Trust document · published before code, kept exact after

What we can see. What we can't. Stated exactly.

Vantell's entire value is trust. For a product like that, one discovered overstatement costs more than ten admitted limitations — so this page says precisely what is true, qualifiers included, and nothing more.

The claim, in two sentences

Your private notes cannot reach us, because the software that could send them doesn't run on our servers. Your shared export we can technically read — it is encrypted with keys we manage, and our workers decrypt it to answer questions on your behalf. Here is precisely how we constrain, monitor, and audit that access.

Two sentences, two different guarantees — and we will never collapse the second into the first.

What never reaches our servers

The software you install locally is two strictly separated components — separate processes, separate OS users:

Your private notes never reach our servers, because the software that could send them doesn't run on them — and the software that runs on your machine with network access can't read them either.

Private is doing real work in that sentence. The shared export — the notes you deliberately marked shareable — does reach our servers, and our workers can read it; that is what the second sentence of the claim above is about. Everything else stays home. On a real, intensively used vault, the shareable layer measured 475 notes out of 187,412 files — we see a quarter of one percent of that brain, and nothing else.

Some exclusions hold no matter what you configure: raw captured material (email, transcripts, chat exports — mostly other people's data, whose subjects never consented) and notes about individuals can never be marked shareable. There is no switch. Not opt-out — the switch does not exist.

What we can technically read — and how it's constrained

Your org admin sees even less

In Vantell, the tenant is the person. Your organization is a federation domain your personal tenant is bound to — it handles billing, membership, and a policy floor (ceilings on disclosure, never overrides upward). This inverts what every B2B tool does, deliberately:

Standard SaaS behaviour What Vantell does instead
Admin exports all tenant data Admin exports org notes, manifests, receipts, usage metrics — never member content
Admin can impersonate a user for support Does not exist. Audited break-glass procedures only
Org-wide search Does not exist. Only mesh queries, which are policy-gated by each owner
Admin sets user permissions Admin sets a policy floor (max levels, allowed contexts, retention) — never a policy override upward
Deleting the org deletes user data Deleting the org unbinds tenants; personal vaults survive

What org admins can never see:

Not policy. Architecture — there is no API for it. Admins see metadata: query volumes, response rates, topic coverage. If a metric could rank employees, it doesn't exist.

You see everything

Radical transparency runs toward the owner, not the platform. Your audit log shows every question ever asked of your brain, by whom, for what stated purpose, at what level, and what was answered or refused — with a signed consent receipt for every grant. Only you can see it, and you can export it: it's your data.

Leaving

Deleting your account destroys your export copy, indices, keys, and audit log by deleting the per-person encryption key that protects them — unrecoverable, immediate, and propagated into backups within a stated window. Contributions you explicitly consented to keep in org-owned notes exist without your name; you can withdraw those too.

Honest limits

Questions this page doesn't answer belong in it. Tell us: hello@vantell.ai.