The Core Privacy Commitments
Your conversations are not used to train public AI models
This is the single most important privacy commitment at Vikk AI. Your conversations, uploaded documents, and generated content are not used to train AI models available to other users or to third parties. This is architectural, not policy. It is not something that could change in a future terms-of-service update and retroactively apply to your past conversations.
Your data is not sold to third parties
Vikk AI does not sell user data, advertising data, or behavioral data. We do not have an advertising revenue model. Our revenue comes from subscriptions, which aligns our incentives with keeping your data private rather than monetizing it.
Third parties do not see your content
Business partners, payment processors, and service providers receive only the minimum information necessary to do their jobs. Your legal conversations are not part of any data shared with third parties.
You can delete anything, anytime
Any conversation, any uploaded document, any generated content can be permanently deleted from your account at any time, in the app. Deleted content is removed from live systems immediately and from backups within 30 days.
You can delete your entire account
Full account deletion is available in settings. After a 30-day grace period (during which you can reverse the deletion if you change your mind), all your content is permanently removed.
Security Controls in Technical Terms
Business and Enterprise Additional Features
SAML 2.0 SSO supported for enterprise identity providers: Okta, Azure AD (Microsoft Entra), Google Workspace, OneLogin, Ping, Duo, and others. SCIM provisioning for automated user management.
TOTP-based MFA available on all plans. Enterprise plans support hardware security keys (YubiKey, FIDO2) for admin accounts.
Full audit logs for Business and Enterprise plans, covering user logins, conversations started, documents uploaded, documents generated, and admin actions. Logs exportable for SIEM integration.
Enterprise plans can configure data retention policies: automatic deletion after 30, 90, 180 days, or custom. Useful for organizations with specific regulatory or policy retention requirements.
Enterprise plans can specify data residency in U.S., EU, or other specific regions depending on availability. Important for organizations subject to data localization requirements.
Healthcare customers can execute a Business Associate Agreement with Vikk AI to use the product for PHI-adjacent matters. Note that Vikk AI is not itself a covered entity; the BAA governs the service provider relationship.
Frequently Asked Questions
-
Are my uploaded contracts and documents really private?
Yes. Uploaded documents are encrypted in transit and at rest, stored in your private account, not shared with third parties, and not used to train public models. You can delete them at any time.
-
Is my conversation with Vikk AI protected by attorney-client privilege?
No. Conversations with an AI are not covered by attorney-client privilege under U.S. law, because Vikk AI is not a licensed attorney and no attorney-client relationship forms through an AI conversation. However, your conversations are strictly confidential by contract: encrypted end-to-end, never shared, never sold, and never used to train public AI models. When you later connect with a verified attorney through Vikk AI's one-tap handoff, your communications with that attorney are protected by privilege under the standard rules, independent of your prior AI conversation.
-
Can law enforcement access my data?
Like any U.S. company, Vikk AI must comply with valid legal process (subpoenas, search warrants, court orders). We publish a public transparency policy documenting how we respond to government and law enforcement data requests, and where legally permitted, we notify users before disclosing their content so they can object or seek to quash. We do not voluntarily disclose user data, and we do not cooperate with requests outside the bounds of lawful legal process.
-
Where is my data stored?
All Vikk AI user data is stored in SOC 2-compliant U.S. cloud infrastructure, encrypted at rest with AES-256 and in transit with TLS 1.3. Business and Enterprise customers with specific data-residency requirements can request dedicated regional storage. No user data is transferred outside the United States without explicit user consent (for example, for international travelers using the service abroad).
-
What happens if Vikk AI is subpoenaed?
Like any company, Vikk AI responds to lawful legal process. Where possible and permitted, we notify users before disclosing their content in response to a legal demand. We publish a transparency report documenting government data requests.
-
Does Vikk AI have a bug bounty program?
Yes. Security researchers are encouraged to responsibly disclose vulnerabilities via our security@vikk.ai contact. We provide bounties for qualifying disclosures.
-
Can Vikk AI see my password?
No. Passwords are hashed and salted using industry-standard algorithms. We cannot retrieve your password; we can only reset it. For maximum security, enable MFA.
-
Is Vikk AI GDPR-compliant?
Yes. EU users have full GDPR rights including access, portability, correction, and erasure, available in account settings. Business and Enterprise plans include Data Processing Agreements (DPAs) for organizational GDPR compliance.
-
What about CCPA and state privacy laws?
Vikk AI honors CCPA, CPRA, and equivalent rights for users in all U.S. states with privacy laws. Users can exercise rights (know, delete, correct, portability) in account settings.
Start using a legal AI built privacy-first. Free, encrypted, deletable on demand.
Are you a Lawyer? Connect with our Users!