Legal
Privacy Policy
Version 2 · Effective 11 September 2026
Also: Terms of Service · Refund Policy
1. Who is responsible and what this policy covers
This policy explains how Veyora Technologies, Inc., a Delaware corporation ("Veyora", "we", "us"), handles personal data when you use Veyora at veyora.ai and the pages, emails and interfaces that belong to it. Veyora Technologies, Inc. is the controller of that data, which means we decide why and how it is processed. We are based in the United States.
Veyora is a research and analysis product for prediction markets. It reads public market data from Kalshi, an exchange we are not affiliated with. We are not an exchange, broker, dealer or investment adviser, we hold no funds and we place no orders, so this policy has nothing to say about trading accounts: we have none of yours. The link "Open on Kalshi" inside the product takes you to Kalshi's own site, where Kalshi's policies apply.
This policy sits beside our Terms of Service and our Refund Policy. Where those documents describe how a feature works, this one describes what data that feature touches. The version number and effective date at the top of this page tell you which edition you are reading.
2. What we collect
We collect only what the product needs to run. The table lists every category, what it holds and where it comes from. We buy nothing about you from data brokers and add nothing from a source the table does not name.
Your email address is required to sign in. To activate the product, you must also declare your US country and state or district of residence or business operation. If you purchase, a complete supported billing address is required. What you sync, what you ask the assistant and whether you buy a plan remain your choice.
| Category | What it holds | Where it comes from |
|---|---|---|
| Customer eligibility | Your declared country and state or district, the time you confirmed them, and whether a billing-location review blocks product access. Full billing addresses are read from Stripe to check eligibility but are not copied into our database. | You, when you confirm eligibility, and Stripe for billing-location validation. |
| Account | Your email address and the time it was verified. If you sign in with Google: the name and profile image Google reports, Google's identifier for your Google account, and the sign-in tokens Google issued to complete that sign-in. We request no ongoing access to your Google data and use those tokens for nothing else. There are no passwords: none is ever created or stored. | You, when you request a sign-in link, or Google, when you sign in with Google. |
| Sessions | One record per sign-in: the session token your browser's cookie carries, when the session was created and when it expires, when it was revoked (if it was), and your browser's user-agent string, which Settings shows you as a coarse device label such as the browser and operating system family. Sessions end after up to 30 days without activity. | Created by the product when you sign in; the user-agent string is what your browser sends with the request. |
| Sign-in security counters | Counts of sign-in attempts and, when enrollment is open, of account creations. Each count is stored under a keyed hash (HMAC) of the normalized email and of a coarsened network source. The source is your network address with its final part removed, so it names a neighborhood of addresses rather than yours. The raw address and the raw email are never stored in these counters, but the service can recompute the pseudonymous keys; they are not anonymous. | Derived by the product from each sign-in request. |
| Workspace mirror | The workspace you build in the product, mirrored to your account so it follows you between browsers. It holds your tracked markets, your models and forecast journal, saved screens, chat threads (your messages and the assistant's answers, together with the answer's list of consulted sources and any ranked driver breakdown), notebooks (source code only, never outputs), workflows and projects, analysis run records, notes, tags and open questions written in earlier versions of the product (kept and synced, though the product no longer edits them), a few onboarding flags, and the preferences that sync. Only keys on a fixed allowlist sync, each under a byte cap. Some keys never leave the device: drafts, recently viewed markets, sync internals and recovery copies. | You, as you use the product. Your browser's local storage stays the source of truth; the account holds a copy. The server reads it only to sync it back to you, to write a market brief you turned on, and to choose which markets a scheduled news refresh covers. |
| Billing | Your plan, billing cadence, subscription status, period dates and any scheduled change. Credit lots and a signed ledger of grants and draws. Records of checkout attempts, a Stripe customer id and subscription id, and, for each event Stripe sends us, its id, type and the subscription or checkout it referred to (not its contents). Payment-location review records retain the provider object reference and a short reason for support and refunds, including after account deletion. These references can be linked to your transaction at Stripe and are not anonymous. Card numbers and payment methods remain with Stripe; we do not store full billing addresses. | You, when you choose a plan or buy a pack, and Stripe, which tells us what was paid. |
| Usage metering | A reservation and settlement per metered operation. For assistant work it records the token counts the AI provider reported and the credits they cost; for a news refresh past your plan's monthly count it records the fixed credit price the product shows before you press it. Daily and monthly budget counters are stored under a keyed hash (HMAC) of the account rather than the account itself, so a stored count does not name you but the service can recompute the pseudonymous keys; they are not anonymous. The product recomputes the key to read your own count back, for example to show how many news refreshes you have left this month; the counts are never joined to your account record and are shown to no one else. | Generated by the product each time you use a metered feature such as the assistant or a news refresh. |
| Market briefs | If you turn briefs on: your chosen cadence (off, daily or weekly), your time zone, when you consented and when you last turned briefs off, an unsubscribe link id, and a delivery log per brief holding its status, the time it was sent, the data timestamps it was built from, aggregate counts, and for each market the brief covered the probability you were last told (so the next brief can say what changed). Log rows are swept after 90 days; the most recent row carrying those market marks is kept as the baseline until a newer one replaces it. | You, in Settings, and the product when it sends a brief. |
| Legal acceptance | Which documents you accepted, their versions, the time and your consent gesture. Before a paid purchase or recurring-plan change, we also retain the accepted offer: plan or pack, price, cadence, applicable tax treatment, cancellation terms and the versioned documents. This limited evidence includes your account reference and email, survives account deletion and does not include a network address, user-agent string or workspace content. | You, when you choose a plan or accept an updated document. |
| Operational logs and reports | Request logs at our hosting provider (time, path, status, response size, your IP address, your browser's user-agent string and similar request metadata). Our own application logs print no emails, tokens, IP addresses or query strings. Error reports your browser sends us are scrubbed of emails, credentials, keys and query strings, printed as a single log line and never stored. Content-security violation reports are reduced to a directive, an origin and a path. Timing instrumentation, when an operator turns it on, carries a closed list of fields and no free text. | Your browser and our servers, as a side effect of serving you. |
| Billing notices | A restricted delivery queue stores the recipient email, accepted-offer facts, subscription or payment reference, immutable message, attempt timestamps, email-provider acceptance and any review resolution. Provider acceptance is not proof of inbox delivery. No workspace content or card number is included. | Your billing actions, verified payment-provider events and our notice worker. |
| Aggregate deletion audit | An operational audit records counts of what was removed and a timestamp, without an account id, email or amount. It is kept for 30 days. A separate restricted erasure record retains the deleted account reference for the 30-day backup window so deletion can be reapplied before a restored copy serves traffic; neither record is described as anonymous. | Written by the product at the moment of deletion. |
| Local browser storage | Data held in your own browser and never sent to us unless it is in the workspace mirror above. It is: local storage keys prefixed "veyora." (preferences and workspace), session storage (the Explore screen you are looking at), and the browser's HTTP cache for the notebook's Python runtime files, which are served from our own site and cached so they are not downloaded again. | Written by the product in your browser. It stays on your device. |
3. What we do not collect
Some things people expect a financial product to collect, we do not. Being clear about them matters as much as listing what we do collect.
- No trading positions or balances. We have no broker connection to Kalshi or any other exchange. We cannot see what you hold, what you have traded or what you have deposited anywhere.
- No card numbers or financial account numbers. Payment details go straight to Stripe and never pass through our servers.
- No government identifiers. We do not ask for a passport, driver's license, social security or tax number.
- No precise location. We do not read GPS or device location. Your IP address reaches our hosting provider with every request and sits in its request logs for the short time it keeps them, and your browser sends it to the image servers named under Cookies and browser storage. Our own records keep only a hashed, coarsened form of it (your address with its final part removed) for abuse prevention, which is pseudonymous and can be recomputed for abuse checks; it is not anonymous.
- No contacts, calendars or files from your device. A file you add to a notebook stays in your browser and is never uploaded.
- No data from children. The product is not for people under 18 and we do not knowingly collect their data.
- No behavioral profile. We do not build advertising profiles, buy data about you from brokers, or track you on other sites.
4. How we use it, and on what legal basis
We use personal data for the purposes below and no others. We do not use it for advertising, we do not sell it, and we do not profile you for advertising. Automated checks enforce eligibility, payment state and usage limits. You can contact support to request review of an eligibility or billing restriction.
| Purpose | What we do | Legal basis (if you are in the EEA or the UK) |
|---|---|---|
| Provide and secure the service | Sign you in, keep your session, mirror your workspace between browsers, meter your usage against your plan (Free includes 10 credits a month), and stop abuse of sign-in and rate limits. | Performance of our contract with you; our legitimate interest in keeping the service secure. |
| Answer your questions | Send your message, the recent conversation and the market's public data to OpenAI to produce an answer, and show you which sources the answer drew on. | Performance of our contract with you. |
| Bill you | Record your plan and purchases, reserve and settle credits for metered work, and reconcile what Stripe tells us with what we grant you. | Performance of our contract with you; our legal obligation to keep financial records. |
| Send you mail | Send sign-in links, the confirmation that your account was deleted, and notices about your account and these documents, such as a change to a price or to this policy. Send market briefs only if you turn them on, with an unsubscribe link in every one. To write a brief, our server reads the tracked-market list from your workspace mirror and states what changed in those markets from public data; that is the only server-side use of your mirror beyond syncing it back to you and the news refresh described next. If we run a scheduled news refresh, the same tracked list decides which markets are refreshed; the refresh itself sends Perplexity market text only. We send no marketing email. | Performance of our contract with you (sign-in links, the deletion confirmation, account and document notices); your consent (briefs), which you can withdraw at any time. |
| Keep the service reliable | Read scrubbed error reports, health checks and, when enabled, timing instrumentation so that we can find and fix what is broken. | Our legitimate interest in running a reliable service. |
| Protect rights, safety and the business | Investigate fraud, abuse and security incidents, establish or defend legal claims, and, if the business is sold or merged, pass the data to the successor with notice to you. | Our legitimate interests in protecting the service, the people who use it and ourselves, and in continuing the business; our legal obligations where a claim or an order is involved. |
| Comply with the law | Keep the records we are required to keep and respond to lawful requests. | Our legal obligations. |
5. The assistant and other AI processing
Veyora's assistant is an AI model reached through OpenAI's API. This section says exactly what leaves our servers for it, with what settings, and what never does.
What is sent when you message the assistant. Your message and the recent history of that conversation, together with a dossier we assemble about the market you are looking at: its price and price history, order book and recent trades, rules, stored news coverage, known catalysts, and the quotes of related contracts in the same event and category. Every section carries the time its data was last read, and if any was delayed the answer's list of sources says so. All of the dossier is public market data or text we generated from it. The request also carries your chosen response depth. We add nothing that identifies you: no email, no account id, no name, and no identifier the provider could use to link your conversations to you. Your own words are the exception. Whatever you type into a message, including anything personal about you or about someone else, goes to OpenAI as you wrote it, so treat the composer as you would any message sent to a company you do not know.
With what settings. Every request is sent with OpenAI's storage turned off (the request carries "store: false"). OpenAI therefore does not keep the conversation to serve a later request, and we never rely on a stored conversation on its side. We do not use your content to train any model, ours or anyone else's. OpenAI's own API terms govern what it retains for abuse monitoring. At the time of writing, its API data policy states that API content is not used for training by default and may be kept for up to 30 days for abuse and misuse monitoring. See OpenAI's API data policies for the current statement.
What is never sent. Your workspace is not part of the dossier. Your notes, your models and forecasts, your saved screens, your notebooks and the files you add to them never go to OpenAI. Nothing the assistant does reads the workspace stored in your account. There are three deliberate exceptions, and each begins with a button you press. Pressing "Discuss this result" on an analysis card, or "Discuss this output in chat" on a notebook cell, sends that one result or output into the conversation. And when the assistant offers to run one of the product's own analyses and you press "Run it" on that offer, the result is sent back to the assistant when the run finishes, so it can interpret it. In every case what crosses is bounded text built from the result's own figures and warnings, never a chart, a file or a file name. A result that read your own local inputs (your saved model or journal, a file you added, or an input pre-filled from your saved estimate) is refused rather than sent. The copy that crosses belongs to that one turn only: it is never stored in the thread and never replayed later.
Usage returned to us. For each answer OpenAI reports how many tokens it processed. We use that count, and only that count, to meter your credits (one credit is 10,000 billable tokens of model work).
News research. When news coverage is gathered for a market, the market's question, its rule text, its current price and how long until it resolves are sent to Perplexity, which returns cited articles. No personal data is included in that request: not who asked, not what you hold, not anything from your workspace.
The contract explainer. The plain-language reading of a market's rules is generated from the market's question and rule text and nothing else. The request carries no price, no news, no history and no personal data, and the result is stored per market, not per person.
What the assistant is. It reasons about markets and may hold analytical views, and it can be wrong. It is not a licensed adviser and it never issues a personalized instruction to trade. Decisions you make after reading it are yours; the Terms of Service say more.
8. Where your data is stored and processed
Veyora is operated from the United States and its data is stored there. Every provider named under Who we share it with also processes data in the United States. If you use the product from somewhere else, your data is transferred to and processed in the United States, where privacy law differs from the law where you live.
If you are in the EEA, the UK or Switzerland, each provider named in the table above processes data for us under its own published data-processing terms, which include the standard contractual clauses approved by the European Commission, with the UK addendum where UK law applies, for the transfers that require them. Those terms are linked from each provider's name in that table, and they apply together with the measures described under How we protect it. We do not rely on your consent for these transfers.
9. How long we keep it
We keep personal data for as long as the purpose it serves lasts, and no longer. The table gives the period for each category.
| Category | How long |
|---|---|
| Account (email, verification time, Google profile fields and sign-in tokens) | For the life of the account. Deleted when you delete the account. |
| Customer eligibility declaration and billing-location block | For the life of the account. Deleted with the account. |
| Sessions | Until the session expires or you revoke it. Expired and revoked session records are deleted by a scheduled sweep 30 days later, or with the account, whichever comes first. |
| Sign-in tokens | Single use. An unused link expires after 15 minutes. Expired records are removed by hourly cleanup, targeted within 24 hours, or when used or deleted with the account, whichever comes first. |
| Sign-in security and usage counters | Removed after seven days of inactivity following the relevant usage window. A monthly allowance is never cleared while its month is active. Keyed hashes replace raw identifiers but are pseudonymous: the service can recompute them to associate a count with your account or source. |
| Workspace mirror | Until you clear it yourself in Settings, Account with Clear cloud workspace (the product's name for the mirror), or delete the account. |
| Billing records | The live billing record is deleted with the account. A restricted minimal financial archive retains transaction facts, credit grants and consumption, subscription closing facts and provider references for seven years after the relevant financial year ends. It contains no workspace content or card numbers. Payment-location support cases remain while unresolved and for 24 months after resolution; ordinary processed provider-event references are swept after 30 days. These references are not anonymous. Stripe retains its own records under its obligations. |
| Usage metering (reservations and settlements) | Deleted with the account. |
| Billing notices | Accepted-notice evidence lasts at least three years from creation and one year after termination, whichever is later; ongoing subscriptions preserve their evidence. Unconfirmed notices remain open support cases until reviewed, then for 24 months after resolution. Dated record-specific holds may extend these periods. |
| Market briefs (preference and delivery log) | The preference row for the life of the account: turning briefs off records that you did (and when) rather than deleting the row. Each delivery log row for 90 days, except the latest row carrying market marks, which is kept as the baseline while briefs remain enabled, until a newer one replaces it. Turning briefs off makes old baseline rows eligible for the same 90-day sweep. |
| Legal acceptance | Accepted paid offers and versioned terms are retained for at least three years after acceptance and one year after termination, whichever is later; an ongoing subscription keeps its evidence. Account deletion does not erase this restricted evidence. Historical acceptance rows retain only the document version and acceptance facts originally recorded. |
| Aggregate deletion audit | 30 days. A separate restricted account-reference erasure record also lasts 30 days so deletions can be reapplied after a backup restore. |
| Hosting request logs | Our operational retention target is 30 days or less, subject to a documented security or legal hold; our hosting is configured to that target. |
| Browser error and CSP reports | Not stored. Each is printed as one log line and kept only as long as the hosting logs above. |
| Database backups and point-in-time history | Our backup and point-in-time retention target is 30 days or less. Deleted data may remain in restricted copies until expiry. If we restore from a backup, we reapply every deletion made since that backup before the restored copy serves anyone. A dated, record-specific legal or security hold may extend a stated period only for the records and purpose it identifies. |
| Local browser storage | On your device until you clear it, or until you choose Sign out & clear this device. |
10. Your rights and controls
Most of what privacy law gives you a right to ask for, you can do yourself in Settings without asking. These controls work for everyone, wherever you live.
- Download an export. Settings, Account gives you a file holding your profile fields, your workspace with its revisions, your billing record (plan, period, grants and ledger), your briefs record and your record of which of these documents you accepted. It never contains tokens, secrets, hashes, counters or any provider identifier.
- Export, import or clear local data. Settings, Local data lists every key the product keeps in your browser, including data from retired features, and lets you export, import or delete it.
- Clear the cloud workspace. Removes the workspace mirror, the copy of your workspace held in your account. Your browser's copy stays, and a signed-in browser mirrors it back on its next visit unless you clear that too. This needs a sign-in within the last 15 minutes.
- List and revoke sessions. Settings, Account shows every signed-in session with its device label and dates. You can revoke any one of them, or choose Sign out everywhere to revoke all of them.
- Delete the account. Delete account removes, in one operation, the account itself, every signed-in session, the account's workspace mirror (tracked markets, models, chat threads, notebooks and analysis runs stored with it), the live billing record (subject to the minimal financial and consent archives described under Retention), the Google link if there was one, and any unused sign-in links. It needs a sign-in within the last 15 minutes. If a subscription is live, we cancel it at Stripe first, and if that cancellation cannot be confirmed the deletion is refused so that nothing keeps billing an account that no longer exists. Where email delivery is configured, a confirmation is sent to the address that was on the account.
- Manage briefs. Turn market briefs on or off and choose daily or weekly in Settings, App preferences. Every brief carries an unsubscribe link that works without signing in.
- Choose which copy wins. The first time you sign in on a browser that already holds a different workspace, the product asks whether the account's copy or the device's copy should win. It lets you export both first, and it keeps the losing copy on the device in a recovery store.
- Disconnect Google. There is no separate control for this yet. If you connected Google, the link stays until you delete the account.
If you are in the EEA or the UK, you also have the rights that the GDPR and the UK GDPR give you. You can ask to access the personal data we hold about you, to have it corrected, to have it erased, and to restrict or object to its processing. You can ask to receive it in a portable form. Where consent is the basis, you can withdraw it at any time; withdrawing does not affect processing that already happened. You also have the right to complain to a supervisory authority. In the UK that is the Information Commissioner's Office. In the EEA it is the data protection authority of the country where you live, listed by the European Data Protection Board.
If you are in California, and to the extent the California Consumer Privacy Act applies to us, and in any case as a matter of our own practice, you have the right to know what personal information we collect, use and disclose. You also have the right to delete it, the right to correct it, the right to opt out of its sale or sharing, and the right not to be treated differently for exercising any of these. In the twelve months before the effective date of this policy we have not sold personal information and have not shared it for cross-context behavioral advertising, and we do not do so now, so there is nothing to opt out of. In the categories the Act uses, we collect identifiers (your email address, the name and profile image Google reports if you sign in with Google, and session and customer identifiers), the US state or district of residence or business location you declare, commercial information (your plan, purchases and credit ledger), and internet or other electronic network activity (request logs at our host, the workspace you sync, your messages to the assistant). The sources and the providers that receive each are the ones named under What we collect and Who we share it with. We collect no sensitive personal information as the Act defines it and make no inferences about you. You may make a request yourself or through an authorized agent; we will ask the agent for your signed permission and will verify the request with you at the account's email address. The California Attorney General's office explains these rights.
If you are in another US state with a privacy law, such as Virginia, Colorado, Connecticut, Utah, Texas or Oregon, you have comparable rights to access, correct, delete and port your data and to opt out of targeted advertising, sale and profiling with legal effects. We do none of those three, and you can exercise the other rights exactly as described below. If we refuse a request in whole or in part, we tell you why, and you may appeal by replying to our answer with "Appeal" in the subject line. We answer an appeal in writing within 45 days, and if we still refuse we tell you how to contact the attorney general of your state. We do not disclose personal information to third parties for their own direct marketing, so there is nothing to report under California's Shine the Light law.
How to exercise a right. Use the controls in Settings where one exists; that is the fastest route and needs no request. For anything else, email hello@veyora.ai from the email address on your account, or use the matching door on the contact page. We verify a request by confirming it came from the account's own email address; we may send a sign-in link to that address to be sure. We confirm that we received a request within 10 business days and answer within 30 days. If a request is complex or there are several, we may take longer where the law allows it (up to two further months under the GDPR, up to 45 further days under California law); if so we tell you within the first period why and how long we need. We do not charge for a request unless it is plainly excessive, and we will say so before doing anything.
11. How we protect it
We build the product so that the data it holds is hard to reach and easy for you to take away. The measures that matter most:
- Every connection uses HTTPS, with HSTS and a set of security headers that stop the site being framed or loaded from places it should not be.
- Sessions live in the database, not in the cookie alone, so any session can be revoked on the server and stops working on its next request.
- There are no passwords to steal. Sign-in links are single use, stored as a hash, expire after 15 minutes and are carried in the URL fragment, which browsers do not send to servers, so a link never lands in a server log.
- Sign-in and usage counters are stored under a keyed hash (HMAC) of the identifier, so neither an email address nor a network address is stored in them but the service can recompute the pseudonymous keys; they are not anonymous.
- Secrets live only in the deployment environment. Nothing in the code repository holds a key.
- Destructive actions (clearing the cloud workspace, deleting the account) need a sign-in within the last 15 minutes, so a session left open on a shared machine cannot be used to destroy your data.
- Account deletion runs as one atomic operation: either every part of it completes, the restricted archive it writes included, or none of it does.
- We hold no card data. Payment details go to Stripe and never touch our servers.
No method of storage or transmission is perfect, and we do not promise that a breach can never happen. If one does affect you, we tell you without undue delay and as the law requires. If you believe you have found a security problem, please write to hello@veyora.ai with "Security" in the subject line and we will respond.
12. Children may not use Veyora
Veyora is not directed to anyone under 18, and prediction-market trading is not open to them. We do not knowingly collect personal data from a person under 18. If we learn that an account belongs to someone under 18, we delete it. If you believe a child has created an account, email hello@veyora.ai and we will act on it.
13. Changes to this policy
The version number and effective date at the top of this page identify the edition you are reading. When we make a change that affects you, such as a new provider, a new use of data or a new right, we raise the version. We tell you at least 14 days before it takes effect, by email to the address on your account, in the product, or both, the same period the Terms of Service state, except for a change the law requires, which applies when the law does. That notice comes before the change applies so you have time to export or delete your data first. Wording fixes that change nothing about what we do are not announced. Each version carries a one-line note of what changed, shown with the document.
14. Contact
Questions about this policy, requests about your data and anything else go to one inbox. Email hello@veyora.ai from the email address on your account, or use the matching door on the contact page. Put "Privacy" in the subject line and it reaches the right person; the contact page's Privacy door does that for you. Our contact details, including a postal address where one is published, appear below.
Email hello@veyora.ai
Web Contact page
Post A postal address is available on request.