Privacy Policy

This policy describes how VERA handles information. It was written against the actual behavior of the software rather than from a template, so where a common practice does not apply to VERA, it says so instead of staying silent. VERA does not sell personal information, does not run advertising or marketing cookies, and does not use your business data to train AI models.

Version
2.2
Effective
August 28, 2026
Last updated
August 28, 2026
Revisions
4
On this page (21 sections)
  1. 1. Two different roles, and why it matters
  2. 2. Information you provide
  3. 3. Location information
  4. 4. Time in the app, and what the account holder can see
  5. 5. Microphone and voice
  6. 6. Information collected automatically
  7. 7. Information from platforms you connect
  8. 8. Team members and employees
  9. 9. How VERA uses information
  10. 10. AI processing
  11. 11. Legal bases for processing
  12. 12. How information is shared
  13. 13. Mobile phone numbers and text messaging
  14. 14. Where information is stored
  15. 15. International data transfers
  16. 16. How information is protected
  17. 17. How long information is kept
  18. 18. Your rights and choices
  19. 19. Children's privacy
  20. 20. Changes to this policy
  21. 21. Contact

1. Two different roles, and why it matters

VERA handles information in two capacities, and your rights differ depending on which one applies.

For your own account information, your billing record, and how you use the product, VERA is the controller. This policy governs that data, and you exercise your rights against us directly.

For the information you put into VERA about your customers, leads, contacts, employees, and jobs, you are the controller and VERA is the processor acting on your instructions. This policy describes what we do with it, but the terms are set by the Data Processing Addendum. If you are one of our customers' customers and want your data corrected or deleted, contact the business you dealt with; we will refer you to them and assist them in responding.

2. Information you provide

The following comes directly from you or from your use of the product.

  • Account information. Your email address, your name if you supply one, and a bcrypt hash of your password if you sign in with one. VERA never stores your password in a readable form. If you sign in with Google, we receive your email address, name, and profile image from Google instead.
  • Business profile. Your business name, industry, services, location, brand voice, brand colors and logo, working hours, and the goals and context you give VERA so it can do useful work. Some of this can be drafted for you by scanning a website address you supply.
  • Customer and operational records. Leads, contacts, companies, deals, appointments, jobs, technicians, support tickets, estimates, invoices, and the notes attached to them. This is where personal data about your own customers and staff lives, including names, email addresses, phone numbers, service addresses, and job details.
  • Files and images. Photographs you upload (including before-and-after job photos), your logo and brand assets, and invoices or estimates you import from another system. Imported documents are retained together with a copy of the original file so the import can be re-checked.
  • Signatures captured from your customers. When your customer accepts an estimate through the public link you sent them, VERA records their typed name or the image of the signature they drew, along with the time and the fact that the link was viewed.
  • Prompts and instructions. The goals, questions, and briefs you write for VERA, and the proposals, approvals, edits, and declines you record against them.
  • Support and feedback. What you send us when you contact support, and the reason you select if you cancel or let a trial lapse, including any free text you add. Cancellation feedback is treated as your data and is deleted with your account.
  • Expenses and receipts. Money-out records: the merchant, amount, date, category, and any note, together with the receipt image or file you upload. A receipt is read to pre-fill those fields, and the original file is kept alongside the record so the reading can be checked. Where an employee filed the expense, the record also names the account that submitted it.
  • Mileage and vehicles. Trips: distance, date and time, start and destination addresses, business purpose, the vehicle, odometer readings, the rate applied, and the reimbursement computed. Trips can also carry one proof image, such as an odometer photo or a parking receipt. Vehicle records hold what you enter about the vehicle. Where an employee filed the trip, the record names the account that submitted it.
  • Text message conversations. Where you use VERA's texting, the phone numbers involved, the content of messages sent and received, any photos sent or received by MMS, the delivery status the carrier reports, and consent records: whether a number opted in or out, when, where the opt-in came from, and the keyword used to opt out.
  • Social posts you publish. The captions, images, and video you compose, the schedule you set, which connected account each post targets, and the publishing outcome the platform reports back.
  • Voice input. When you use a voice conversation or a voice-guided intake, what you say is transcribed and the resulting text is handled like anything else you type. See the microphone section below for where the audio itself goes.
  • Connected platform credentials. The OAuth tokens and API keys for platforms you connect. These are encrypted at rest with AES-256-GCM and are never displayed back to you or written to logs. For providers connected through a broker, the credential is held by that broker rather than by VERA, as described on the Subprocessor List.

3. Location information

VERA can access your device's precise location, and this section explains exactly when and why, because a privacy policy that buries it is not doing its job.

Location is used for one feature: the Mileage Log. When you press Start on a drive, VERA asks your browser for permission and then records position readings for the duration of that trip so the distance driven can be measured rather than estimated. Recording is bounded by the trip: it starts when you start the drive and stops when you end it. VERA does not track your location in the background, does not record location when the Mileage Log is not recording a drive, and has no ability to locate you when you are not using it.

Each reading holds a latitude and longitude, the time it was taken, and, where the device reports them, an accuracy figure, speed, and heading. From the readings VERA derives the trip's start and end addresses and its route, and those derived values live on the trip record.

Coordinates and addresses are sent to a mapping provider to turn them into addresses, routes, and distances, where a mapping provider is configured for the deployment. The provider and what it receives are named on the Subprocessor List. Results are cached under a hash of the normalized request rather than the raw address, so the cache is not a searchable record of where anyone has been.

Raw location readings and the trip records built from them are kept for different periods, because they are different things: the readings are the working data behind a measurement, and the trip is a financial record. The Data Retention Policy states both periods.

You control this at two levels. VERA only asks for location when you start a drive, and your browser or phone controls whether the permission is granted at all; you can refuse it, or withdraw it later in your browser or device settings, and the rest of VERA continues to work. Mileage can also be entered by hand with no location access. The account holder can additionally set the retention period for raw readings, including turning their storage off entirely.

4. Time in the app, and what the account holder can see

VERA measures how long an account is in the app and which of its screens that time was on, and shows the result to the account holder of the business. If you joined someone else's business from an invitation, that means your employer can see how long you spent in VERA and which of the employee screens you were on. This section says exactly what that does and does not include, because a measurement made about a person should not have to be discovered.

What is measured: your browser reports that the VERA tab is in front of you and that you have moved, typed, scrolled or tapped within the last few minutes. While both are true it sends a signal roughly every thirty seconds naming the route you are on. Time accrues in those intervals and each one is capped, so a tab left open overnight adds one interval and then stops. When the tab is hidden, closed, or untouched, nothing accrues.

What is recorded: the route, reduced to the page it names. Record identifiers are replaced before storage and the query string is dropped apart from the keys that name a tab, so a stored entry can say that you were on an estimate and cannot say which estimate, which customer, or what you searched for. Nothing you type, view inside a record, or upload is recorded here, and neither is your location.

What it is not: this is time with the app open, not hours worked. It is stored separately from timesheet hours, it is never read by payroll, and it is never priced. Time you spend in your own business's workspace is your own tenant's and is not visible to any business you work for.

You can see the same figures the business sees, on your account screen in the employee view. The records are deleted when the account they describe is deleted, including the records held inside businesses you worked for.

5. Microphone and voice

VERA has voice features: you can hold a spoken conversation with the assistant, and some guided intakes accept spoken answers. These need microphone permission, which your browser asks for the first time you start one. VERA does not listen otherwise and does not request the microphone anywhere else.

Speech is turned into text by your browser's own speech recognition rather than by VERA. What reaches VERA's servers is the transcript, not the audio. VERA does not receive, store, or transmit recordings of your voice, and there is no audio file of a session for us to keep. Your browser's own handling of the audio, which for some browsers involves sending it to the browser vendor for recognition, is governed by that browser's privacy policy and not by ours.

The transcript is treated as though you had typed it: it becomes part of the conversation, may be sent to the AI provider to produce a reply, and is stored with that conversation until you delete it or delete your account.

For VERA's spoken replies, the text of the reply is sent to a speech provider which returns audio, and the audio is streamed to your browser rather than stored. Only the reply text is sent; your microphone audio is not. That provider is named on the Subprocessor List.

6. Information collected automatically

VERA collects a deliberately small amount of technical information.

  • Server logs. Ordinary application and error logs generated while serving requests. These are operational records, not a behavioral analytics product.
  • Rate limiting counters. To stop brute-force sign-in attempts and abuse, VERA keeps short-lived counters keyed by IP address or email address for actions such as login, sign-up, and password reset. Each counter is overwritten when its window resets.
  • Product usage signals. Counts and timestamps that make the product work and that back your own dashboards: credit usage, when a proposal was approved, when an estimate link was first opened, how many times it was viewed, and daily business metrics computed from your connected platforms.
  • Marketing site analytics. Vercel Web Analytics and Vercel Speed Insights measure page views and performance on our public pages. VERA's own custom events are limited to a closed set of values (an industry slug, which surface a card was clicked on, a position, a dwell time in seconds, and a trimmed search term). Email addresses, names, and free-typed content are never sent to analytics by design.
  • Audit trail. Every proposal, approval, edit, decline, execution, and failure in your account is written to an append-only audit log, along with security events such as password resets, session revocations, and estimate link rotations. Secrets and tokens are never written to it.
What VERA does not collect
CategoryStatus
Payment card numbersNever touch VERA's servers. Stripe collects and stores them.
Advertising or cross-site tracking identifiersNot used. VERA runs no ad pixels or marketing tags.
Background or continuous locationNot collected. Precise location IS collected, but only while a drive you started in the Mileage Log is recording. See Location information above.
CameraNot requested. The Permissions-Policy header blocks camera access outright. Photographs are uploaded as files you choose.
Voice recordingsNot collected. Voice features transcribe speech in your browser and send VERA the text; no audio reaches or is stored on our servers.
Biometric identifiersNot collected. A drawn signature image is not processed as a biometric template, and no voiceprint is derived from voice features.
Government identifiersNot collected.
Data purchased from brokersNot acquired.

7. Information from platforms you connect

When you connect a third-party platform, VERA reads the data that platform's permissions describe, and only to perform the work you asked for. You choose which platforms to connect, and disconnecting one revokes VERA's ongoing access and removes the stored credential.

VERA's integration catalog spans roughly 150 providers across accounting, payments, CRM, scheduling, email, communication, marketing, social, ecommerce, shipping, analytics, field service, and more. What each connection reads or writes is shown on its card before you connect it. Broadly:

  • Accounting and field service. Customers, estimates, quotes, jobs, invoices, and payments, read-only, so VERA can report on the business and pre-fill documents. QuickBooks Online and Jobber are read-only integrations.
  • Stores and payments. Orders, customers, products, and payment records, read-only, to compute revenue, order counts, and average order value.
  • Social networks. Publishing the posts you compose, and reading the metrics those platforms expose (impressions, views, engagement, audience insights) so VERA can report on performance. Content you schedule or publish, including its images and video, is transmitted to the platform you selected, where that platform's own terms and privacy policy govern it. Once published it is outside VERA's control, and deleting it in VERA does not remove it from the platform. VERA does not post without your instruction or an automation rule you configured.
  • Email and calendar. Sending the campaigns and messages you approve through your own provider account, reading campaign results, and reading calendar events to schedule around them.
  • News and market sources. Industry Radar reads publicly available news through a news API. This uses public sources, not your account data or your customers' data.

8. Team members and employees

A VERA business account can hold several people. The account holder invites them, each accepts with their own sign-in rather than a shared login, and each is given a role that decides what they can reach.

If you are an employee or team member using VERA, understand where your information goes. VERA holds your name, the email address you were invited at, your role, and the record of what you did in the workspace. The business that invited you is the controller of that information; VERA processes it on their instructions.

What you submit into the workspace is the business's record, not a private one. Expenses you file, including the receipt images, and trips you file, including the distance, the addresses, any location-derived route, and any proof image, are visible to the account holder and to anyone whose role lets them review submissions. Each submission names the account that filed it, which is what makes approval and reimbursement work.

Location is not an exception to your own control. VERA only records position while you start and run a drive, your device's permission gates it, and you can decline it and enter mileage by hand. VERA does not give an employer any ability to locate you outside a drive you started, and it has no live-tracking or monitoring view.

Your role only reaches the business that invited you. Deactivating a member closes their access while leaving their name on the records they filed, because those records belong to the business.

To correct or remove information a business holds about you in VERA, ask that business. If you contact us instead we will refer the request to them and assist them in responding, as the Data Processing Addendum requires.

9. How VERA uses information

We use information to operate the Service: to authenticate you, to generate drafts and proposals, to execute the actions you approve, to sync and display data from platforms you connect, to build your estimates, invoices, and reports, to meter credit usage, to enforce plan limits and rate limits, to detect and prevent abuse, to provide support, and to send you transactional email about your account.

We use aggregated, non-identifying usage information to understand which parts of the product are useful and where they fail, and to plan what to build next.

We do not sell personal information, do not share it for cross-context behavioral advertising, do not use your business data or your customers' data to train AI models, and do not use the content of your account for marketing to other customers.

10. AI processing

To generate content and analysis, VERA sends the relevant part of your prompt and business context to a third-party AI provider over an API, receives a response, and stores that response in your account. We send what the task needs and no more.

Text generation uses Anthropic's Claude models. Image generation, where configured, uses OpenAI or Google Gemini for the image background; the text and logo overlay is drawn deterministically by VERA and never leaves our servers. Without an AI provider configured, VERA falls back to non-AI output rather than failing.

VERA does not send prompts to AI providers for training, and our providers' commercial API terms do not grant them training rights over API inputs. Providers may retain inputs briefly for abuse monitoring under their own policies, which we do not control. The AI Usage Policy covers this in more detail.

12. How information is shared

VERA shares information with service providers that are necessary to run the product, each under terms requiring them to protect it and use it only for the services they provide to us. They are listed individually, with what each one receives, on the Subprocessor List.

We share information with a platform you connect only to the extent needed to perform the action you requested on that platform.

We may disclose information where we are legally required to, to enforce our Terms, or to protect the rights, property, or safety of VERA, our customers, or the public. Where the law allows it and it is not counterproductive, we will tell the affected account holder about a legal request before responding.

If VERA is involved in a merger, acquisition, financing, or sale of assets, information may transfer as part of that transaction. It would remain subject to this policy, and we would give notice before any material change in how it is handled.

13. Mobile phone numbers and text messaging

Text messaging is treated separately here because mobile carriers hold it to a stricter standard than the rest of this policy, and because the answer is short.

Mobile phone numbers and text messaging consent collected for these programs are never sold, rented, or shared with third parties or affiliates for their own marketing or promotional purposes. Phone numbers are shared only with the messaging carrier that delivers the message, and with service providers acting on our instructions, in order to send the message you asked for.

Text messaging originator opt-in data and consent records are excluded from sharing with third parties for their own purposes. They are not used for advertising, are not sold, and are not transferred to a data broker. Sharing with service providers acting on our instructions, such as the messaging carrier that delivers a message, is limited to what delivering that message requires.

A person who receives a text can stop it by replying STOP to the message, which is applied automatically. The Mobile Messaging Opt-In Policy sets out how consent is collected and recorded, and the SMS Terms of Service set out what may be sent.

14. Where information is stored

VERA runs as a containerized Next.js application against a managed PostgreSQL database. Uploaded photographs, receipts, mileage proof images, MMS media, generated images, and imported documents are stored as encoded data inside that same database rather than in a separate object storage service, so there is no additional storage provider holding your files.

Because files live in the database rather than on a public bucket, they have no public URL. Every file is served through an application route that requires a signed-in session and checks that the file belongs to your account before returning any bytes, so a file cannot be reached by guessing an address and does not become readable to anyone who happens to hold a link. Where an employee uploads a file, the upload is bound to the account that sent it, so a submission cannot be attached to someone else's record. Deleting the record a file belongs to deletes the file, and deleting your account deletes all of them.

The one exception is media attached to a social post, which is by definition being published. Platforms fetch the image or video themselves, without a session, so that file is served through a separate link that carries a signed, expiring token naming the account and the asset. The link cannot be forged or guessed and stops working after a short window, but while it is valid it does not require a sign-in. Anything you publish leaves VERA.

Hosting and database infrastructure is provided by the platform providers named on the Subprocessor List. Their default regions are in the United States.

15. International data transfers

VERA operates from the United States and its infrastructure and subprocessors are primarily located there. If you use VERA from outside the United States, your information will be transferred to, stored in, and processed in the United States, which may not offer the same level of legal protection as your home country.

For transfers of personal data out of the European Economic Area, the United Kingdom, or Switzerland, VERA relies on the European Commission's Standard Contractual Clauses, incorporated by reference into the Data Processing Addendum, together with the UK International Data Transfer Addendum where the UK GDPR applies.

VERA has not certified to the EU-US Data Privacy Framework, and does not claim any adequacy decision applies to it directly. Some of our subprocessors have their own certifications; that is their status, not ours.

16. How information is protected

Traffic is served over HTTPS, plain HTTP requests are redirected in production, and HSTS is asserted. Passwords are hashed with bcrypt with a work factor of 12 (src/lib/password.ts). Connector credentials are encrypted with AES-256-GCM (src/lib/crypto.ts) using a key held separately from the session-signing secret. Every request is scoped to the signed-in account, and sessions can be revoked across every device at once.

Inbound webhooks are verified against each provider's signature scheme and deduplicated so a replayed delivery cannot be applied twice. Server-side fetches of addresses you supply are validated against private and internal ranges to prevent them being pointed at internal systems. Public estimate links use 256 bits of cryptographically secure randomness, are throttled against guessing, and are never written to logs in full.

No system is perfectly secure, and VERA holds no security certification. The Security Policy lists exactly which controls are in place and, just as importantly, which common controls are not yet.

17. How long information is kept

In summary: your business records are kept for as long as your account exists and are deleted when you delete the account. VERA runs little automated deletion, and where it does, it is because the data is more sensitive than it is useful to keep.

The scheduled prunes today are: raw location readings from mileage recording, removed after 30 days by default and configurable by the account holder, including turning their storage off; voided mileage trips past the account's trip retention window, with approved and reimbursed trips never automatically removed because they are financial records; the mapping cache, which expires on its own and holds no account identifier; and Industry Radar news articles, removed after 30 days.

The Data Retention Policy gives the full table, including what survives account deletion and why.

18. Your rights and choices

You can review and correct your business profile, brand details, and records directly in the app. You can disconnect any integration from Settings. You can export a machine-readable copy of your account data from Settings. You can permanently delete your account from Settings, which is immediate and irreversible.

Depending on where you live, you may also have statutory rights of access, correction, deletion, portability, restriction, objection, and the right not to be discriminated against for exercising them. The GDPR Privacy Rights page and the California Privacy Notice explain how to exercise them and how we verify a request.

To make a request that the app itself cannot service, write to support@myvera.io. We respond within the time the applicable law requires, and within 30 days where no specific period applies.

19. Children's privacy

VERA is a business tool sold to businesses. It is not directed to children, we do not knowingly collect personal information from anyone under 18, and no part of the product is designed for or marketed to minors. Account holders must be at least 18 or the age of majority in their jurisdiction.

If you believe a child has provided us with personal information, write to support@myvera.io and we will delete it. If you use VERA in a business that serves families, remember that any information about a minor you enter as a customer record is data you control, and your own obligations under laws such as COPPA apply to it.

20. Changes to this policy

We may update this policy. Material changes are recorded in the change history at the bottom of this page with a new version number and effective date, and account holders are notified by email or in-app notice before the change takes effect where practicable.

21. Contact

Privacy questions and rights requests: support@myvera.io. VERA has not appointed a data protection officer or an EU or UK representative under Articles 27 and 37 of the GDPR; whether one is required depends on the scale of our EU and UK processing, and it is on the list of items for legal review.

Change history

Every revision of this document, newest first. Material changes are notified to account holders before they take effect where practicable.

  1. v2.2August 28, 2026

    Added a dedicated section on mobile phone numbers and text messaging, stating that mobile opt-in data and consent are never sold or shared with third parties for their own marketing, and pointing to the new SMS Terms of Service and Mobile Messaging Opt-In Policy.

  2. v2.1August 12, 2026

    Corrected the disclosure that precise geolocation and the microphone are not used. Added sections on location, on microphone and voice, and on team members and employees, and added data categories for expenses and receipts, mileage and its proof images, SMS and MMS conversations and consent, social publishing, and voice input. Corrected the Permissions-Policy description, described how stored files are access-controlled, and restated retention to include the location and mileage prunes.

  3. v2.0July 28, 2026

    Rewritten following a full codebase audit. Added controller and processor roles, the specific data inventory, a list of what is deliberately not collected, legal bases, storage location, international transfers, and links to the retention, deletion, GDPR, and California notices.

  4. v1.0July 7, 2026

    Initial Privacy Policy published.

Questions about this document?

Legal and contracts: support@myvera.io. Privacy and data rights: support@myvera.io. Security reports: support@myvera.io.

Related

This document is a carefully drafted policy written against how VERA actually works. It is not legal advice, and it should be reviewed by a licensed attorney in your jurisdiction before you rely on it.