3. What personal data we process, and why
3.1 Visiting this website
The public website sets no advertising cookies and runs no third-party analytics or social-media scripts. Our hosting infrastructure necessarily processes limited technical request data, such as IP address, URL, timestamp, browser information and referrer, in server logs used for delivery, security and fault diagnosis.
3.2 Early-access, account and subscription data
We may process your name, work email address, organisation, role, invitation and account status, authentication records, customer membership, subscription, usage period, run balance, credit grants and billing or administrative records. Authentication may include password-session data and passkey credentials; Vera stores the credential material needed to verify a passkey, not your biometric data.
3.3 Contacting us
If you email hello@iamvera.ai, privacy@iamvera.ai or security@iamvera.ai, we process your address, message and attachments to respond. Security reports are handled under our Security Policy.
3.4 Chats, projects and verification runs
When you use Vera, we process questions, instructions, project settings, selected models, messages, compact session memory, sources, model feedback, corrections, token and cost records, audit events and other run metadata needed to provide and evidence the service.
Chat-uploaded filesPDFs attached to a chat run are processed temporarily for that active request. The original uploaded PDF is not retained as a reusable file after the request. Metadata such as filename, size, page count, extracted-character count, status and run association may remain in session history.
Vera Office documentsDocuments created or opened through Vera Office are stored in the customer-isolated tenant environment so authorised users can open, edit, save, version and collaborate on them. Office-document records include ownership, project or session association, access settings and document status.
3.5 External AI model routing
Vera routes model calls through OpenRouter to the providers selected for the session, such as Anthropic, OpenAI, xAI and Perplexity. Every model selected for the chain performs its configured role. The run trace records which providers were called and the associated tokens and costs.
3.6 Semantic Privacy Shield
For document and selection tasks, Vera applies the Semantic Privacy Shield inside the customer-isolated environment before external model calls. Detected sensitive values are replaced with synthetic, session-bound equivalents; a private vault keeps the mapping; and a verification gate checks the prepared outbound context. If that gate fails, nothing is transmitted.
The Shield is a risk-reduction and fail-closed processing control, not a claim that every indirect identifier can always be detected or that re-identification is impossible. Professional judgement about the material submitted remains necessary.