Local workspaces
Vector Desktop is designed to keep repositories, sessions, preferences, checkpoints, browser state, and workspace metadata on your computer. Vector does not require a website account and does not upload your repository as part of ordinary local use.
Model and tool providers
Prompts, selected files, tool results, or other context may be sent to the model and integration providers you choose. Their privacy policies apply. Vector does not centrally store your model API keys as part of the license service.
Billing and license data
Stripe processes payment details. Vector receives and stores the billing email, Stripe customer and subscription identifiers, subscription status, renewal state, license metadata, a hashed activation token, a one-way device identifier derived from stable hardware and system characteristics of the computer you activate, device name/platform, and recent verification timestamps. Vector does not receive your full card number.
Purchase email
Resend delivers the purchase confirmation and license key. The message contains your billing email, license key, expiration date, and purchase link. Resend processes that delivery under its own privacy terms.
Local memory
Vector can keep durable notes about how you work — conventions you follow, corrections you have made, preferences you have stated — so it does not have to re-ask across projects. This is a plain file in your own configuration directory on your computer. It is never uploaded to Vector. Its contents are included in prompts sent to the model provider you have chosen, in the same way your other project context is. You can view the file, see its size and location, and erase it entirely from Settings.
Help assistant
When you ask the in-app help assistant a question, your question and the matching sections of Vector's own documentation are sent to a Vector-operated endpoint and forwarded to Groq, which generates the answer. Your repository, files, and session contents are not sent. Groq processes that request under its own privacy terms. To prevent abuse, Vector temporarily stores a keyed, non-reversible identifier derived from the request's network address; the counter expires after ten minutes.
Bug reports
If you send a bug report from inside Vector, the description you write is delivered by email to Vector support, together with your application version, operating system, processor architecture, and release channel, and your email address if you choose to provide one. Nothing else is attached. Short-lived abuse-prevention counters use keyed identifiers derived from the request's network address and, when supplied, a one-way identifier derived from the reporter email.
Screen and desktop control
Optional plugins can capture the screen or control the mouse and keyboard. These run on your computer, only after you connect the plugin, and only when you ask an agent to use them. Your operating system additionally requires you to grant screen recording and accessibility permission before they can function. Screenshots taken this way may be sent to the model provider you have chosen so it can act on what is shown.
Diagnostics
Remote crash diagnostics are disabled by default. If you explicitly enable them in Settings, Vector uses Sentry to receive the application version, operating system, stack traces, and technical error state. Vector disables default personally identifiable information and performance tracing and removes request, user, breadcrumb, and extra fields before transmission. Vector does not intentionally attach repository files, prompts, terminal output, or provider credentials. You can turn remote diagnostics off at any time. Local crash dumps remain on your computer.
Connected cloud services
When you connect Vercel, Netlify, Supabase, GitHub, GitLab, an MCP server, or another provider, Vector sends only the requests needed for the operation you approve. Provider credentials are stored by the desktop application, and each provider's own privacy terms apply.
Security and retention
Packaged Vector builds protect provider credentials and the local credential-vault key with the operating system's credential store and stop with a visible error when secure storage is unavailable. Activation tokens are stored locally in a restricted application file. Server-side billing records store hashes rather than plaintext activation tokens. Purchase, subscription, payment-failure, and license records are retained as needed to provide access, prevent abuse, resolve disputes, and satisfy legal obligations. Abuse counters expire automatically at the end of their stated rate-limit windows.
Your choices
You can disconnect providers, remove local data, cancel renewal, and deactivate a computer from Vector. For billing or privacy requests, contact krishnabharadwaj0521@gmail.com.