VerraVerra
HomeProductDocs
Book a DemoSign in / Sign up

Privacy

Privacy policy

Last updated June 3, 2026

This Privacy Policy describes how Verra handles personal information when you visit helloverra.com, access the Verra dashboard, use the Verra Workspace, or send traffic through the Verra gateway. It explains what we collect, why, with whom we share it, how long we keep it, and the choices you have. The Verra browser extension has its own narrower policy at /privacy/extension.

If you have questions about this policy, contact privacy@helloverra.com.

Who we are

Verra is a governance layer for AI agents. We sit between an organization's applications and the AI providers they call, enforcing policy, logging hash-verifiable evidence, and routing sensitive content to private model targets. Our customers are organizations that use Verra to govern their own AI usage; the end users we interact with are typically employees of those customer organizations.

What information we collect

Account information

When you sign up or are invited to an organization, we collect your email address, name (where provided), profile photo (where provided), the organization you belong to, and the role assigned to you within that organization.

Usage and telemetry

We collect technical information about how Verra is used: request timestamps, IP addresses, user-agent strings, page paths, feature interactions, and error reports. Where we issue cookies, we use them strictly for authentication, session continuity, and product analytics. We do not use third-party advertising cookies.

Customer data passing through the gateway

When a customer routes traffic through the Verra gateway, prompts, tool calls, and model responses flow through our infrastructure in order to be analyzed against policy. We retain metadata about these calls: request shape, model target, applied policy verdict, tool names, content classifiers, redaction events, timestamps, and hashes. We do not persist the raw bodies of prompts or completions as part of normal operation; raw bodies remain at the model provider and the customer's originating system. Customers can opt into deeper retention via their organization configuration; this is off by default.

Workspace content

If your organization uses Verra Workspace, we host content the organization explicitly uploads: meeting transcripts, decks, memos, board documents, market research, drafted communications, and agent-generated outputs derived from them. We treat this content as customer data: it is yours, controlled by your organization, and subject to the access controls your organization configures (RBAC and row-level security).

Integration data

When your organization connects a third-party integration such as Gmail, Google Calendar, Google Drive, Affinity, Salesforce, HubSpot, Attio, Standard Metrics, or Fathom, we receive only the scopes that integration was authorized for, and only on behalf of the organization member who connected it. We use this data to power the workflows the customer configured.

Gmail policy. Verra never sends mail on the user's behalf. We request the read scope to index interactions and the “compose draft” scope to stage proposed replies; both stay inside Gmail until the user opens Gmail and sends the draft themselves. The Gmail send scope is never requested.

How we use information

  • Provide the Service. Authenticate users, route governed traffic, evaluate policies, log evidence, deliver workspace surfaces.
  • Improve safety and quality. Detect injection attempts, jailbreaks, PII leakage, and tool misuse patterns; tune policy defaults; investigate incidents.
  • Communicate. Send transactional email such as approvals, digests, and security notices; product updates where you have agreed.
  • Billing. Issue invoices and process payments through our payment processor.
  • Legal compliance. Meet our regulatory obligations and defend our rights where lawful.

Legal bases (EEA and UK users)

Where the GDPR applies, we process personal information on the following bases: performance of a contract (operating Verra for the organization that engaged us), legitimate interests (securing the Service, preventing abuse, product improvement), legal obligation, and, where required, your consent.

Sub-processors

We use the following sub-processors to deliver Verra. Each is bound by data-protection terms consistent with this policy.

Sub-processorPurposeRegion
Amazon Web Services (AWS)Infrastructure hosting, secrets storage, and model inference via BedrockUnited States
SupabaseAuthentication and application databaseUnited States
VercelFrontend hosting and edge deliveryUnited States / Global
Anthropic (via AWS Bedrock)LLM inference for governed model callsUnited States
OpenAIEmbeddings and judge model for selected pipelinesUnited States
ResendTransactional email deliveryUnited States

Customer-initiated integrations such as Affinity, Salesforce, HubSpot, Attio, Standard Metrics, Fathom, and Google Workspace are not Verra sub-processors. They are third parties the customer chooses to connect under their own contract.

When we share information

We share personal information only in these cases:

  • With the sub-processors above, strictly to deliver Verra.
  • Within your own organization, according to the access controls (RBAC and row-level security) your organization configures.
  • To comply with a valid legal request, after we have evaluated it for proper scope and tried to narrow it where appropriate.
  • In connection with a corporate transaction such as a merger, acquisition, or sale of assets, subject to confidentiality and equivalent privacy protections.

We do not sell personal information.

Retention

Account and configuration data is retained for the life of the organization's engagement and 30 days after termination, then deleted or anonymized.

Gateway audit metadata is retained for up to seven years from the date of the event to support customers' compliance obligations, then archived or deleted per the customer's configuration.

Workspace content is retained for the life of the organization's engagement plus 30 days, unless the customer requests earlier deletion via their administrator.

Security

We host Verra on AWS in the United States. Data in transit is encrypted with TLS 1.2 or higher. Sensitive credentials are encrypted at rest with envelope encryption (pgsodium AEAD) and stored in AWS Secrets Manager. We use least-privilege IAM, per-tenant row-level security, and tenant-scoped vector namespaces to isolate data across organizations.

International data transfers

Verra is operated from the United States. If you access Verra from outside the United States, your information will be transferred to and processed in the United States and other jurisdictions where our sub-processors operate. Where required, we rely on the European Commission's Standard Contractual Clauses and equivalent transfer mechanisms.

Your rights

Depending on where you live, you may have the right to access, correct, delete, port, or restrict the processing of your personal information; to object to processing; and to withdraw consent. To exercise any of these, email privacy@helloverra.com. We will verify your identity before acting and respond within the period required by applicable law.

California residents may also designate an authorized agent and may request the categories of personal information collected, the categories of sources, and the categories of third parties with whom we have shared their information in the past 12 months. We do not sell or share personal information for cross-context behavioral advertising.

If your organization is the controller of the data (Workspace content, integration data, gateway traffic), please direct rights requests to your organization's administrator first. We will assist them as a processor.

Children

Verra is not directed to children under 16. We do not knowingly collect personal information from anyone under 16. If you believe we have, contact us and we will delete it.

Changes to this policy

We may update this Privacy Policy from time to time. When we do, we will revise the “Last updated” date above. Material changes will be communicated by email or through a prominent notice in Verra before they take effect.

Contact

For any questions or to exercise your rights, contact privacy@helloverra.com.