Privacy
Last updated 22 September 2026
Controller. Senfina Creative Studio FZC LLC, United Arab Emirates. Contact info@senfina.studio. This notice describes the service as it is built today; when the service changes, this page changes with it.
What VIDECRA is, in one line
A deterministic scenario engine: it runs a shock you state through versioned rules and returns a range. It is not a forecast, not investment advice, and it does not decide anything for you.
What we collect
When you create an account — your email address and the identifier issued by our authentication provider. We do not ask for or store a name, a phone number, an address or a payment method.
What you create in the product — the scenarios you save, the comparisons and briefs you write, the company profiles you enter, the decisions you record and the observations you attach to them. They live in your workspace and are visible to that workspace's members.
Operational logs — for each API request: method, path, scenario family, status code, latency, server instance, and a salted hash of your IP address. The raw address is never written to our database and the hash cannot be turned back into one. For the optional AI narrative we store the run id, the model name, whether the output passed validation, an error heading and the latency — never the text.
On your device — your theme and language preference, and, if you use the product signed out, the scenarios you save locally. These stay in your browser.
What we do not do
- We do not sell or rent personal data.
- We do not build advertising profiles or track you across other sites.
- We do not use your workspace content to train models.
- The AI features send only the numbers and labels of the run you are looking at; the model provider acts as a processor, not a controller.
Legal bases (EEA and UK visitors)
- Contract — running your account and the features you ask for.
- Legitimate interests — keeping the service secure and available, which is what the hashed-address logs above are for.
- Consent — anonymous usage and performance measurement, which you can withdraw at any time below.
Who processes data for us
| Processor | What it does | Where |
|---|---|---|
| Clerk | authentication, session cookies, sign-in emails | United States |
| Neon | the PostgreSQL database holding accounts and workspace content | serverless Postgres |
| Fly.io | hosting the API | Frankfurt region |
| Vercel | hosting the web application; with consent, anonymous usage and performance measurement | global edge |
| Sentry | error reports from the application | United States |
| An LLM API provider | generates the optional AI narrative from a run's numbers | named in the product |
Transfers outside the EEA rely on those processors' standard contractual clauses.
How long we keep things
- Account and workspace content — until you delete it or ask us to delete your account.
- Operational logs — kept for diagnostics. A scheduled purge is not implemented yet; this line will state the period once it enforces one. We would rather say that than print a retention period we do not keep.
- Backups — on our database provider's own schedule.
Your rights
Access, correction, deletion, restriction, objection and portability where the law gives them to you. Write to info@senfina.studio and we answer within 30 days. Today deletion and export are done by hand on request; self-service is on the roadmap. In the EEA or the UK you may also complain to your supervisory authority.
Children
The service is not intended for anyone under 18 and we do not knowingly collect their data.
Changes
Material changes are announced in the product before they take effect.
Your choice
No choice is currently saved.