This policy explains what data Verity collects, how we use it, who we share it with, and what control you have over it. We've written it in plain English. If anything's unclear, email hello@withverity.co and we'll explain.
Verity is operated by a small team that handles privacy the way we'd want our own data handled: minimum collection, no resale, deletion on request.
What we collect
We collect three kinds of data:
Account information
- Your name and email address (via Clerk, our authentication provider)
- Your billing details (handled by Stripe — we never see or store your card number)
- Login timestamps and basic usage metadata (when you signed up, last active, device type)
Business data you give us
- Your business profile (industry, location, services, team size, revenue range, goals, constraints)
- The content of conversations you have with Verity
- Plans, documents, open loops, weekly check-ins, and other things you create in the app
- Files and notes you upload as context (financials, customer lists, marketing materials, etc.)
- Your brand assets (logo, colors, notes) if you provide them
Data from integrations you connect
- If you connect Jobber: customer info, jobs, quotes, invoices, and related business data — only what we need to surface in conversations (read-only access)
- Encrypted access tokens for each integration (we use AES-256-GCM at rest)
- We do not get access to data outside the scopes you grant during the OAuth flow
Technical data
- Basic web logs (IP address, user agent, timestamp) — used for security and debugging, retained no more than 30 days
- Push notification endpoints if you enable notifications
- Cookies needed to keep you signed in (Clerk session cookie) — no advertising cookies, no third-party tracking pixels
How we use it
We use your data for one thing: making Verity work for you. Specifically:
- Routing your messages to AI providers (Anthropic and OpenAI) so Verity can respond
- Storing your conversation history, plans, documents, and open loops so they persist across sessions
- Generating semantic embeddings of past sessions so Verity remembers relevant context
- Fetching data from integrations you've connected (e.g., your Jobber snapshot)
- Sending you product emails (welcome, weekly recap, trial reminders, re-engagement) and push notifications you've opted into
- Processing payments through Stripe
- Detecting abuse, fraud, and security issues
We do not use your data to train AI models. We do not sell your data to anyone. We do not share it with advertisers or run advertising on the platform.
Who we share it with
We use third-party services ("subprocessors") to run Verity. Each only sees the data needed for its specific job:
| Service | What they see | Why |
|---|
| Clerk | Email, name, login activity | Authentication |
| Stripe | Email, payment details, subscription status | Payments |
| Anthropic | The content of your messages and the system prompt context | AI responses (Claude models) |
| OpenAI | Session summaries (for embeddings only — no chat content) | Semantic memory across sessions |
| Neon | All your data (database hosting) | Database |
| Vercel | Application traffic and logs | App hosting |
| Cloudflare | DNS queries, email routing | DNS + inbound email |
| Resend | Your email + email content we send you | Outbound product emails |
| Jobber | Whatever you authorize via OAuth (when you connect it) | CRM integration (optional) |
Each of these services has its own privacy policy. We pick them because they're well-regarded on security and privacy. Their handling of your data is bound by their own terms, plus the data processing agreements we have with them where applicable.
Specifically on AI training: Anthropic does not train on data sent via the API (their commercial API terms). OpenAI does not train on data sent via the API either (their API data policy). We only use the API tier for both providers.
Beyond these subprocessors, we don't share your data with anyone, except:
- When required by law (subpoena, court order, etc.) — we'll notify you unless legally prohibited
- To protect against fraud, abuse, or serious safety issues
- In the event Verity is acquired or merges with another company — your data would transfer under the new owner subject to the same terms (we'd notify you and give you a window to delete first)
How long we keep your data
- Active account data: for as long as your account exists
- After you delete your account: we remove your data within 30 days, except where retention is required (tax records, fraud investigations) — those are kept only as long as legally required
- Backups: our database backups roll off automatically within 35 days; deleted data disappears from backups within that window
- Web logs: 30 days max
- Encrypted CRM access tokens: deleted immediately when you disconnect the integration
Your rights
You can, at any time:
- Access your data — most of it is visible in the app; for the rest, email us
- Export your data — email hello@withverity.co and we'll send you a JSON export within 14 days
- Correct your data — edit it directly in the app, or email us for things you can't edit yourself
- Delete your data — close your account from Settings, or email us. We delete within 30 days unless legally required to retain
- Disconnect integrations — Settings → Integrations → Disconnect, anytime
- Opt out of emails — every email has an unsubscribe link; or turn off notifications in Settings
- Object to processing — if you're in a jurisdiction with GDPR/CCPA-style rights and you want us to stop processing your data, email us and we'll work through it with you
Security
We take security seriously and use industry-standard practices:
- All traffic is encrypted in transit via TLS
- Data is encrypted at rest in our database (Neon)
- OAuth tokens for third-party integrations are encrypted with AES-256-GCM using keys we control
- Access to production systems is limited to the people who need it
- We use well-regarded infrastructure providers (Vercel, Neon, Clerk, Cloudflare) with strong security records
That said, no system is perfectly secure. If we ever experience a breach affecting your data, we'll notify you within 72 hours of discovering it, in line with applicable law.
Cookies and tracking
We use the minimum cookies needed to make the app work:
- Authentication cookies (Clerk) — required for sign-in
- A session storage flag used during onboarding (cleared automatically after use)
We do not use advertising cookies, third-party tracking pixels, or behavioral analytics that follow you around the web. If we ever add product analytics, it will be a privacy-respecting tool (e.g., Plausible) that doesn't use personal identifiers.
Children
Verity is not designed or directed at people under 18. We don't knowingly collect data from minors. If you believe a minor has signed up, email us and we'll delete the account.
International users
Verity is operated from the United States, and our infrastructure is primarily based in the US. By using the service from outside the US, you consent to your data being transferred to and processed in the US, which may not have the same data protection laws as your home country.
If you're in the EU/UK, the legal basis for our processing is the contract we have with you (you signed up for the service) and our legitimate interest in running Verity well. You have the rights granted under GDPR — see "Your rights" above.
If you're in California, you have CCPA rights — see "Your rights" above. We don't sell personal information.
Changes to this policy
We'll update this policy as Verity changes. If we make a material change to how we handle your data, we'll email you and post a notice in the app at least 30 days before the change takes effect.
Contact
Privacy questions or requests: hello@withverity.co. We try to respond within 5 business days.
See also: Terms of Service