Skip to main content
Legal · Privacy

Privacy Policy

Last updated · August 5, 2026

1. Introduction

Vertos AI ("we," "our," or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our AI-powered automation platform for trade contractors.

By using our services, you agree to the collection and use of information in accordance with this policy. If you do not agree with our policies, please do not use our services.

2. Information We Collect

2.1 Information You Provide

  • Account Information: Name, email address, company name, job title when you register
  • Business Data: Job schedules, customer information, invoices, and operational data you upload for automation
  • Communication Data: Messages, support tickets, and feedback you send us
  • Payment Information: Billing details processed by our payment provider (Stripe) - we do not store full card numbers

2.2 Information Collected Automatically

  • Usage Data: Features used, actions taken, time spent on platform
  • Device Information: Browser type, operating system, IP address
  • Cookies: Session cookies for authentication, preference cookies for settings
  • Log Data: Access times, pages viewed, error logs

2.3 AI Processing Data

Our AI systems process your business data to provide automation services. This includes:

  • Lead capture from job boards (Angi, Thumbtack, HomeAdvisor)
  • Automated lead qualification and scoring
  • Instant lead response via SMS and email
  • Lead management dashboard and analytics

Important: Your data is never used to train our AI models without explicit consent. Your business data remains private and is only used to provide services to you. For details on how our AI systems work, see our AI Transparency Documentation.

3. How We Use Your Information

We use collected information for:

  • Service Delivery: Providing scheduling, dispatch, follow-up, and invoicing automation
  • Account Management: Managing your account, authentication, and preferences
  • Communication: Sending service updates, security alerts, and support responses
  • Improvement: Analyzing usage patterns to improve our platform (aggregated, anonymized)
  • Legal Compliance: Meeting regulatory obligations and responding to legal requests
  • Security: Detecting and preventing fraud, abuse, and security incidents

4. Data Sharing and Disclosure

We do not sell your personal data. We may share information with:

  • Service Providers: Cloud hosting (Vercel), authentication (Clerk), payment processing (Stripe), email (Resend) - all bound by data processing agreements
  • Legal Requirements: When required by law, court order, or government request
  • Business Transfers: In connection with merger, acquisition, or asset sale (with notice)
  • With Consent: When you explicitly authorize sharing

SMS and mobile communications: Mobile phone numbers and SMS opt-in consent collected through our contact form are used only to send you the text messages you requested. This mobile information is not shared with third parties or affiliates for marketing or promotional purposes. Text-messaging originator data is shared only with our SMS delivery provider (Twilio) solely to deliver those messages. See our SMS Terms for message frequency, opt-out (STOP), and help (HELP) details.

5. Google User Data (Inbox Sorter)

Our Inbox Sorter product connects to your Google account to organize your inbox. This section describes exactly what we access, why, where it goes, and how to revoke it. It applies only to Inbox Sorter; our other products do not connect to Google.

5.1 Permissions We Request

  • gmail.modify: Read your messages and change their labels so we can file them, mark them read, archive them, move them to Trash, and save draft replies. We deliberately do not request the permission required to permanently delete mail, so anything Inbox Sorter removes goes to your Trash and stays recoverable.
  • userinfo.email: Read the email address of the account you connect, so we know which mailbox we are working in.
  • Not requested: We do not request permission to send email on your behalf. Inbox Sorter can write a draft, but only you can send it.

5.2 What We Access

  • For every new message: the sender, recipients, subject, a short preview supplied by Gmail, and the routing headers that identify bulk mail.
  • Full message text: read only for messages filed into a folder where you have explicitly turned on automatic drafting, because writing a useful reply requires reading the message. Every folder has this off by default.
  • Your labels: so we can create and apply the folders you define.
  • Not accessed: attachments, contacts, calendar, Drive, or any Google service other than Gmail.

5.3 How We Use It

Solely to provide the features you turned on: sorting mail into your folders, flagging urgent or VIP senders, notifying you, and drafting replies for your review. We do not use your Gmail data for advertising, we do not sell it, and we do not use it to build profiles of you or of the people who email you.

5.4 Who Else Sees It

  • Anthropic: the sender, subject, and preview of a message are sent to the Claude API to decide which folder it belongs in. For folders with drafting enabled, the message text is also sent so a reply can be written. Anthropic does not use data submitted through its API to train its models.
  • Supabase: hosts the database holding your settings and the records described in section 5.5.
  • Vercel: runs the application itself.
  • Notification providers: if you enable alerts, the sender and subject of the message that triggered the alert are sent to the notification service you configure.

We do not transfer your Gmail data to anyone else except where necessary to provide these features, to comply with applicable law, or as part of a merger or acquisition with advance notice to you.

5.5 What We Store, and For How Long

  • Access credentials: your Google tokens, encrypted at rest with AES-256-GCM.
  • Your configuration: folder names and descriptions, routing rules, VIP senders, and any drafting instructions you write.
  • A decision record: for each message we act on, the Gmail message identifier, which folder we chose, how confident we were, and a short plain-language reason. Sender addresses appear here and in the rules the system learns from your corrections.
  • Not stored: we do not retain the body of your messages. Message text is used to make a decision or write a draft and is not written to our database.

Records are kept while your account is active. When you close your account or disconnect Google, we delete your tokens immediately and the remaining records within 30 days.

5.6 Human Access

Our staff do not read your email. The narrow exceptions are: when you explicitly ask us to look at something while helping you, when necessary to investigate a security incident or abuse, when required by law, or when the data has been aggregated and stripped of anything identifying.

5.7 No AI Model Training

We do not use your Gmail data to develop, improve, or train generalized artificial intelligence or machine learning models, and we do not permit our providers to do so. The learning Inbox Sorter does is confined to your own mailbox: when you move a message, it creates a rule for your account only. Nothing learned from your mail affects any other customer.

5.8 Revoking Access and Deleting Your Data

You can disconnect Inbox Sorter at any time from your Google account permissions page at myaccount.google.com/permissions, which immediately stops all access. Revoking does not change anything already in your mailbox: labels stay, and anything in Trash can still be restored. To have your stored records deleted, email privacy@vertosai.com and we will confirm within 30 days.

5.9 Limited Use Commitment

Vertos AI use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

6. Data Security

We implement industry-standard security measures:

  • TLS 1.3 encryption for all data in transit
  • AES-256 encryption for data at rest
  • Enterprise-grade hosting infrastructure
  • Regular security assessments
  • Role-based access controls
  • Multi-factor authentication support

7. Data Retention

We retain your data as follows:

  • Account Data: Duration of account plus 30 days after deletion request
  • Business Data: As required by regulations or until you request deletion
  • Usage Logs: 90 days for operational purposes
  • Backups: 7 days rolling retention

8. Your Rights (GDPR/CCPA)

Depending on your location, you may have the right to:

  • Access: Request a copy of your personal data
  • Rectification: Correct inaccurate or incomplete data
  • Erasure: Request deletion of your data ("right to be forgotten")
  • Portability: Receive your data in a machine-readable format
  • Restriction: Limit how we process your data
  • Objection: Object to certain processing activities
  • Withdraw Consent: Withdraw previously given consent
  • Non-Discrimination: Exercise rights without discriminatory treatment (CCPA)

To exercise these rights, contact us at privacy@vertosai.com or use the data management tools in your account settings.

9. Data Processing Locations

Your data is processed and stored in the following locations:

9.1 Primary Infrastructure

  • Application Hosting: Vercel (United States, US East region)
  • Database: Neon PostgreSQL (United States, AWS us-east-1)
  • Authentication: Clerk (United States)
  • Payment Processing: Stripe (United States)
  • Email Services: Resend (United States)

9.2 Content Delivery

Static content (images, CSS, JavaScript) is distributed globally via Vercel's edge network and cached at locations nearest to users for optimal performance. No personal data is stored in edge caches.

Enterprise Data Residency: Enterprise customers with specific data residency requirements can contact sales@vertosai.com to discuss regional deployment options. See our Data Residency Documentation for more details.

10. International Data Transfers

Your data may be processed in the United States and other countries where our service providers operate. We ensure appropriate safeguards through:

  • Standard Contractual Clauses (SCCs) approved by the European Commission (Decision 2021/914)
  • Data Processing Agreements with all sub-processors
  • Compliance with EU-US Data Privacy Framework where applicable
  • Transfer Impact Assessments as required post-Schrems II

10.1 Sub-processors

We engage third-party service providers (sub-processors) to help deliver our services. All sub-processors are bound by data protection obligations and are listed on our Sub-processors page. We notify customers of any changes to sub-processors at least 30 days in advance.

10.2 GDPR Compliance

For customers in the European Economic Area (EEA), we provide:

  • A Data Processing Agreement (DPA) compliant with GDPR Article 28
  • Standard Contractual Clauses for international transfers
  • Technical and organizational security measures
  • Data Subject rights procedures (access, rectification, erasure, portability)

11. Cookies and Tracking

We use the following types of cookies:

  • Essential: Required for authentication and core functionality
  • Functional: Remember your preferences and settings
  • Analytics: Understand how users interact with our platform (anonymized)

You can manage cookie preferences in your browser settings. Disabling essential cookies may affect platform functionality.

12. Children's Privacy

Our services are not directed to individuals under 18. We do not knowingly collect data from children. If you believe we have collected data from a child, contact us immediately.

13. Changes to This Policy

We may update this policy periodically. We will notify you of material changes via email or prominent notice on our platform. Continued use after changes constitutes acceptance.

14. Contact Us

For privacy-related inquiries:

For EU residents, you have the right to lodge a complaint with your local supervisory authority if you believe your data protection rights have been violated.