Cập nhật lần cuối: May 2026 · VisionAI Workspace Beta
Nội dung Orbit của bạn nằm trong Google Drive của bạn, đây là bản ghi chính. VisionAI Workspace đọc và ghi vào đó khi bạn đang sử dụng nền tảng, chỉ giữ lại bộ nhớ đệm ngắn hạn (tự động xóa trong vòng 24 giờ) cùng với dữ liệu tài khoản/sử dụng để vận hành dịch vụ. Nội dung thực sự của bạn vẫn ở trong Drive của bạn, dưới sự kiểm soát của bạn.
VisionAI Workspace được thiết kế để bạn sở hữu dữ liệu của mình. Chúng tôi chỉ thu thập mức tối thiểu cần thiết để cung cấp dịch vụ:
Chúng tôi sử dụng dữ liệu thu thập chỉ để vận hành nền tảng VisionAI Workspace:
Khi đăng nhập, VisionAI Workspace yêu cầu quyền OAuth để truy cập Google Sheets, Google Drive (chỉ tạo file) và Google Docs thay mặt bạn. Quyền truy cập này chỉ được dùng để:
Quan trọng: Nếu bạn thu hồi quyền truy cập Google Drive của VisionAI Workspace bất cứ lúc nào, nền tảng sẽ không thể tiếp cận workspace và sẽ ngừng hoạt động cho đến khi quyền truy cập được khôi phục. Dữ liệu của bạn trong Google Drive vẫn là của bạn và không bị ảnh hưởng.
VisionAI Workspace sử dụng kiến trúc AI đa nhà cung cấp được thiết kế để mở rộng theo thời gian. Khi bạn gửi nhiệm vụ, nội dung prompt được xử lý tạm thời bởi một trong các nhà cung cấp AI sau để tạo phản hồi — chính xác là nhà cung cấp nào tùy theo từng yêu cầu:
VisionAI Workspace không lưu giữ bản sao prompt hoặc kết quả AI ngoài Google Sheet của bạn. Tuy nhiên, mỗi nhà cung cấp AI bên thứ ba có thể ghi nhật ký hoặc xử lý dữ liệu đầu vào tạm thời theo chính sách bảo mật riêng. Chúng tôi khuyến nghị xem xét chính sách bảo mật của từng nhà cung cấp nếu bạn có lo ngại.
Để gửi email giao dịch và tài khoản (như xác nhận danh sách chờ, thông báo và lời mời), VisionAI Workspace sử dụng Brevo, nhà cung cấp dịch vụ gửi email bên thứ ba. Khi chúng tôi gửi email cho bạn, địa chỉ email và nội dung tin nhắn của bạn được Brevo xử lý chỉ để gửi email đó. Brevo xử lý dữ liệu này theo chính sách bảo mật riêng. Chúng tôi không sử dụng Brevo cho quảng cáo.
How it is protected. All traffic between your browser, this platform and Google's APIs runs over HTTPS/TLS. Your Google OAuth tokens are stored in our Supabase Postgres database, encrypted at rest, and are read only by server-side code — they are never sent to your browser and never appear in client-side JavaScript. Account records are protected by row-level security so one account cannot read another's, and the elevated key used for server-side work exists only in server environment variables, never in the app bundle.
The narrowest scopes that work. Drive access is drive.file, which reaches only files this application itself created for you — not the rest of your Drive. Calendar access is calendar.app.created, which reaches only a secondary calendar this application itself created; it cannot see your primary calendar or any event this app did not write. Either can be revoked at any time from your Google Account settings.
Limited Use. VisionAI Workspace's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. The use of raw or derived user data received from Workspace APIs will adhere to the Google User Data Policy, including the Limited Use requirements.
We do not train models on your data. We do not use Google user data — raw, aggregated, anonymized or derived — to create, train, or improve any machine learning or artificial intelligence model of our own, and we never sell it or transfer it for advertising.
One open question, stated plainly rather than left out. Content is processed by third-party AI providers to carry out your requests, and those providers set their own terms. Google's Gemini API states that on its free tier, submitted content may be used to improve Google's products and models. We have asked Google directly whether routing content that originated in your Google Sheet through their own Gemini API falls within the Limited Use requirements, and we will update this policy with their answer. If it does not, we will either move that integration to a paid tier — where Google states it does not use submitted content to improve its products — or remove it.
Which AI services see your content, and when. Content is sent to an AI provider only to carry out something you asked for — running a worker on a task, generating an image, summarizing or drafting an email — and only for as long as that request takes. The providers currently used are Groq, Google Gemini, Mistral AI, OpenRouter (a gateway that routes to other providers), Cloudflare Workers AI and Hugging Face. We do not operate self-hosted or offline models; each of these is reached over an API.
Gmail (development only). The Gmail integration is presently limited to the platform owner's own account — a server-side check runs before any request reaches Google, so no other user can trigger it or see its consent screen. It requests gmail.modify (reading messages and most write actions — marking read, archiving — but not permanently deleting), https://mail.google.com/ (Gmail's broadest scope, requested solely because permanent delete has no narrower scope available; everything else this integration does works under gmail.modify alone), and gmail.compose (creating, editing and deleting drafts this app itself created — no code path sends mail beyond that). Message bodies are read live from Google and are not copied to our database. An email you explicitly attach to an orbit or a task is copied into your own Google Sheet — the same file that already stores the rest of your workspace — not to our servers. Two AI-generated artifacts derived from a message you asked to summarize or suggest a task from — the summary and the suggestion — are stored in our database per message so they don't have to be regenerated on every visit; nothing else about a message's content is retained.
Xác thực được xử lý qua Google OAuth và quản lý bởi Supabase, nhà cung cấp cơ sở hạ tầng xác thực của chúng tôi. Supabase lưu trữ an toàn các token OAuth của bạn để duy trì tính liên tục của phiên. VisionAI Workspace không có quyền truy cập vào mật khẩu Google hoặc bất kỳ thông tin xác thực nào ngoài các token OAuth cần thiết. Phiên được gắn với việc sử dụng nền tảng của bạn.
Cookie: VisionAI Workspace chỉ sử dụng cookie phiên thiết yếu. Các cookie này cần thiết cho xác thực và duy trì đăng nhập trong phiên của bạn. Chúng tôi không sử dụng cookie quảng cáo, pixel theo dõi hoặc cookie phân tích bên thứ ba. Cookie thiết yếu không thể tắt mà không làm hỏng chức năng nền tảng cốt lõi.
Phiên bản beta hiện tại của VisionAI Workspace miễn phí sử dụng và không yêu cầu thông tin thanh toán. Khi các tính năng Pro có phí được giới thiệu, tất cả thanh toán sẽ được xử lý bởi bộ xử lý thanh toán bên thứ ba an toàn. VisionAI Workspace sẽ không bao giờ lưu trữ trực tiếp số thẻ tín dụng, chi tiết ngân hàng hoặc bất kỳ thông tin xác thực thanh toán nào. Danh tính của bộ xử lý thanh toán sẽ được tiết lộ khi các tính năng có phí được ra mắt.
Vì dữ liệu workspace của bạn nằm trong Google Drive của riêng bạn, nó sẽ tồn tại chừng nào bạn còn giữ nó ở đó. Ngoài thông tin tài khoản (tên, email, token OAuth qua Supabase), chúng tôi còn lưu giữ dữ liệu vận hành cần thiết để chạy nền tảng — nhật ký sử dụng và độ tin cậy, hồ sơ lên lịch và thông báo, lịch sử thanh toán cho bất kỳ gói mua nào, và bộ nhớ đệm hiệu năng ngắn hạn của nội dung workspace của bạn (tự động xóa trong vòng 24 giờ). Nếu bạn yêu cầu xóa tài khoản, chúng tôi sẽ xóa dữ liệu này khỏi Supabase. Google Sheet và bất kỳ file nào trong Drive của bạn là của bạn và phải được bạn trực tiếp xóa.
Bạn có quyền:
VisionAI Workspace dành cho người trưởng thành và không hướng đến bất kỳ ai dưới 18 tuổi. Chúng tôi không cố ý thu thập thông tin cá nhân từ bất kỳ ai dưới 18 tuổi. Nếu bạn cho rằng người dưới 18 tuổi đã cung cấp cho chúng tôi dữ liệu cá nhân, hãy liên hệ và chúng tôi sẽ thực hiện các bước để xóa nó.
Khi VisionAI Workspace phát triển vượt ra ngoài giai đoạn beta, chính sách bảo mật này sẽ được cập nhật để phản ánh các tính năng, nhà cung cấp và yêu cầu pháp lý mới. Chúng tôi sẽ thông báo cho người dùng hoạt động về các thay đổi quan trọng qua email hoặc thông báo trong ứng dụng. Tiếp tục sử dụng nền tảng sau các thay đổi cấu thành sự chấp nhận chính sách được cập nhật.
Whose Drive shared content is written to. A workspace can have more than one person in it: an owner, and the crew they invite. The owner’s Google Drive is the system of record for the whole workspace. When a crew member uploads a file or an image to a conversation, or an AI worker produces an artifact for one of the workspace’s orbits, that content is written to the owner’s Drive under the owner’s Google account — never to the crew member’s own Drive. One consequence is worth stating plainly rather than leaving to be discovered: because attachments are stored in the owner’s Drive, a workspace owner may be able to see a file that was attached to a conversation they are not a member of, even though the conversation itself is not readable by them.
What we store for messaging. Conversation membership, message text, attachment references, emoji reactions, read state and your per-conversation notification preference are stored in our Supabase Postgres database rather than in Google Drive. Row-level security restricts reads to the members of a conversation. Typing indicators and who is currently viewing a conversation are broadcast live between connected clients and are not stored at all.
Who can see a message. An orbit’s crew room is readable by everyone the owner has granted that orbit to, and its membership is kept in step with that grant automatically. A direct message is readable only by its participants, and can only be started between people who share at least one orbit — with the exception of the workspace owner, who is reachable by anyone in their workspace and may group any of their crew together.
Notifications carry part of the message. When a message needs to reach somebody who is not looking at the app, the notification contains the sender’s name, the orbit’s name or an indication that it is a direct message, and the first 90 characters of the message body. Depending on your settings that is delivered in-app, by email through Brevo, and as a web push notification through your browser or operating system’s push service. If you would rather message content did not leave the app that way, set a conversation to Quiet or Muted using the bell in its header.
Messages are not sent to AI providers. Conversations between people in a workspace are not routed to any AI model. Content reaches an AI provider only when somebody explicitly runs a worker on a task, as described in Section 4.
Deleting, and leaving a workspace. Deleting a message clears its text and its attachment references from our database; the underlying file already written to the workspace owner’s Drive is not removed by that action and has to be deleted from Drive by its owner. If an owner withdraws your access to the last orbit you hold in their workspace — including by archiving that orbit — your membership ends and you lose access to that workspace’s orbits, rooms and message history. Messages you sent and files you uploaded stay with the workspace. Deleting your own VisionAI Workspace account removes your account data from our systems; it does not retract content you contributed to somebody else’s workspace.
Nếu bạn có câu hỏi về chính sách bảo mật này, dữ liệu của bạn hoặc cách VisionAI Workspace xử lý thông tin của bạn, hãy liên hệ trực tiếp:
Gửi Yêu Cầu Bảo Mật