Privacy notice.
This notice explains the limited personal information Virasai AI handles through its public website and email contact route.
Last updated: 17 August 2026
Who this applies to
This notice applies to virasai.com and to messages sent to [email protected]. Virasai AI is commercial work informed by VaHive Systems Lab and is operated by Titiya Ruangkwam trading as Virasai AI, established in Thailand. Titiya Ruangkwam trading as Virasai AI is the data controller for the information described here. For privacy questions or requests, use that email address.
Because we are established in Thailand, Thailand’s Personal Data Protection Act B.E. 2562 (2019) applies to this processing. Where you contact us from somewhere with its own data-protection law, we will handle a request under whichever regime gives you the stronger right rather than arguing about which one applies.
What this site loads
Every page is static and self-contained. It loads no third-party scripts, fonts, images, or embeds; there is no analytics of any kind, no advertising technology, and no tag manager. The site sets no cookies, so there is nothing to consent to and no banner asking you to. This is a property of how the site is built rather than a promise about how it is configured, and you can confirm it from your browser’s network panel.
Pages that link outward — to GitHub, LinkedIn, Medium, X, Substack, Zenodo, or a support link — are ordinary links. Following one takes you to an organisation with its own privacy practices and its own tracking, over which we have no control and from which we receive nothing. This site sends only its own address as the referrer when you follow a link off it.
What we collect
The website offers no accounts, no checkout, no on-site contact form, and no automated mailing-list signup. Every route that reaches us — contact, advisory enquiries, and the architecture waiting list — opens your own email client, so nothing is submitted to this site.
If you email us, we receive the information you choose to include, such as your name, email address, organisation, and enquiry. Cloudflare, which hosts this site, processes basic technical request data such as IP address, request headers, and server logs in order to deliver and protect it. We do not combine that data with anything else, and we do not use it to identify visitors.
The Watch pages contain no personal information
The Watch section publishes evidence about public npm packages: version numbers, file inventories, dependency lists, and artifact digests. It records software, not people. There is no public subscription to it, and we do not hold a list of who reads it.
Why we use it
We use enquiry information to read, respond to, and manage the conversation; to protect the website; and to meet legal obligations where they apply. We do not sell personal information. We do not use enquiry emails to send marketing unless you have clearly asked to receive updates, and you can ask us to stop at any time.
Sharing and international processing
We use the service providers needed to operate email and web hosting, currently Cloudflare for hosting and delivery. They process information on our behalf and operate in more than one country, so serving a page or delivering an email may involve processing outside your own. We do not share enquiry information for another organisation’s marketing. We may disclose information where reasonably necessary to protect rights or security, or where required by law.
Retention and security
We keep routine enquiry correspondence only for as long as needed to respond, maintain a reasonable business record, or meet an obligation. We review it periodically and aim to delete or anonymise routine correspondence within 24 months after the last meaningful contact, unless a longer period is reasonably necessary.
Email is not a secure channel. Please do not send credentials, API keys, secrets, or unnecessary sensitive data — and note that our tools are built not to want them: Sentinel reads public artifacts by name and version and never accepts credentials.
Your choices
You can ask us to access, correct, delete, or stop using personal information we hold about you, and to withdraw a consent you have given, subject to applicable law and any necessary exceptions. You can also object to marketing at any time. Email [email protected] with your request. We may need to confirm your identity before acting on it, and we aim to respond within 30 days.
If you are not satisfied with how we have handled a request, you can complain to the Personal Data Protection Committee in Thailand, or to the data-protection authority where you live. We would rather you told us first, but that route does not depend on our agreement.
Changes
If this site ever introduces analytics, a form, or anything that sets a cookie, this notice and any required consent mechanism will be updated before the change is introduced, not after. We may also update this notice when the website, its providers, or its services change; the date above identifies the current version.