01 Who we are
Veyrd is a task workspace for product teams, available at veyrd.com, through its API at api.veyrd.com, and to agents over the Model Context Protocol. In this policy, “Veyrd”, “we” and “us” mean the operator of that service. “You” means anyone who visits the site, has an account, joins a workspace as a guest, or submits an intake form.
When your organisation uses Veyrd, it decides what goes into its workspaces and who can see it. For that content we act on the workspace's behalf. For account, billing and security information we decide how it is used, as described here.
02 What we collect
Account details you give us:
- Your name, username, email address and, if you add one, a profile picture.
- Your password, stored only as a salted hash, and any passkeys you register, stored as public-key credentials.
Work you and your team put into a workspace:
- Projects, tasks, descriptions, comments and reactions, checklists, attachments, tags, custom fields, due and start dates, dependencies, time entries, recurring rules, goals, dashboards, saved views, automations and webhook endpoints.
- The record of each task: who changed what and when, including changes made by automations, integrations and agents.
- What guests and intake-form submitters send, such as a name, an email address and the request itself.
Information created when you use the service:
- For each signed-in session, the IP address, browser and device description, and when it was created and last used, so you can see and end your sessions.
- Notifications and your notification preferences, and which tasks you have read.
- Service logs used to keep Veyrd running, secure and within rate limits.
Billing information for paid workspaces:
- The plan, number of members, currency, billing interval and subscription status.
- Payment details are collected and processed by Paddle. We receive references to the customer and subscription, not full card numbers.
03 Integrations you connect
Integrations are off until someone with permission connects them. When they are connected, Veyrd receives only what the connection needs:
- GitHub: the installation, the repositories it is granted, and pull request and commit details linked to tasks.
- Slack: the installation and access tokens, the channel list, and member names and email addresses so Slack users can be matched to Veyrd members. Veyrd posts messages to the channels you choose.
- Google Calendar: your email address and permission to read your calendars and create events, so due dates can appear on your own calendar. Each member connects their own calendar.
- API keys and MCP clients: the key or client, when it was used, and the OAuth tokens that authorise it. Everything an agent changes is written to the task record.
- Webhooks: the endpoint you configure and a history of deliveries.
Each of these services has its own privacy terms for the information they hold. Disconnecting an integration stops new information from flowing to or from it.
04 How we use it
- To provide the workspace: storing your work, keeping it in sync in real time, and sending the notifications and emails you ask for.
- To sign you in and keep your account secure, including detecting and limiting abuse.
- To run billing, enforce plan limits and handle support requests.
- To keep the service reliable, investigate incidents and recover from failures.
We do not sell personal information, use it for advertising, or load third-party analytics or advertising trackers.
05 AI discussion summaries
Summaries are off unless a workspace turns them on. When a member asks for a summary, Veyrd sends a bounded excerpt of that one task to the language-model provider configured for the service: the task description up to 2,000 characters and up to 100 comments of up to 1,000 characters each, no more than 24,000 characters in total. Names of comment authors are included so the summary can say who decided what.
The provider returns a short summary, which is shown to the member. Depending on configuration the provider is OpenAI, Google (Gemini) or Moonshot AI, whose own terms govern how they handle requests. Summary usage is counted against the workspace's plan.
06 Service providers
We use these providers to run Veyrd. They process information only to provide their service to us:
- Cloudflare R2, for storing attachments and profile pictures.
- Pusher, for real-time updates in the app.
- ZeptoMail and Resend, for sending email.
- Paddle, for checkout, payments, invoices and tax on paid plans.
- OpenAI, Google or Moonshot AI, for AI summaries when a workspace has turned them on.
- Our hosting and database providers, which run the application and store its data.
07 When Veyrd staff can see your content
Our operators work from account and service metadata, and cannot see your names and email addresses until they deliberately reveal one account or workspace, which is recorded. They cannot browse a list of our customers.
Reading your workspace content needs your approval. Asking us for help with a task approves us for that task. An operator may also ask, in which case the workspace creator or an admin approves or refuses it, and an unanswered request lapses after 24 hours. Approved access lasts 30 minutes and reaches only the items the request named.
Three situations let an operator open access without waiting for you: responding to a live incident, investigating a security problem, and restoring a broken service. Each one requires a ticket reference, lasts 10 minutes rather than 30, and notifies your workspace immediately. Only a security investigation may hold that notice back, for at most seven days, after which it is released automatically.
Every access, approved or not, is written to an audit log your workspace can read in its settings, and those records cannot be altered or deleted. Audit records are kept for a year.
08 How long we keep it
- Workspace content stays until someone deletes it. Deleted tasks, projects and workspaces go to the trash first and can be restored for 48 hours on the Free plan or 30 days on the Paid plan, after which they are permanently deleted, attachments included.
- When you delete your account, we remove your passkeys, sessions, API keys, agent authorisations, notifications, workspace memberships and assignments, and replace your name and email with an anonymous identity. Work you contributed to a shared workspace, such as tasks, comments and record entries, stays with that workspace under the anonymous identity. You need to transfer or trash workspaces you own first.
- Operator audit records are kept for 365 days.
- Billing records are kept as long as tax and accounting rules require.
09 Your choices and rights
- Export your account data from your account settings, and, as a workspace admin, export a workspace's tasks as CSV.
- Correct your profile, change your password, manage passkeys and end sessions at any time.
- Choose which notifications you receive, and disconnect integrations and API keys.
- Delete your account from your account settings.
Depending on where you live, you may also have the right to object to or restrict certain processing, and to complain to a data protection authority. For content in a workspace that belongs to your organisation, contact the workspace owner first; we will help them respond. For anything else, write to us at the address below.
11 Security
Passwords are hashed, passkeys are supported, traffic is encrypted in transit, requests are rate limited and input is sanitised, and requests from GitHub and Slack are verified by signature. No system is perfectly secure; if you find a vulnerability, please tell us at the address below.
12 Transfers, children and changes
Our providers may process information in countries other than yours. Veyrd is not directed at children under 16, and we do not knowingly collect their information. If we change this policy in a way that matters, we will update the date above and tell account holders before the change takes effect.
13 Contact
Questions about this policy or your information: [email protected].