Última actualización: May 2026 · VisionAI Workspace Beta
Tu contenido de Orbit vive en tu Google Drive, que es el registro principal. VisionAI Workspace lee y escribe en él mientras usas la plataforma, conservando solo una caché de corta duración (se borra automáticamente en un plazo de 24 horas) además de datos de cuenta/uso para operar el servicio. Tu contenido real permanece en tu Drive, bajo tu control.
VisionAI Workspace está diseñado para que tú seas el dueño de tus datos. Recopilamos el mínimo necesario para proporcionar el servicio:
Usamos los datos que recopilamos únicamente para operar la plataforma VisionAI Workspace:
Cuando inicias sesión, VisionAI Workspace solicita permiso OAuth para acceder a Google Sheets, Google Drive (solo creación de archivos) y Google Docs en tu nombre. Este acceso se usa exclusivamente para:
Importante: Si revocas el acceso de VisionAI Workspace a Google Drive en cualquier momento, la plataforma no podrá acceder a tu espacio de trabajo y dejará de funcionar hasta que se restaure el acceso. Tus datos en Google Drive siguen siendo tuyos y no se ven afectados.
VisionAI Workspace utiliza una arquitectura de IA multi-proveedor diseñada para expandirse con el tiempo. Cuando envías una tarea, el contenido de tu prompt es procesado temporalmente por uno de los siguientes proveedores de IA para generar una respuesta — cuál exactamente varía según la solicitud:
VisionAI Workspace no retiene copias de tus prompts o resultados de IA fuera de tu Google Sheet. Sin embargo, cada proveedor de IA de terceros puede registrar o procesar temporalmente tus entradas según sus propias políticas de privacidad. Recomendamos revisar las políticas de privacidad individuales de estos proveedores si tienes preocupaciones sobre cómo manejan los datos.
Para enviar correos transaccionales y de cuenta (como confirmaciones de lista de espera, notificaciones e invitaciones), VisionAI Workspace utiliza Brevo, un proveedor externo de entrega de correo electrónico. Cuando te enviamos un correo, tu dirección de correo electrónico y el contenido del mensaje son procesados por Brevo únicamente para entregar ese correo. Brevo procesa estos datos según su propia política de privacidad. No usamos Brevo para publicidad.
How it is protected. All traffic between your browser, this platform and Google's APIs runs over HTTPS/TLS. Your Google OAuth tokens are stored in our Supabase Postgres database, encrypted at rest, and are read only by server-side code — they are never sent to your browser and never appear in client-side JavaScript. Account records are protected by row-level security so one account cannot read another's, and the elevated key used for server-side work exists only in server environment variables, never in the app bundle.
The narrowest scopes that work. Drive access is drive.file, which reaches only files this application itself created for you — not the rest of your Drive. Calendar access is calendar.app.created, which reaches only a secondary calendar this application itself created; it cannot see your primary calendar or any event this app did not write. Either can be revoked at any time from your Google Account settings.
Limited Use. VisionAI Workspace's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. The use of raw or derived user data received from Workspace APIs will adhere to the Google User Data Policy, including the Limited Use requirements.
We do not train models on your data. We do not use Google user data — raw, aggregated, anonymized or derived — to create, train, or improve any machine learning or artificial intelligence model of our own, and we never sell it or transfer it for advertising.
One open question, stated plainly rather than left out. Content is processed by third-party AI providers to carry out your requests, and those providers set their own terms. Google's Gemini API states that on its free tier, submitted content may be used to improve Google's products and models. We have asked Google directly whether routing content that originated in your Google Sheet through their own Gemini API falls within the Limited Use requirements, and we will update this policy with their answer. If it does not, we will either move that integration to a paid tier — where Google states it does not use submitted content to improve its products — or remove it.
Which AI services see your content, and when. Content is sent to an AI provider only to carry out something you asked for — running a worker on a task, generating an image, summarizing or drafting an email — and only for as long as that request takes. The providers currently used are Groq, Google Gemini, Mistral AI, OpenRouter (a gateway that routes to other providers), Cloudflare Workers AI and Hugging Face. We do not operate self-hosted or offline models; each of these is reached over an API.
Gmail (development only). The Gmail integration is presently limited to the platform owner's own account — a server-side check runs before any request reaches Google, so no other user can trigger it or see its consent screen. It requests gmail.modify (reading messages and most write actions — marking read, archiving — but not permanently deleting), https://mail.google.com/ (Gmail's broadest scope, requested solely because permanent delete has no narrower scope available; everything else this integration does works under gmail.modify alone), and gmail.compose (creating, editing and deleting drafts this app itself created — no code path sends mail beyond that). Message bodies are read live from Google and are not copied to our database. An email you explicitly attach to an orbit or a task is copied into your own Google Sheet — the same file that already stores the rest of your workspace — not to our servers. Two AI-generated artifacts derived from a message you asked to summarize or suggest a task from — the summary and the suggestion — are stored in our database per message so they don't have to be regenerated on every visit; nothing else about a message's content is retained.
La autenticación se gestiona a través de Google OAuth y es administrada por Supabase, nuestro proveedor de infraestructura de autenticación. Supabase almacena tus tokens OAuth de forma segura para mantener la continuidad de la sesión. VisionAI Workspace no tiene acceso a tu contraseña de Google ni a ninguna credencial más allá de los tokens OAuth necesarios para operar tu espacio de trabajo. Las sesiones están vinculadas a tu uso activo de la plataforma.
Cookies: VisionAI Workspace utiliza únicamente cookies de sesión esenciales. Estas cookies son necesarias para la autenticación y para mantenerte conectado durante tu sesión. No usamos cookies publicitarias, píxeles de seguimiento ni cookies de análisis de terceros. Las cookies esenciales no pueden desactivarse sin romper la funcionalidad principal de la plataforma.
La versión beta actual de VisionAI Workspace es gratuita y no requiere información de pago. Cuando se introduzcan funciones Pro de pago, toda la facturación será gestionada por un procesador de pagos seguro de terceros. VisionAI Workspace nunca almacenará tu número de tarjeta de crédito, datos bancarios ni ninguna credencial de pago directamente. La identidad del procesador de pagos se divulgará cuando se lancen las funciones de pago.
Dado que los datos de tu espacio de trabajo viven en tu propio Google Drive, persisten mientras elijas mantenerlos ahí. Además de la información de tu cuenta (nombre, correo, tokens OAuth vía Supabase), también conservamos los datos operativos necesarios para hacer funcionar la plataforma — registros de uso y fiabilidad, registros de programación y notificaciones, historial de pagos de cualquier paquete comprado, y cachés de rendimiento de corta duración de tu contenido de espacio de trabajo (se borran automáticamente en un plazo de 24 horas). Si solicitas la eliminación de tu cuenta, eliminaremos estos datos de Supabase. Tu Google Sheet y cualquier archivo en tu Drive son tuyos y debes eliminarlos directamente.
Tienes derecho a:
VisionAI Workspace está destinado a adultos y no está dirigido a menores de 18 años. No recopilamos intencionalmente información personal de menores de 18 años. Si crees que un menor de 18 años nos ha proporcionado datos personales, contáctanos y tomaremos medidas para eliminarlos.
A medida que VisionAI Workspace crezca más allá de la beta, esta política de privacidad se actualizará para reflejar nuevas funciones, proveedores y requisitos legales. Notificaremos a los usuarios activos sobre cambios materiales por correo electrónico o un aviso en la aplicación. El uso continuado de la plataforma después de los cambios constituye la aceptación de la política actualizada.
Whose Drive shared content is written to. A workspace can have more than one person in it: an owner, and the crew they invite. The owner’s Google Drive is the system of record for the whole workspace. When a crew member uploads a file or an image to a conversation, or an AI worker produces an artifact for one of the workspace’s orbits, that content is written to the owner’s Drive under the owner’s Google account — never to the crew member’s own Drive. One consequence is worth stating plainly rather than leaving to be discovered: because attachments are stored in the owner’s Drive, a workspace owner may be able to see a file that was attached to a conversation they are not a member of, even though the conversation itself is not readable by them.
What we store for messaging. Conversation membership, message text, attachment references, emoji reactions, read state and your per-conversation notification preference are stored in our Supabase Postgres database rather than in Google Drive. Row-level security restricts reads to the members of a conversation. Typing indicators and who is currently viewing a conversation are broadcast live between connected clients and are not stored at all.
Who can see a message. An orbit’s crew room is readable by everyone the owner has granted that orbit to, and its membership is kept in step with that grant automatically. A direct message is readable only by its participants, and can only be started between people who share at least one orbit — with the exception of the workspace owner, who is reachable by anyone in their workspace and may group any of their crew together.
Notifications carry part of the message. When a message needs to reach somebody who is not looking at the app, the notification contains the sender’s name, the orbit’s name or an indication that it is a direct message, and the first 90 characters of the message body. Depending on your settings that is delivered in-app, by email through Brevo, and as a web push notification through your browser or operating system’s push service. If you would rather message content did not leave the app that way, set a conversation to Quiet or Muted using the bell in its header.
Messages are not sent to AI providers. Conversations between people in a workspace are not routed to any AI model. Content reaches an AI provider only when somebody explicitly runs a worker on a task, as described in Section 4.
Deleting, and leaving a workspace. Deleting a message clears its text and its attachment references from our database; the underlying file already written to the workspace owner’s Drive is not removed by that action and has to be deleted from Drive by its owner. If an owner withdraws your access to the last orbit you hold in their workspace — including by archiving that orbit — your membership ends and you lose access to that workspace’s orbits, rooms and message history. Messages you sent and files you uploaded stay with the workspace. Deleting your own VisionAI Workspace account removes your account data from our systems; it does not retract content you contributed to somebody else’s workspace.
Si tienes preguntas sobre esta política de privacidad, tus datos o cómo VisionAI Workspace maneja tu información, comunícate directamente:
Enviar una Solicitud de Privacidad