Privacy Policy
Last updated: September 1, 2026
Vigilimate AI is a training and compliance platform. This policy explains what personal information we handle, why, and what rights you have. It covers the Vigilimate AI website, the learner and administrator web portal, and the Vigilimate AI mobile apps for iOS and Android.
1. Who controls your information
Most people use Vigilimate AI because their employer or another organization gave them an account. In that case the organization decides what training you are assigned and how long its records are kept, it is the controller of that data, and we process it on the organization's instructions. If you want your information changed or removed, ask that organization first; we will help them act on your request.
Where we decide how information is used ourselves (for example, someone contacting us through this website) we are the controller.
2. Information we collect
Account information. Your name, email address, and password. Passwords are stored only as a salted hash; nobody at Vigilimate AI can read them.
Organization and role. Which organization your account belongs to, and whether you are an owner, manager, or learner there.
Training records. The assignments you are given, the lessons and modules you complete, your assessment attempts and scores, the programs you finish, the certificates and credentials you earn, recertification history, and your signed acknowledgments of policies or waivers. A signed acknowledgment also records the time you signed and, for evidentiary purposes, the device and network address it was signed from.
Support and contact. Anything you send us directly, such as a support request or a form on this site.
Technical and diagnostic data. When the apps or portal encounter an error we collect a crash or error report, which may include your account identifier, device model, operating system version, and app version. We deliberately strip authorization tokens out of these reports before they are sent.
Notification data. If you turn on push notifications, we store a device notification identifier so a reminder can reach that device.
We do not collect your location, we do not use advertising identifiers, and we do not track you across other companies' apps or websites.
3. How we use it
- To give you access to the training your organization assigned, and to record that you completed it.
- To issue and verify certificates and credentials.
- To let your organization's managers see who is compliant and what is outstanding, this is the purpose of the product.
- To send you notices about assignments, due dates, and recertification, if you have enabled them.
- To answer support requests.
- To keep the service working, secure, and free of abuse, and to diagnose faults.
We do not use your training records to advertise to you, and we do not sell personal information.
4. Who we share it with
- Your organization. Managers, administrators, and owners in your organization can see your assignments, progress, completions, and credentials. That visibility is the point of a compliance platform, and you should assume it applies to everything you do in the product.
- A partner who manages your organization's account, where your organization was set up through a reseller or agency.
- Service providers who operate the platform for us, cloud hosting and databases, authentication, error monitoring, email delivery, and push notification delivery. They may process personal information only to provide those services to us, under contract, and may not use it for their own purposes.
- Legal authorities, where we are required by law to disclose, or where disclosure is necessary to protect someone's safety or our legal rights.
We do not sell personal information, and we do not share it for cross-context behavioral advertising.
If you would like the current list of our service providers by name, write to us and we will provide it.
5. How long we keep it
We keep your account information for as long as your account exists.
Training records are kept for as long as your organization needs them. Because Vigilimate AI exists to evidence that required training happened, your organization may be obliged to retain proof of completion even after you leave, for an auditor, a regulator, or an insurer.
6. Deleting your account
You can delete your account yourself: in the mobile app, open Settings → Danger zone → Delete account. In the web portal, contact your organization's administrator or write to us.
When you delete your account we permanently remove your sign-in, your profile, your organization memberships, your assignments, and your lesson, module, and assessment progress. This cannot be undone.
We retain, with your name and identifying details removed, the record that a credential was issued, its recertification history, and the fact that an acknowledgment was signed at a given time. This is deliberate. A certificate carries a public verification link that an auditor or a future employer may already hold, and a signed attestation is evidence your organization is required to keep, neither should disappear because an individual account was closed. What survives says that someone in the organization earned or signed something on a date. It does not say who.
7. Your rights
Depending on where you live, you may have the right to access the personal information we hold about you, correct it, delete it, receive a copy in a portable form, object to or restrict certain processing, and withdraw consent you previously gave. You also have the right not to be discriminated against for exercising these rights.
To exercise any of them, contact your organization's administrator, or write to us at support@vigilimate.com. We may need to verify your identity first. Where your organization is the controller of the data, we will refer your request to them and assist them in answering it.
8. Security
We encrypt data in transit and at rest, isolate each organization's data at the database level so one organization cannot read another's, restrict internal access to those who need it, and monitor for faults and abuse. No system is perfectly secure, but we treat these records as what they are: evidence people rely on.
9. Children
Vigilimate AI is a workplace product and is not directed to children. We do not knowingly collect personal information from anyone under 16. If you believe a child has given us information, write to us and we will delete it.
10. International transfers
We operate in the United States, and information you give us is processed there. If you are outside the United States, using the service means your information is transferred to a country whose data protection laws may differ from your own. Where required, we rely on appropriate safeguards for those transfers.
11. Changes to this policy
If we change this policy we will update the date at the top, and we will tell you in the product before a material change takes effect.
12. Contact us
Questions about this policy, or about the information we hold: support@vigilimate.com.