Privacy Policy
Last updated 8 October 2026. What we collect, why, and who it's shared with — no data we don't need.
In short
- We never collect or have access to private keys or seed phrases. Wallet data we store is limited to public addresses.
- We use a small number of named subprocessors (listed below) to run the Service — email delivery, subscription billing, hosting, and analytics. We don't sell your data.
- On our public pages (not the signed-in app), we can measure our Quora ads with Quora's pixel. In the UK and EEA it loads only if you press Allow; elsewhere it is on unless you press No thanks. See Ad measurement.
- Payment records (amount, recipient, network, timestamps) are kept as an audit trail — this is also public information on the blockchain itself, independent of anything we store.
1. Data we collect
Account data: name, email address, and a hashed password (via Better Auth) when you sign up.
Wallet data: the public address of any wallet you connect, which provider you used (MetaMask, Coinbase, Phantom, WalletConnect), and — where you enable delegated auto-pay — the allowance amount and network you authorized. We never request, receive, or store private keys, seed phrases, or wallet passwords.
Policy and payment data: the spend policies you configure (limits, allowed assets/networks/recipients) and a record of every payment your agents request — amount, asset, recipient, network, policy decision, and on-chain transaction reference once confirmed.
Agent credentials: a hashed MCP bearer credential per agent endpoint you create. The credential itself is shown to you once and not recoverable by us afterward.
Usage data: pages visited, general interaction events (e.g. wallet connected, endpoint created, payment approved), and technical data like IP address and browser type, collected via Google Analytics. Uncaught application errors are also logged this way, so we can find and fix bugs.
Support requests: anything you submit through the Report an issue form, including a referenced payment ID if you provide one.
2. Why we collect it
- To operate your account and enforce your spend policies
- To send transactional email (verification, approval requests, receipts)
- To bill paid subscriptions and sync plan entitlements
- To investigate bugs, abuse, and support requests
- To understand product usage and improve the Service
We do not use your data to train third-party AI models.
3. Who we share data with
We use the following subprocessors to run the Service. Each receives only what it needs to perform its function:
- Resend — transactional email delivery (verification links, payment approval notifications)
- RevenueCat — subscription billing and plan entitlement management (receives your account ID and email)
- Neon / Vercel — database and application hosting
- Google Analytics — product usage analytics and error tracking
- Quora — ad measurement on our public pages, subject to your choice (see Ad measurement)
- WalletConnect / Reown, Coinbase — wallet connection infrastructure when you choose those connection methods; these providers see connection metadata (not your private keys) per their own privacy policies
We do not sell personal data. We disclose data beyond the above only if required by law, to protect against fraud or abuse, or with your consent.
Note on blockchain data: once a payment is confirmed on-chain, the wallet addresses, amount, and transaction details are permanently public on that blockchain (Base) — this is inherent to how public blockchains work, independent of anything Veyra stores or controls.
4a. Ad measurement (Quora)
We advertise Veyra on Quora. To learn whether those ads bring anyone here, our public pages (home, pricing, docs, help, sign-in and these policies) can load the Quora Pixel from Quora, Inc. It is never loaded in the signed-in app: the dashboard, onboarding and payment approval pages.
- Your choice: a small notice offers Allow and No thanks, and your answer is remembered in this browser.
- Depends on where you are: if your browser's time zone is in the UK or the European Economic Area, the pixel is not loaded at all until you press Allow. Everywhere else it is on by default, unless you press No thanks, after which nothing more is sent to Quora.
- What it reports: which public page was viewed and for how long, clicks that lead to sign-up, and that an account was created. Like any web request, this carries your IP address and browser details. Pages whose address could identify you or a payment are never reported.
- What it stores: if you arrived from a Quora ad, the ad click identifier in a cookie on this site (
quora_qclid, 90 days); Quora may also read its own cookies if you are signed in to quora.com. Your choice is kept in this browser's local storage. We do not send your email address, name, wallet addresses or payment details to Quora. - Where it goes: to Quora, Inc., under the Quora Privacy Policy.
5. Data retention
We retain account and payment records for as long as your account is active and for a reasonable period after closure to meet audit, legal, and fraud-prevention obligations. You can request deletion of your account data at any time (see below); payment records tied to on-chain transactions cannot be deleted from the blockchain itself, only from our own systems.
6. Your rights
Depending on your location, you may have rights to access, correct, or delete your personal data, or to object to certain processing. To exercise any of these, use Help → Report an issue with the subject "Privacy request" — we'll respond directly.
7. Children's privacy
The Service is not directed to anyone under 18, and we do not knowingly collect data from children.
8. Changes to this policy
We may update this policy as the Service evolves. Material changes will be reflected by updating the "Last updated" date above.
9. Contact
Questions about this policy or your data: use Help → Report an issue. See also our Terms of Service.