# Vantage Office Privacy Policy

**Version:** 1.2.4  
**Effective date:** July 27, 2026

Vantage Office is local-first. That1Dev does not receive ordinary local project content merely because you use the desktop application. The sections below explain when data can leave your device.

## Local project and organizer data
Projects, settings, local templates, Calendar data, cached Aegis Mail content, account references, encrypted activation state, and diagnostic logs are stored in the Vantage workspace or application-data directory. Operating-system users, administrators, malware, backups, disk tools, and enabled sync providers may still access data according to their privileges.

## Windows OneDrive and Linux cloud folders
On Windows, you may place the Vantage workspace in your local OneDrive folder. On Linux, you may select a local folder synchronized by Nextcloud, ownCloud, Dropbox, pCloud, Google Drive, MEGA, Syncthing, or another provider. Vantage writes ordinary files to that folder; the provider then processes them under its terms. Cloud storage is distinct from Vantage Continuity encryption.

## Vantage Continuity
Continuity transfers an AES-256-GCM encrypted project package between explicitly paired Windows or Linux devices. Devices, routers, firewalls, and network providers can observe connection metadata. The receiving device obtains decrypted content after the user supplies the one-time transfer information and key.

## Aegis Mail
Gmail and Google Workspace accounts use Google’s system-browser OAuth flow and the read-only Gmail API permission `https://www.googleapis.com/auth/gmail.readonly`. Outlook and Microsoft 365 accounts use Microsoft’s system-browser OAuth flow and delegated Microsoft Graph permissions `User.Read` and `Mail.Read`. Vantage does not request permission through these connections to send, delete, archive, label, or modify messages. The provider processes the sign-in and consent page. Vantage receives access and refresh tokens rather than the provider password, verifies the authorized mailbox, and stores the tokens using operating-system-protected local storage where available.

Yahoo Mail, iCloud Mail, Fastmail, and custom providers use certificate-validated TLS IMAP in the Advanced setup. When a provider requires an app-specific password, users should create one at that provider and must not enter their normal account password. Advanced credentials are sent directly to the selected mail provider and protected locally.

Aegis downloads a bounded number of recent messages for local processing. Synced message content, headers, and imported attachments remain on the device or in the user-selected synchronized workspace. Remote images are blocked by default, active content is not executed, and links pass through Threat Ledger before opening. Removing an account deletes Vantage’s stored authorization and attempts provider revocation where supported, but does not delete provider-side mail and may not delete messages already imported into a project or backup.

## Microsoft account and OneDrive authorization
Microsoft account connection is optional and requires explicit consent. Microsoft processes sign-in, account, OneDrive, and organizational data under Microsoft’s terms. Disconnecting the account removes Vantage’s stored tokens; it does not delete Microsoft account data or files already stored in OneDrive.

## Vantage AI
Local grammar and local design tools do not require network transmission. The managed Cloudflare Workers AI assistant is available without customer endpoint or token setup. Before each connected request, you choose which project areas—such as Page, Grid, Base, Stage, or Proof—Vantage may include. Mail, Calendar, credentials, license keys, encryption keys, unrelated projects, and arbitrary local files are excluded. The Vantage Cloudflare Worker and Cloudflare Workers AI can process the prompt, authorized context, IP address, timestamps, and ordinary service metadata. Included provider credits and availability are limited; connected AI may be temporarily unavailable. Do not authorize confidential content unless your organization permits those providers.

## Online media
Wikimedia Commons searches send the search term and ordinary connection metadata to Wikimedia. GIPHY searches send the search term, rating, API key, and ordinary connection metadata to GIPHY. Selected media, source URLs, creator, license, and attribution may be saved in projects. Users must review rights and attribution.

## Activation and payments
LemonSqueezy processes checkout and payment details under its own policies. Vantage contacts the LemonSqueezy License API directly over HTTPS for activation, validation, and deactivation; no separate Vantage activation backend is required. LemonSqueezy receives the license key, product/variant identifiers, activation instance, status, limits, and validation timestamps. Because LemonSqueezy requires the key for later validation and deactivation, Vantage keeps it only inside operating-system-protected local application state where that protection is available.

## Updates and websites
The app contacts the Vantage Cloudflare release endpoint to retrieve signed update metadata and packages. Cloudflare can process IP address, time, requested file, and ordinary HTTP logs. The Vantage website is designed without analytics or advertising trackers. It uses no cookies by default; hosted checkout providers may use their own cookies after you leave or open checkout.

## Diagnostics and security logs
Vantage can keep local diagnostic and security-decision logs. Logs should avoid credentials, tokens, encrypted content, private mail bodies, and sensitive URL query data. If you voluntarily send logs to support, That1Dev processes what you submit to diagnose the issue.

## Retention and rights
Local data remains until you remove it or your device/provider deletes it. Third-party services keep data under their policies. Depending on your location, you may request access, correction, or deletion of personal information held by That1Dev, subject to verification and lawful retention. Most local-only content is controlled directly by you.

## Security and children
No system is perfectly secure. Maintain updates, backups, strong account recovery, and device encryption. Vantage is not directed to children under the applicable minimum digital-consent age.

## Contact
Privacy requests: **cbusinessact@proton.me**


### Vantage Marketplace online catalog

When Vantage checks or downloads the online Marketplace, the Vantage Cloudflare service receives ordinary network metadata such as IP address, request time, requested package path, and user-agent information. Signed Marketplace objects are stored in a private, Vantage-only Backblaze B2 bucket and are retrieved by the Cloudflare service. No Vantage account, mail credential, license key, project content, Continuity key, or document content is sent for Marketplace catalog or package downloads.
