VEGA Style

Privacy policy

VEGA Style for macOS and Windows. Last updated 7 October 2026.

VEGA Style rewrites an AI-written draft to sound like you. It can also write from key points you give it, in your own style. Training on your writing, rewriting the text, and writing from key points all happen on the equipment of our contractor, RunPod, Inc., in the United States. Only during training and retraining, we also send a selection of the text you give us to a second contractor, Anthropic, PBC. Anthropic, PBC is a company in the United States, and it processes that text in the United States. Nothing is sent to Anthropic, PBC when you rewrite a draft or write from key points. Your account information is kept by a third contractor, Cloudflare, Inc. Section 4, Where processing happens, and sharing, covers what we send to contractors in other countries. How long we keep what you give us, and how to have it deleted, are covered in section 5, Keeping and deleting.

1. Scope

This policy covers VEGA Style, a service from VEGA Works that combines an app for macOS and Windows with the equipment of our contractors. VEGA Works is the data controller. Contact details are at the end.

2. What we collect

InformationSourceWhere it is kept
Text you write during onboardingWhat you typeOur contractor's equipment (RunPod, Inc.), encrypted. A backup of it, still encrypted, is also kept in Cloudflare, Inc.'s storage service (R2). A temporary copy is also kept with Cloudflare, Inc. until training finishes.
Existing text you hand over to usWhat you give usOnly the parts used for training are kept on our contractor's equipment (RunPod, Inc.), encrypted. A backup of them, still encrypted, is also kept in Cloudflare, Inc.'s storage service (R2). Until training finishes, a temporary copy of everything you handed over is also kept with Cloudflare, Inc.
Trained voice (“coefficients”): numbers that describe how you write, used to rewrite drafts and write from key points in your styleCreated by us from your writing during trainingOur contractor's equipment (Cloudflare, Inc.)
Personal model (built from your writing, so it can reflect your phrasing; used to rewrite drafts and write from key points in your style)Created by us during training, only when you hand over enough writingOur contractor's equipment (RunPod, Inc.), encrypted. Decrypted there only while it is in use. A backup of it, still encrypted, is also kept in Cloudflare, Inc.'s storage service (R2).
Fingerprint of the training text (a code made from short fragments that cannot be turned back into the original text; used only to check that a rewrite or text written from key points does not copy the training text word for word)Created by us from your writing during trainingIt is kept in the same place as your personal model: encrypted, on our contractor's equipment (RunPod, Inc.). A backup of it, still encrypted, is also kept in Cloudflare, Inc.'s storage service (R2). How long it is kept is covered in section 5, Keeping and deleting.
The draft you send us to be rewritten, the key points you send us to write from, and their resultsWhat you type (the result comes from our processing)Not kept on our equipment. Not written to storage at our contractor, RunPod, either. The request record in its job system does keep what you send (the draft or key points) for at most 70 minutes after the request. Under its own specification, the rewritten result and the result of writing from key points disappear within 30 minutes of processing finishing.
Settings, such as the kind of writing and your finished-candidate choiceWhat you chooseOur contractor's equipment (Cloudflare, Inc.)
Your email addressWhat you typeOur contractor's equipment (Cloudflare, Inc.)
Your sign-in records (date and time, plus your browser or device type)Recorded automaticallyOur contractor's equipment (Cloudflare, Inc.)
The verification codeIssued by usOur contractor's equipment (Cloudflare, Inc.)
Connection information (such as your IP address)Recorded automaticallyOur contractor's equipment (Cloudflare, Inc.)
Your subscription details and status (plan, renewal date, and similar)Notice from our payment providerOur contractor's equipment (Cloudflare, Inc.)
Key points (a short statement of what each selected fragment of your text says; used only during training, to learn how you write)Written by the AI service of our contractor, Anthropic, PBC, from fragments of your text that we select, during training and retrainingNot kept by us. They exist only inside the training job and are thrown away when it ends. How Anthropic, PBC handles them is described in section 4.
Your usage records (rewrite count and length, count and length of writing from key points, and your training runs)Recorded automaticallyOur contractor's equipment (Cloudflare, Inc.)
Your payment detailsWhat you enter with a payment providerKept only by the payment provider — we never keep it

We also use your email address to send the verification code.

For emails among the writing you hand over, the app removes quoted text, forwarded content, and signatures before sending. It also replaces email addresses, phone numbers, URLs, and postal codes with placeholders before sending. For the writing you hand over, the app also replaces the addressee names, personal names, and company names that the app finds with placeholders before sending. Names cannot be reliably detected by the app, so they may remain. For the writing you hand over, before sending, you can check on the app's screen what has been replaced with placeholders, and add remaining words yourself so that they are replaced too.

File names, sender addresses, and dates are not sent. Greetings and sign-offs are kept.

We collect nothing beyond what is listed above.

3. Why

The information we collect is used only to:

  • learn your writing and build a voice or a personal model from it
  • have an AI service write short “key points” from selected fragments of your text, and use them to learn how you write
  • rewrite the draft you give us or write from the key points you give us, using that voice or personal model
  • check how close the rewrite or the text written from key points is to your voice, so we can confirm the quality
  • check that a rewrite or text written from key points does not copy your training text verbatim
  • reach you and identify your account
  • confirm your sign-in and help prevent abuse
  • check your subscription status and provide the service
  • check that the combined number of characters in the rewrites we write for you and the text we write from key points each month stays within your subscription's range

None of it is used for advertising. We never sell your writing or your information. We share it only with our payment providers and the contractors named in section 4, Where processing happens, and sharing.

4. Where processing happens, and sharing

Training on your writing, rewriting the text, and writing from key points all happen on the equipment of our contractor, RunPod, Inc., in the United States. None of it is ever processed only on your own device. Only during training and retraining, we also send a selection of the text you give us to a second contractor, Anthropic, PBC, in the United States. Nothing is sent to Anthropic, PBC when you rewrite a draft or write from key points.

Traffic to our contractor (RunPod, Inc.) is encrypted. The draft you send us to be rewritten, the key points you send us to write from, and their results are not saved in the storage of our contractor (RunPod, Inc.). The request record in RunPod, Inc.'s job system does keep what you send (the draft or key points) for at most 70 minutes after the request. We set that 70-minute limit ourselves, as the total of 30 minutes waiting in the queue, 10 minutes of processing, and 30 minutes for the result to stay. Under RunPod, Inc.'s own specification, the rewritten result and the result of writing from key points disappear within 30 minutes of processing finishing. Our contract with them says they may use it only for our purposes, never their own.

Unlike the draft you send us to be rewritten and the key points you send us to write from, text you write during onboarding and existing text you hand over to us is stored on our contractor's equipment, RunPod, Inc. We store it encrypted, and it is decrypted on that equipment only while being used for training or retraining.

When you give us enough text, the personal model we build from it, and a fingerprint of the text used to train it — short fragments converted into a form that cannot be turned back into the original text — are also stored, encrypted, on the same contractor's equipment. They too are decrypted there only while being processed.

Because your personal model is trained on your text, it can reflect wording and expressions from that text. We treat it with the same care as the text itself.

We use the fingerprint only to check that a rewrite or text written from key points does not copy your training text verbatim.

Only during training and retraining, we send selected fragments of your text over HTTPS (encrypted) to the AI service of our contractor, Anthropic, PBC. Anthropic, PBC is a company in the United States, and it processes the fragments in the United States. We fix the processing location with a setting, check that it was followed, and stop using the service if it was not.

For each fragment we send, the AI service writes a short statement of what it says, which we call a “key point.” We use the key points only while training. They exist only inside the training job and are thrown away when it ends, so we do not keep them.

We send only the fragments we select, each about 100 to 400 characters long. If you wrote text during onboarding, that is about 12 to 20 fragments; if you handed over existing writing, it is at most about 30. When we retrain, we select fragments again from your stored text and send them again.

Before the text leaves your device, the app replaces email addresses, phone numbers, URLs, and postal codes with placeholders. For the writing you hand over, before the text leaves your device, the app also replaces the addressee names, personal names, and company names that the app finds with placeholders. Names may remain in a fragment, because the app cannot reliably detect them.

Apart from what appears inside the fragments themselves, we do not send your name, email address, account ID, or anything else that identifies you. We also do not send the parts of your text we did not select, the drafts you send us to be rewritten, the key points you send us to write from, the rewritten results, or the results of writing from key points.

Anthropic's published rules say that it automatically deletes inputs and outputs from its systems within 30 days of receiving or generating them. They also say it may keep them longer to enforce its Usage Policy or to comply with the law. Content flagged by its safety systems may be kept for up to 2 years.

We do not use any Anthropic service that keeps data longer. We cannot delete what we have sent: it is deleted on Anthropic's schedule, described above. Asking us to delete your data does not shorten that schedule.

Anthropic's Commercial Terms of Service say that Anthropic may not train its AI models on content that its business customers, such as us, send to its services. Anthropic also says that the only exceptions are when a customer explicitly sends feedback or gives permission. We send no feedback and give no permission.

Anthropic's data processing addendum (DPA) is part of its commercial terms, and it lets Anthropic, PBC use subprocessors, which are other companies that help it process data. Subprocessors may handle what we send. Anthropic publishes the list at https://trust.anthropic.com/subprocessors, and it includes companies outside the United States.

What we say here about where Anthropic processes data, how long it keeps it, whether it trains on it, and its subprocessors comes from Anthropic's own published rules. We read them on 1 October 2026.

We also keep a backup of the encrypted files stored on the equipment of our contractor, RunPod, Inc. The files are your stored text and, if you have them, your personal model and fingerprint. The backup is an exact copy of those files, kept in the storage service (R2) of our contractor, Cloudflare, Inc.

We do this so that your stored text and personal model can be restored if the storage at RunPod, Inc. is lost.

The copies stay encrypted. The key is different for each customer, and it is not kept with the copies. File names contain only random IDs, never names or email addresses.

Cloudflare's own encryption at rest applies on top of that, and traffic to it is encrypted with TLS. The backup is not public.

We make a copy when training finishes, and compare the copies with the originals once a week. When we delete the originals, we delete the copies too, as described in section 5. The backup is kept in the United States.

We created the storage for the backup in R2 with its jurisdiction (the region where data is stored and processed) set to the United States. Cloudflare guarantees that data in storage with this setting is stored and processed within that jurisdiction. This guarantee is stated in Cloudflare's R2 documentation. Our software connects only to the endpoint for that jurisdiction.

We also use a third contractor, Cloudflare, Inc., in the United States, to store your account information. That covers your email address, your sign-in records, your subscription status, and your usage records. Cloudflare also stores your trained voice, linked to your account. A temporary copy of the text you give us is also kept there until training finishes, and is deleted when training finishes. What happens if training fails or is cancelled is covered in section 5, Keeping and deleting.

Cloudflare also sends the verification-code email and handles the connection to our service. The verification-code email comes from noreply@mail.vegaworks.net. Handling the connection means routing your traffic and helping us prevent abuse.

For storage, we set the region to Asia-Pacific. That is a setting, not a guarantee, and storage is not limited to Japan. Connections are handled at whichever Cloudflare facility is closest to you.

Traffic to Cloudflare is encrypted (TLS), and what it stores is encrypted (AES-256). We convert the verification code into a form that cannot be reversed, even by us. The same goes for the key that keeps you signed in. Our contract with Cloudflare includes a data processing agreement (DPA). It limits Cloudflare to using what we give it only to provide the service, and only as we instruct.

Providing information to companies abroad

We provide the text you give us to contractors abroad. Here are three things to know: the country, that country's system for protecting personal information, and the measures the contractors take.

The country is the United States of America. The contractors that receive the text you give us are RunPod, Inc., Anthropic, PBC, and Cloudflare, Inc. All three are companies in the United States. Anthropic, PBC receives only selected fragments of the text.

Japan's Personal Information Protection Commission (PPC) has surveyed how the United States protects personal information, and has published the result. The survey covers the federal level, and reflects the situation as of October 2021. Its main points are:

  • There is no comprehensive federal law on protecting personal information.
  • There are laws for particular sectors, for example electronic communications, finance, and health care.
  • The United States has taken part in the APEC Cross-Border Privacy Rules (CBPR) system since 25 July 2012. The PPC treats this as an indicator that private businesses are expected to offer a certain level of protection.
  • Within the scope of the survey, the PPC found no law that obliges businesses in general to cooperate with government information collection or to keep personal information inside the country, but the survey's scope is limited and it is not exhaustive. However, government agencies may ask businesses to provide information in accordance with procedures set out in individual laws and regulations.

The PPC notes that the information may have changed since October 2021. For details, see the PPC's page (updated 25 January 2022): https://www.ppc.go.jp/enforcement/infoprovision/laws/offshore_report_america/

The PPC's information on other countries' systems is on this page: https://www.ppc.go.jp/personalinfo/legal/kaiseihogohou/#gaikoku

Here are the measures the three companies take to protect personal information. We list only what we could confirm in each company's contract terms, which we read on 1 October 2026.

RunPod, Inc.'s published data processing agreement (DPA) covers processing only on instructions, confidentiality for its personnel, and security measures. It also covers 10 business days' notice before RunPod adds a subprocessor, help with requests from individuals, notice of a breach without undue delay, and deletion on request. RunPod says it holds ISO 27001 and SOC 2 Type 2 certification. These provisions are set out in the contract (DPA) between us and RunPod.

Anthropic's contract terms (its Commercial Terms of Service, and the data processing addendum that is part of them) set out the following. It processes what we send only to provide the service, on our instructions, and does not sell or share it. It may not train its AI models on what we send. Its personnel are bound by confidentiality, and its security measures include encryption and access controls with multi-factor authentication. It must hold its subprocessors to terms substantially as protective, and gives us notice of new ones. It also helps with requests from individuals, and notifies us of a breach within 48 hours.

Our contract with Cloudflare, Inc. includes its customer data processing agreement (DPA). The DPA says Cloudflare processes data only to provide the service, on our instructions. It also covers confidentiality for Cloudflare's personnel, and security measures: encryption, multi-factor authentication, and ISO/IEC 27001 and SOC 2 Type II certification. Subprocessors must accept terms no less protective, and we get advance notice of them. The DPA also covers help with requests from individuals, notice of a breach without undue delay, and deletion or return of data when the contract ends. Cloudflare says it holds Global CBPR and Global PRP certifications (2025).

Besides these contracts, we take our own measures. We encrypt the stored text, the personal model, and the fingerprint before we store them, with a different key for each customer. We do not send Anthropic your name, email address, or account ID, and we attach nothing else that identifies you. The app replaces email addresses, phone numbers, URLs, and postal codes with placeholders before the text leaves your device. For the writing you hand over, the app also replaces the addressee names, personal names, and company names that the app finds with placeholders before the text leaves your device. Names cannot be reliably detected, so a name inside a fragment may remain.

Except for these three contractors (RunPod, Inc.; Anthropic, PBC; and Cloudflare, Inc.), we never share your writing or information with anyone else.

5. Keeping and deleting

Text you wrote during onboarding, and the parts of the existing text you hand over that we used for training, are kept encrypted. We keep them for retraining after a base model update, or for training combined with more text you add later. They are stored on our contractor's equipment (RunPod, Inc.). We also keep an encrypted backup, so the data can be restored if that equipment loses it.

When your monthly plan ends, including cancellation, a refund, or a stop in payment, we delete the stored text and the fingerprint of your training text. If the end of your plan does not trigger that deletion, the stored text and any temporary copy stay until you delete them with “Delete stored writing”, or delete your account. That applies in three cases:

  • You have not started your monthly plan.
  • You train again after your monthly plan ends. The text you hand over again stays stored.
  • A training failed or was cancelled. We keep the temporary copy so you can try again.

There is no time limit in any of these cases.

Any existing text you handed over that we did not end up using is discarded, never used for training. We do not store it. The temporary copy kept with Cloudflare, Inc., including the part we did not use, is deleted when training finishes. If training fails or is cancelled, we keep it, as described above.

Your trained voice or personal model is kept with no fixed retention period. It stays in place while your monthly subscription is paused, so resuming picks up right where you left off. Your trained voice and personal model are deleted when you delete your account. A fingerprint of your training text is created when training takes place. Your fingerprint is deleted when your monthly plan ends, when you use “Delete stored writing”, or when you delete your account.

You can delete your data yourself in the VEGA Works Account Center.

  • “Delete stored writing” deletes only your stored text and the fingerprint of your training text. You can use it whatever your plan.
  • “Delete account” deletes your account and everything linked to it.

“Delete stored writing” deletes the following.

  • The temporary copy kept with Cloudflare, Inc.
  • The stored text on RunPod's equipment
  • The backup of the stored text
  • The fingerprint of your training text

It does not delete your trained voice or personal model. It also does not delete the records of your training runs and of your rewrites and writing from key points. All of these are deleted when you delete your account. The records of your training runs and of your rewrites and writing from key points contain no text. We use them to count your monthly use. To train again afterwards, you hand over your text again.

With either button, deletion goes like this. First, our server writes down the deletion order. Then a scheduled job passes the order on to the files on our contractor's equipment (RunPod, Inc.) and to the backup. The job keeps checking until the deletion is done, and tries up to 36 times. If all 36 attempts fail, we look into the cause and complete the deletion. The temporary copy in our database is deleted at once. The files on our contractor's equipment and the backup are deleted in turn, after we accept the request. This can take a few hours.

If you send your request to support@vegaworks.net, we carry out the same deletion as the buttons. However, we accept only requests that arrive from your registered email address. We (the operator) send a confirmation email to that address, and we carry out the deletion after a confirmation reply arrives from the same address.

When you delete your account, we start deleting the following right away. There is no grace period, and it cannot be undone. Before deleting, we ask you to enter a new verification code, sent by email.

  • Your email address
  • Your sign-in records
  • The text you handed over (stored text, and the temporary copy)
  • Your trained voice, personal model, and fingerprint
  • Your usage records, including the records of your training runs and of your rewrites and writing from key points
  • Your subscription details
  • The card saved at KOMOJU

We first stop your monthly subscription, and then delete the saved card together with your customer record at KOMOJU. If we cannot reach KOMOJU, nothing is deleted, and we ask you to try again.

When we write down the deletion order for your account, we also discard the value your encryption key is made from (the “salt”). After that, any of your stored text, personal model, or fingerprint that has not been deleted yet can no longer be read.

Your monthly subscription stops, and no further charges are made. A training in progress is cancelled, and any retrainings you have not used are lost.

If you want to delete your account before you choose your finished candidate (delivery), ask for a refund first. Write to support@vegaworks.net. After the refund, you can delete your account. See Refunds in the terms of use.

If you sign in again later with the same email address, you get a new, empty account.

Our database automatically keeps 30 days of backups, and we cannot turn this off. Your deleted data can remain in those backups for up to 30 days, then it is gone completely.

Separately, we keep an encrypted backup of the stored text, personal model, and fingerprint. When we delete the originals, we delete the backup too.

Even when you delete your account, we cannot delete the following ourselves.

  • The text fragments we sent to Anthropic, PBC
  • Records in RunPod, Inc.'s job system (a rewrite or write-from-key-points job is deleted on RunPod's side at most 70 minutes after submission, and a training job at most 6.5 hours after submission)
  • RunPod's logs (deleted on RunPod's side after 90 days)
  • Records of the emails we sent
  • Payment records kept by KOMOJU
  • What remains in the database backups (for up to 30 days, as above)

Anthropic's published rules say it automatically deletes what it receives, and what it produces, within 30 days. Asking us to delete does not shorten that period. In the cases described in section 4, Anthropic may keep it longer.

Training, rewriting, and writing from key points run on the equipment of our contractor, RunPod, Inc. Your stored text, personal model, and fingerprint are encrypted there, with a different key for each customer. While a job runs, your text is decrypted in memory and handled on a GPU.

During training, rewriting, and writing from key points, your text passes through RunPod's job system. A training job, including its input, is deleted on RunPod's side at most 6.5 hours after it is submitted. A rewrite or write-from-key-points job, including its input, is deleted on RunPod's side at most 70 minutes after it is submitted. We set that limit ourselves, using RunPod's job-lifetime setting. RunPod's published documentation says that the results of a job are deleted on its side 30 minutes after the job completes. RunPod's logs are deleted after 90 days. Our processing does not write your text or keys into logs. Further details of RunPod's own records follow RunPod's own rules.

KOMOJU's payment records follow KOMOJU's own rules. We keep no payment records.

The verification code stops working 10 minutes after we send it. Expired codes are deleted on a rolling basis.

Your sign-in record for each browser or device expires 30 days after you last used that browser or device. Expired records are deleted on a rolling basis.

Access records, including connection information, are deleted automatically after seven days at most. The converted value we use for rate limits is deleted on a rolling basis once it passes 24 hours old.

Records of your rewrites and writing from key points are kept for 400 days. Records older than that are deleted on a rolling basis. Records of your training runs are deleted when you delete your account.

We keep your email address, the last time you signed in, and your subscription status while you use the service, and delete them if you ask. Deleting your account also deletes the text, trained voice, personal model, and fingerprint linked to it. Records the law requires us to keep are not part of that deletion.

6. Payment information

Your payment provider handles your payment information — not VEGA Works. We never receive or keep your card number or any other payment details.

When you delete your account, the card saved at KOMOJU is deleted too. Payment records stay with KOMOJU, under its own rules, and we keep none.

VEGA Style's payments run through KOMOJU, a service from DEGICA Co., Ltd. We send KOMOJU your email address, the number that identifies your account with us, and the plan you chose. KOMOJU sends us back the payment result and notice of whether your card was saved.

7. Changes

This policy may change. When it does, the date at the top changes. Material changes are noted in the app's release notes as well.

8. Contact

Questions about this policy or about how your information is handled: