The short version. Vorkar is a diagnosis layer that reads your systems on demand — it is not a data
warehouse and does not bulk-copy your business records to keep. You control what it may connect to,
and you control what may ever be sent to a language model. Credentials are encrypted at rest,
traffic is encrypted in transit, and every credential change, action and filter decision is audited.
1. Who we are
Vorkar is a product of Share Slate Inc. ("Share Slate", "we", "us"), a company incorporated in the United States. Vorkar is a US product, developed and operated from the United States. We serve customers globally, including in Europe. For anything in this policy, contact privacy@vorkar.io.
For personal data in your connected business systems, you are the data controller and Share Slate acts as your processor. For the account and website data described below, Share Slate is the controller.
2. What we collect
a. Account data
- Your email address and role (admin/developer or consumer), and a password stored only as a bcrypt hash — we never store or see your password.
- Session tokens (signed JWTs) issued when you sign in.
b. Connection configuration
- The systems you connect: names, protocols, endpoints, and the credentials or OAuth tokens needed to reach them. These are encrypted at rest and are never returned to your browser.
- Discovered schema (object and field names) so rules and questions can use real fields.
c. Your business data
- Vorkar queries your systems on demand to answer a question or run a check. Results are returned to you and used to produce the answer. Vorkar is not a warehouse and does not bulk-copy your records for its own storage.
- Some operational records are retained so the product can function and be auditable: chat sessions and their answers, detected incidents, execution/run history, and action records.
d. Website & forms
- If you submit the Contact or Support form, we store what you send us — name, company, role, work email and your message — with a timestamp, so we can reply.
- Our web server keeps standard access logs (including IP address) for security and abuse prevention. Secrets are redacted from logs.
- We do not use advertising cookies or third-party marketing trackers on this site.
3. How we use it
- To authenticate you and keep your session active.
- To connect to the systems you configure and answer the questions you ask.
- To detect incidents, produce reports, and maintain the audit trail.
- To reply to your Contact/Support messages, and for billing and account administration.
- To keep the service secure and prevent abuse.
We do not sell your data. We do not use your business data to train models.
4. Language models and your data
Answering a plain-English question involves sending the relevant query results to a third-party large-language-model provider to interpret the question and phrase the answer. This is central to how Vorkar works, and you control it:
- The record filter runs before anything reaches the model. You author rules — per system+object, per business entity, or per field — for data that must never be sent. Matching records are still processed and counted; only their content is withheld, and the answer tells you how many were withheld.
- Field-level rules redact a named field (and its per-system aliases) everywhere it appears.
- Every exclusion is audited by what, which rule, which system — never the sensitive value itself.
If you connect a system and author no rules, the query results for the questions you ask will be sent to the model. That is a configuration choice you make, and the product states it plainly.
5. Data residency — self-hosted vs cloud
Self-hosted / your own infrastructure: if you run Vorkar on infrastructure you control, your account data, connection configuration and operational records stay in the region and environment you chose. Share Slate does not receive them. Calls to the LLM provider still leave your network unless you configure otherwise.
Vorkar cloud: if we host it for you, the service and its data are currently hosted in Amazon Web Services in India (ap-south-1) and administered from the United States. Personal data may therefore be transferred to and accessed from the United States and India.
If your organisation requires a specific region (e.g. EU-only hosting), tell us before you start — email
sales@vorkar.io. We will not claim a residency guarantee we haven't actually configured for you.
6. Security
- In transit: HTTPS/TLS across the site and the platform, with HTTP redirected to HTTPS.
- At rest: connection credentials and OAuth tokens are encrypted using Fernet (AES-128-CBC with HMAC-SHA256 authentication) and decrypted only at the point of use. Passwords are bcrypt-hashed.
- Per environment: each environment holds its own credentials. There is no silent fallback to another environment's secrets — an unconfigured environment says so.
- Least privilege: Vorkar reads by default. Writes only happen through propose → approve → execute → undo, with a human approval and an audit record.
- Audit: credential changes, deployments, actions, filter decisions and admin operations are recorded with actor and timestamp.
- Sessions: signed JWTs with a 12-hour idle timeout and sliding renewal. Login is rate-limited.
- Logs: secrets are redacted from application logs.
No system is perfectly secure, and we won't pretend otherwise. We hold no security certifications (e.g. SOC 2, ISO 27001) at this time and do not claim any. If you need specific controls or evidence, ask us before you buy.
7. Retention
- Account data: for as long as your account exists, then deleted on request.
- Connection credentials: until you remove the connection or environment.
- Operational records (sessions, incidents, run history, audit): retained while your account is active so the product remains auditable. Audit records are append-only.
- Contact/Support submissions: kept while we handle your enquiry and for a reasonable period afterwards for our records.
- Access logs: short-lived, for security and abuse prevention.
8. Sharing
We share data only with service providers needed to run Vorkar:
- Cloud hosting (Amazon Web Services) — for the hosted service.
- LLM provider — for the query results sent to answer your questions, subject to your record filter (section 4).
- Email routing (Cloudflare) — to receive mail sent to our @vorkar.io addresses.
- Where required by law, or to protect our rights, users or the service.
We do not sell or rent personal data, and we run no advertising trackers.
9. Your rights
Subject to applicable law, you may request access to, correction of, deletion of, or a copy of your personal data, and you may object to or ask us to restrict certain processing. Email privacy@vorkar.io and we will respond within a reasonable period, and within any period the law requires.
EU / UK (GDPR)
If you are in the European Economic Area or the UK:
- Our legal bases are contract (providing the service you signed up for), legitimate interests (securing the service, replying to your enquiry) and consent where it applies.
- For personal data inside your connected systems, you are the controller and we act as processor on your documented instructions.
- Share Slate Inc. is a US company and the hosted service currently runs in AWS India — so your data may be transferred outside the EEA/UK. Where such transfers require a safeguard, we rely on the European Commission's Standard Contractual Clauses. We will sign a Data Processing Addendum incorporating them on request: privacy@vorkar.io.
- You have the right to lodge a complaint with your local supervisory authority.
- We have not appointed an EU representative under Article 27; if that is a requirement for your organisation, contact us before purchasing.
California
We do not sell or share personal information as those terms are defined under the CCPA/CPRA. You may exercise access and deletion rights via privacy@vorkar.io, and we won't discriminate against you for doing so.
10. Children
Vorkar is a business product and is not directed to anyone under 16. We don't knowingly collect their data.
11. Changes
If we change this policy we'll update the date at the top, and tell account holders directly if the change is material.
12. Contact
Share Slate Inc. — Vorkar
Privacy: privacy@vorkar.io
General: contact@vorkar.io ·
Support: support@vorkar.io
This policy describes our practices; it isn't legal advice.