Privacy and data protection

Privacy Policy

This policy explains what IamVera.ai processes across the public website, customer accounts, chat runs, the Semantic Privacy Shield and Vera Office — including what reaches external AI providers and what remains in the customer-isolated environment.

Last updated: 13 July 2026 · Version 1.1

How IamVera handles confidential documents and external AI providers

IamVera separates customer-isolated storage, local Privacy Shield processing and external AI model routing. Chat-uploaded PDFs are processed temporarily, Vera Office documents remain in the customer environment for authorised collaboration, and document or selection context is released to selected external models only after Privacy Shield transformation and verification.

This summary does not replace the detailed provisions below. Controller and processor roles, lawful bases, providers, international transfers and retention depend on the processing context and the applicable customer documentation.

1. Who we are and which role we have

I am Vera (iamvera.ai) is operated by The Coding Company B.V., a company registered in the Netherlands.

For website visitors, account administration, subscriptions, billing and our own communications, The Coding Company B.V. acts as data controller. Where a customer uses Vera to process professional documents and case content on its instructions, the customer will generally be the controller and The Coding Company B.V. the processor, as defined in the applicable agreement. The precise allocation depends on the processing context.

Privacy and data-subject requests: privacy@iamvera.ai
General contact: hello@iamvera.ai
Security reports: security@iamvera.ai (see our Security Policy)

We do not use a blanket “GDPR compliant” claim as a substitute for documentation. Data flows, responsibilities, safeguards and any data-processing agreement are described in the applicable service and customer documentation.

2. This policy at a glance

  • No advertising trackers or third-party analytics on the public iamvera.ai website. Fonts are self-hosted.
  • Account and service data includes your identity, authentication, organisation membership, subscription and usage records.
  • Chat-uploaded PDFs are processed temporarily for the active run and are not retained as reusable source files; file and run metadata may remain in session history.
  • Vera Office documents are stored in the customer-isolated tenant environment because saving, versioning and authorised collaboration require persistent document storage.
  • Document and selection tasks use the Semantic Privacy Shield before external model calls. If the privacy verification gate fails, no document context is transmitted.
  • Every selected model is recorded. External model calls are routed through OpenRouter to the selected providers, and the run trace records models, tokens, costs and review steps.
  • You retain the GDPR rights that apply to the processing context, including access, rectification, erasure, restriction, objection and portability.

3. What personal data we process, and why

3.1 Visiting this website

The public website sets no advertising cookies and runs no third-party analytics or social-media scripts. Our hosting infrastructure necessarily processes limited technical request data, such as IP address, URL, timestamp, browser information and referrer, in server logs used for delivery, security and fault diagnosis.

3.2 Early-access, account and subscription data

We may process your name, work email address, organisation, role, invitation and account status, authentication records, customer membership, subscription, usage period, run balance, credit grants and billing or administrative records. Authentication may include password-session data and passkey credentials; Vera stores the credential material needed to verify a passkey, not your biometric data.

3.3 Contacting us

If you email hello@iamvera.ai, privacy@iamvera.ai or security@iamvera.ai, we process your address, message and attachments to respond. Security reports are handled under our Security Policy.

3.4 Chats, projects and verification runs

When you use Vera, we process questions, instructions, project settings, selected models, messages, compact session memory, sources, model feedback, corrections, token and cost records, audit events and other run metadata needed to provide and evidence the service.

PDFs attached to a chat run are processed temporarily for that active request. The original uploaded PDF is not retained as a reusable file after the request. Metadata such as filename, size, page count, extracted-character count, status and run association may remain in session history.

Documents created or opened through Vera Office are stored in the customer-isolated tenant environment so authorised users can open, edit, save, version and collaborate on them. Office-document records include ownership, project or session association, access settings and document status.

3.5 External AI model routing

Vera routes model calls through OpenRouter to the providers selected for the session, such as Anthropic, OpenAI, xAI and Perplexity. Every model selected for the chain performs its configured role. The run trace records which providers were called and the associated tokens and costs.

3.6 Semantic Privacy Shield

For document and selection tasks, Vera applies the Semantic Privacy Shield inside the customer-isolated environment before external model calls. Detected sensitive values are replaced with synthetic, session-bound equivalents; a private vault keeps the mapping; and a verification gate checks the prepared outbound context. If that gate fails, nothing is transmitted.

The Shield is a risk-reduction and fail-closed processing control, not a claim that every indirect identifier can always be detected or that re-identification is impossible. Professional judgement about the material submitted remains necessary.

5. Who receives data

We do not sell personal data. Data may be received by:

  • Infrastructure, database, email and operational suppliers that provide the service under appropriate contractual arrangements.
  • OpenRouter and the external AI providers selected for a run, which receive the prompt and permitted context needed for their configured role. For document and selection tasks, outbound context is released only after Privacy Shield transformation and verification.
  • Authorised users within the same customer environment, according to project, session and document permissions.
  • Authorities or professional advisers where disclosure is legally required or necessary to establish, exercise or defend legal claims.

Provider identity and model participation are visible in the Vera trace so customers can assess the data flow for each run.

6. International transfers

Vera’s customer environments and document-protection processing are operated on infrastructure in the European Union. External model routing through OpenRouter and selected providers may nevertheless involve recipients outside the European Economic Area.

Where Chapter V GDPR applies, the relevant provider and customer arrangements must provide an applicable transfer mechanism, such as an adequacy decision or Standard Contractual Clauses. The Semantic Privacy Shield reduces exposure before those external calls, but it does not remove the need to assess providers, purposes and transfer safeguards.

7. How long we keep data

DataRetention approach
Chat-uploaded PDF source fileFor the active request only; it is not retained as a reusable uploaded file after processing
PDF metadata and run associationUntil the related session or account data is deleted under the service controls
Vera Office documents and versionsUntil deleted by an authorised user, removed under the customer agreement, or the tenant is decommissioned
Projects, sessions, messages, memory and model-run traceWhile required for the customer account and until deletion or contractual retention rules apply
Account, membership, subscription and usage recordsFor the account lifecycle and any necessary contractual, security or dispute period
Server and security logsRotated according to operational security needs
Invoices and statutory administrationFor the applicable legal retention period

Specific enterprise or regulated-sector retention requirements may be documented in the customer agreement.

8. Security

Vera uses technical and organisational measures appropriate to its risk profile. These include encrypted transport, access controls, passkey-capable authentication, customer-isolated application environments, restricted document permissions, recorded model and usage events, and fail-closed Privacy Shield processing for document context.

No system is perfectly secure. We maintain a responsible-disclosure process and welcome reports at security@iamvera.ai.

9. Your rights

Under the GDPR you have the right to:

  • Access the personal data we hold about you (Art. 15);
  • Rectify inaccurate or incomplete data (Art. 16);
  • Erase your data ("right to be forgotten", Art. 17);
  • Restrict processing (Art. 18);
  • Receive your data in a portable format (Art. 20);
  • Object to processing based on legitimate interest (Art. 21);
  • Withdraw consent at any time, without affecting the lawfulness of processing before withdrawal (Art. 7(3)).

To exercise any of these rights, email privacy@iamvera.ai. We respond within one month, as the GDPR requires; if a request is complex we may extend by two further months and will tell you why.

You also have the right to lodge a complaint with a supervisory authority. For The Coding Company B.V. the lead authority is the Dutch Data Protection Authority, Autoriteit Persoonsgegevens (autoriteitpersoonsgegevens.nl). We would appreciate the chance to address your concern first, but you are never required to contact us before complaining.

10. AI output and automated decision-making

Vera produces AI-generated, multi-model-verified answers as a tool for your own professional judgement. Vera does not make automated decisions about you that produce legal or similarly significant effects within the meaning of Art. 22 GDPR. Final responsibility for acting on an answer stays with the professional using it — that is a design principle, not a disclaimer.

11. Children

Vera is a professional tool and is not directed at children. We do not knowingly collect personal data from anyone under 16. If you believe a minor has provided us with personal data, contact privacy@iamvera.ai and we will delete it.

12. Changes to this policy

We update this policy when the service, providers, contractual arrangements or data flows materially change. The current version is published at https://iamvera.ai/privacy-policy.

Last updated: 13 July 2026 · Version 1.1

Questions about IamVera’s data handling

These answers summarise selected parts of the policy. The complete provisions above remain authoritative.

No. IamVera does not sell personal data. Data is shared only where needed to provide the service, comply with law, protect legal claims or support authorised users within the relevant customer environment.

For ordinary chat tasks, the selected provider receives the prompt and permitted context required for its configured role. For document and selection tasks, external providers receive only context released after Semantic Privacy Shield transformation and verification.

No. A chat-uploaded PDF is processed temporarily for the active request and is not retained as a reusable source file after processing. File metadata and the relationship to the run may remain in session history.

Vera Office documents remain in the customer-isolated tenant environment because opening, editing, saving, versioning and authorised collaboration require persistent document storage.

Yes. OpenRouter and selected AI providers may involve recipients outside the European Economic Area. Where Chapter V GDPR applies, an appropriate transfer mechanism and provider assessment remain necessary.

IamVera fails closed. If the privacy gate does not approve the prepared document or selection context, no document content is transmitted to external AI providers.