Privacy Policy

Last updated: 11 September 2026

1. Who we are

The Vavio service and website (together, the “Service”) are operated by Vectorwise LLC, a limited liability company formed in Wyoming, United States, trading under the Vavio brand (“we”, “us”, “our”). This Privacy Policy explains what personal data we collect when you visit our website or use the Service, how we use and share it, and the choices and rights you have.

2. The Service in summary

Vavio lets businesses (our “Customers”) build AI employees — cloud workers hired for a real job role. A Customer describes the job, gives the employee standing rules and knowledge (its Skills), authorises the accounts and tools it may use (its Connectors), decides which of its Actions require the Customer’s approval, and connects the Channels it works on. The Customer’s owners and teammates then work with it in Chat, Review and Manage, and every unit of work it performs is a run that leaves evidence.

That shape decides who is responsible for what. We are the controller for personal data about the people who deal with us directly — account holders and teammates, visitors to our marketing website, and people who contact us. We are a processor for the personal data inside a Customer’s workspace: what the Customer tells its employee, the files and records it gives it, the messages its employee exchanges with the Customer’s own customers and contacts on a Channel, and the evidence of the work it does. The Customer is the controller of that data and decides what its employee may do with it — see Section 11.

3. Personal data we collect

We collect the following categories of personal data:

  • Account data: name (if provided), email address, password (stored as a salted hash), workspace and role information.
  • Billing data: when you subscribe to a paid plan, our payments processor collects card details and billing address. We do not store full card numbers on our systems.
  • Usage data: how you use the Service (e.g. AI employees created, configuration changes, sessions, feature usage, and the credits and AI spend a run consumes) for security, support, billing, and product improvement.
  • Communications: messages you send us (e.g. support requests and other correspondence, including through our contact form) and our responses.
  • Technical data: IP address, browser type and version, device identifiers, language, time zone, and similar information needed for security, fraud prevention, and operation.
  • Marketing data: records of preferences, consents, and interactions with our marketing emails or ads, where applicable and lawful.

Inside a Customer’s workspace we hold the following on that Customer’s behalf. Where it contains personal data, the Customer is the controller and we process it on their instructions:

  • Conversations: what owners and teammates say to an AI employee in Chat, and the messages it exchanges on a connected Channel — including messages written by people outside the business, such as a customer who emails in or writes on Slack or Telegram, together with their address or handle.
  • Instructions and memory: the Skills, standing rules, corrections, learned instructions, pinned facts, and Training memory that shape how an employee does its job, with a history of the changes.
  • Files and knowledge: documents and other files given to an employee — images, PDFs, Word and text documents, spreadsheets — and the searchable extracts made from them. Those extracts are stored and searched inside our own database; document text is not sent to a separate search vendor.
  • Audio and transcription: voice notes and spoken input, and the text transcription made from them. The recording is kept beside the text.
  • Runs and evidence: the record of each unit of work — what the employee did, the tools and Actions it called, what it read and changed, what it held for approval and what the Customer decided, errors, and cost.
  • Connector credentials: the access tokens, API keys, and connection settings for the accounts a Customer connects. They are held under envelope encryption, used only to perform that Customer’s work, and never shown back to us or to anyone else in plain text.
  • Contacts and business records: contacts, leads, and the records an employee reads or writes in the systems the Customer connects — a mailbox, a spreadsheet, a database, a task tracker.
  • Device records: if you use the mobile app, the push token and delivery records needed to send you notifications.

4. How we use personal data

As a controller — for the first list at Section 3, not for what sits inside a Customer’s workspace — we use personal data to:

  • Provide, operate, and maintain the Service and our website.
  • Create and manage accounts, authenticate users, and prevent unauthorised access.
  • Process payments and manage subscriptions.
  • Respond to support requests and other communications you initiate.
  • Improve the Service: diagnose issues, fix bugs, analyse usage trends, and develop new features. Our product analytics are identified, not anonymous: when you are signed in we send your user identifier, email address, plan, and business identifier to our analytics provider, and we record masked session replays of the product interface. Section 14 and our Cookie Policy explain the controls.
  • Send service-related messages (e.g. transactional notifications, security alerts, material changes to terms or policies).
  • Send marketing communications about Vavio where we have a lawful basis to do so. You can opt out at any time using the unsubscribe link in our emails or by contacting us.
  • Comply with legal obligations and enforce our terms.

5. Legal bases (UK and EEA)

If you are in the United Kingdom, European Economic Area, or Switzerland, we rely on the following legal bases under the UK GDPR and EU GDPR:

  • Contract: to provide the Service to you and to handle your requests.
  • Legitimate interests: to secure the Service, prevent fraud and abuse, improve our products, and communicate with you about features or offers relevant to your role, balanced against your rights.
  • Consent: where required by law (e.g. certain analytics or advertising cookies, certain marketing messages). You can withdraw consent at any time.
  • Legal obligation: where we are required to process personal data by applicable law.

6. AI and automated processing

An AI employee runs on large language models provided by third parties. Doing its job means sending the relevant parts of a Customer’s data to those providers. You should be aware that:

  • Conversations, instructions, extracts from files, and the material an employee needs to decide and carry out a step are transmitted to one or more model providers we use as sub-processors, either routed through our model broker or sent directly to the provider. Section 7 names them.
  • Audio is sent to our transcription provider to be turned into text. Text extracts from files are sent to an embeddings provider so an employee can search a Customer’s own documents; the resulting index is stored in our own database.
  • When an employee searches the public web, the search query goes to our search provider.
  • We do not sell personal data, and we do not use Customer data to train our own AI models. We use each model provider under its API terms. We are not in a position to guarantee, on those providers’ behalf, what every one of them does with content after it reaches them, so we do not make that promise here; their own terms and privacy notices govern it, and we will tell you which providers a workspace uses on request.
  • AI-generated output and AI-chosen actions can be incorrect or incomplete. Customers decide which Actions require their approval before an employee may take them, are responsible for the Skills and knowledge they configure, and choose what human review to apply.
  • We do not use these AI systems to make decisions about individuals that produce legal or similarly significant effects on them.

7. Sharing and sub-processors

We do not sell personal data. We share personal data only with:

Sub-processors. These are the services we use to run Vavio. We require them to provide appropriate protections and to process personal data only on our documented instructions or for their own permitted purposes under applicable law. This is the complete current list:

  • Vercel — hosting for our website and application.
  • Supabase — our primary database, sign-in and authentication, and file storage. Nearly everything described in Section 3 is held here.
  • Cloudflare — the compute that runs AI employees, its per-employee state store, object storage, and the anti-abuse check on our contact form.
  • OpenRouter — the broker that routes work to model providers, and the models it routes to.
  • OpenAI — models reached directly, audio transcription, and the embeddings that make a Customer’s documents searchable.
  • Anthropic and xAI — models reached directly.
  • Tavily — public-web search when an employee needs to look something up.
  • Composio — the broker that connects an employee to some third-party tools, currently Airtable, Google Calendar, Google Sheets, Hacker News, Linear, and Notion.
  • Stripe — payments and subscriptions, including card details, which are held by Stripe and not by us.
  • Resend — sending our service and lifecycle email.
  • Upstash — queueing and rate limiting.
  • PostHog — product analytics and masked session replay, as described in Section 4.
  • Expo — mobile push notifications, which are delivered onward by Apple and Google’s push services.
  • Google, Meta, Microsoft, and LinkedIn — advertising measurement on our marketing website only, and only where the recorded consent state permits advertising. In the UK and EEA that means only after you opt in. Elsewhere, including the United States, it starts on from your first visit and runs until you turn it off. See Section 14.

Services a Customer directs us to. Separately from the list above, an AI employee sends and receives data through the accounts and endpoints its own business connects — for example a Google or Gmail account, Slack, Telegram, a database, or another API a Customer configures — and communicates with the people that business asks it to. Those are the Customer’s own choices, made under the Customer’s own relationship with each service, not sub-processors we appoint.

  • Professional advisers (e.g. accountants, lawyers) and corporate transactions (e.g. in connection with a merger, acquisition, or sale of assets), under appropriate confidentiality protections.
  • Authorities or third parties where we are required to do so by law, to respond to lawful requests, to protect our rights, or to protect the safety of users or others.

We keep this list current. If it has changed since the date at the top of this page, ask us at hello@vavio.ai.

8. International data transfers

We are based in the United States, and personal data may be processed in the United States and in other countries where we or our sub-processors operate. Where we transfer personal data from the United Kingdom, European Economic Area, or Switzerland to a country that has not received an adequacy decision, we rely on appropriate safeguards (typically the European Commission’s Standard Contractual Clauses, the UK International Data Transfer Addendum, or the equivalent Swiss mechanism), together with technical and organisational measures.

9. Retention

We keep personal data for as long as we need it for the purposes described in this Privacy Policy. Account data, the contents of a workspace, and the evidence of the work an AI employee has done are kept while the account and business are active, because they are what the product is for. There is no per-Customer retention setting in the product today; what follows is what actually happens.

When you delete your account we complete the request end to end within 30 days, and we can tell you what it reached. Delete your account sets out the steps.

  • What deletion reaches: your records in our primary database, your sign-in and authentication records, your registered devices, and the media we hold for you. That boundary is recorded in the receipt we can give you, so it is checkable rather than a claim.
  • What it does not reach in our own systems, yet. Your AI employees run on a separate working store, kept close to the compute so they can respond quickly. It holds conversation messages, what the employee remembers, turn logs, and run records — and those records remain outside the automatic deletion pass. We would rather say that than let you assume otherwise. Building that pass is open work, and we will update this page when it lands.
  • What it does not reach on your devices. If you used the mobile app, the device you delete from clears its own cached copy — your employee roster and any unsent chat or correction drafts — on a best-effort basis. We do not currently send any instruction to your other devices, so a second phone or tablet keeps its cached copy until you sign out of it or remove the app.
  • What it does not reach outside us: data that already left us to do your work — what was sent to a model provider, an email that has been delivered, a record an employee wrote into a system you connected. We work through those separately after the deletion, and we can tell you the outcome of each one: deleted, never sent, kept by that service under its own rules, outside our power to delete, or still being cleared. We say which rather than implying deletion reaches everywhere, because it does not.
  • Business and financial records — invoices, subscriptions, usage ledgers, approvals, and audit records — are kept for seven years. Your name and email are removed and you are represented only by a stable, pseudonymous identifier.
  • Operational and security logs are kept for up to 90 days.
  • Backups roll off on an approximately 30-day cycle and are not used to restore a deleted account.

A business’s own data belongs to that business. If you are a teammate rather than the owner, deleting your personal account does not delete the business or its employees’ work; the owner controls that. When personal data is no longer needed for any of the purposes above, we delete or anonymise it.

10. Your rights

Depending on where you live, you may have the following rights regarding your personal data:

  • Access: request a copy of personal data we hold about you.
  • Rectification: ask us to correct inaccurate or incomplete data.
  • Erasure: ask us to delete personal data, subject to legal limits.
  • Restriction or objection: ask us to restrict, or object to, certain processing.
  • Portability: ask us to provide certain personal data in a portable format. A download comes in two halves: your own record — your profile, the agreements you accepted, your memberships, and the identity of each business you belong to — which you can always get; and the business archive — employees, runs, evidence, contacts, billing — which opens only for a current owner of an active business, or for the owner named in the record of a business that has been closed. A former or removed teammate receives their own record, not their former employer’s business data.
  • Withdraw consent: where we rely on consent, withdraw it at any time without affecting prior lawful processing.
  • Complain: lodge a complaint with your local data protection authority (e.g. the UK Information Commissioner’s Office, or your EEA supervisory authority).

If you are a California resident, the California Consumer Privacy Act (“CCPA”) gives you additional rights, including the right to know what personal information we have collected, the right to request deletion, the right to correct, and the right to opt out of any “sale” or “sharing” of personal information as those terms are defined under the CCPA. We do not sell personal information. To exercise these rights, contact us using the details below. We will not discriminate against you for exercising your rights.

If our processing of your personal data is on behalf of one of our Customers — for example, you emailed a business and its AI employee handled your message, or your details sit in that business’s contacts — please direct your request to that business. We will assist them in responding.

11. Customer-controlled data

For everything inside a Customer’s workspace — the second list at Section 3 — that Customer is the data controller and we are the processor. The Customer decides what its AI employee is told, which accounts it may use, which of its Actions require approval, and who it communicates with. The Customer is responsible for the lawful basis on which it collects and uses that data, for giving appropriate notice and (where required) obtaining consent from the people whose data it puts into the Service or whom its employee contacts, and for honouring data subject requests from those people. Our processing of that data is governed by our agreement with the Customer, including any data processing terms incorporated by reference.

12. Security

We use technical and organisational measures designed to protect personal data against unauthorised access, alteration, disclosure, or destruction. These include encryption of data in transit, database access rules that keep one business’s data separate from another’s, access controls and least-privilege provisioning, logging and monitoring, and vendor diligence for our sub-processors. The credentials a business connects are held under envelope encryption — each secret is encrypted with its own key, which is itself encrypted with a master key held separately — and are used only to perform that business’s work. No method of transmission or storage is perfectly secure; we cannot guarantee absolute security but work to keep our practices in line with industry standards for a company of our size and stage.

13. Children

The Service is a business product intended for adults using it on behalf of an organisation. It is not directed to children. We do not knowingly collect personal data from children under 16 (or under 13 in the United States, where applicable). If you believe a child has provided us with personal data, please contact us and we will take appropriate steps to delete it.

14. Cookies and similar technologies

We and selected third parties use cookies and similar technologies on our website and in the Service for purposes such as keeping you signed in, remembering your cookie choices, analytics and session replay, and advertising measurement. In the UK and EEA, everything other than what is strictly necessary starts switched off and our analytics do not run until you opt in. Elsewhere, including the United States, the optional groups — analytics and advertising alike — start on from your first visit and run until you turn them off, which you can do at any time. Further detail and your choices are in our Cookie Policy.

Where the recorded consent state permits advertising — in the UK and EEA only after you opt in, elsewhere from your first visit until you turn it off — the following advertising tags may transmit cookie and device identifiers, page visits, and conversion events to the named providers for advertising and measurement:

15. Changes to this policy

We may update this Privacy Policy from time to time to reflect changes to the Service, our practices, or applicable law. When we make material changes, we will update the “Last updated” date and, where appropriate, notify you (for example, by email or an in-product notice). Continued use of the Service after a change takes effect constitutes acknowledgement of the updated policy.

16. Contact

For privacy questions or to exercise your rights, contact Vectorwise LLC (Vavio) at hello@vavio.ai. Postal / legal notices: Vectorwise LLC, 1309 Coffeen Avenue STE 1200, Sheridan, WY 82801, USA. We will respond within a reasonable time and within the period required by applicable law.