Privacy

Last updated 22 September 2026

Controller. Senfina Creative Studio FZC LLC, United Arab Emirates. Contact info@senfina.studio. This notice describes the service as it is built today; when the service changes, this page changes with it.

What VIDECRA is, in one line

A deterministic scenario engine: it runs a shock you state through versioned rules and returns a range. It is not a forecast, not investment advice, and it does not decide anything for you.

What we collect

When you create an account — your email address and the identifier issued by our authentication provider. We do not ask for or store a name, a phone number, an address or a payment method.

What you create in the product — the scenarios you save, the comparisons and briefs you write, the company profiles you enter, the decisions you record and the observations you attach to them. They live in your workspace and are visible to that workspace's members.

Operational logs — for each API request: method, path, scenario family, status code, latency, server instance, and a salted hash of your IP address. The raw address is never written to our database and the hash cannot be turned back into one. For the optional AI narrative we store the run id, the model name, whether the output passed validation, an error heading and the latency — never the text.

On your device — your theme and language preference, and, if you use the product signed out, the scenarios you save locally. These stay in your browser.

What we do not do

  • We do not sell or rent personal data.
  • We do not build advertising profiles or track you across other sites.
  • We do not use your workspace content to train models.
  • The AI features send only the numbers and labels of the run you are looking at; the model provider acts as a processor, not a controller.

Legal bases (EEA and UK visitors)

  • Contract — running your account and the features you ask for.
  • Legitimate interests — keeping the service secure and available, which is what the hashed-address logs above are for.
  • Consent — anonymous usage and performance measurement, which you can withdraw at any time below.

Who processes data for us

ProcessorWhat it doesWhere
Clerkauthentication, session cookies, sign-in emailsUnited States
Neonthe PostgreSQL database holding accounts and workspace contentserverless Postgres
Fly.iohosting the APIFrankfurt region
Vercelhosting the web application; with consent, anonymous usage and performance measurementglobal edge
Sentryerror reports from the applicationUnited States
An LLM API providergenerates the optional AI narrative from a run's numbersnamed in the product

Transfers outside the EEA rely on those processors' standard contractual clauses.

How long we keep things

  • Account and workspace content — until you delete it or ask us to delete your account.
  • Operational logs — kept for diagnostics. A scheduled purge is not implemented yet; this line will state the period once it enforces one. We would rather say that than print a retention period we do not keep.
  • Backups — on our database provider's own schedule.

Your rights

Access, correction, deletion, restriction, objection and portability where the law gives them to you. Write to info@senfina.studio and we answer within 30 days. Today deletion and export are done by hand on request; self-service is on the roadmap. In the EEA or the UK you may also complain to your supervisory authority.

Children

The service is not intended for anyone under 18 and we do not knowingly collect their data.

Changes

Material changes are announced in the product before they take effect.

No choice is currently saved.