1. Privacy by design
Veynota is designed around account control, revocable device credentials, selectable retention and the principle that raw audio should not be stored indefinitely by default.
2. Information Veynota may process
- account and authentication information
- paired-device identifiers and device health
- voice session metadata and usage
- conversation text, memories and reminders you choose to create
- support requests and order information when commerce opens
- limited product analytics when enabled
3. Voice and AI processing
Voice interactions may be transmitted to Veynota's AI and infrastructure providers to provide the requested feature. Veynota does not require customers to provide their own OpenAI API key.
4. Raw audio
Cloud raw-audio storage is off by default in the current privacy settings. If a future feature allows you to enable it, the selected retention period and purpose should be shown before the setting is saved.
5. Memory and transcripts
Veynota may retain conversation text, saved memories and reminders according to the user's settings and product requirements. Controls for editing and deletion are being expanded as the product hardens.
6. Consent and choices
Veynota aims to obtain meaningful consent for collections, uses and disclosures that are not integral to the service, especially where information may be sensitive.
7. Founder List and launch marketing
If you join the Veynota One Founder List, Veynota stores your email address, explicit marketing consent, referral attribution, and limited campaign parameters such as UTM source/campaign. Founder List email includes an unsubscribe mechanism, and unsubscribing cancels pending Founder List lifecycle messages.
Public launch funnel events use a session-scoped first-party visitor identifier for aggregate conversion measurement. The growth event table is not designed to store raw voice, conversation text, or IP addresses.
8. Providers
Veynota may use infrastructure, AI, payment, email and analytics providers to operate the service. Provider access should be limited to what is necessary for the service being delivered.
9. Security and breach response
Veynota uses authenticated accounts, revocable credentials and server-side secrets. No online system can guarantee absolute security. A production privacy program must include incident and breach-response procedures.
10. Access, correction and deletion
Production launch processes will include a documented channel for privacy requests, including access, correction and deletion requests where applicable.
Reference: Office of the Privacy Commissioner of Canada guidance on meaningful consent and PIPEDA responsibilities.