Veritas Agent Logo Veritas Agent
  • Home
  • Creators
  • Pricing
  • Features
  • Download
  • Updates
Legal

Privacy Policy

This policy explains how Veritas Agent handles your information. Last updated: 23/08/2026.

1. Scope and overview

This Privacy Policy applies to Veritas Agent websites, apps, and services. Veritas Agent is operated by Bradley Bulman (ABN 28 283 798 533). We handle personal information in accordance with the Australian Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). It describes what information we collect, how we use it, which services help us operate, and the controls available to you.

To keep signed-in requests responsive, active server instances may temporarily cache verified account, plan, role, and organization-membership results for a short period. These operational caches are bounded, expire automatically, are not used to bypass authoritative usage-limit checks, and do not change the underlying account records or their retention.

Veritas Agent is designed to provide AI-assisted chat, document analysis, image analysis, grounding/search features, searchable saved conversation history, optional Meeting Assistant and Voice Notes features, optional email delivery tools, and optional personalization controls.

If we retire an optional workspace tool, we stop collecting new data through that tool. Any information previously stored through it remains subject to the existing account export and deletion controls, backup practices, and any legal retention obligations described in this policy.

If you enable Scheduled Research, we store the research brief, recurrence, browser-detected IANA timezone, schedule status, delivery timestamps, generated content, source links, AI token usage counts or estimates, and delivery/error metadata needed to produce and troubleshoot recurring or manually triggered schedules. You may separately opt a schedule into specific connected sources. When selected, Veritas first performs public-web research, then may make one bounded, read-only lookup in a selected connected app only where it materially improves the report. We store the source choice and a minimal report evidence summary; provider IDs, credentials, and raw provider metadata are not included in the delivered report. You can remove a source from a schedule or disconnect the account at any time to stop future scheduled access. We use your account plan and role to apply saved schedule limits. For each run, AI may derive public-web subtopics, research questions, search queries, freshness needs, source priorities, search depth, and a proposed deliverable from the saved brief. Those derived queries may be sent to AI search-grounding or web-search providers to retrieve current public results; private memory details are not used as public search terms. When Memories is enabled, a separate Truth Matrix selection step may process your enabled saved memories against the saved brief and public research evidence, then provide only the selected memories as private context for report synthesis. Memories are not used in public searches and are not shown in the delivered email as a memory list. You can disable Memories or delete saved memories to stop their future use. Scheduled content is sent only to the verified email address on your account. Completed content and source snapshots are retained for up to 30 days, unless deleted earlier through your account or account deletion request.

When Memories is enabled, Veritas Agent may process all memories you have saved and enabled as private context for a chat response or report, rather than applying a fixed memory-count limit. Saved memories may include AI-generated Context Signals used for personalization and context routing, including by adding signals to older memories when needed. Context Signals do not change your memory controls: disabling or deleting memories also stops or removes the related memory context and metadata.

Document sectioning, image-context indexing, and private Context Signals do not change the categories of information collected, the purposes of processing, or your privacy controls. Veritas Context Intelligence may use short snippets from prior messages, model responses, document sections, and internal context-selection metadata to help the AI select relevant context for the current request. To make an Evidence view available after a conversation reload, a response may retain a bounded snapshot of the selected document-section context with its existing conversation metadata. When available, the signed-in user can view the selected document title, section label, and that saved context for the relevant response.

Administrators may use the Truth Matrix Evaluator to submit one document for a private retrieval diagnostic. The document is extracted in the browser, sent to our AI provider to create temporary sections and test questions, and processed in-memory to measure context selection for that run. Veritas Agent does not save the evaluator source document or generated evaluation artifacts by default. Access is restricted to authorized administrators, who must ensure they have authority to submit the document.

2. Information we collect

2.1 Account and profile data

  • Name, email address, and authentication records used to create and secure your account.
  • Profile settings such as username, plan status, preferences, and terms-agreement status.

2.2 Conversation and content data

  • Chat messages, prompts, and model responses.
  • Conversation metadata, including timestamps, private Context Signals that may describe granular document sections, short context-selection snippets or summaries, document section counts/word counts, AI token usage counts or estimates, context-token savings estimates, and related context used to support your session.
  • Saved items for optional personalization features, such as memories and private memory Context Signals.

2.2A Enterprise organization data

  • If you use Veritas Agent through a business or enterprise workspace, we may process organization names, slugs, ownership records, admin/member role data, invite records, invite token metadata, workspace metadata, organization settings, audit logs, and enterprise billing identifiers or billing status.
  • Enterprise registration records may include company profile details such as country, ABN or other business identifiers supplied to us, legal business name, trading name, business type, website, phone number, and business address.
  • For Enterprise owners, we may check organization billing status and selected billing interval to decide whether the owner can enter the platform, manage workspace settings, or invite members.
  • Business invite records may include the invited email address, inviter details, organization name, role, status, expiry, and limited token data needed to create, validate, expire, or revoke an invitation.
  • Authorized administrators may permanently delete admin-created business invite records and linked workspace setup records, including related organization invite, membership, billing, and audit records associated with that pending workspace.
  • Enterprise content may be stored in customer data tables scoped by organization membership, organization identifiers, and access controls so business data remains separated from personal consumer data and from other organizations.
  • Organization owners or administrators may be able to manage members, remove member workspace access, review workspace settings, view audit/security events, control organization-owned data, and manage admin-led Enterprise purchase or contact-sales workflows according to their role and applicable workspace settings.
  • Organization owners may assign or remove a member's organizational job title and department within the business workspace. These assignments are organization-scoped member profile data, are visible to authorized workspace members, and are recorded with related workspace audit activity.
  • When Enterprise workspace leadership is transferred, we update the workspace ownership record and affected administrator roles and record the transfer in the organization audit log.
  • For Enterprise workspaces, we may aggregate organization-scoped assistant-message token metadata by calendar month so workspace administrators can review usage, recent activity, and an estimated month-end projection. This view does not expose message content or individual member usage.
  • When an Enterprise owner connects an app that delivers an enabled Proactive Engine event, we store a minimized event case and the active organization roster used for its assessment. The case contains only the source fields needed to assess the request, such as a subject, message text, sender, channel, and timestamp; it does not retain raw provider payloads, credentials, provider URLs, or transport diagnostics. Veritas records its proposed priority, recipient, in-platform notification, and reason so the organization can review the recommendation.
  • Removing a member from an enterprise organization removes that user's access to the business workspace and may create an audit record, but it does not delete the user's personal Veritas Agent account.
  • An authorized Enterprise owner may delete a company workspace. This cancels the linked Enterprise subscription where possible and deletes organization-owned workspace records, member links, invites, billing rows, and organization-scoped app data. It does not delete the personal Veritas Agent accounts of the owner or members.

2.3 Files and media

  • Uploaded documents, images, and audio files, including the content and metadata needed for preview and AI processing. Chat audio is sent to Google Gemini through its temporary Files API for the requested analysis and is not saved to Veritas Agent application storage by this upload feature. We request deletion of that temporary Gemini file after the response completes; provider retention and processing remain subject to Google's applicable terms.
  • For uploaded images, concise AI-generated Context Signals, factual summaries, and human-readable display labels used to organize images and select relevant prior image context. These labels may be incomplete or corrected over time and do not change the stored upload filename.
  • AI-generated documents and exports, including filenames, file type, size, storage path, download URL metadata, and generation details needed to save, preview, and download the file.
  • Public or shareable file URLs when required by product features such as previews or support tooling.

2.4 Meeting Assistant and Voice Notes data

  • If you use Meeting Assistant in the desktop application, Veritas Agent may capture microphone audio, desktop/system audio where available, and related technical metadata such as recording time, file type, file size, and storage path.
  • If you use Voice Notes in a browser or on a mobile device, Veritas Agent captures only the microphone audio that you explicitly permit your browser to provide. Voice Notes does not capture desktop/system audio, other app audio, phone-call audio, or audio from other device sources.
  • If you enable the optional setting to hide the minimized recording control from supported Windows screen sharing, the setting is stored locally in your browser/application storage. The feature requests operating-system capture exclusion for the control itself; it does not collect additional meeting content or guarantee exclusion by every capture method.
  • Meeting Assistant and Voice Notes may generate transcripts, AI-generated speaker labels or speaker turns, transcript segments, timestamped summaries, key moments, action items, follow-ups, decisions, and other notes from a recording. Speaker labels are inferred from the recording and are not identity verification or biometric voiceprints.
  • Audio and generated notes may include personal information about you and other people, including voices, names, opinions, business information, and other information discussed in the recording. Depending on the recording, this may include sensitive information.
  • When audio is saved, it is stored in private application storage and accessed through time-limited signed URLs for playback. Transcript, summary data, and AI token usage counts or estimates may be stored with the related conversation so you can review and ask follow-up questions about the recording and so we can monitor operational usage.
  • Transcripts and generated notes may be treated like document content for internal indexing, sectioning, and retrieval so follow-up questions can use organized recording context.

2.5 Contacts and communication data

  • Email contacts you save in-app.
  • Email payload content when you use the email tool (recipient, subject, body, and reply-to details).
  • Scheduled post and Scheduled Research instructions, cadence, browser-detected timezone, generated summaries, source links, delivery records, AI token usage counts or estimates, and, when your Memories setting is enabled, Truth Matrix-selected saved-memory context used to personalize scheduled synthesis.
  • Admin-created business invite emails, including delivery metadata needed to send, troubleshoot, expire, or resend invitations.
  • Support and issue report submissions, including request type, title, description, optional screenshots, collaboration details, and operational context such as page URL, browser user agent, app version, chat ID, viewport size, and language where available.

2.5A Skills

  • If you create a Skill, we store its name, description, workflow instructions, version, status, ownership, and timestamps so you can select and reuse it in chat.
  • When you select a Skill in a chat, its saved instructions are processed with that chat request by our AI provider to produce the requested result. Skills do not independently connect to third-party accounts or grant new permissions.
  • We may retain a minimal record that a selected Skill was used for a chat workflow, including the skill version and operational outcome needed for reliability and security. We do not use Skill instructions to override core safety, access, or approval controls.

2.6 Optional location data

  • If enabled by you, location coordinates (latitude/longitude), approximate address details, country/state/city fields, and location update timestamps.
  • Location-derived preferences such as currency context.

2.7 Billing and subscription data

  • Plan and subscription status, billing frequency, and related Stripe customer/subscription identifiers.
  • Organization billing status, Enterprise purchase workflow status, contact-sales request context, company profile summaries used for billing administration, active member seat counts, billing-band snapshots, next-invoice previews, and admin-led checkout or billing-management metadata where applicable.
  • Payment events and metadata needed to maintain your selected plan in the app.

2.8 Connected integration data

  • If you connect a third-party account through our managed integration provider, we may store connection metadata such as provider account email/address, provider account ID, granted scopes, capability flags, connection timestamps, and related status/error fields. Connections are associated with your Veritas Agent user or organization context and are not intended to be shared across unrelated customers.
  • Composio securely maintains the OAuth credentials or tokens for managed connected accounts and uses them to access the connected service on your behalf. Veritas Agent stores provider-side connection identifiers rather than underlying connected-service credentials.
  • To plan, execute, display, secure, and troubleshoot connected-tool actions, we and our providers may process tool names, action instructions and arguments, selected account identifiers, results returned by the connected service, approval or automatic-execution policy status, timestamps, errors, and audit or run records. This information can include personal or business content from the service you connected.
  • For an Enterprise connected-app event that has been enabled in Composio, Composio may deliver a signed event to Veritas Agent when that event occurs. We verify the signature, reject stale or invalid deliveries, minimize the event, and use the active organization roster to prepare an organization-scoped recommendation. Disconnecting the account or disabling the event in Composio stops future event intake; it does not remove records already retained under the organization's applicable retention controls.
  • If you connect Linear or HubSpot, requested results may include project and issue details or CRM contact, company, deal, and support-ticket fields. Veritas Agent limits initial indexes and sends detailed descriptions, associations, comments, or activity history for AI processing only when needed for the workflow you requested.

2.9 Local and session storage

  • Browser local/session storage values used for session continuity and convenience features, such as remembered login email, style selections, and transient UI state.

2.10 Security and abuse-prevention data

  • For public support and password-reset protection, we may create one-way HMAC hashes of a requester's IP address and, for password resets, the submitted email address. These hashes are used only to apply short security rate limits; we do not store the raw IP address or email in the rate-limit record.

3. How we use information and our lawful bases

Depending on the feature and context, Veritas Agent processes personal information to perform our contract with you, with your consent, for legitimate interests such as security and service improvement, or to meet legal obligations.

  • Provide core functionality, including chat, file analysis, and account access.
  • Use concise image Context Signals to select relevant prior image context for follow-up requests, rather than sending unrelated images where possible.
  • Operate optional features you enable, such as Memories. When enabled, all of your saved enabled memories may be processed as private AI context for personalization and context routing; you can disable Memories or delete individual or all saved memories in-app.
  • Run and deliver Scheduled Research reports at the local time and frequency you select, or when you manually trigger a saved schedule, using your browser-detected timezone and Truth Matrix-selected enabled saved-memory context only to improve relevance and framing.
  • Store, present, and apply Skills you create and explicitly select, so Veritas Agent can follow your reusable workflow preferences for the relevant chat request.
  • Process Meeting Assistant recordings and Voice Notes to generate speaker-labelled transcripts, timestamped summaries, notes, and playback references you request.
  • Maintain and troubleshoot service reliability, security, and abuse prevention.
  • Monitor operational AI usage through provider-reported, provider preflight, or estimated token counts and context-token savings metrics. For eligible Truth Matrix requests, we may ask the AI provider to count both the exact selected request and the otherwise excluded full-context comparison before generation. This counterfactual count sends that excluded context to the AI provider solely to measure input-token differences; it does not generate an additional answer. We retain a bounded operational ledger containing account and conversation references, run/call type, model, usage counts, cost/pricing snapshots, timing, and bounded status metadata—not prompt text, response content, raw provider payloads, credentials, or provider URLs. These metrics support private Truth Matrix Impact views and admin analytics for capacity planning and service health. We may reconcile aggregate service costs using Google Cloud Billing exports in BigQuery; reconciliation totals are account-level records and not a disclosure of individual prompts.
  • Authorized administrators can export a Token Usage Dashboard PDF. The report is generated in the administrator's browser from aggregate statistics scoped to the signed-in account; it excludes other accounts, conversation and message identifiers, prompts, responses, and run identifiers. Exporting does not create a new report copy in Veritas Agent storage.
  • Process subscriptions and apply plan entitlements.
  • Send and manage business workspace invitations, validate invite tokens, apply organization roles, maintain audit logs, record company profile details, and support organization billing or Enterprise sales workflows.
  • Operate enabled Enterprise Proactive Engine connected-app events, verify incoming event deliveries, prepare an in-platform alert using the organization's active roster, and maintain minimal security and accountability records.
  • Respond to support requests, product feedback, collaboration requests, and bug reports, including routing requests by category and using submitted details to diagnose issues or assess product ideas.

Where Meeting Assistant or Voice Notes captures or processes audio involving other people, you are responsible for ensuring you have any required consent, authority, or other lawful basis before recording or submitting that audio for processing.

4. Third-party services used to process data

Veritas Agent uses third-party providers as processors/sub-processors for specific functions:

  • Supabase: authentication, database, and private/public storage for application data, including saved meeting audio when Meeting Assistant storage is used.
  • Google Identity: optional Google sign-in authentication. Google Workspace connected-account authorization and actions are provided through Composio when you choose to connect a Google account.
  • Google Gemini API: AI prompt/response generation and related model processing.
  • Brave Search API: web/news retrieval, extracted web context/snippets, and grounding-related search output.
  • Stripe: subscription checkout, organization billing operations, billing-status updates, and webhook events.
  • Resend: transactional email delivery, including business workspace invitations and email sent through the app.
  • OpenStreetMap Nominatim: reverse geocoding when location tracking is enabled.
  • Composio: optional connected-account authorization, credential management, tool discovery, and execution of actions against third-party services you choose to connect.
  • GitHub: delivery of publicly available desktop installer files and update metadata. The desktop app checks the published release for a newer app version; this request may include standard technical information such as the installed app version and operating-system platform.

4.1 Managed connected tools

Connected tools are optional. When Composio or another managed integration provider is used, Veritas Agent sends a user- or organization-scoped identifier and the minimum tool request data needed to discover available actions, establish or check your connection, and execute the action. Tool results may be returned to Veritas Agent and processed by our AI provider when needed to decide the next step or prepare the response you requested. Where safe, Veritas Agent minimizes returned results before AI processing by removing provider transport diagnostics and retaining only the fields needed for the current workflow; it may request a narrower page, cursor, range, query, or detail view when more is needed. A connected service and the managed integration provider may process this data under their own privacy terms and in jurisdictions where they operate.

Veritas Agent may automatically perform eligible connected-tool steps within configured limits. If you enable automatic private email drafts in Settings, the preference is stored with your account and allows only creation of a private Gmail or Outlook draft when you request one; it does not allow sending, replying, scheduling, publishing, deleting, changing recipients, or other external changes without review. Actions classified as consequential, external, or otherwise requiring review pause for your approval. You can disable the preference or disconnect an account to stop future automatic access; neither action reverses completed actions or automatically deletes data retained independently by the connected service.

4.2 Provider-specific connected data

Google integrations are optional and are connected through Composio. Veritas Agent requests only the scopes configured for the features you enable, such as selected Gmail, Google Calendar, or Google Drive operations. The exact permissions are presented during authorization.

Microsoft 365 integrations are optional. If you connect Outlook, OneDrive, Microsoft Teams, or SharePoint through Composio, Veritas Agent requests access only for the enabled email, calendar, message, site, or file workflows. Microsoft presents the applicable permissions during authorization, and an organization administrator may need to approve them.

Work-management and CRM integrations are optional. If you connect Linear or HubSpot through Composio, Veritas Agent may search and retrieve selected work items or business records and, only after review where required, create or update them. The connected provider presents the applicable permissions during authorization.

  • Account connection: We use Google identity/profile information to identify the connected account and display connection status in the app.
  • Gmail: At your request, enabled tools may search or retrieve messages and threads, retrieve attachments or contacts, create drafts, reply to threads, or send email. For an initial message search, Veritas Agent minimizes the AI-visible result to metadata, a short preview, and attachment count for up to 10 messages. Any further page remains bounded and is retrieved only when the current page cannot answer a broad request. It retrieves decoded message content or attachment details only when needed for the workflow you requested. Message content and metadata are processed only as needed to perform and explain that workflow.
  • Google Calendar: Enabled tools may list calendars and events, find events or free time, and—after required review—create, update, or delete events. Event details may include titles, times, time zones, locations, descriptions, and attendees.
  • Google Drive: Enabled tools may find files, read metadata, export or parse file content, and—after required review—create text files or upload files. Retrieved file content may be substantial or sensitive and may be processed by our AI provider when needed for your request.
  • Stored connection data: Composio maintains the underlying OAuth credentials for managed connections. Veritas Agent stores or uses provider-side connection identifiers instead of raw provider credentials.
  • Returned action data: Data returned from Google to fulfill your request, including message, contact, attachment, calendar, or Drive information and action status, may appear in your session or stored application data as part of the feature you used.
  • AI formatting/synthesis: When a Google action result is turned into a natural-language response inside Veritas Agent, the action result may be processed by our AI provider to format or synthesize the answer you asked for.
  • Disconnect and revocation: Disconnecting a managed connection asks Composio to revoke or remove the relevant connected account. Remote revocation may fail outside our control, and disconnecting does not reverse actions already completed.

4.3 Slack and Notion connected data

If you connect Slack, enabled tools may find channels or users and retrieve message, channel, or thread content; reviewed actions may send or schedule messages. If you connect Notion, enabled tools may search pages or databases and retrieve page content; reviewed actions may create pages, add content, or update pages. Returned content may be processed by our AI provider when needed to complete your request. Access remains limited by the permissions of the connected account and the pages, channels, or workspaces made available to the connection.

5. Data retention and deletion

We retain data as needed to provide the service, maintain account integrity, comply with legal obligations, and support security and operational requirements.

Meeting Assistant and Voice Notes transcripts, summaries, timestamp data, and saved audio are retained with the related conversation unless you delete the conversation, delete your account data, or a shorter retention setting is introduced and selected. Deletion workflows attempt to remove both database records and related storage objects, including saved audio, but some data may persist in backups, logs, or legally required records for a limited period.

Enterprise organization data may be retained under the control of the organization even if an individual member leaves or deletes a personal account. Organization-owned data deletion, export, retention, access transfer, invite-token expiry, invite deletion, workspace deletion, or audit-log handling may require action by an organization owner or administrator.

Connected-account metadata, tool-call results, approval decisions, and run or audit records are retained only as needed to provide the feature, preserve security and accountability, resolve disputes, and meet legal obligations. Disconnecting an integration removes or disables the active connection in Veritas Agent and, where supported, requests credential revocation or deletion from the integration provider. Limited tool and audit records may remain for those purposes, and the connected service may retain content or actions under its own policies. Account or workspace deletion requests include associated connection records subject to applicable organization controls, backups, security records, and legal retention requirements.

Truth Matrix operational usage and reconciliation records are retained only for the periods needed for service operations, cost reconciliation, security, dispute resolution, and legal obligations. These records do not include the prompt or model response solely for accounting, and remain subject to applicable account-deletion, backup, security-record, and legal-retention limits.

Security rate-limit records contain only one-way HMAC identifiers, an endpoint category, and a request counter/window. They are retained only for the applicable short rate-limit window and operational security troubleshooting, then are replaced or removed through routine maintenance.

You can use in-app controls to remove major categories of stored data, including chat history, meeting data, files, and user data. If you need help removing meeting recordings or related generated notes, contact us using the privacy contact details below.

6. Security practices

We use technical and organizational controls intended to protect personal information. Saved meeting audio is intended to be stored in private storage and accessed through time-limited signed URLs rather than permanent public URLs. No system can guarantee absolute security, and you are responsible for safeguarding your account credentials and device access.

7. International processing and storage

Based on current system configuration, core managed database/storage infrastructure may operate in Australia and may replicate within that region for reliability. Third-party processors may handle data in additional jurisdictions according to their own infrastructure and compliance practices.

8. Your controls and rights

  • Review and update profile/settings information in-app.
  • Export a machine-readable copy of account data from Privacy & Data settings.
  • Disable optional features such as location tracking or memories.
  • Choose whether to use Meeting Assistant or Voice Notes and avoid recording or uploading audio where you do not have permission to do so.
  • Disconnect managed accounts through Connected apps to stop future access through those connections.
  • Use in-app deletion controls to remove chats, meeting or Voice Notes summaries, saved audio, files, and other stored user data.
  • For enterprise workspaces, contact your organization owner or administrator for organization-owned data access, correction, export, deletion, invite status, role changes, billing status, audit logs, or workspace membership changes.
  • Submit access, deletion, correction, restriction, objection, portability, CCPA opt-out, CCPA sensitive-use limit, or other privacy requests through Privacy & Data settings.
  • Email veritas.agent.delivery@gmail.com for privacy questions or requests.

9. CCPA privacy choices and Global Privacy Control

Veritas Agent does not sell or share personal information for cross-context behavioral advertising. This protection applies by default to every user; there is no separate in-app sale or sharing opt-out to enable.

If your browser sends a Global Privacy Control signal, we treat it as an opt-out signal for that browser/device where applicable.

10. Children and sensitive use

Veritas Agent is not intended for unlawful use or unauthorized processing of sensitive personal data. Do not upload/share data, record meetings, or process audio involving people unless you have the necessary rights, consent, or lawful basis to do so.

11. Changes to this policy

We may update this Privacy Policy from time to time. Material changes will be reflected by a revised last-updated date. Continued use of Veritas Agent after an update means you accept the revised policy.

12. Contact

For privacy-related questions, requests, or complaints, use Privacy & Data settings in the app or email veritas.agent.delivery@gmail.com. If your complaint is not resolved to your satisfaction, you may contact the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au or by calling 1300 363 992.

13. Notifiable Data Breaches

In the event of a data breach that is likely to result in serious harm, Veritas Agent will notify affected individuals and the Office of the Australian Information Commissioner as required under the Notifiable Data Breaches scheme.

This document is provided for product transparency and operational notice and does not constitute legal advice.

Veritas Agent Logo
Veritas Agent Future-ready conversations for every team.

Navigate

  • Creators
  • Pricing
  • Features
  • Download
  • Change Logs

Legal

  • Privacy Policy
  • Do Not Sell or Share
  • Terms & Conditions
Veritas Agent Stella Bradley

© Veritas Agent. All rights reserved.