Privacy Policy

Last updated: August 30, 2026

This Privacy Policy explains how Authaz Tecnologia da Informação LTDA, with its registered office at Rua Pais Leme 215, Conj. 1713, São Paulo–SP 05424-150, Brazil, processes account information and observability telemetry when operating Vight. Customers control what telemetry their applications send and should configure instrumentation to avoid unnecessary personal or sensitive data.

Data we collect

We process account and workspace information such as names, email addresses, authentication identifiers, team memberships, roles, subscription status, and billing customer identifiers. Telemetry may include traces, metrics, logs, service and deployment metadata, network and database attributes, timestamps, and error details. We also collect limited security, usage, and diagnostic records needed to operate the service.

How we use data

We use data to authenticate users, enforce tenant boundaries, ingest and display telemetry, detect incidents, deliver alerts, administer subscriptions, prevent abuse, troubleshoot failures, and improve reliability. We process customer telemetry to perform our contract with the customer and process security and operational records for our legitimate interest in protecting and improving the service. Where consent is legally required, we request it separately.

Sub-processors and storage

Vight currently uses Vercel for the web control plane, Railway for application services, PostgreSQL, and Redis, ClickHouse Cloud for telemetry storage and analytics, Authaz for identity and authorization, Stripe for payments, and configured email, Slack, or webhook providers for notifications. Production workloads may be processed in the United States and European Union. We use contractual and technical safeguards when data crosses borders.

Retention and security

Telemetry is retained for the periods displayed in the customer's plan and workspace settings, after which ClickHouse expiration policies remove it. Account, billing, and incident records are retained while the workspace is active and as needed for legal, security, and accounting obligations. Encrypted transport, scoped credentials, tenant-aware queries, backups, monitoring, and access controls are used to protect data, but no service can guarantee absolute security.

Sharing and disclosure

We do not sell personal information. We disclose data to the service providers listed above only as needed to operate Vight, to a successor in a corporate transaction subject to appropriate safeguards, when instructed by the customer, or when legally required. Notification webhooks deliver the content and destination a workspace administrator configures.

Your choices and rights

Workspace administrators can control team access, revoke ingestion keys, set available retention policies, and stop telemetry collection in their applications. Depending on applicable law, individuals may request access, correction, export, restriction, objection, or deletion of personal information. Send requests to support@vight.io; we may need to verify identity and coordinate with the customer that controls the workspace.

Changes and contact

We may update this policy as Vight and its providers change. We will update the date above and provide additional notice for material changes when required. Authaz Tecnologia da Informação LTDA is the operator responsible for this policy. Privacy and data-protection questions, including sub-processor or deletion requests, may be sent to support@vight.io or to our registered office above.

Questions about this page? support@vight.io