TalqoratalqoraOpen console

Privacy Policy

Talqora LLC
San Francisco, California, United States
Effective date: January 24, 2026

This Privacy Policy explains how Talqora LLC (“Talqora,” “we,” “us,” or “our”) collects, uses, discloses, and protects information in connection with Talqora Vector, our API-first vector storage and retrieval service. It applies to the Talqora website, console, documentation, APIs, file-processing features, support channels, and related services.

1. Our privacy commitments

Talqora is designed for teams building intelligent systems that need controlled vector storage and retrieval. We use information to provide the service, secure accounts, enforce authorization, measure usage, communicate with customers, and meet legal obligations. We do not sell Customer Content, and we do not use Customer Content to train, fine-tune, evaluate, or improve general-purpose artificial intelligence models.

Talqora maintains a privacy and security program designed to support compliance with applicable data-protection laws, including the EU General Data Protection Regulation (“GDPR”), the UK GDPR where applicable, and applicable California privacy requirements. This policy explains the operational commitments supporting that program. It is not a certification or legal opinion.

2. Information we collect

Account and organization information

We collect information needed to create and administer an account or organization, such as name, work email, authentication identifiers, organization name, membership, role, plan, billing contact, and communication preferences.

API and usage information

When an API or console request is made, we may collect the API key identifier or authenticated user identifier, organization and index identifiers, request method, timestamps, response status, approximate request and transfer size, latency, region, quota usage, and security events. We do not need to store an API secret in plaintext to operate the service.

Customer Content

Customer Content can include vectors, sparse text, metadata, files, queries, prompts, responses, URLs, and other information that a customer chooses to submit. Customers control the content they send and determine the purposes for which their applications use it. Talqora processes Customer Content to provide storage, indexing, file processing, retrieval, deletion, support, security, and related service functions.

Communications and support

We collect information included in support requests, sales conversations, product feedback, invitations, onboarding messages, and other communications. We may retain records of communications to resolve issues, administer accounts, improve support, and meet legal obligations.

Device and website information

We may collect limited browser, device, IP address, cookie, and similar technical information needed for authentication, session security, fraud prevention, performance, and basic website operation. We do not use advertising profiles to target people with Customer Content or confidential service data.

3. How the API works

Talqora is an API-first service. A customer creates an organization and one or more regional indexes, selects immutable index settings, creates scoped credentials, and sends authenticated HTTPS requests to write, query, or delete records. Query responses are returned to the requesting application according to the index and key permissions. File-processing jobs are asynchronous and may involve receiving a source file, extracting text, creating chunks, generating retrieval representations, and writing the resulting records to the customer’s selected index.

The service keeps control-plane records such as organizations, memberships, authorization scopes, index configuration, idempotency records, usage history, billing entitlements, and job state. Vector and retrieval content is stored in managed regional storage required to operate the selected index. Talqora does not use the control plane as a general-purpose document archive or as a training corpus.

3.1 Regional processing and AWS-managed infrastructure

Talqora offers regional indexes so customers can choose the intended processing geography for their workload. The currently supported options are US East (us-east-1), São Paulo (sa-east-1), Europe (eu-west-1), and Singapore (ap-southeast-1). The Europe option is the AWS Region identified as Europe (Ireland); it can serve customers in Berlin and elsewhere in the European Union, but it is not an AWS Region located in Berlin. Customers that need a specific European country or a different residency boundary should confirm availability with Talqora before sending personal data.

Each regional version is hosted and operated using AWS-managed infrastructure in the selected AWS Region. AWS secures the underlying cloud infrastructure under its shared-responsibility model, while Talqora manages the application layer, access controls, routing, configuration, retention behavior, customer support, and privacy program. AWS’s certifications and controls are supporting safeguards; they are not a blanket certification that Talqora or a customer’s specific processing is compliant. Talqora assesses its use of AWS and applies appropriate contractual, technical, and organizational measures for the applicable processing.

For the selected geography, Talqora’s compliance program is designed to support GDPR and UK GDPR requirements in Europe, LGPD requirements in Brazil, PDPA requirements in Singapore, and applicable US and California privacy requirements in the United States. We apply the same baseline security and privacy controls across regions, then add the contractual, transfer, rights, retention, and response measures required by the applicable legal framework. Compliance depends on the processing context and customer instructions; it is not created solely by choosing a geographic region or an AWS service.

The selected region governs the primary regional storage and retrieval path. Account administration, authentication, operational telemetry, security response, support, billing, legal requests, backups, and service-provider operations may involve other locations when necessary. We limit those activities to the purposes described in this policy and use lawful transfer safeguards where required.

4. Purposes and legal bases

Depending on the context, Talqora processes personal information for the following purposes:

  • providing, authenticating, securing, monitoring, and supporting the service;
  • creating and administering organizations, memberships, indexes, API keys, and billing;
  • processing Customer Content according to a customer’s documented instructions;
  • preventing abuse, fraud, unauthorized access, and security incidents;
  • sending transactional, operational, onboarding, and account communications;
  • improving reliability, capacity planning, and service performance using aggregated or de-identified information;
  • complying with court orders, lawful requests, tax rules, accounting duties, and other legal obligations; and
  • protecting the rights, safety, property, and legitimate interests of Talqora, customers, users, and the public.

For information Talqora controls directly, our legal bases may include performance of a contract, legitimate interests, consent, and compliance with legal obligations. Where Talqora acts as a processor or service provider for Customer Content, the customer determines the lawful basis and remains responsible for notices, permissions, and instructions.

5. GDPR and UK GDPR roles

For account, billing, security, support, and service-administration information, Talqora may act as a controller. For personal data that a customer submits to an index, file-processing job, or API request, Talqora generally acts as a processor and the customer generally acts as controller. The precise roles depend on the facts, the customer’s instructions, and applicable law.

Talqora supports GDPR and UK GDPR requirements through documented processing instructions, confidentiality obligations, access controls, security measures, subprocessors, incident procedures, retention controls, assistance with data-subject requests, and lawful transfer mechanisms. Customers that require a data-processing agreement may request one from Talqora. A customer remains responsible for determining whether its use of the service is lawful, providing appropriate notices, responding to its users, and configuring retention and access controls.

6. No AI training or model improvement

Talqora does not use Customer Content to train, fine-tune, evaluate, benchmark, or improve general-purpose AI models. Customer Content is processed only as necessary to provide the service requested by the customer, maintain security and reliability, provide support when authorized, comply with law, or perform another documented customer instruction.

Aggregated or de-identified service metrics may be used for capacity planning, abuse prevention, reliability analysis, and product operations when they do not reasonably identify a customer, person, or Customer Content. Talqora does not sell or license Customer Content for model training.

6.1 File-processing safety controls

File processing is not permitted for hacking, malware, credential theft, phishing, ransomware, exploit development, unauthorized access, evasion of security controls, surveillance, harassment, doxxing, threats, violence, or other activity intended to harm a person, organization, system, or the public. This restriction applies even when the stated purpose is research, testing, education, or automation.

Talqora uses automated guardrails and abuse-detection systems to identify prohibited or dangerous file-processing activity. These systems may process technical signals, file characteristics, request context, and content patterns only as needed to enforce safety, protect the service and people, and respond to abuse. Talqora does not routinely read customer files. Limited access by authorized personnel or service providers may occur when necessary for security, support, incident response, legal obligations, or abuse investigation.

When automated controls or other evidence indicate activity that could harm a person, organization, system, or the public, Talqora may block a job, revoke credentials, suspend or permanently disable an account, preserve security records, and cooperate with lawful authorities. We may act immediately, without prior notice and, where legally permitted and reasonably necessary to prevent evasion or further harm, without providing a detailed explanation. We may provide notice or an appeal path when it is safe, lawful, and appropriate.

7. Disclosures and service providers

Talqora may disclose information to service providers that help us provide hosting, storage, authentication, communications, payment processing, monitoring, security, customer support, and professional services. These providers may process information only for contracted purposes and under confidentiality and security obligations appropriate to their role.

Talqora may disclose information when required by law, valid legal process, or an emergency involving safety; to enforce agreements; to detect or prevent fraud, abuse, or security threats; or to protect rights and property. If legally permitted, Talqora will seek to provide notice before responding to a government request involving Customer Content and will disclose only the information reasonably required.

Talqora does not sell personal information and does not share personal information for cross-context behavioral advertising. We do not sell or share Customer Content.

8. International transfers

Talqora is based in San Francisco, California, United States. Information may be processed in the United States and other locations where Talqora or its service providers operate. When a transfer of personal data is subject to European, United Kingdom, or Swiss transfer restrictions, Talqora uses an appropriate lawful mechanism, which may include an adequacy decision, standard contractual clauses, or another recognized safeguard. Talqora assesses transfer risks and applies supplementary measures appropriate to the processing.

9. Security

Talqora uses reasonable administrative, technical, and organizational safeguards designed to protect information against unauthorized access, alteration, loss, misuse, and disclosure. Controls include encryption in transit, protected managed storage, scoped API keys, least-privilege access, logging, monitoring, change management, vulnerability management, backup and recovery practices, confidentiality commitments, and incident response procedures.

Customers are responsible for protecting credentials, choosing narrow scopes, rotating keys, validating integrations, limiting access within their organization, and avoiding unnecessary sensitive data. No service can guarantee absolute security. If Talqora confirms a personal-data incident affecting Customer Content, Talqora will notify the relevant customer without undue delay as required by applicable law and will provide reasonably available information needed for the customer’s response.

10. Retention and deletion

Talqora retains information only for as long as reasonably necessary for the purposes described in this policy, the customer’s instructions, the applicable plan, or legal requirements. Account, authorization, billing, audit, and security records may be retained for longer where needed to establish, exercise, or defend legal claims, prevent abuse, reconcile transactions, or comply with law.

Customers can delete indexes, records, files, jobs, and accounts through available controls or by contacting support. Deletion from active systems may be followed by limited retention in backups, logs, or legal records until those systems cycle or the retention obligation ends. When acting as a processor, Talqora follows the customer’s deletion and return instructions subject to applicable law and documented service limitations.

11. Your privacy rights

Depending on where you live and Talqora’s role, you may have rights to request access to, correction of, deletion of, restriction of, or portability of personal information; to object to certain processing; to withdraw consent; and to lodge a complaint with a supervisory authority. You may also have rights to know the categories and purposes of information collected and to request information about disclosures.

To submit a request, email team@talqora.com with enough information for us to verify and respond to the request. If you are an end user whose information was submitted by a Talqora customer, direct the request to that customer first; Talqora will assist the customer as required by applicable law. Talqora will not discriminate against you for exercising a privacy right and may use reasonable verification steps to protect accounts and personal information.

California residents may have rights under the California Consumer Privacy Act and related California privacy laws, subject to applicable exceptions and thresholds. Talqora does not sell or share personal information as those terms are used for targeted advertising. Requests can be sent to the email above, and an authorized agent may submit a request with appropriate proof of authorization.

12. Children

Talqora Vector is a business and developer service and is not directed to children under 16. We do not knowingly collect personal information directly from children in violation of applicable law. If you believe a child submitted personal information to us, contact us so we can investigate and delete it where appropriate.

13. Cookies and similar technologies

Talqora may use necessary cookies or local storage for authentication, session continuity, language preferences, security, and basic service operation. We may use limited analytics that help us understand performance and usage of public pages. You can control cookies through your browser, but disabling necessary technologies may affect login or console functionality.

14. Changes and contact

We may update this policy to reflect changes in the service, law, or privacy program. We will post the updated version and change the effective date. For material changes, we will provide additional notice where required.

Talqora LLC
San Francisco, California, United States
Privacy and legal requests: team@talqora.com
General support: team@talqora.com