Skip to content
Vikk Site - Product - Privacy

Secure and Private:Encryption, No Training on User Data, Deletion on Demand


Legal conversations are among the most sensitive content a person or business shares with any software. You are describing disputes, documenting grievances, uploading contracts that may contain confidential information, drafting responses to adversaries. The security and privacy guarantees a legal AI provides are not marketing copy; they are the reason you can use the product at all. This page lays out exactly how Vikk AI handles security and privacy, with enough technical specificity that you can evaluate the commitments rather than trust them on faith.

The Core Privacy Commitments

Your conversations are not used to train public AI models

This is the single most important privacy commitment at Vikk AI. Your conversations, uploaded documents, and generated content are not used to train AI models available to other users or to third parties. This is architectural, not policy. It is not something that could change in a future terms-of-service update and retroactively apply to your past conversations.

Your data is not sold to third parties

Vikk AI does not sell user data, advertising data, or behavioral data. We do not have an advertising revenue model. Our revenue comes from subscriptions, which aligns our incentives with keeping your data private rather than monetizing it.

Third parties do not see your content

Business partners, payment processors, and service providers receive only the minimum information necessary to do their jobs. Your legal conversations are not part of any data shared with third parties.

You can delete anything, anytime

Any conversation, any uploaded document, any generated content can be permanently deleted from your account at any time, in the app. Deleted content is removed from live systems immediately and from backups within 30 days.

You can delete your entire account

Full account deletion is available in settings. After a 30-day grace period (during which you can reverse the deletion if you change your mind), all your content is permanently removed.

Security Controls in Technical Terms

Encryption in transit

All connections to Vikk AI use TLS 1.3, the current industry-standard encryption protocol. Your messages, uploaded documents, and generated content are encrypted the moment they leave your device and remain encrypted until they reach Vikk AI's servers.


Encryption at rest

Data stored in Vikk AI's infrastructure is encrypted using AES-256, the same encryption standard used by U.S. government classified systems. Encryption keys are managed through a hardware security module with access controlled by a minimum-necessary principle.


Network security

Vikk AI's infrastructure runs in hardened cloud environments with private networks, intrusion detection, DDoS protection, and continuous monitoring for unusual traffic patterns.


Access controls

Vikk AI employees do not have routine access to user conversations. Access to production systems is restricted by role, requires multi-factor authentication, and is audit-logged. Incident response procedures prohibit engineers from accessing user content except under specific documented circumstances (such as a user-reported bug where the user has explicitly consented to content review).


Compliance posture

Business Premium and Enterprise plans include SOC 2 Type II posture, with controls independently audited by a Big Four firm. HIPAA compliance features are available for healthcare customers via BAA. Compliance with GDPR, CCPA, and state privacy laws is designed into the product architecturally.

Business and Enterprise Additional Features

Single Sign-On (SSO)

SAML 2.0 SSO supported for enterprise identity providers: Okta, Azure AD (Microsoft Entra), Google Workspace, OneLogin, Ping, Duo, and others. SCIM provisioning for automated user management.

Multi-factor authentication

TOTP-based MFA available on all plans. Enterprise plans support hardware security keys (YubiKey, FIDO2) for admin accounts.

Audit logging

Full audit logs for Business and Enterprise plans, covering user logins, conversations started, documents uploaded, documents generated, and admin actions. Logs exportable for SIEM integration.

Custom data retention

Enterprise plans can configure data retention policies: automatic deletion after 30, 90, 180 days, or custom. Useful for organizations with specific regulatory or policy retention requirements.

Data residency

Enterprise plans can specify data residency in U.S., EU, or other specific regions depending on availability. Important for organizations subject to data localization requirements.

BAA for HIPAA

Healthcare customers can execute a Business Associate Agreement with Vikk AI to use the product for PHI-adjacent matters. Note that Vikk AI is not itself a covered entity; the BAA governs the service provider relationship.

What We Do Not Do

To be clear about the specific things we do not do with your data:

We do not sell your conversations, your documents, or any derivative data
We do not use your conversations to train AI models available to others
We do not serve you advertising based on your legal conversations
We do not share your content with AI model vendors for training purposes
We do not retain data after you delete it (beyond the 30-day backup window for disaster recovery)
We do not use your data to build profiles for resale or analysis outside Vikk AI's own product

A Note on Honesty About Limits

No security or privacy system is perfect. Vikk AI is not unhackable; no cloud service is. What we can commit to is (1) industry-standard security practices, independently audited, (2) architectural privacy commitments that cannot be unilaterally changed, (3) user control over data deletion, and (4) transparency about incidents if they ever occur. That is the practical guarantee. Anyone claiming more than that is marketing.

Frequently Asked Questions

  • Are my uploaded contracts and documents really private?

    Yes. Uploaded documents are encrypted in transit and at rest, stored in your private account, not shared with third parties, and not used to train public models. You can delete them at any time.

  • Is my conversation with Vikk AI protected by attorney-client privilege?

    No. Conversations with an AI are not covered by attorney-client privilege under U.S. law, because Vikk AI is not a licensed attorney and no attorney-client relationship forms through an AI conversation. However, your conversations are strictly confidential by contract: encrypted end-to-end, never shared, never sold, and never used to train public AI models. When you later connect with a verified attorney through Vikk AI's one-tap handoff, your communications with that attorney are protected by privilege under the standard rules, independent of your prior AI conversation.

  • Can law enforcement access my data?

    Like any U.S. company, Vikk AI must comply with valid legal process (subpoenas, search warrants, court orders). We publish a public transparency policy documenting how we respond to government and law enforcement data requests, and where legally permitted, we notify users before disclosing their content so they can object or seek to quash. We do not voluntarily disclose user data, and we do not cooperate with requests outside the bounds of lawful legal process.

  • Where is my data stored?

    All Vikk AI user data is stored in SOC 2-compliant U.S. cloud infrastructure, encrypted at rest with AES-256 and in transit with TLS 1.3. Business and Enterprise customers with specific data-residency requirements can request dedicated regional storage. No user data is transferred outside the United States without explicit user consent (for example, for international travelers using the service abroad).

  • What happens if Vikk AI is subpoenaed?

    Like any company, Vikk AI responds to lawful legal process. Where possible and permitted, we notify users before disclosing their content in response to a legal demand. We publish a transparency report documenting government data requests.

  • Does Vikk AI have a bug bounty program?

    Yes. Security researchers are encouraged to responsibly disclose vulnerabilities via our security@vikk.ai contact. We provide bounties for qualifying disclosures.

  • Can Vikk AI see my password?

    No. Passwords are hashed and salted using industry-standard algorithms. We cannot retrieve your password; we can only reset it. For maximum security, enable MFA.

  • Is Vikk AI GDPR-compliant?

    Yes. EU users have full GDPR rights including access, portability, correction, and erasure, available in account settings. Business and Enterprise plans include Data Processing Agreements (DPAs) for organizational GDPR compliance.

  • What about CCPA and state privacy laws?

    Vikk AI honors CCPA, CPRA, and equivalent rights for users in all U.S. states with privacy laws. Users can exercise rights (know, delete, correct, portability) in account settings.

Start using a legal AI built privacy-first. Free, encrypted, deletable on demand.

2026 © Vikk Ai

WEBSITE & SEO by NATIVERANK