VIGILGLM
Open chat

Privacy Policy

Effective 3 October 2026 · Version 2026-10-07 · VIGIL GLM (vigilglm.ai) · ABN 51 317 709 329 · Australia

We collect information to run your account, and we measure platform usage (which pages are visited and what devices are used) so development focuses on what people actually use. We never sell your data or use your chats to train models.


1. Who runs this

VIGIL GLM is run by an individual in Australia trading as VIGIL GLM, ABN 51 317 709 329. That is a registered business name, not a company. Privacy questions go to admin@vigilglm.ai, answered by a person.

2. What we hold on you

On the account side: your email, the name you give us, a hashed password (never the real one), your role, plan status, and credit balance.

Your conversations are stored too, both sides of them, so your history is there when you come back. Projects hold their names, instructions, memories, and the files you upload. We pull the text out of PDFs and Word docs automatically so SIERRA can read them.

SIERRA also keeps account memory, the things she learns about you, like your name. Every entry is visible, editable, and deletable from the Account Memory menu. No black box.

For usage and billing we keep credit transactions, document generations, and Studio runs (script and output included, kept for security auditing), plus payment status. Administrators can see account-level credit totals and which product features were used, so the service can be operated. That view does not include prompts, replies, or files. Card details never touch our servers; Stripe handles those. Connection metadata, including IP address, is used for rate limiting and stopping abuse, and our host keeps ordinary service logs.

When something you ask for fails, we keep a short reliability record so an administrator can find and fix the problem: which account, which feature, the error, and sizes such as token counts. It never contains what you wrote, what SIERRA replied, or your files. These records are deleted after 30 days, or with your account.

If you create an API key, we store only a hash of it, never the key itself, plus a short prefix so you can tell your keys apart. If you set up a daily digest, the brief is written for your email address and delivered to it; the topic is yours and is not shared with anyone.

3. What we never do
4. Why we have it
5. Cookies and platform analytics

We set a necessary first-party session cookie so you stay signed in. We do not set advertising cookies.

We use Umami, a lightweight open-source analytics service hosted at Umami Cloud, to understand platform usage: which pages are visited, and what device types and browsers are used to access VIGIL, so development focuses on the devices and pages people actually prefer. This measurement is on by default for visitors who are not signed in and for registered accounts. Signed-in users can switch it off at any time in Settings → Platform analytics; it is on for new accounts automatically.

The Android app measures the same thing from its side: one sanitized event each time it opens, carrying no account identity, no device identifier and never any conversation content. The app has its own Platform analytics switch in Settings, set to the same choice as your account.

Analytics is deliberately narrow. Umami receives page paths and technical details such as browser and device type. Page paths are stripped of URL queries, fragments and referrers before they leave the browser, and capability URLs such as shared-conversation links are reduced to their page name, so the unguessable tokens in them never reach the vendor. Umami sets no cookies and is not used for advertising, profiling or cross-site tracking. No account identity, prompts, files or conversation content are ever sent. Turning analytics off in Settings stops further collection; it does not erase measurements already collected. Accounts that opt out also clear any analytics cookies left by the Google Analytics service this platform used until 4 October 2026.

6. Who else sees it

Your messages have to reach the model to get an answer, which means Z.ai (who run the GLM models) processes them under their own policies; that is simply how the service works. When web search is used, the search query is sent to Tavily or Z.ai to retrieve relevant sources. If you choose the natural lighting option when changing a photo background, that photo is sent to DeepInfra to generate a background whose light matches the picture; the people in your photo are then restored from your own file, pixel for pixel, so what comes back is not a generated likeness of them. Ordinary background changes, including white, blue, blur, cutout and your own uploaded background, are done on our own server and no photo leaves it. Stripe processes payments under theirs. Our host sees connection metadata, as hosts do. Umami Cloud processes the limited pageview information described above as our analytics processor. We do not share account or conversation data for marketing.

When a reply is spoken aloud in a voice conversation, on the website or in the Android app, the text of that reply is sent to DeepInfra to produce the audio. Meeting recordings you submit for transcription, and documents you submit for parsing, are sent to Z.ai.

Cloudflare sits in front of our servers, so your connection passes through it, and it stores generated files for us. Proton delivers the email we send you. If you sign in with Google or GitHub, that company tells us your email address and confirms who you are. If you import a repository, we fetch it from GitHub with the access you gave. If you connect an outside service on a paid plan, the requests you approve go to that service.

7. Where it lives

Account data, chats, and billing records sit in MongoDB Atlas in Sydney, Australia. Generated files sit in Cloudflare R2, or in Atlas GridFS if R2 is not configured. The application runs on servers in Sydney, Australia, rented from Kamatera. Z.ai's processing location is set by Z.ai, not by us; we cannot promise that prompts stay in Australia once they leave for a reply.

Platform analytics pageviews are processed by Umami Cloud outside Australia. DeepInfra, Tavily, Stripe, Cloudflare and Proton also choose where they process what we send them.

8. Job Hunter

Job Hunter is available on Light and Pro. We store your hunt, saved roles, supplied résumé and background, generated documents and progress you record. Relevant résumé text and user-authored conversation context are sent to Z.ai to prepare documents. Search uses the providers listed above.

For each role you can tailor a résumé or prepare an email and cover letter. You review, copy or download the result and submit it yourself through your own email or the employer's application page. Job Hunter does not send applications, connect to your mailbox or process employer replies.

Records from the retired mail feature may remain in your existing hunt or account export. Legacy Job Hunter mail expires after 90 days; no new mail is ingested. Saved roles and documents remain until you delete the hunt or account.

9. The Android and Linux apps

The apps use the same account as the website, so everything above applies to them. This section covers what each app adds.

VIGIL for Android keeps a session token, your email address and your settings in the phone's secure storage. It does not keep your password, and it does not keep a copy of your chats on the phone. Chats are loaded from your account each time. Turn off Remember this device and the phone forgets the session when the app closes.

The Android lock uses the fingerprint, face or screen lock already set up on the phone. The phone does the check and tells the app only whether it passed. No biometric data reaches the app or us.

The app uses the microphone only after you tap dictate or voice. The phone's speech recognition service turns what you say into text, and on most Android phones that service is Google's. It may process the audio under its own policy. We receive the text and never the audio. Spoken replies are produced as described in section 6, and each audio clip is deleted from the phone after it plays.

The Android app contains no advertising or crash reporting software. Its only analytics is the Umami platform measurement described in section 5, and it carries no device identifiers.

VIGIL Desktop for Linux shows the hosted website in its own window. It keeps its sign-in cookies in its own profile on your computer. The app adds no analytics of its own. The website's analytics setting in section 5 still applies.

VIGIL-Code for Linux works on folders you open on your own computer. It saves its chats on that computer, inside the project folder, and they are not added to your account's chat history. To get a reply it sends your message to us and on to Z.ai, together with the project name, folder path, file list, git branch and last commit subject, basic system details, the project's instruction files, and whatever files and command output the agent reads for the task. We record the usage and cost of each request for billing. The AppImage version checks vigilglm.ai for updates.

10. How long we keep it

Conversations, projects, and memories stay while your account does; that is the point of them. Studio execution logs are kept for 30 days for security auditing. Generated-image records are kept for 30 days after they close. Billing records stay as long as tax law says they must. Legacy Job Hunter mail is kept for 90 days; the mail feature is retired. Rate-limit counters are stored under hashed keys, expire on their own, and are not a profile. Host technical logs cycle on the host's ordinary schedule, typically weeks, not years. Delete your account and we delete or de-identify your data, minus the records the law makes us keep.

11. What you control
12. How we protect it

HTTPS everywhere, passwords hashed, access locked down, scripts executed in isolated sandboxes, rate limiting against abuse. We do the basics properly and then some. That said, nothing connected to the internet is perfectly secure, and we will not pretend otherwise.

13. Kids

VIGIL is not for children under 13, or under whatever the minimum digital age is where you live. If you think a child has given us personal information, tell us and we will delete it. Job Hunter is for people who can lawfully apply for work. Do not use Job Hunter if you are under 18.

14. Changes

If this policy changes in a meaningful way, the date at the top changes with it. Keep using VIGIL after that and you accept the update.

15. Talk to us

Privacy questions go to admin@vigilglm.ai. Real answers from VIGIL GLM in Australia, ABN 51 317 709 329.


Questions about this document? Contact admin@vigilglm.ai. See also: Terms of Service · Privacy Policy · Usage Policy · Changelog · Demos · Downloads · Documentation

Privacy policy · VIGIL GLM