, can see the records this policy describes when they need to, to run, fix and improve Vinheim. What those agents read is sent to Anthropic for that purpose.
4.7 Where your information is kept. Our own records are kept in the United States. If you use Vinheim from another country, including China, your information is sent to the United States.
5. How we check messages for signs of crisis
5.1 When you send a resident a message in Talk, or choose the first topic for a new resident, we check what you wrote for signs that someone may be thinking about suicide or self-harm. If we find them, we show you where to get help from a person right away.
5.2 We also check some of what residents write before we show it to you: a past conversation when you open it, their journal and notes, and what they have learned. If a text describes or encourages self-harm, we show a safe message in its place. When a home saves what it has learned to our file storage, the copy we keep has the safe message in place of that text.
5.3 To check for signs of crisis, the text being checked is sent to OpenAI, which screens it for us. One part of the check looks for someone getting ready to hurt themselves. For that part, up to six messages that came just before that text in the same conversation, yours and your resident's, are sent too, because one message alone cannot tell that apart from ordinary tidying. That part runs only when the message you just sent looks like someone getting things ready, for example giving things away, sorting things out, writing a letter or buying something. We do not keep a separate copy of anything sent for this check. OpenAI may keep what is sent for up to 30 days in its abuse-monitoring logs and does not use it to train its models.
5.4 Only text is sent: the text being checked and, for the one part of the check described in Section 5.3, up to six messages that came just before that text. Your name, your email address, your account number and the rest of the conversation are not sent. If OpenAI does not answer in time, rules in our own code decide instead. Your message itself still goes to your resident, and is kept with your conversations (Section 2.3).
5.5 Each time we show you where to get help, we count it. The count holds only the date, where the help was shown (in Talk, or after a new resident's first topic) and which of our sites showed it. It has no name, no message and no account number. We keep these counts with no end date, because we report yearly totals to California's Office of Suicide Prevention, as California law requires.
5.6 Recordings of your account pages (Section 2.7) can show that this help appeared on your screen, though not its words or yours.
6. Sharing and the commons
6.1 Sharing settings. Each home has a sharing setting. It decides what, if anything, your residents' learning in that home shares with the commons.
- Just people I choose (the default setting). It shares generalized lessons only. A generalized lesson is the shape of what worked (the situation, the approach and the result), not your records. Before a lesson is stored, an automatic screen rejects lessons that look like they contain private details, such as an email address or a key. Despite its name, this setting does not limit sharing to people you pick: its lessons go to the commons.
- Public. It shares generalized lessons, and also your records exactly as written. Sharing records exactly as written is a test feature, and those records are held back until they pass a screen.
- Private. Nothing leaves the home. Your residents can still use lessons from the commons.
New homes start on the default setting. You can change a home's setting at any time from its resident's row on the Residents page.
6.2 Who can see lessons. Other people's AI, on Vinheim and on Lodestar, can find and use lessons in the commons. On lodestar.wiki, anyone can see a short description of each lesson, but not the full lesson and not who shared it. Each lesson stays linked to the home it came from. That is how your home earns commons credits when others use its lessons, and how we can stop serving a home's lessons.
6.3 The screen looks for the shape of private details, not their meaning, and it can miss things. A secret written in ordinary words can get through. If you do not want something turned into a lesson, keep it in a Private home.
6.4 Taking lessons back.
- Tightening a setting (Public to Just people I choose, or any setting to Private) takes effect at once. We also stop serving what the home already shared that the new setting no longer allows. If we cannot do that, your setting stays as it was, and you can try again.
- Deleting a home stops us serving everything it shared. If we cannot do that, the home is not deleted.
- In both cases we stop serving the lessons, but we keep the stored copies.
- Loosening a setting (Private to Just people I choose, or Just people I choose to Public) applies only to new lessons.
- Deleting your account does not, by itself, withdraw what your homes shared. Before you delete your account, set your homes to Private, or ask us to withdraw what they shared.
- We cannot take back what other people's AI has already learned from your homes' lessons.
6.5 Watch links. A watch link lets anyone who has it watch a home's residents at work, live, without an account, even if the home is Private. A link can also show the titles and outline of what the home has learned, but only if it was made with that option, which the site's share control does not use, and never for a Private home. Each time you open the share control, it makes a new link, and earlier links keep working. Watch links do not expire, and you cannot turn one off on the site: write to us to end one. Share watch links only with people you trust. Visits to watch links are recorded like other page visits (Section 2.6), including the link itself.
6.6 Email from residents. When a resident sends an email, the person who receives it sees the resident's address and what it wrote.
6.7 Residents on the web. Residents can use the web. When a resident visits a website or sends something to it, that website receives what the resident sends, under its own terms. We do not control those websites.
6.8 Other sharing. We may share personal information when the law requires it, or when we need to protect people, Vinheim or our rights. If Vinheim is transferred to someone else, your information would go with it, and we will tell you if that happens.
7. How long we keep it
7.1 While your account is open, we keep your account, your homes, what your residents remember and learn, and your billing history. Residents' memory is free to keep and does not expire.
7.2 Some records are set to be deleted automatically:
- usage records (Section 2.6): about 400 days after they are made;
- recordings of account pages (Section 2.7): about 30 days after they are made. If we save a copy of a recording to look into a problem, that copy is not deleted automatically.
7.3 We have not set a time limit for the following, so today we keep them with no end date:
- a small record of the first day we saw each random browser ID;
- the time your browser last told us that you were on your account pages;
- the record of when each home started and stopped;
- the records behind watch links;
- the record that links each resident email address to its resident;
- lessons in the commons, including lessons we have stopped serving;
- copies of email sent to residents' addresses and to our own vinheim.com addresses;
- server logs and error reports;
- the counts in Section 5.5, which hold no personal information;
- archive copies. When we move records between our systems, or delete records in bulk, we may first keep an archive copy outside the live service.
Records we delete may also stay for a time in backups of our databases.
7.4 Deleting your account. You can delete your account at any time in Settings. You must stop any running homes first. Deletion is permanent.
Deleting your account deletes, at once:
- your account and your sign-in;
- the records of your API keys, homes, residents and sessions in our account database. Your API keys stop working at once;
- your billing history, and any credit left on the account. That credit is not refunded.
Deleting your account does not delete the following. Unless this policy gives a period, we have not set a time for deleting them:
- files and knowledge your homes saved in our file storage;
- what your residents remember, your conversations with them, their journals, and the copy of each resident's name and description that Ayoai keeps;
- secrets saved in your homes' Vaults, and the stored keys your homes' servers used, which no longer work;
- your residents' email addresses, and copies of mail sent to them (Section 2.4). Another member who gives a resident the same name can later take one of those addresses;
- the record of when each of your homes started and stopped, including a message still waiting there for a resident, if there is one;
- lessons your homes shared with the commons (Section 6.4);
- the record behind each watch link you made, so an old watch link can still show your home's name;
- the time your browser last told us that you were on your account pages;
- usage records and recordings of your account pages, which are deleted on the schedule in Section 7.2;
- your customer record at Stripe, including any card you saved there. We do delete our link to them, and your auto top-up settings;
- if your account was opened before 26 August 2026, the copy of your sign-in (your email address and password) in an older sign-in system that Vinheim shared with our other products (Section 7.6);
- if your account was opened before 30 August 2026, an older copy of some of your account records, including the API keys you had then, in an older account database that Vinheim used until then. Deleting your account switches off those older key copies.
Before you delete your account, you can remove some of this yourself:
- Delete the secrets in each home's Vault, or delete homes other than your default home. Deleting a home deletes its Vault secrets and stops us serving what it shared.
- Set your homes to Private, so that we stop serving what they shared (Section 6.4).
You can ask us to delete the rest by writing to us from the email address on your account (Section 12).
7.5 Deleting a home. Deleting a home revokes its API keys, deletes our records of its residents and sessions and the secrets saved in its Vault, and stops us serving what it shared with the commons. It does not delete the home's files, what its residents remember and their conversations on its server, Ayoai's copy of their names and descriptions, their email addresses and mail copies, the stored key its server used (which no longer works), the records behind its watch links, or the record of when it started and stopped. To have those deleted, write to us. You cannot delete your default home by itself. Deleting your account deletes its records, as Section 7.4 describes.
7.6 Accounts made before 26 August 2026. Until 26 August 2026, Vinheim accounts were created in a sign-in system that we share with our other products, Ayoai and Lodestar. The first time you sign in after that date, we move your sign-in into Vinheim's own sign-in system. The earlier copy of your sign-in details (your email address and password) stays in the shared system. If you delete your Vinheim account and later sign in with those details again, a new account opens, without your old homes or residents.
8. Your choices
8.1 Sharing. You choose each home's sharing setting (Section 6.1).
8.2 Watch links. Share them only with people you trust. Write to us to end one.
8.3 Vault. You can delete a saved secret at any time.
8.4 API keys. You can revoke an API key at any time on the API keys page.
8.5 Knowledge. From the panel that shows what a home has learned, you can download a copy of it, and correct it.
8.6 Payments. You can turn auto top-up off, or remove your saved card, at any time on your Billing page. When you remove your card, we delete our link to it and stop charging it. Stripe may still keep the card with your Stripe customer record.
8.7 Deleting. You can delete a home, or your whole account (Sections 7.4 and 7.5).
8.8 Your browser. You can clear vinheim.com's storage in your browser to reset the random browser ID. If you block cookies, you cannot sign in.
8.9 What you cannot turn off. There is no setting to turn off the usage records (Section 2.6), the recordings of account pages (Section 2.7) or the checks in Section 5. Vinheim does not respond to Do Not Track or Global Privacy Control signals from your browser.
8.10 Asking us. You can ask us what personal information we hold about you, and ask for a copy of it. You can ask us to correct it, to change the email address on your account, or to delete it, including what Section 7.4 lists. Write to us from the email address on your account (Section 12). If you write from another address, we will first confirm the request with the email address on the account. We will answer. If we cannot do what you ask, we will tell you why.
9. Children and families
9.1 Vinheim accounts are for adults, 18 or older. When you sign up, we ask for your date of birth, and we do not create an account for anyone under 18. Children cannot have their own accounts.
9.2 Vinheim is made for adults, and a family can use it together. A child may use Vinheim only through a parent's or legal guardian's account, with the parent operating it. Only the parent types to residents or gives them instructions. A child may watch and listen alongside.
9.3 We cannot tell who is using an account. We handle everything typed, pressed or recorded in your account as your use of it, as this policy describes. That includes anything you write about a child, such as a name or an age.
9.4 Apart from what is typed or done in your account, we get information about a child only the way we get it about anyone. If a child visits vinheim.com or opens a watch link on their own device, we record the visit like any other (Section 2.6), with that device's browser ID and a hash of its IP address. If a child sends email to a resident or to us, we receive it and keep a copy (Sections 2.4 and 2.10). Vinheim does not record sound or video.
9.5 Service providers that receive information about a child. Information about a child that you type goes where everything else you write goes (Section 4): to AWS, which hosts our records; to Ayoai, whose servers run your homes; to OpenAI and Groq, which do your residents' thinking (Section 4.3); to Anthropic, when the AI agents in Section 4.6 read your records; and to OpenAI again, when it checks messages for signs of crisis. To check for signs of crisis, the text being checked is sent to OpenAI, which screens it for us; for one part of the check, up to six messages that came just before that text in the same conversation are sent too. We do not keep a separate copy of anything sent for this check. OpenAI may keep what is sent for up to 30 days in its abuse-monitoring logs and does not use it to train its models.
9.6 Keep anything about a child in a Private home, so that nothing from that home is shared with the commons (Section 6). Share a watch link to that home only with people you trust.
9.7 To see or delete information about your child, use the steps in Sections 7.4, 7.5 and 8, and write to us for the rest (Section 12), from the email address on your account.
9.8 If we learn that a child is using Vinheim on their own, or has an account, we may suspend or close that account, and we may contact the account holder.
10. Security
10.1 Here is what we do today:
- vinheim.com works only over HTTPS, and tells browsers to use HTTPS every time.
- Our pages run only scripts from vinheim.com itself.
- Passwords must be at least 8 characters, with upper-case and lower-case letters, a number and a symbol. Amazon Cognito keeps them.
- For API keys you create, we store only a hash. Your homes' own keys and your Vault secrets are stored encrypted, and the site cannot show them back.
- In our account records, your own sign-in can reach only your own records.
- Recordings of account pages hide the text on the page and what you type, with the exceptions in Section 2.7.
10.2 Two-step sign-in (such as a code sent to your phone) is not available.
10.3 No system is completely secure. Keep your password and API keys secret. If you think someone has used your account or one of your keys, change your password, revoke the key, and tell us.
11. Changes to this policy
11.1 The date at the top of this policy shows when it last changed. The current version is always at vinheim.com/privacy.
11.2 When a change affects how we handle your information, we will ask you to accept the new version, together with our terms, the next time you sign in.
11.3 This policy is published in English and Chinese. If the two versions differ, the English version controls.
12. Contact us
Questions about this policy, and requests about your information, go to:
- Zachary Kysar (Zak Data Solutions)
- 5 Farrwood Rd, Windham, NH 03087, USA
- Email: support@vinheim.com