Privacy Policy
Last updated: August 15, 2026
Vyneron ("we", "our", "us") operates the web application at app.vyneron.com and its Telegram and Slack integrations. This Privacy Policy explains how we collect, use, store, and protect your personal data.
1. Data We Collect
We collect only the data necessary to provide our service:
- Account information: Name, email address, and password (hashed). If you sign in with Google, we receive your Google ID, name, and email.
- User content: Tasks, notes, recurring routines, chat messages, and file attachments you create within the app.
- Messaging channel data: If you connect Telegram or Slack, we store the identifier for that account so we can deliver reminders and process the messages you send the bot. For Slack we also store the workspace installation and its access token, encrypted at rest.
- Usage & behavioural data: Basic analytics (page views, feature usage) via Vercel Analytics, and anonymized session analytics & heatmaps on our marketing site (vyneron.com) via Microsoft Clarity. Clarity masks typed text and form inputs by default and helps us understand how visitors navigate the site. We do not use advertising cookies.
- Payment data: Subscription and billing information is processed by Paddle, our merchant of record. We store only your customer ID and subscription status — never your credit card details.
2. How We Use Your Data
- To provide and maintain the Vyneron service (task management, AI chat, reminders)
- To send transactional emails (password reset, subscription changes, welcome messages)
- To process AI requests — your messages are sent to third-party AI providers (Google Gemini, Groq, OpenAI, or Anthropic Claude) to generate responses. We do not use your data to train AI models.
- To improve the service based on aggregated, anonymized usage patterns
3. AI Data Processing
When you use AI features (chat, OCR, voice transcription), your input is sent to third-party AI providers for processing. These providers process data according to their own privacy policies. If you use the BYOK (Bring Your Own Key) feature, your API key is stored securely and requests are made directly with your key.
We do not sell, share, or use your content to train any AI models.
4. Data Storage and Security
- Your data is stored on secured servers.
- Passwords are hashed using bcrypt — we never store plaintext passwords.
- File attachments are stored on Cloudflare R2 with company-level isolation.
- All communication is encrypted via HTTPS/TLS.
- API keys you provide (BYOK) are stored in the database and transmitted only to the respective AI provider.
5. Data Sharing
We do not sell your personal data. We share data only with:
- AI providers (Google, Groq, OpenAI) — to process your AI requests. If you supply your own provider key, the request goes to your own account with that provider instead, which may be Anthropic, OpenRouter or Together AI
- Paddle — to process payments (merchant of record)
- Resend — to deliver transactional emails
- Cloudflare — for CDN, security, and file storage (R2)
- Hetzner — hosts the application and database in Nuremberg, Germany
- Sentry — error monitoring, with personal data capture switched off
- Telegram and Slack — only if you connect that channel yourself
- Microsoft Clarity — anonymized session analytics and heatmaps on our marketing site (vyneron.com)
- Law enforcement — only if required by law
The complete list, including what data reaches each one and where it is processed, is on our sub-processors page.
6. Your Rights
You have the right to:
- Access your data — all your tasks, notes, and account info are visible in the app
- Export your data — use the self-service export in Account Settings, or contact support@vyneron.com
- Delete your account and all associated data — use the self-service deletion in Account Settings, which you can cancel during the grace period described below, or contact support@vyneron.com
- Correct inaccurate data via the app settings
7. Data Retention
- Active accounts: data retained as long as your account is active
- Completed tasks: auto-deleted after the period you configure (default: 7 days)
- Account deletion you request: the account is deactivated immediately and permanently deleted after a 15 day grace period, during which you can cancel the request and get everything back. If a workspace member requests deletion, the workspace owner approves it first.
- Members deactivated by a plan change: if a subscription is downgraded and a seat is removed, that member's data is kept for 90 days before permanent deletion, so the workspace can restore the seat without losing work. This window is longer than the one above on purpose.
- Cancelled subscriptions: data retained for 30 days after expiry, then eligible for cleanup
- Backups: encrypted database backups are kept for 30 days and then deleted automatically. Data you deleted can therefore persist in a backup for up to 30 days after it disappears from the app.
8. Cookies
We use essential cookies/localStorage for authentication (JWT token) and user preferences (language, theme). On our marketing site (vyneron.com) we also use Microsoft Clarity, which sets a first-party analytics cookie to measure how visitors interact with the page (session replay and heatmaps); it masks typed content by default. We do not use advertising cookies.
9. Children's Privacy
Vyneron is not intended for users under 16 years of age. We do not knowingly collect data from children.
10. Changes to This Policy
We may update this Privacy Policy from time to time. Changes will be posted on this page with an updated date. Continued use of the service after changes constitutes acceptance.
11. Contact
For privacy-related questions or data requests:
Email: support@vyneron.com
© 2026 Vyneron. All rights reserved.