What we collect, and what happens to it.
This notice covers vosky.ai — the marketing site, the assistant on it, the consult form, and the client portal behind sign-in. It is written to be read by a risk or vendor-management team, so it names the actual systems rather than describing them in general terms.
Last updated 2026-07-25
1. Who we are
Vosky AI is the AI division of Vosky Technologies, an IT, cloud and smart-home consultancy based in Colleyville, Texas. We are the controller of the data described below.
- Email — info@vosky.ai
- Phone — (214) 702-9523
- Post — 1501 Hall Johnson Rd #403, Colleyville, TX 76034
TODO: confirm The registered legal entity name and state of formation, and whether the mailing address above is also the address for legal notices.
2. What this notice does not cover
Client engagements are governed by the written agreement for that engagement, not by this page. Where we build a system inside your own cloud tenant — your Microsoft 365, your Azure subscription — the data in it stays in an environment you own and audit, and your agreement and any data-processing addendum control what we may do with it. This notice describes only what vosky.ai itself stores.
3. What we collect
Consult requests
The form on the home page collects your name, work email, business name, and the message you write. The server also records the IP address the request came from and the time it arrived. The record is written to our database before we attempt to email it, so a lead is never lost to a mail outage — which means a submitted enquiry is stored even if the notification email fails.
The form carries a hidden field no person can see or tab to. If it is filled in, the submission is treated as automated and discarded. We also decline more than five submissions from one IP address in a day.
Chat with the assistant
The assistant on the home page is a live demo of the kind of system we build. The messages you type are sent to Anthropic's API to generate a reply. They leave our platform to do that. Anthropic is named as a subprocessor in section 5.
We do not store the transcript. What we do store is a spend ledger: a row keyed by ip:<your address>:<date> holding the number of calls and the amount spent in micro-dollars, which is how the daily and monthly cost caps are enforced. Your conversation is not retained beyond that accounting.
Do not put confidential, customer or non-public personal information into the chat box. It is a demo on a public page. If you need to tell us something sensitive, email or call us.
Client portal accounts
For people we give access to the portal, we store:
- The account record — email address (lower-cased), name, role (admin, staff or client), the organisation the account belongs to, status, when it was created, and when it was last seen.
- Passkeys — the public key, algorithm, signature counter, the transports the authenticator reported, a label you choose, and when it was created and last used. Passkeys are public-key credentials; we never hold anything that could sign on your behalf.
- Sessions — one row per signed-in device, holding the session id, the time it was created and expires, when it was last seen, the browser user-agent string, the IP address, and how you proved who you were.
- Recovery codes — stored hashed, never in the clear.
- Invitations and sign-in links — the email address, intended role and organisation, and a hash of the token. The token itself is emailed and never stored.
Readiness Audit records
During a Readiness Audit we record what we learn about your institution: name, rough size, systems and core provider, where documents live, regulatory and data-residency constraints, the opportunities we identify, and our notes and verdict. These records are business information about the organisation. They are not intended to hold consumer records or non-public personal information, and we ask clients not to place any there.
Access log
Every read, write, deletion and failed lookup on a client-data path is written to an access log with the acting user, the action, the record touched, the IP address and the time. This exists so that the organisation-scoping can be proved to behave rather than asserted. Consult-form submissions are logged here too.
Cookies and third parties on the page
- One cookie.
vosky_auth, set only when you sign in. It isHttpOnly,Secure,SameSite=Lax, and carries a session identifier and a signature — nothing about you. It lasts 30 days for staff accounts and 14 for client accounts, and one day for a session opened with a recovery code. - No analytics, no advertising, no tracking pixels. There is no Google Analytics, no tag manager, no session-replay tool and no advertising script anywhere on this site. We checked before writing that sentence.
- Web fonts are loaded from Google Fonts (
fonts.googleapis.comandfonts.gstatic.com), which means Google receives your IP address and user-agent when a page loads. Nothing else is sent, and no cookie is set by that request.
4. Why we hold it
- To answer you. Consult requests exist so a person can reply.
- To run the portal. Accounts, passkeys and sessions are what make sign-in and per-device revocation possible.
- To deliver the engagement. Audit records are the working material of the deliverable you are paying for.
- To keep it secure and affordable. IP addresses, the access log and the spend ledger exist to stop abuse, prove who saw what, and keep a public AI endpoint from running up an unbounded bill.
We do not sell personal information, we do not share it for cross-context behavioural advertising, and we do not use it to train AI models.
5. Subprocessors
These are the third parties that process data on our behalf for vosky.ai itself. Per-engagement subprocessors are listed in the engagement agreement and can differ.
| Provider | What it does | What reaches it |
|---|---|---|
| Cloudflare | Hosting, edge compute (Workers), the database (D1), DNS and the TLS termination in front of the site | Everything. All site traffic, and every record described in section 3 |
| Anthropic | The large language model behind the assistant on the home page, and behind audit drafting in our internal workspace | The messages you type into the chat box and the conversation history within that session; and, for clients, the audit intake when a Vosky consultant asks the workspace to draft findings. Nothing from the leads table, and no account or credential data, is sent |
| Microsoft 365 / Graph | Transactional email sent from info@vosky.ai — lead notifications, your acknowledgement, invitations and sign-in links |
The contents of those messages, including your name, email address and the message you submitted. Sent mail is kept in the mailbox |
| Google Fonts | Serves the two typefaces the pages use | Your IP address and user-agent, from your browser directly. No data of ours is sent to Google |
To be plain about the ones that matter most in a review: chat messages leave our platform and are transmitted to Anthropic over TLS in order to be answered, and audit intake is transmitted to Anthropic when a Vosky consultant asks the workspace to draft findings during your assessment. The second happens only when a person initiates it, only for staff, and always produces a draft a human reviews before it is used. Anthropic's commercial terms state that API inputs and outputs are not used to train their models. If this is not acceptable under your vendor policy, tell us at engagement and we will run the assessment without it.
TODO: confirm Whether a zero-data-retention agreement is in place with Anthropic. Until it is confirmed in writing, this page must not claim that Anthropic retains nothing.
6. Where it is stored
Everything vosky.ai stores lives in Cloudflare D1, a database created in the WNAM region — western North America, United States. The application itself runs on Cloudflare Workers at the edge, so requests are served from whichever Cloudflare location is nearest to you, but the durable data stays in the region above.
Transactional email lives in the info@vosky.ai mailbox in our Microsoft 365 tenant.
TODO: confirm The Microsoft 365 tenant's data residency geography, so we can state where mailbox contents sit rather than implying it.
7. How long we keep it
| Record | Kept for |
|---|---|
| Consult requests | Until you ask us to delete them. They are not aged out automatically today TODO: confirm |
| Chat messages | Not retained by us. Only the per-IP daily and site-wide spend counters remain |
| Chat spend counters | One row per IP per day and per site per day and month; not deleted on a schedule today TODO: confirm |
| Audit records | For the life of the engagement and afterwards as our record of the work, until deletion is requested |
| Account records and passkeys | While the account is active, and until you ask us to remove it |
| Sessions | Expire after 30 days (staff) or 14 days (client); one day for a recovery-code session. Revoked immediately on request |
| Sign-in challenges | Five minutes, and deleted the moment they are used |
| Emailed sign-in links | Fifteen minutes, single use |
| Access log | Retained as the audit trail; no automatic purge today TODO: confirm |
8. Export, correction and deletion
Email info@vosky.ai from an address we can tie to the record, or call (214) 702-9523. Ask for an export, a correction, or deletion. We will respond within 30 days.
Two honest caveats. We may keep what we need to meet a legal or accounting obligation, and to defend a claim. And we cannot delete a copy that only exists inside your own systems — where a build runs in your tenant, deletion there is a change you or we make in your environment, coordinated in writing.
If you have a client account you can also do some of this yourself: the account page lists every device signed in as you and revokes any of them, and lets you remove an enrolled passkey.
TODO: lawyer Whether the Texas Data Privacy and Security Act applies to Vosky, or whether the small-business exemption does. If it applies, this section needs the statutory rights list and an appeals process.
9. Security
The controls behind the portal — passkey authentication, per-device revocable sessions, role and organisation scoping, and full access logging — are described in detail on the data and security overview, along with a plain list of the things we do not yet have.
10. Children
This is a business-to-business service. It is not directed at children and we do not knowingly collect information from anyone under 18.
11. Changes
When this notice changes we update the date at the top. If a change materially affects how we handle data belonging to an existing client, we will tell that client directly rather than relying on them to reread the page.
12. Contact
Questions about this notice, a due-diligence questionnaire you would like completed, or a request about your data:
- info@vosky.ai
- (214) 702-9523
- 1501 Hall Johnson Rd #403, Colleyville, TX 76034