Privacy & security
viora is built to answer questions, not to watch people.
What viora stores
- Your profile and knowledge base: what you entered and the text of website pages it read.
- Questions visitors asked, with whether they were answered, so you can improve your profile.
- Leads: only what a visitor chooses to type into the lead form.
What viora doesn't store
- No IP addresses. Limits use a one-way code made from the connection and browser, mixed with a secret, that can't be turned back into an address.
- No cookies and no tracking across websites. The widget only remembers, for that browser tab, that it already said hello.
- No conversations attached to a person. History lives in the visitor's browser and is sent only to answer follow-up questions.
Protection against abuse
- Per-visitor limits on questions and messages, and a daily limit per site.
- Allowed websites: set
allowed_originsso only your domains can use your assistant. - Spam protection on sign-up with Cloudflare Turnstile, and a hidden field that catches bots on the lead form.
- Your site key is stored only as a hash. Rotate it from the dashboard if it ever leaks.
Where data lives
viora cloud runs on Cloudflare: Workers for the API, D1 for the database, Vectorize for search and Workers AI for the models. Self-hosted viora keeps everything in one SQLite file on your server; only the text needed for each request goes to the AI provider you chose.
Reporting a problem
Found a security issue? Email hello@incpritech.com. Please don't post it publicly until we've fixed it.