VeraGen Privacy Policy
Last updated: October 4, 2026
This Privacy Policy explains how VeraGen LLC ("VeraGen", "we", "us" or "our") collects, uses, shares and protects personal data when you visit veragen.ai or use the VeraGen AI Hub at hub.veragen.ai and related services (together, the "Service"). It also explains your choices and rights.
It should be read with our Terms of Use.
---
The short version
- Your content is yours. We use what you put into VeraGen only to provide the Service to you.
- We do not use your content to train AI models, and we do not sell your personal data.
- Each account is private. Your data is kept separate from every other customer's, and nothing is public until you publish it.
- We use a small number of service providers (listed in section 7), mainly Amazon Web Services, to run the Service.
- You can ask us to access, correct, export or delete your personal data at hello@veragen.ai.
---
1. Who is responsible for your data
When VeraGen is the controller. We are the controller of personal data we collect to run our business: your account and profile, billing records, sign-in and security records, support requests, and visits to veragen.ai.
When VeraGen is a processor. Our customers put their own material into the Hub, which can include personal data about other people: for example contacts and emails in Thrive CRM, leads in Lead Generation, people who take a published course, team members, and people mentioned in documents. For that data, the customer is the controller and VeraGen is the customer's processor. We process it only to provide the Service, on the customer's instructions. If your data is in a VeraGen customer's account and you want to exercise your rights, please contact that customer; we will help them respond. A Data Processing Agreement (DPA) is available to customers on request at hello@veragen.ai.
2. What we collect
2.1 Information you give us
- Account and profile: your name, email address, password (stored by our sign-in provider, never readable by us), role, and the accounts and projects you belong to. Optional profile details you add, such as a photo, timezone, a short bio, affiliation, and links to your website and social profiles.
- Account details: account name and web handle; primary contact name, email and phone; billing email; company legal name, website, address and tax or VAT number (printed on statements).
- Your content: everything you upload or create in the Hub, such as documents, files, pages, datasets, prototypes, images, videos, audio, courses, quizzes, social posts, workflows, prompts and chat conversations with our AI assistant, and the AI output generated for you.
- Information about other people that you add: for example CRM contacts and notes, emails, calendar events, leads, team invitations, and course-taker details. See section 1.
- Voice input: if you use the microphone button, your speech is converted to text. Audio is processed to produce the text and is not kept as a recording by us.
- Support and feedback: what you tell us when you contact support or use Report an issue. A report includes the page and time, your IP address, an approximate location derived from your browser's timezone, your browser and device type, any errors the Hub noticed, and any screenshots you attach (we remove location metadata from screenshots).
- Access requests on veragen.ai: if you request access, your name, work email, organisation and anything you write in the form, together with the IP address and browser type of the request, which we use to prevent abuse.
2.2 Information collected automatically
- Sign-in and security records: sign-in events, two-factor authentication codes (valid for ten minutes), an audit log of significant actions (who did what, when, the result and the IP address), and a record of service emails sent (recipient and subject).
- Usage and billing records: which features you used, AI model usage (for example, tokens in and out), storage and compute, the cost of each, and which person and app it belongs to. We need this to bill you and to show you exactly where your balance went.
- Technical data: IP address, browser and device information, and server logs used to run, secure and troubleshoot the Service.
- Public pages: when someone views a public profile or published project, we count views using a pseudonymous key made from a one-way hash of the IP address, browser and date. It changes every day and we do not store the raw IP address for this. Public chatbots and similar public features use a hashed IP address for rate limiting. Questions asked of a public chatbot are sent to the AI model to answer them but are not stored; we keep only daily counts.
- Public courses and quizzes: when someone takes a course or quiz a customer has published, we collect their answers and, if the course asks for them, their name and email address, plus a hashed IP address and the browser type to prevent abuse. This data belongs to the customer who published the course (see section 1).
- News site subscriptions: if you subscribe to a news site published with VeraGen, we store your email address after you confirm it (double opt-in), and you can unsubscribe at any time.
2.3 Information from connected services and third parties
- Connected accounts. If you choose to connect another service, we receive the data needed for the feature you turned on, using the permissions you grant:
- Google (Sign in with Google for Thrive): your email address and permission to read and send Gmail (`gmail.readonly`, `gmail.send`) and read your Google Calendar (`calendar.readonly`), so Thrive can show your inbox and calendar and send the emails you write. We do not request permission to delete your mail.
- Google Drive: read-only access (`drive.readonly`) so you can import the files you choose into Data Management.
- Other mailboxes (IMAP/SMTP): for providers such as Microsoft 365, iCloud, Fastmail, Yahoo and Zoho, your mail server settings and the password or app password you give us, so Thrive can sync and send your mail.
- X (Twitter): your X profile and permission to read and publish posts on your behalf, read who you follow, and stay connected (`tweet.read`, `tweet.write`, `users.read`, `follows.read`, `space.read`, `offline.access`).
- LinkedIn: your basic profile and permission to post on your behalf (`openid`, `profile`, `w_member_social`).
- Slack: your workspace name and permission for the VeraGen app to post the messages you set up, list channels, and look up a workspace member by email address so a message can be sent to them directly.
- Private calendar links (.ics): the link you paste, so Thrive can show the events in it.
- X home timeline (news feeds): if you connect X to a news feed, we read and store the posts in your home timeline, the accounts you follow, and Spaces, so the feed can show them.
- Public social media content. Echo reads public X posts that mention or reply to the handles you choose to monitor, using VeraGen's own X access (nobody connects an account). We store those posts with their authors' public profile details (handle, name, picture and follower count).
- Lead data from People Data Labs (when enabled). If your account uses People data in Lead Generation, we obtain business contact data about the people you search for (such as name, job title, employer, work email and phone, including a mobile number) from People Data Labs. We never request or store personal email addresses. This feature is currently not available.
- Payment information from Stripe. Stripe processes your card. We receive and store only a customer reference, the card brand, last four digits and expiry date, and the result of each payment. We never see or store your full card number.
- Web search and pages. When you ask the Service to research or crawl the web, we fetch public web pages and search results, which may contain personal data published on those pages.
3. How we use personal data, and our legal bases
| Purpose | Examples | Legal basis (GDPR / UK GDPR) | |---|---|---| | Provide the Service | Create your account, store and show your content, run AI requests, render videos, sync mail you connected, publish what you choose | Performance of our contract with you | | Billing | Charge plan fees and top-ups, meter usage, issue statements, send low-balance notices | Contract; legal obligation (tax and accounting records) | | Security and integrity | Sign-in, two-factor codes, audit logs, rate limits, fraud and abuse prevention, automated checks of content before it is published | Legitimate interests (keeping the Service and our customers safe); legal obligation | | Support | Answer questions and reports, fix problems | Contract; legitimate interests | | Service messages | Invitations, password resets, sign-in codes, statements, notices of changes to our terms | Contract; legitimate interests | | Improve and operate the Service | Understand which features are used and how they perform, using usage records | Legitimate interests (we do not use your content to train AI models) | | Marketing about VeraGen | Product news, only where permitted | Consent, or legitimate interests where the law allows, always with an easy opt-out | | Legal | Comply with law, respond to lawful requests, enforce our terms | Legal obligation; legitimate interests |
Where we rely on legitimate interests, we have weighed them against your rights. You can object at any time (section 9).
Automated checks. Before certain content reaches the public (social posts, public chatbot answers and news articles), it is checked automatically, using AI, for sexual content, graphic violence and illegal activity, and may be held. A held item can be reviewed by a person at VeraGen on request. These checks do not produce decisions with legal or similarly significant effects on individuals.
4. AI and your data
- We do not use your content to train AI models. We do not train, fine-tune or improve any AI model with your content, prompts or output.
- How AI requests work. When you ask the Service to do something with AI, the relevant part of your content and your request are sent to an AI model provider, the answer comes back, and it is stored in your account.
- Our AI providers. We use models hosted on Amazon Bedrock (Amazon Web Services), including Anthropic Claude models for writing and research, Amazon Titan for document search, and Stability AI models for images; and Google Cloud Vertex AI for video (Veo), music (Lyria) and some image generation. Under their terms with us, these providers do not use the data we send them to train their models, and they process it on our behalf to return the result.
- Search indexes. To let the AI search your documents, we create mathematical representations ("embeddings") of your content. They are stored in your account's index, used only for your account, and deleted with your content.
- Speech. Voice input uses Amazon Transcribe, and read-aloud uses Amazon Polly. A read-aloud audio file is cached for one day so it is not generated twice, then deleted.
5. Google user data
VeraGen's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. In particular:
- We use Gmail, Calendar and Drive data only to provide the features you turned on: showing your inbox and calendar in Thrive, sending emails you write, and importing files you pick.
- We do not use Google user data for advertising, do not sell it, and do not use it to train AI models.
- People at VeraGen do not read your Google data, except with your explicit permission (for example, to help with a support request), when needed for security or legal compliance, or when the data has been aggregated and made anonymous for internal operations.
6. How we share personal data
We do not sell personal data, and we do not share it for cross-context behavioural advertising. We share it only:
- Within your account, according to the roles and permissions your owner and admins set.
- When you publish. Content you publish (for example, a public profile, project, course or post) is visible to anyone, may be indexed by search engines, and may be copied by others.
- When you connect a service, we send that service what is needed to do what you asked (for example, publishing a post to X or sending an email through your mailbox).
- With our service providers (sub-processors) listed in section 7, who process data on our behalf under contracts that limit their use of it.
- For legal reasons, if we believe in good faith that the law requires it, or to protect the rights, safety or property of our customers, the public or VeraGen. Where allowed, we will tell the affected customer first.
- In a business transfer, such as a merger or acquisition, under the protections of this Policy.
7. Our service providers (sub-processors)
| Provider | What they do for us | Data involved | Location | |---|---|---|---| | Amazon Web Services | Hosting, database (Aurora PostgreSQL), file storage (S3), sign-in (Cognito), content delivery (CloudFront), secret storage (Secrets Manager), background processing, document text extraction (Textract), speech (Transcribe, Polly) | All Service data | United States | | Amazon Bedrock (AWS) | AI models: Anthropic Claude, Amazon Titan, Stability AI | Prompts and the content needed to answer them | United States | | Google Cloud (Vertex AI) | AI video, music and image generation | Prompts and reference images for those requests | United States, and Google's global endpoint for some image requests | | Stripe | Card payments and saved cards | Billing contact, payment card details (held by Stripe), payment history | United States | | Microsoft Clarity | How visitors use veragen.ai (the public website only, not the Hub): pages viewed, clicks, scrolling and session replays | Device and browser details, approximate location, interactions on the site; text typed into forms is masked | United States | | Mailgun | Sending service emails (invitations, sign-in codes, statements, notices) | Recipient name and email, email content | United States | | Firecrawl | Fetching and rendering public web pages for research, crawls and lead generation | Web addresses and search terms you ask for | United States | | Serper | Web search results | Search terms | United Kingdom | | People Data Labs (only when enabled) | Business contact data for Lead Generation | Search criteria you enter | United States | | Storyblocks | Licensed stock video, images and music in Video Studio | Search terms | United States | | Openverse (WordPress.org) | Openly licensed stock images | Search terms | United States | | GitLab | VeraGen's own version history of published prototypes | Prototype files, and the name and email of the person who published | United States |
Services you connect. When you connect Google, X, LinkedIn, Slack or a mailbox, data passes between us and that service at your request. Those companies act under their own terms and privacy policies, not as our sub-processors.
Our website and the Hub load typefaces from Google Fonts, which means your browser contacts Google's servers and shares your IP address with Google.
We will update this list before adding a new sub-processor that handles customer personal data. Customers with a DPA can ask to be notified of changes.
8. Where your data is stored, and international transfers
VeraGen runs on Amazon Web Services in the United States, mainly in the US East (N. Virginia) region, with some AI processing in other US regions. Google Vertex AI requests are processed in the United States, except some image requests that use Google's global endpoint.
If you are in the European Economic Area, the United Kingdom or Switzerland, your personal data is transferred to the United States. Where required, we rely on appropriate safeguards for these transfers, such as the European Commission's Standard Contractual Clauses (and the UK Addendum), and our providers' equivalent commitments.
9. Your rights and choices
Everyone. You can view and update most of your profile in My Profile, and owners and admins can manage account details in Account → Settings. You can disconnect connected accounts at any time in the Service, and revoke VeraGen's access in the other service's own settings (for example, your Google Account permissions page).
EEA, UK and Switzerland (GDPR). You have the right to access, correct, delete, restrict or object to our processing of your personal data, to data portability, and to withdraw consent at any time where we rely on consent. You also have the right to complain to your local data protection authority.
California and other US states. Residents of California and other states with privacy laws (such as Colorado, Connecticut, Virginia, Utah, Texas and Oregon) have the right to know what personal data we collect and how we use and disclose it, to access it, to correct it, to delete it, and to obtain a portable copy. We do not sell or "share" personal information as those laws define it, we do not use sensitive personal information to infer characteristics about you, and we do not use personal data for targeted advertising or profiling with legal or similarly significant effects. We will not discriminate against you for exercising your rights. You may use an authorised agent; we may ask for proof of authorisation.
In the last 12 months we have collected these categories of personal information, for the purposes in section 3: identifiers (name, email, IP address); customer records (contact and billing details); commercial information (plans, purchases and usage); internet or network activity (sign-in and usage records); audio (voice input, converted to text and not kept); professional information (job title and employer, where you or your customer provide it); and the content you choose to put in the Service. We disclose these only to the service providers in section 7 and as described in section 6.
How to make a request. Email hello@veragen.ai. We will verify your identity (usually by confirming control of your account email) and respond within the time the law requires, normally within one month (GDPR) or 45 days (US state laws). If we decline your request, you may appeal by replying to our decision; we will respond to the appeal within the time the law requires.
If your data is held in a VeraGen customer's account (for example, as a CRM contact or lead), please contact that customer first, as they control it. If you contact us, we will pass your request to them.
10. How long we keep data
We keep personal data only as long as we need it for the purposes in this Policy.
- Your content is kept while your account is active, until you delete it. Most items you delete are first moved to an archive or trash so they can be restored; some are then permanently deleted automatically, for example emails in Thrive's trash after 30 days. Deleting a project permanently deletes, within 30 days, its files, documents and conversations.
- Synced email in Thrive: message bodies are deleted after the retention period set for the mailbox (90 days by default); the subject line and sender are kept with the record.
- Course takers who are not VeraGen users are anonymised after the period the course owner sets (two years by default).
- Erasing a contact. Owners and admins can permanently erase a CRM contact, including stored emails with them. To make sure that person is not contacted or imported again, we keep only their email address on a do-not-contact list, unless the customer chooses otherwise.
- Connected accounts. When you disconnect a service, we stop using its access and delete the stored access tokens. For most services we also revoke our access at the service; you can always revoke it in the service's own settings too. Stored credentials are permanently removed after a 7-day recovery period. When you disconnect a mailbox you choose whether to delete the email already synced or keep it. Files you imported from Google Drive stay in Data Management until you delete them. Removing an Echo source deletes everything captured from it.
- Closed accounts. When an account is closed, we stop processing its data except to complete billing and meet legal obligations, and we delete or anonymise its content and personal data within 30 days, unless the law requires us to keep it longer.
- Backups. Database backups are kept for up to 35 days and are then deleted. Deleted data may remain in backups until then.
- Logs. Operational logs are kept for 30 days. Security audit records and usage records are kept for as long as needed to bill you, protect the Service and investigate incidents.
- Billing records are kept for as long as tax and accounting laws require, typically seven years.
11. Security
We protect personal data with technical and organisational measures appropriate to the risk, including:
- Isolation between customers. Every customer's data is tied to its own account, and the Service checks every request against the signed-in person's verified account membership before returning any data. Requests for another customer's data are refused.
- Encryption in transit using HTTPS (TLS) between your browser and the Service, and between the Service and our providers.
- Encryption at rest for stored files. Our databases and their backups are also encrypted at rest, using keys managed in AWS Key Management Service.
- Secrets kept separately. Mailbox passwords, Google and Slack access, calendar links and API keys you add are stored in AWS Secrets Manager, not in the main database. Social network access tokens are stored in our database, which only the Service can reach.
- Sign-in security: individual accounts, optional email two-factor authentication, and automatic sign-out after 60 minutes of inactivity.
- Least access: access to production systems is limited to the people who need it, and actions are logged. When needed to provide support or investigate a problem, authorised VeraGen staff can view an account as its user would; these sessions are time-limited and recorded in the audit log.
No system is perfectly secure. If we become aware of a breach affecting your personal data, we will notify you and the authorities as the law requires.
12. Cookies and similar technologies
In the Hub, we use only what is strictly necessary to sign you in and keep you signed in:
- an `id_token` cookie that proves you are signed in, valid for up to one hour and renewed while you are active;
- browser local storage, used by our sign-in provider (Amazon Cognito) to keep your session, and by the Hub to remember preferences (such as your selected account and timezone) and share your inactivity timer across tabs;
- a short-lived cookie (30 minutes) used only when authorised VeraGen staff view an account for support.
These are cleared when you sign out. We do not use advertising or cross-site tracking cookies in the Hub, and we do not use third-party analytics.
On veragen.ai, we use Microsoft Clarity to understand how visitors use the website: which pages they view, where they click and scroll, and replays of sessions, so we can improve the site. Clarity sets its own cookies (such as `_clck` and `_clsk`, kept for up to a year) and masks text typed into forms. We do not use advertising cookies, and Clarity does not run in the Hub. You can block or delete these cookies in your browser settings; the site works without them. Microsoft's privacy statement: https://privacy.microsoft.com/privacystatement. The site also loads fonts from Google Fonts (see section 7).
In the Hub we use only strictly necessary cookies. If we add other non-essential cookies, we will update this Policy.
Do Not Track and Global Privacy Control. Because we do not track you across sites or sell or share personal data, there is nothing for these signals to switch off. We honour Global Privacy Control as an opt-out of sale or sharing where the law requires.
13. Children
The Service is for businesses and is not directed to children. You must be at least 18 to have an account. We do not knowingly collect personal data from children under 16 (or under 13 in the United States). If you believe a child has given us personal data, contact hello@veragen.ai and we will delete it.
14. Changes to this Policy
We may update this Policy from time to time. If a change is material, we will tell you by email or in the Service before it takes effect. The "Last updated" date at the top shows when it last changed.
15. Contact us
VeraGen LLC 30 N Gould St, Ste R, Sheridan, WY 82801, USA
Privacy questions and requests: hello@veragen.ai General support: hello@veragen.ai