← Back to policies

Privacy Policy

Last updated: September 9, 2026

This policy explains what Vesperion Gate Inc. collects, why we use it, who receives it, and your choices. It covers our websites, Thicket, and LensCherry (the “Services”). We do not sell personal information or private customer content.

We are a Canadian company headquartered in Ontario. We determine how information is used for account administration, billing, security, and our own business correspondence. For personal information in customer content processed on a customer's behalf, the customer determines the purposes and we act on its instructions under our Data Processing Addendum. This policy explains those operations too; it does not replace that agreement.

If an organization provides your account, it controls the workspace, membership, and sharing. Contact that organization about its use of your information. You can also contact [email protected]; we will help or refer your request to the responsible customer.

What we collect and why

Identity, access, and billing

We process your name, email address, organization details, account preferences, and any profile image you provide. Authentication records can include sessions, IP addresses, device or browser information, sign-in events, and security settings. If you choose an external sign-in provider, we receive the identity information required for that sign-in.

Our payment processor handles payment-card details. We retain transaction references, billing information, purchase and subscription history, and limited card information such as the last four digits for invoicing, taxes, support, and fraud prevention. Full card numbers are not stored on our application servers.

Content and product activity

We store content you upload, receive, or maintain and the information needed to organize and share it. Thicket content includes projects, tasks, messages, documents, comments, files, chat, schedules, assignments, notifications, and activity. LensCherry content includes prompts, reference photos, generated images, model profiles, generation settings, and processing results. We use it to provide requested features, enforce permissions and plan limits, and operate the Services.

Usage and diagnostic information helps us understand product operation, investigate errors, and secure accounts. This includes account identifiers, feature use, timestamps, browser and operating-system details, performance information, and error reports. Diagnostics can contain personal information and error context; they are not necessarily anonymous. Dedicated MCP audit records have the narrower format described below.

Correspondence and device permissions

We retain support requests, account communications, and information you volunteer to respond and maintain an issue history. We ask permission before recording a customer interview. Marketing communications include an unsubscribe option; essential service and security notices are separate.

Our apps may request device permissions for notifications, photos, the camera, or other optional features. You can control permissions in device settings. Refusing permission may prevent the associated feature from working.

Connected apps, APIs, CLI tools, and AI agents

You can choose external applications, scripts, and AI tools to use Thicket through its API, official command-line tools, and supported connectors, including MCP. An owner or administrator can also create an agent member for an external runtime. These interfaces provide access to Thicket; they do not themselves supply an AI model that generates or summarizes workspace content.

When you authorize a tool, we receive its requests and submitted content and return information for supported operations within the connected account's permissions. Responses can include workspace content, organization and project details, names and identifiers, tasks, messages, documents, comments, chat, file information, schedules, notifications, and activity. Authentication also involves account and connection identifiers, permissions, and email where authorized. Available operations differ by interface; the current MCP catalog does not transfer file contents.

A connection acts as the authorizing person or an agent member with its own identity. Access follows that account's current organization and project permissions, the credential's read or write permissions, and supported operations. The current OAuth connection follows access across the authorizing account's organizations; it is not restricted to one organization or project selected during consent. Membership and permission changes can change its access.

Write access allows supported changes, including creating and editing content, completing and organizing work, managing subscriptions and notifications, posting content that may notify people, and moving supported items to Trash. The current MCP catalog has no permanent deletion, restore, billing, people-management, account-settings, or file-transfer operations. Other interfaces expose additional operations. See Thicket's connection help.

Returned information may reach the external tool's operator and AI providers. Storage, retention, human review, processing locations, and use for model training or improvement depend on your or your organization's agreement, account type, settings, and policies with them. Read-only access still shares information. An AI using the API or CLI can receive the same kinds of information as an AI using MCP.

Choosing a compatible tool does not automatically make its provider our subprocessor or mean we endorse its data practices. Our commitments for providers we hire do not automatically apply to independently selected tools. Only authorize access you are entitled to grant and choose a tool suitable for the information involved.

Disconnect OAuth apps in My settings → Connected apps, revoke personal tokens in My settings → API tokens, or use the administrative controls for an agent member. Revocation prevents subsequent requests using that authorization; a request already in progress may finish. It does not undo actions, revoke separate credentials, or delete information already received externally. Use the external provider's controls to manage its copies. Contact us for assistance with providers we engage on your behalf.

AI processing we arrange

Thicket and model training

We do not use private Thicket customer content to train general-purpose AI models. Using Thicket or authorizing an integration grants us no permission to do so. Our provider-selection policy prohibits sending private customer content for general-purpose model training and requires appropriate data-protection terms before a provider may process it on our behalf. Independently selected tools follow the arrangements above.

LensCherry

LensCherry uses Google's Gemini API for requested image generation, editing, and prompt assistance, and Google Cloud Vision for automated image safety screening. Processing includes prompts, reference images, generated content, and technical request information. A LensCherry “model” is a profile with reference images that guide generation; the current workflow does not train separate model weights for each person.

We do not use uploaded photos or generated content to train general-purpose models. We use paid Gemini API processing for customer content, and our operating policy requires Google's applicable data-processing terms for that use. These terms distinguish paid processing from free developer tools. They do not promise zero retention: Google publishes a 55-day abuse-monitoring period. New image-generation requests opt out of optional Interaction storage; earlier stored interactions may remain until deleted or their retention expires, up to 55 days under the paid service. Authorized safety review and legal preservation may apply. Our provider register links to the applicable information.

We store generation results in your account and moderation outcomes for safety and support. Authorized staff may review reported or flagged content to investigate abuse. Automated screening does not detect every prohibited image.

Staff AI assistants

We use AI assistant tools from Anthropic (Claude) and OpenAI (ChatGPT and Codex) internally, to help our own staff with work like writing and reviewing software. They are not part of the products and do not operate on your content. We keep private customer content, support correspondence, and identifiable production records out of these tools, so no customer personal data goes to them and they are not our subprocessors.

Training on our conversations is disabled through each provider's account settings. The providers' terms keep exceptions for feedback we choose to submit and, for Anthropic, for content flagged for safety review, so we do not submit feedback from work that involves anything sensitive. If we later adopt a business or API account with a data processing agreement and allow customer data in a staff tool, we will list the provider in our provider register and post notice through the policy update history and its feed first.

Recipients and staff access

Providers help with hosting, storage, backups, network protection, authentication features, payments, email, support, diagnostics, and LensCherry's AI processing. Our provider register identifies their roles and products. We remain responsible for our obligations when engaging processors.

Workspace information is shared according to permissions and settings. At your direction, it can also be disclosed through integrations, exports, public links, or notifications. Email and push notifications may include activity and content previews, depending on the feature and settings.

Staff access is limited to what is needed for an authorized purpose. We ask permission before inspecting private account content for your support request. We may also access the minimum information necessary to fix failed operations, investigate security incidents or abuse, enforce our terms, or meet legal obligations.

We assess government requests and disclose or preserve information when legally required, or when permitted and necessary to address an emergency. We seek to limit disclosure and notify affected customers unless prohibited by law or an emergency makes prior notice inappropriate. Providers may also face lawful requests in their processing countries.

Information may transfer in an acquisition, merger, or reorganization, subject to applicable protections. We will notify you before a materially different privacy policy applies. We may analyze aggregated or de-identified information that is no longer reasonably identifiable; merely hashed or account-linked information is not treated as anonymous.

Cookies, measurement, and anti-bot protection

Cookies and similar storage support sign-in, security, and preferences. We also collect operational and product-use information as described above. Browser settings can limit storage, although blocking essential cookies can prevent features from working.

We use Plausible Analytics to measure visits to Thicket's public website and signup page. It receives public page URLs, campaign labels, referring website origins, and technical browser and network information to produce traffic, device and approximate-location statistics. Our integration removes other URL parameters and fragments before sending events and excludes private workspace, invitation and authentication pages. It does not send account identities, form contents or customer conversion events. Plausible uses no analytics cookies or persistent visitor identifiers; it processes website visitor data in the European Union. See our provider register for its data-handling and deletion information.

Cloudflare provides network protection and Turnstile checks on selected forms. It processes technical browser and network information to distinguish legitimate requests from abuse; we receive a verification result. Supported API, CLI, and MCP clients use their designated authentication flows.

If we introduce optional advertising or analytics technologies requiring consent, we will identify their purposes and providers and obtain consent before enabling them. This policy does not authorize undisclosed advertising trackers or sharing customer email hashes with ad networks.

Retention and deletion

Retention depends on the information and its purpose. Content posted by an AI tool becomes account content like any other authorized post. Connection audit, billing, and provider records have separate schedules.

  • Active account content: retained to provide the account until deletion, closure, or another applicable retention rule. Cancelling a paid plan alone does not delete content.
  • Thicket Trash: supported items and projects normally remain recoverable for 30 days. Authorized Trash controls can permanently remove them earlier. Some operations, including deletion of chat messages through the API or product, are immediate. MCP has no permanent-delete or restore tool.
  • Account closure: Thicket workspace access ends and a 30-day recovery period begins. LensCherry offers 30 days to cancel a deletion request. Permanent removal from active systems is scheduled when the recovery period ends. Contact support for help exercising an erasure right.
  • Backups: deleted content can remain temporarily in restricted recovery backups. Logical database backups retain every six-hour copy through 7 days and the latest copy per day through 28 days, with no monthly or annual tier. Physical database and WAL recovery normally spans about two weeks and is monitored against a 29-day maximum-age guard. File-version backups expire 28 days after a daily replica archives a removal or replacement. Together with the 30-day account-recovery period and daily processing, ordinary customer-content recovery copies are scheduled for deletion within 60 days of account closure. Configuration backups rotate after 90 days because the reviewed archive contains infrastructure configuration and encrypted secrets rather than customer workspace or photo content. A policy correction does not remove an applicable deletion right or a commitment in a separately agreed contract.
  • MCP security audit: the dedicated table contains account, credential and client identifiers, tool names, organization and request identifiers, times, outcomes, and duration. It does not store full tool arguments or responses. Records are scheduled for deletion after 180 days and may remain after account closure for security and accountability.
  • Duplicate-action records: certain MCP writes store a request fingerprint and structured result that may include item titles, identifiers, URLs, and timestamps. Records expire after 24 hours and are removed by routine cleanup.
  • Other records: security, diagnostic, and support records are retained while needed to investigate issues, secure services, resolve disputes, or meet legal duties. Retention depends on the record and provider. Accounting and tax records can outlast closure. Access is restricted and continued retention must remain necessary for the stated purpose.
  • External copies: see our provider register for processing we arrange. Independently selected tools follow their own schedules; disconnecting does not delete their copies.

Deletion jobs and backup rotation run on schedules, so expiry does not promise removal at an exact second. Necessary legal preservation can extend retention, with access restricted to that purpose. Deletion instructions must be reapplied after restoring a backup before restored content returns to ordinary use. Account-content deletion does not erase all legally required billing or security records.

Security and processing locations

Public connections use HTTPS. Uploaded files use encryption at rest and database backups are encrypted. Most database content is readable by the application to provide the service; these products are not end-to-end encrypted. Access controls, restricted administration, and backups complement encryption. See Trust and Security.

Application servers, databases, primary object storage, and backups for Thicket and LensCherry are in the United States. Staff administration takes place from Canada. Providers may process information elsewhere through support, network, email, payment, or AI infrastructure. US primary storage does not mean all processing occurs only in the US.

We must use the safeguards required for each applicable international transfer. Canada's adequacy arrangements apply within their scope and do not automatically cover onward transfers elsewhere. The Data Processing Addendum addresses customer-data processing and transfer safeguards. Using a service is not a substitute for a legally required transfer mechanism. Contact us for information about safeguards applicable to your account.

Your rights and choices

Depending on applicable law, you may request access, a copy or portable export, correction, deletion, restriction, or an explanation of our collection and disclosures. You may object to certain processing, withdraw consent where it is the legal basis, unsubscribe from marketing, and complain to a regulator. Exercising a right will not cause unlawful discrimination. Withdrawing consent does not invalidate earlier lawful processing.

Email [email protected]. We may verify identity and authority before acting and will respond within the applicable legal period. Some requests must go to the organization controlling a workspace. If we cannot fully fulfill a request, we will explain the limitation and available review or complaint route.

For processing subject to the GDPR or UK GDPR, relevant legal bases include contract performance, legal obligations, legitimate interests such as security and service administration, and consent where required. When we are a processor, the customer is responsible for its legal basis and instructions.

California residents may have rights to know, access, correct, delete, and limit certain uses. Our service-provider or contractor role concerns customer personal information processed under the customer agreement; it does not automatically describe our separate account, billing, or business-administration activities. We do not sell personal information or share it for cross-context behavioral advertising.

You can complain to the Office of the Privacy Commissioner of Canada or the applicable provincial commissioner. In the EEA or UK, contact your competent data protection authority.

Changes and contact

We may update this policy to reflect new practices or legal requirements. If we make significant changes, we will refresh the date at the top of the affected page and record the change in the policy update history; subscribe to the policy updates feed to be notified. Where the law requires a specific notice or fresh consent, we provide it separately.

Contact Vesperion Gate Inc. at [email protected] for privacy questions or [email protected] for account assistance.