Verde← Back to Verde

Privacy Policy

Last updated: July 20, 2026

This policy explains what Verde collects, why, and the choices you have. It reflects how the product works today. Verde is operated by Enthusiast, LLC.

When you use Verde as an individual, we act as the controller of your account information. When your employer or team subscribes and you use Verde on their behalf, we generally act as a processor of the content in their teams and vaults, and they determine how it is used.

Information we collect

  • Account information. Your name and email address, managed through our authentication provider (Neon Auth / Better Auth). If you sign in with Google, we receive basic profile information (name, email) from Google.
  • Content you create. The teams, vaults, buckets, and documents (“memories”) you and your teammates create, including their text, metadata, and tags.
  • Connections and tokens. When you connect an AI client, we store records of the OAuth clients you authorize and hashed representations of access and refresh tokens (the plaintext is shown only once at creation and is not stored).
  • Activity data. An activity log of actions taken in your vault (for example, documents created or searches run) to power usage insights and audit history. Entries record the actor, the action, whether it came from the dashboard or an AI client, and — for searches — the query text.
  • Billing information. If your team subscribes to a paid plan, we store your plan, subscription status, billing interval, seat count, and the identifiers Stripe assigns to your customer and subscription records. We send Stripe your team name and the billing contact’s email address. Card details are entered directly into Stripe and never reach our servers; we do not store card numbers, expiry dates, billing addresses, or tax identifiers.
  • Technical data. IP address and basic request metadata, used for security, abuse prevention, and rate limiting. Rate limiting stores a short-lived record derived from your IP address in our database; it expires as each rate-limit window rolls over.

Cookies and local storage

Our authentication provider sets cookies that are strictly necessary to sign you in and keep you signed in. We do not use advertising or cross-site tracking cookies, and we do not run third-party analytics. Your browser also stores a small amount of local preference data (such as your light/dark theme choice and whether you have dismissed onboarding tips); that data stays in your browser.

How we use information

  • to provide, maintain, and secure the Service;
  • to enforce permissions and team and vault boundaries;
  • to prevent abuse (including rate limiting) and diagnose errors;
  • to show usage insights within your own vault;
  • to process payments, manage subscriptions and seat counts, and enforce plan limits;
  • to send transactional email — team invitations, sign-in codes, and password-reset links. We do not send marketing email.

We do not sell your personal information.

Service providers (sub-processors)

We share data with vendors that help us run the Service, only as needed to provide it:

  • Neon — managed Postgres database and managed authentication (identity and sessions). Some authentication email, such as email verification, may be delivered by Neon’s own email provider.
  • Vercel — application hosting and serverless compute.
  • Stripe — payment processing and subscription billing for paid plans (receives your team name, billing contact email, and card details entered directly into Stripe’s payment form).
  • Resend — delivery of transactional email such as team invitations and sign-in codes (receives the recipient address and the contents of that email).
  • Google — only if you choose to sign in with Google.
  • Sentry — error monitoring, if enabled for the deployment (receives error details, stack traces, and limited request context such as the URL path).

We do not send your content to any AI or machine-learning provider, and we do not use your content to train models. Search runs inside our own database. When you connect an AI client over MCP, that client retrieves content on your instruction and handles it under its own provider’s terms, which we do not control.

Our database and application are hosted in the United States (AWS US East). If you access Verde from outside the United States, your information will be transferred to and processed there.

Data retention

We retain Your Content for as long as your team or vault exists. Documents are archived rather than erased, so history stays available; deleting a team or vault is immediate and permanent and removes its content, including archived documents (subject to limited backup retention).

Activity log retention depends on your plan. We automatically delete activity-log entries older than your plan’s window — 30 days on Free, 90 days on Team, 365 days on Business, and unlimited on Enterprise — with a short grace buffer before deletion runs. If a paid subscription lapses, the team’s activity log is pruned on the Free window, which permanently deletes older entries. This applies only to the activity log; your documents are not deleted by plan retention.

Your rights and choices

  • Access / export. You can export a copy of your account and content data as a JSON file from your account settings. The export covers your profile, team memberships, the documents you authored, your access-token records (never the token secrets), and your activity history. It does not include records held by our authentication provider, such as sign-in history — contact us to request those.
  • Account deletion. You can delete your account from your account settings. Deletion is a soft delete with a 30-day grace period: your account is deactivated immediately (you’re signed out and access is blocked), but your data is retained for 30 days so you can restore it by signing back in. After 30 days, your personal data is permanently deleted or anonymized — your private documents and connections are removed, and content you contributed to shared teams is retained but stripped of your identity. If you are the sole owner of a team with other members, you’ll be asked to transfer ownership first so the team isn’t left stranded. Deleting your account also cancels any subscription for teams that are removed with it. One limitation to be aware of: the identity record held by our authentication provider (Neon Auth) — such as your email address and sign-in history — is not always removable by our automated purge. Where it cannot be removed automatically, your account remains permanently blocked from signing in, and you can contact us to request erasure of the remaining identity record.
  • Team and vault deletion. You can delete teams and vaults you own from their settings at any time.
  • Correction. You can edit your content and profile at any time.

Depending on where you live, you may have additional rights under laws such as the GDPR or CCPA. Contact us to exercise them; we do not discriminate against you for doing so.

Business customers and data processing agreements

If you use Verde on behalf of a business and need a Data Processing Agreement, we will provide one on request — contact privacy@getverde.ai. Where required for transfers of personal data out of the European Economic Area or the United Kingdom, that agreement incorporates Standard Contractual Clauses.

Users in the European Economic Area and United Kingdom

We do not currently market or direct Verde to the EEA or UK, and we have no establishment there. We recognize that people in those regions may nonetheless find and use the Service, so we aim to handle their information consistently with the GDPR and UK GDPR.

Legal bases. Where the GDPR applies, we rely on: performance of a contract to create your account, host your content, and provide the Service; legitimate interests to secure the Service, prevent abuse, diagnose errors, and understand usage within your own workspace; legal obligation to meet tax, accounting, and compliance duties; and consent where we ask for it, which you may withdraw at any time.

International transfers. Our infrastructure is in the United States, so using the Service means your information is transferred there. Where required, we rely on appropriate safeguards for those transfers, including the European Commission’s Standard Contractual Clauses, and our sub-processors are engaged under comparable terms.

Your rights. Subject to the conditions in those laws, you may request access to, correction of, deletion of, or a portable copy of your personal data; object to or ask us to restrict certain processing; and lodge a complaint with your local supervisory authority. Many of these are available directly in your account settings; for the rest, contact us at the address below and we will respond within the time the law allows.

We have not appointed an EU or UK representative under Article 27, as we do not target those markets. We will revisit this if that changes.

Security

Data is transmitted over TLS. Access and refresh tokens are stored only as hashes. Access to your content is enforced server-side by vault, role, permission level, and ownership rules, and is re-checked on every request — including requests made by AI clients, so revoking someone’s access takes effect immediately. No system is perfectly secure, but we work to protect your information.

Children

Verde is a business product intended for users aged 18 and over. It is not directed to children, we do not knowingly collect personal information from them, and we will delete any such information we discover. If you believe a child has provided us information, contact us at the address below.

Changes to this policy

We may update this policy; material changes will be reflected by updating the “Last updated” date above.

Contact

Privacy questions or requests: privacy@getverde.ai.