Privacy Policy
This policy describes how VERA handles information. It was written against the actual behavior of the software rather than from a template, so where a common practice does not apply to VERA, it says so instead of staying silent. VERA does not sell personal information, does not run advertising or marketing cookies, and does not use your business data to train AI models.
- Version
- 2.0
- Effective
- July 28, 2026
- Last updated
- July 28, 2026
- Revisions
- 2
On this page (16 sections)
- 1. Two different roles, and why it matters
- 2. Information you provide
- 3. Information collected automatically
- 4. Information from platforms you connect
- 5. How VERA uses information
- 6. AI processing
- 7. Legal bases for processing
- 8. How information is shared
- 9. Where information is stored
- 10. International data transfers
- 11. How information is protected
- 12. How long information is kept
- 13. Your rights and choices
- 14. Children's privacy
- 15. Changes to this policy
- 16. Contact
1. Two different roles, and why it matters
VERA handles information in two capacities, and your rights differ depending on which one applies.
For your own account information, your billing record, and how you use the product, VERA is the controller. This policy governs that data, and you exercise your rights against us directly.
For the information you put into VERA about your customers, leads, contacts, employees, and jobs, you are the controller and VERA is the processor acting on your instructions. This policy describes what we do with it, but the terms are set by the Data Processing Addendum. If you are one of our customers' customers and want your data corrected or deleted, contact the business you dealt with; we will refer you to them and assist them in responding.
2. Information you provide
The following comes directly from you or from your use of the product.
- Account information. Your email address, your name if you supply one, and a bcrypt hash of your password if you sign in with one. VERA never stores your password in a readable form. If you sign in with Google, we receive your email address, name, and profile image from Google instead.
- Business profile. Your business name, industry, services, location, brand voice, brand colors and logo, working hours, and the goals and context you give VERA so it can do useful work. Some of this can be drafted for you by scanning a website address you supply.
- Customer and operational records. Leads, contacts, companies, deals, appointments, jobs, technicians, support tickets, estimates, invoices, and the notes attached to them. This is where personal data about your own customers and staff lives, including names, email addresses, phone numbers, service addresses, and job details.
- Files and images. Photographs you upload (including before-and-after job photos), your logo and brand assets, and invoices or estimates you import from another system. Imported documents are retained together with a copy of the original file so the import can be re-checked.
- Signatures captured from your customers. When your customer accepts an estimate through the public link you sent them, VERA records their typed name or the image of the signature they drew, along with the time and the fact that the link was viewed.
- Prompts and instructions. The goals, questions, and briefs you write for VERA, and the proposals, approvals, edits, and declines you record against them.
- Support and feedback. What you send us when you contact support, and the reason you select if you cancel or let a trial lapse, including any free text you add. Cancellation feedback is treated as your data and is deleted with your account.
- Connected platform credentials. The OAuth tokens and API keys for platforms you connect. These are encrypted at rest with AES-256-GCM and are never displayed back to you or written to logs.
3. Information collected automatically
VERA collects a deliberately small amount of technical information.
- Server logs. Ordinary application and error logs generated while serving requests. These are operational records, not a behavioral analytics product.
- Rate limiting counters. To stop brute-force sign-in attempts and abuse, VERA keeps short-lived counters keyed by IP address or email address for actions such as login, sign-up, and password reset. Each counter is overwritten when its window resets.
- Product usage signals. Counts and timestamps that make the product work and that back your own dashboards: credit usage, when a proposal was approved, when an estimate link was first opened, how many times it was viewed, and daily business metrics computed from your connected platforms.
- Marketing site analytics. Vercel Web Analytics and Vercel Speed Insights measure page views and performance on our public pages. VERA's own custom events are limited to a closed set of values (an industry slug, which surface a card was clicked on, a position, a dwell time in seconds, and a trimmed search term). Email addresses, names, and free-typed content are never sent to analytics by design.
- Audit trail. Every proposal, approval, edit, decline, execution, and failure in your account is written to an append-only audit log, along with security events such as password resets, session revocations, and estimate link rotations. Secrets and tokens are never written to it.
| Category | Status |
|---|---|
| Payment card numbers | Never touch VERA's servers. Stripe collects and stores them. |
| Advertising or cross-site tracking identifiers | Not used. VERA runs no ad pixels or marketing tags. |
| Precise geolocation | Not collected. The Permissions-Policy header disables geolocation, camera, and microphone. |
| Biometric identifiers | Not collected. A drawn signature image is not processed as a biometric template. |
| Government identifiers | Not collected. |
| Data purchased from brokers | Not acquired. |
4. Information from platforms you connect
When you connect a third-party platform, VERA reads the data that platform's permissions describe, and only to perform the work you asked for. You choose which platforms to connect, and disconnecting one revokes VERA's ongoing access and removes the stored credential.
VERA's integration catalog spans roughly 150 providers across accounting, payments, CRM, scheduling, email, communication, marketing, social, ecommerce, shipping, analytics, field service, and more. What each connection reads or writes is shown on its card before you connect it. Broadly:
- Accounting and field service. Customers, estimates, quotes, jobs, invoices, and payments, read-only, so VERA can report on the business and pre-fill documents. QuickBooks Online and Jobber are read-only integrations.
- Stores and payments. Orders, customers, products, and payment records, read-only, to compute revenue, order counts, and average order value.
- Social networks. Publishing the posts you approve, and reading the metrics those platforms expose (impressions, views, engagement, audience insights) so VERA can report on performance. VERA does not post without your approval or an automation rule you configured.
- Email and calendar. Sending the campaigns and messages you approve through your own provider account, reading campaign results, and reading calendar events to schedule around them.
- News and market sources. Industry Radar reads publicly available news through a news API. This uses public sources, not your account data or your customers' data.
5. How VERA uses information
We use information to operate the Service: to authenticate you, to generate drafts and proposals, to execute the actions you approve, to sync and display data from platforms you connect, to build your estimates, invoices, and reports, to meter credit usage, to enforce plan limits and rate limits, to detect and prevent abuse, to provide support, and to send you transactional email about your account.
We use aggregated, non-identifying usage information to understand which parts of the product are useful and where they fail, and to plan what to build next.
We do not sell personal information, do not share it for cross-context behavioral advertising, do not use your business data or your customers' data to train AI models, and do not use the content of your account for marketing to other customers.
6. AI processing
To generate content and analysis, VERA sends the relevant part of your prompt and business context to a third-party AI provider over an API, receives a response, and stores that response in your account. We send what the task needs and no more.
Text generation uses Anthropic's Claude models. Image generation, where configured, uses OpenAI or Google Gemini for the image background; the text and logo overlay is drawn deterministically by VERA and never leaves our servers. Without an AI provider configured, VERA falls back to non-AI output rather than failing.
VERA does not send prompts to AI providers for training, and our providers' commercial API terms do not grant them training rights over API inputs. Providers may retain inputs briefly for abuse monitoring under their own policies, which we do not control. The AI Usage Policy covers this in more detail.
7. Legal bases for processing
Where the UK or EU GDPR applies, VERA relies on the following legal bases for the data it controls:
- Performance of a contract. Creating and maintaining your account, providing the features you subscribe to, processing payment, and providing support.
- Legitimate interests. Securing the Service, preventing fraud and abuse, keeping an audit trail, measuring aggregate product usage, and improving the product. We balance these against your rights and keep the data involved minimal.
- Legal obligation. Retaining financial and tax records, and responding to lawful requests.
- Consent. Optional communications you opt into. You can withdraw consent at any time without affecting processing already carried out.
- Your instructions. For personal data about your own customers, VERA processes on your documented instructions as your processor. Your own legal basis for that data is yours to establish.
9. Where information is stored
VERA runs as a containerized Next.js application against a managed PostgreSQL database. Uploaded photographs, generated images, and imported documents are stored as encoded data inside that same database rather than in a separate object storage service, so there is no additional storage provider holding your files.
Hosting and database infrastructure is provided by the platform providers named on the Subprocessor List. Their default regions are in the United States.
10. International data transfers
VERA operates from the United States and its infrastructure and subprocessors are primarily located there. If you use VERA from outside the United States, your information will be transferred to, stored in, and processed in the United States, which may not offer the same level of legal protection as your home country.
For transfers of personal data out of the European Economic Area, the United Kingdom, or Switzerland, VERA relies on the European Commission's Standard Contractual Clauses, incorporated by reference into the Data Processing Addendum, together with the UK International Data Transfer Addendum where the UK GDPR applies.
VERA has not certified to the EU-US Data Privacy Framework, and does not claim any adequacy decision applies to it directly. Some of our subprocessors have their own certifications; that is their status, not ours.
11. How information is protected
Traffic is served over HTTPS, plain HTTP requests are redirected in production, and HSTS is asserted. Passwords are hashed with bcrypt with a work factor of 12 (src/lib/password.ts). Connector credentials are encrypted with AES-256-GCM (src/lib/crypto.ts) using a key held separately from the session-signing secret. Every request is scoped to the signed-in account, and sessions can be revoked across every device at once.
Inbound webhooks are verified against each provider's signature scheme and deduplicated so a replayed delivery cannot be applied twice. Server-side fetches of addresses you supply are validated against private and internal ranges to prevent them being pointed at internal systems. Public estimate links use 256 bits of cryptographically secure randomness, are throttled against guessing, and are never written to logs in full.
No system is perfectly secure, and VERA holds no security certification. The Security Policy lists exactly which controls are in place and, just as importantly, which common controls are not yet.
12. How long information is kept
In summary: your account data is kept for as long as your account exists, and is hard-deleted when you delete the account. VERA runs almost no automated deletion of your data; the one scheduled prune is Industry Radar news articles, removed after 30 days.
The Data Retention Policy gives the full table, including what survives account deletion and why.
13. Your rights and choices
You can review and correct your business profile, brand details, and records directly in the app. You can disconnect any integration from Settings. You can export a machine-readable copy of your account data from Settings. You can permanently delete your account from Settings, which is immediate and irreversible.
Depending on where you live, you may also have statutory rights of access, correction, deletion, portability, restriction, objection, and the right not to be discriminated against for exercising them. The GDPR Privacy Rights page and the California Privacy Notice explain how to exercise them and how we verify a request.
To make a request that the app itself cannot service, write to support@myvera.io. We respond within the time the applicable law requires, and within 30 days where no specific period applies.
14. Children's privacy
VERA is a business tool sold to businesses. It is not directed to children, we do not knowingly collect personal information from anyone under 18, and no part of the product is designed for or marketed to minors. Account holders must be at least 18 or the age of majority in their jurisdiction.
If you believe a child has provided us with personal information, write to support@myvera.io and we will delete it. If you use VERA in a business that serves families, remember that any information about a minor you enter as a customer record is data you control, and your own obligations under laws such as COPPA apply to it.
15. Changes to this policy
We may update this policy. Material changes are recorded in the change history at the bottom of this page with a new version number and effective date, and account holders are notified by email or in-app notice before the change takes effect where practicable.
16. Contact
Privacy questions and rights requests: support@myvera.io. VERA has not appointed a data protection officer or an EU or UK representative under Articles 27 and 37 of the GDPR; whether one is required depends on the scale of our EU and UK processing, and it is on the list of items for legal review.
Change history
Every revision of this document, newest first. Material changes are notified to account holders before they take effect where practicable.
- v2.0July 28, 2026
Rewritten following a full codebase audit. Added controller and processor roles, the specific data inventory, a list of what is deliberately not collected, legal bases, storage location, international transfers, and links to the retention, deletion, GDPR, and California notices.
- v1.0July 7, 2026
Initial Privacy Policy published.
Questions about this document?
Legal and contracts: support@myvera.io. Privacy and data rights: support@myvera.io. Security reports: support@myvera.io.
Related
This document is a carefully drafted policy written against how VERA actually works. It is not legal advice, and it should be reviewed by a licensed attorney in your jurisdiction before you rely on it.
