viora by INCPRITECH

Privacy & security

viora is built to answer questions, not to watch people.

What viora stores

  • Your profile and knowledge base: what you entered and the text of website pages it read.
  • Questions visitors asked, with whether they were answered, so you can improve your profile.
  • Leads: only what a visitor chooses to type into the lead form.

What viora doesn't store

  • No IP addresses. Limits use a one-way code made from the connection and browser, mixed with a secret, that can't be turned back into an address.
  • No cookies and no tracking across websites. The widget only remembers, for that browser tab, that it already said hello.
  • No conversations attached to a person. History lives in the visitor's browser and is sent only to answer follow-up questions.

Protection against abuse

  • Per-visitor limits on questions and messages, and a daily limit per site.
  • Allowed websites: set allowed_origins so only your domains can use your assistant.
  • Spam protection on sign-up with Cloudflare Turnstile, and a hidden field that catches bots on the lead form.
  • Your site key is stored only as a hash. Rotate it from the dashboard if it ever leaks.

Where data lives

viora cloud runs on Cloudflare: Workers for the API, D1 for the database, Vectorize for search and Workers AI for the models. Self-hosted viora keeps everything in one SQLite file on your server; only the text needed for each request goes to the AI provider you chose.

Reporting a problem

Found a security issue? Email hello@incpritech.com. Please don't post it publicly until we've fixed it.