Privacy Policy
Last updated: August 2026
Verayn is currently operated by an individual developer during an early access phase, not yet a registered company. This policy explains what data is collected and how it is used while that remains the case.
1. What we collect
- Your email address, to create your account and sign you in.
- The prompts you send and the AI responses you receive, so your chat history can be saved and shown back to you.
- Content you add to your work: team chats, sessions, decisions, notes, and agent runs.
- Files (such as PDFs) you choose to upload for AI analysis.
- Basic usage data (which models and features you use, and how much).
- Feedback you send through the app.
- For any tools you connect (see section 4): a secure access token for that account, stored encrypted, plus the specific data the AI reads from it while helping you.
- Signals your Echo learns from your own activity (see section 5).
2. How your data is used, and the AI providers involved
Your prompts and related content are sent to one or more third-party AI providers to generate responses. Verayn uses several different models rather than a single one, and different requests may go to different providers; these are reached through an AI routing service (OpenRouter). We use your data to run the features you use, personalize your Echo, and keep your history. We do not sell your data. If you use Discover, you can choose to share a prompt and its AI response; when you do, your name, email, and account are not shown to other users.
3. Where your data is stored
Data is stored using Supabase (database) and processed through Vercel (hosting) and OpenRouter and its model providers (AI access). Connected tools you authorize are accessed through their own providers. These providers may store or process data outside your home country.
4. Connected accounts (Connectors)
You can connect third-party accounts such as GitHub or email. When connected, the AI can read from that account to help with your work (for example, reading recent items or files), and the relevant content is sent to the AI provider as part of generating a response, the same as any other prompt content. Reading is used only to carry out what you ask. Any action that would change something in a connected account requires explicit human approval first and is never automatic. Your access token is stored encrypted and is used only to perform the reads and approved actions you request. You can disconnect any account at any time, which stops further access.
4a. Google user data (Gmail and Google Drive)
If you connect Gmail, Verayn requests only the “gmail.metadata” scope: message headers (sender, recipients, subject, date) and labels. We never request or access message bodies, attachments, or the ability to send email. This access is read-only, used only to provide the in-product features you explicitly invoke, and revocable at any time by disconnecting the account.
If you connect Google Drive, Verayn requests only the “drive.readonly” scope: listing and searching your files and reading their content (for example a Google Doc you ask the assistant to use). We never request the ability to create, change, or delete files. This access is read-only, used only to provide the in-product features you explicitly invoke, and revocable at any time by disconnecting the account.
Verayn’s use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We do not transfer this data to third parties except as needed to provide the service or as required by law; we do not use it for advertising; and no humans read it except with your explicit consent, for security, or as required by law. Connector tokens are encrypted at rest.
5. Your Echo (personal AI)
Your Echo is a personal profile that learns from your own conversations and choices so the AI can respond more like you. Your Echo is private to you. It is not shared with your team, and other users cannot see it. You can view what it has learned, edit it, and reset it from your settings. Your Echo can act on your behalf inside your team (for example, weighing in on a team question) only in ways you have set up, and only its output is shown, not the underlying learning data.
6. Teams: what is private vs shared
- Shared with your team: content you create in a team, including team chats, sessions, team decisions, notes, and agent runs, is visible to the other members of that team.
- Private to you: personal (non-team) chats, your account details, and your Echo and its learning data are not shared with your team.
7. Agent runs
Agents are longer AI tasks that run inside a team session. Their progress and results are visible to your team. Like connectors, any action an agent wants to take in the outside world pauses for human approval before it happens.
8. Data retention and deletion
- Deleting your account: you can permanently delete your account and its data at any time from Settings. This removes your personal chats, your Echo and its learning, your uploaded files, your connector links and stored tokens, and your account record.
- Leaving a team: if you leave a team, your private data and Echo remain yours and are unaffected. Content you contributed to the team’s shared space (team chats, decisions, agent runs) remains with the team so it keeps working, unless the team or its owner deletes it.
- Some records may persist briefly in encrypted backups before being overwritten, and providers may retain limited logs as part of their own operations.
9. Children
Verayn is not directed at children. You must be at least 16 years old, or the minimum age required in your country if that is higher, to use it, and we do not knowingly collect data from children under that age.
10. Changes
This policy may be updated as the product evolves, especially once a formal company structure is in place. Material changes will be reflected here with an updated date.
11. Contact
Questions about this policy can be sent through the “Send Feedback” option in the app, or by email at verayn.app@gmail.com.