01Signing in
Vessero has no passwords of its own: Google is the only way in, so your account is as well protected as your Google Account, two-step verification included. We ask Google only for the basic sign-in details, never see your Google password, and keep no Google access or refresh tokens. A suspended account is refused at sign-in.
02Your session
Once you are signed in, your session is a signed token in an HTTP-only cookie: scripts running in a page cannot read it, and it cannot be altered without the signature failing. What you can see and change is decided on the server for every request, never in the browser.
03Your work and files
Boards, generations and uploads are private to your account unless you share them. A board is shared by adding people as editors or viewers, or by an invite link you can revoke at any time.
Media is kept in object storage and served through signed links that expire, so a link that leaks does not stay open forever. Traffic is encrypted in transit, and storage is encrypted at rest by the provider. Product pictures you import or upload are re-encoded, which strips location and other hidden metadata from them.
04Payments
Payments are handled by Stripe. Your card details go to Stripe directly and never reach our servers.
05Links you give us
When Vessero reads a product page or a picture from a link you paste, the request goes through a guard that refuses private and internal network addresses, so a link cannot be used to reach systems behind our servers.
06Access by our team
Access to accounts is limited to the people who operate the service and answer support, and every administrative action taken on an account is recorded in an audit log.
07Abuse and limits
Requests are rate-limited per account, so no one can overwhelm the service or run up charges in a burst, and anything that spends credits shows its price before it runs.
08Your data
You can download everything in your account, or delete it, from Settings. Delete your data explains how, and the Privacy Policy sets out what we hold and who processes it.
09Reporting a vulnerability
If you find a weakness, email support@vessero.com with "Security" in the subject, the steps to reproduce it and what it lets someone do. We will reply, and keep you told what we are doing about it.
While you look, please do not access or change other people's data, run anything that slows the service down for others, or spend credits that are not yours, and give us a reasonable time to fix a problem before you describe it publicly. The same contact is in our security.txt.