Veyrd
PricingSign inJoin the waitlist

Legal · Updated 11 October 2026

Privacy policy

In short

  • We collect what it takes to run your workspace: your account, the work you put in it, and how you sign in.
  • We don't sell your data, show ads, or use third-party analytics.
  • Staff cannot read your workspace content unless you approve it, for the items you name, and your workspace keeps the record.
  • AI summaries stay off until a workspace turns them on.

On this page

  1. 01 Who we are
  2. 02 What we collect
  3. 03 Integrations you connect
  4. 04 The Veyrd Inspections browser extension
  5. 05 How we use it
  6. 06 AI discussion summaries
  7. 07 Service providers
  8. 08 When Veyrd staff can see your content
  9. 09 How long we keep it
  10. 10 Your choices and rights
  11. 11 Cookies and local storage
  12. 12 Security
  13. 13 Transfers, children and changes
  14. 14 Contact
Terms of service

01 Who we are

Veyrd is a task workspace for product teams, available at veyrd.com, through its API at api.veyrd.com, and to agents over the Model Context Protocol. In this policy, “Veyrd”, “we” and “us” mean the operator of that service. “You” means anyone who visits the site, has an account, joins a workspace as a guest, or submits an intake form.

When your organisation uses Veyrd, it decides what goes into its workspaces and who can see it. For that content we act on the workspace's behalf. For account, billing and security information we decide how it is used, as described here.

02 What we collect

Account details you give us:

  • Your name, username, email address and, if you add one, a profile picture.
  • Your password, stored only as a salted hash, and any passkeys you register, stored as public-key credentials.

Work you and your team put into a workspace:

  • Projects, tasks, descriptions, comments and reactions, checklists, attachments, tags, custom fields, due and start dates, dependencies, time entries, recurring rules, goals, dashboards, saved views, automations and webhook endpoints.
  • The record of each task: who changed what and when, including changes made by automations, integrations and agents.
  • What guests and intake-form submitters send, such as a name, an email address and the request itself.

Information created when you use the service:

  • For each signed-in session, the IP address, browser and device description, and when it was created and last used, so you can see and end your sessions.
  • Notifications and your notification preferences, and which tasks you have read.
  • Service logs used to keep Veyrd running, secure and within rate limits.

Billing information for paid workspaces:

  • The plan, number of members, currency, billing interval and subscription status.
  • Payment details are collected and processed by Paddle. We receive references to the customer and subscription, not full card numbers.

03 Integrations you connect

Integrations are off until someone with permission connects them. When they are connected, Veyrd receives only what the connection needs:

  • GitHub: the installation, the repositories it is granted, and pull request and commit details linked to tasks.
  • Slack: the installation and access tokens, the channel list, and member names and email addresses so Slack users can be matched to Veyrd members. Veyrd posts messages to the channels you choose.
  • Google Calendar: your email address and permission to read your calendars and create events, so due dates can appear on your own calendar. Each member connects their own calendar.
  • API keys and MCP clients: the key or client, when it was used, and the OAuth tokens that authorise it. Everything an agent changes is written to the task record.
  • Webhooks: the endpoint you configure and a history of deliveries.
  • The Veyrd Inspections browser extension: described in its own section below.

Each of these services has its own privacy terms for the information they hold. Disconnecting an integration stops new information from flowing to or from it.

04 The Veyrd Inspections browser extension

The extension lets members report problems they find on a web page as findings in Veyrd. It does nothing on a page until you open it there by clicking its icon or using its keyboard shortcut, or until you allow it to activate on that site by itself. It cannot read pages you have not opened it on, and it never reads your browsing history.

You connect it to Veyrd from a page on veyrd.com, where you choose the workspaces it can send findings to. It receives its own access token, kept in the extension's storage on your device, and never sees your Veyrd password. Its token reaches only inspections, findings, and the tasks and projects you can choose from. Each connected browser is listed under Connected apps in your account settings, where you can disconnect it; signing out of Veyrd does not disconnect it.

While it is open on a page, the extension records, in that tab only:

  • The page's last 50 console errors and warnings: the message, the file and line it came from, and up to 20 lines of its stack trace.
  • The page's last 50 failed network requests: the method, the address without its query string, the status code and how long it took. It never records request or response headers or bodies.
  • If you turn on the click trail, your last 30 clicks and page changes: the kind of element, its visible label and the page path. It never records what you type into a field. The click trail is not available on production sites or sites your workspace has not mapped to an environment.

These records stay in the tab and are discarded when you close or reload it. Nothing is sent to Veyrd until you send a finding. When you do, the finding can include:

  • What you write: a title, severity, description, and expected and actual results.
  • A screenshot of the visible part of the tab, if you take one, with the marks you add. You can blur anything private before attaching it. The extension hides itself while it takes the screenshot.
  • An element you point at, if you pick one: its role, accessible name, a CSS selector and its position on the screen. Never its value.
  • The page address without its query string, your browser and operating system, the window size and pixel ratio, the time, and the environment label your workspace gave the site.
  • The console entries, failed requests and click trail recorded above.

Before anything is sent, a preview lists every item and lets you remove any of them. Text that looks like a secret, such as an access token or API key, is masked before it reaches the preview. A sent finding becomes workspace content: it is stored, shown to the workspace's members and deleted like any other finding, and its screenshot is stored with Cloudflare R2.

Alongside its token, the extension keeps in its storage on your device your name, email address and profile picture, the workspaces you connected, the inspection active in each tab until the tab closes, the workspace and project you last used, where you placed its toolbar, and the prompts you have dismissed. It talks only to Veyrd, contains no analytics or advertising code, and does not share what it records with anyone else.

05 How we use it

  • To provide the workspace: storing your work, keeping it in sync in real time, and sending the notifications and emails you ask for.
  • To sign you in and keep your account secure, including detecting and limiting abuse.
  • To run billing, enforce plan limits and handle support requests.
  • To keep the service reliable, investigate incidents and recover from failures.

We do not sell personal information, use it for advertising, or load third-party analytics or advertising trackers.

06 AI discussion summaries

Summaries are off unless a workspace turns them on. When a member asks for a summary, Veyrd sends a bounded excerpt of that one task to the language-model provider configured for the service: the task description up to 2,000 characters and up to 100 comments of up to 1,000 characters each, no more than 24,000 characters in total. Names of comment authors are included so the summary can say who decided what.

The provider returns a short summary, which is shown to the member. Depending on configuration the provider is OpenAI, Google (Gemini) or Moonshot AI, whose own terms govern how they handle requests. Summary usage is counted against the workspace's plan.

07 Service providers

We use these providers to run Veyrd. They process information only to provide their service to us:

  • Cloudflare R2, for storing attachments and profile pictures.
  • Pusher, for real-time updates in the app.
  • ZeptoMail and Resend, for sending email.
  • Paddle, for checkout, payments, invoices and tax on paid plans.
  • OpenAI, Google or Moonshot AI, for AI summaries when a workspace has turned them on.
  • Our hosting and database providers, which run the application and store its data.

08 When Veyrd staff can see your content

Our operators work from account and service metadata, and cannot see your names and email addresses until they deliberately reveal one account or workspace, which is recorded. They cannot browse a list of our customers.

Reading your workspace content needs your approval. Asking us for help with a task approves us for that task. An operator may also ask, in which case the workspace creator or an admin approves or refuses it, and an unanswered request lapses after 24 hours. Approved access lasts 30 minutes and reaches only the items the request named.

Three situations let an operator open access without waiting for you: responding to a live incident, investigating a security problem, and restoring a broken service. Each one requires a ticket reference, lasts 10 minutes rather than 30, and notifies your workspace immediately. Only a security investigation may hold that notice back, for at most seven days, after which it is released automatically.

Every access, approved or not, is written to an audit log your workspace can read in its settings, and those records cannot be altered or deleted. Audit records are kept for a year.

09 How long we keep it

  • Workspace content stays until someone deletes it. Deleted tasks, projects and workspaces go to the trash first and can be restored for 48 hours on the Free plan or 30 days on the Paid plan, after which they are permanently deleted, attachments included.
  • When you delete your account, we remove your passkeys, sessions, API keys, agent authorisations, notifications, workspace memberships and assignments, and replace your name and email with an anonymous identity. Work you contributed to a shared workspace, such as tasks, comments and record entries, stays with that workspace under the anonymous identity. You need to transfer or trash workspaces you own first.
  • Operator audit records are kept for 365 days.
  • Billing records are kept as long as tax and accounting rules require.

10 Your choices and rights

  • Export your account data from your account settings, and, as a workspace admin, export a workspace's tasks as CSV.
  • Correct your profile, change your password, manage passkeys and end sessions at any time.
  • Choose which notifications you receive, and disconnect integrations, API keys and the browser extension.
  • Delete your account from your account settings.

Depending on where you live, you may also have the right to object to or restrict certain processing, and to complain to a data protection authority. For content in a workspace that belongs to your organisation, contact the workspace owner first; we will help them respond. For anything else, write to us at the address below.

11 Cookies and local storage

Veyrd sets one cookie to keep you signed in. The app also uses your browser's storage for things like remembering your last workspace for twelve hours, holding a guest's access while they view a shared task, and whether you have already seen the introduction on this site. None of these are used for advertising or tracking across sites.

12 Security

Passwords are hashed, passkeys are supported, traffic is encrypted in transit, requests are rate limited and input is sanitised, and requests from GitHub and Slack are verified by signature. No system is perfectly secure; if you find a vulnerability, please tell us at the address below.

13 Transfers, children and changes

Our providers may process information in countries other than yours. Veyrd is not directed at children under 16, and we do not knowingly collect their information. If we change this policy in a way that matters, we will update the date above and tell account holders before the change takes effect.

14 Contact

Questions about this policy or your information: legal@veyrd.com.

Work, in context.

Every task keeps its own record.

Features

  • The record
  • Views and planning
  • Automation
  • Integrations
  • Outside the team
  • Agents and the API
  • All features

Product

  • Pricing

Legal

  • Privacy policy
  • Terms of service

Account

  • Sign in
  • Join the waitlist

Veyrd

© 2026 Veyrdveyrd.com