Data We Collect
During pre-launch, Vexlynk collects waitlist information so we can contact people who ask to hear about the product.
- Waitlist data: email address, selected language, source, signup timestamp, and confirmation status.
- Optional form data: if a future form asks for a name or similar field, it will be used only to personalize Vexlynk communication.
- Technical data: basic request information may be processed by hosting, security, analytics, or email delivery systems to keep the service reliable.
Account Data
When you create a Vexlynk account, we collect your email address, authentication status, plan and entitlement state, workspace preferences, and product activity needed to run the service.
We use that data to operate Vexlynk, secure your account, provide support, improve the product, and send you important service notices. This paragraph covers your account data only — Google user data is governed exclusively by the Google section below.
Google OAuth And Google User Data
When you choose to connect a Google account, Vexlynk requests — through Google's OAuth consent screen — only the narrowest access needed for the feature you enable, and only when you enable it. Most access is read-only; the one write permission (Google Calendar event editing) is requested separately, at the moment you first use event editing — never up-front. Vexlynk also receives your basic Google profile (name and email) to identify the connected account. The Google data Vexlynk can access today is:
- YouTube data (youtube.readonly): Vexlynk reads, read-only, your channel's title, subscriber count, total views, video count, and your recent uploads' titles and view, like, and comment counts. For competitor and trending features it reads the same kind of public channel and video data for the channels or regions you specify. This is shown to you in Vexlynk and used by your in-app assistant to summarize your channel and content. Vexlynk never posts, modifies, or deletes anything on your YouTube account.
- YouTube Analytics (yt-analytics.readonly): For your own channel, Vexlynk reads, read-only, your analytics for the date range you choose: views, watch time, average view duration, and subscribers gained and lost. This is shown to you as performance cards and used by your in-app assistant to summarize how your channel is performing.
- Google Analytics (analytics.readonly): If you connect a Google Analytics account, Vexlynk reads, read-only, the GA4 property reports you choose — sessions, users, and page metrics for the date range you select. This is shown to you as analytics cards and used by your in-app assistant to summarize your site's performance. Vexlynk never changes anything in your Google Analytics account.
- Gmail (gmail.readonly): If you connect Gmail, Vexlynk reads, read-only, your recent inbox metadata — sender, subject, date, and Gmail's own short snippet — to show an inbox overview card and let your in-app assistant produce a brief of your inbox. Vexlynk never fetches full message bodies or attachments, and never sends, modifies, deletes, or labels email. Replying opens Gmail itself.
- Google Calendar (calendar.readonly): If you connect Google Calendar, Vexlynk reads, read-only, your upcoming events — titles, times, and attendees — to display them in calendar cards on your workspace and let your in-app assistant summarize your schedule.
- Google Calendar event editing (calendar.events): Only if you use event editing in the Calendar Sync card does Vexlynk ask for this additional permission, at that moment — never up-front. It is used solely to create, update, or delete the specific events you act on in Vexlynk, mirrored to your own Google Calendar. If you never edit events, this permission is never requested.
- Google Business Profile (business.manage): If you connect a Google Business Profile, Vexlynk reads your business locations, ratings, and reviews to display them in your workspace. Google offers no read-only permission for this data, so its management scope is required — but Vexlynk uses it strictly read-only and never edits, posts to, or deletes anything on your Business Profile.
- Access: Vexlynk accesses this data only after you grant permission through Google's OAuth consent screen, and only while your account stays connected. You can disconnect at any time.
- Use: Vexlynk uses Google data only to provide the features you enable — displaying it in your workspace and letting your in-app assistant summarize it for you — and for the security of that connection. Vexlynk does not use Google data for advertising, does not sell it, and never uses it to train AI or machine-learning models.
- Storage: Vexlynk stores your Google connection tokens encrypted on its server and keeps only the connection metadata needed to operate the features you enabled.
- Sharing: Vexlynk does not sell Google user data. We do not share it except as needed to provide the service, comply with law, protect users, or follow your direction.
- Compliance: Vexlynk's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Google user data is used solely to provide and improve Vexlynk's user-facing features — displaying your own YouTube, Google Analytics, Calendar, and Business Profile data in your workspace. It is not used for advertising, not sold, not shared except as required to provide these features or comply with law, and never used to train AI or machine-learning models.
Social Accounts You Connect
If you choose to connect a social account (an Instagram Business or Creator account, a Facebook Page, or a TikTok account), you authorize the connection on that platform's own consent screen. Vexlynk then retrieves read-only analytics for the account you connected: account identifiers, public profile details (such as your username and display name), follower counts, reach, engagement, and post-performance metrics. Vexlynk reads this data to show it to you; it never posts, uploads, or publishes to your accounts.
These connections are managed through Zernio, our social-integrations service provider. Zernio maintains the platform connection on our behalf and processes your social account identifiers and analytics metrics so Vexlynk can retrieve them. Zernio processes this data only to provide the integration.
Note on TikTok: TikTok's authorization bundles posting permissions together with read access and cannot be requested separately. Vexlynk only ever reads analytics — the code is built so that posting is not possible.
We keep a history of your account's metric totals while the account stays connected, so trends can be shown over time. Disconnecting an account removes the connection at the provider and deletes that account's metric history from our servers. Deleting your Vexlynk account removes all of your social connections and the associated provider-side records.
How We Use Data
- To manage the Vexlynk waitlist and send launch updates.
- To provide, secure, maintain, and improve Vexlynk. Google user data is excluded from every general purpose in this section — it is used only as described in the Google section above.
- To support account access, product workflows, and future integrations that users choose to enable.
- To prevent abuse, investigate issues, and comply with legal obligations.
Analytics
Vexlynk may use privacy-conscious analytics, including Google Analytics, to understand how the public launch pages are used and how the waitlist flow performs.
Analytics may help us understand page visits, general traffic sources, approximate geographic region, waitlist conversion, language preference, and site performance.
- No email addresses: Vexlynk does not send waitlist email addresses to analytics.
- No verification tokens: Vexlynk does not send Turnstile tokens or raw form payloads to analytics.
- No sale of personal data: Vexlynk does not sell personal data.
Security Verification
Vexlynk uses Cloudflare Turnstile to help verify waitlist submissions and reduce automated abuse.
Turnstile may run in invisible mode, which means verification can happen silently without a visible challenge or widget on screen.
- Cloudflare Turnstile: Turnstile verification is processed by Cloudflare, and Vexlynk references Cloudflare's Turnstile Privacy Addendum for that processing.
- Purpose: Vexlynk uses Turnstile for bot prevention, abuse protection, and waitlist security.
- No analytics sharing: Vexlynk does not send Turnstile tokens to analytics or marketing systems.
Where Your Data Is Stored
Desktop app — your machine first. Boards, card content, agent memory, source outputs and diagnostics are stored in a local database on your own computer. Cloud sync is off by default: it is something you switch on deliberately, and it is not available on the Free plan. With sync off, nothing about your boards leaves your device — the cloud holds only your account, your entitlement, hosted-AI usage counts, and encrypted tokens for any accounts you choose to connect.
When you turn sync on, snapshots of your boards are stored in our Supabase project under access rules that allow only your own account to read them. Before a snapshot is uploaded it is stripped of secrets, API keys and absolute file paths; the contents of files on your computer are never uploaded.
Web app (workspace.vexlynk.app) — always in the cloud. The web version has no local storage mode. Your boards are stored in our Supabase project from the moment you create them, and the desktop sync setting does not apply. If you want your data to stay on your own machine, use the desktop app with sync switched off.
- Security controls: We use server-side secrets, access restrictions, row-level access rules, input validation and abuse protection. No system can be guaranteed perfectly secure, but we design Vexlynk to limit what any single failure can expose.
- Limits we want you to know about: Cloud snapshots are encrypted in transit and at rest by our hosting provider, but they are not additionally encrypted with a key that only you hold — which means we are technically able to access them. Access is restricted to the service systems that operate Vexlynk. Deleting a board on your own device does not by itself remove snapshots already stored in the cloud; deleting your cloud data or your account does.
Sharing And Service Providers
Vexlynk may use trusted service providers for hosting, database storage, email delivery, security, analytics, and product operations. These providers process data only as needed to support Vexlynk.
For social sources, account connections and analytics retrieval are processed by Zernio (social-integrations provider) — see “Social Accounts You Connect” above.
We do not sell personal data or Google user data.
Data Deletion Requests
You can delete your data yourself, at any time, from Settings → Account → Manage my data. No email or support request is needed.
- Clear local data (desktop app): Removes the workspace stored on your computer — boards, media, documents and cached voice models. Your cloud data is unaffected and re-syncs the next time you sign in, and you stay signed in.
- Delete cloud data: Removes your boards and board snapshots, connected-account tokens, hosted-AI usage records and idea votes from our servers. Your account and plan stay active, and data on your own device is untouched.
- Delete my account: Permanently deletes your account and everything attached to it — cloud boards and snapshots, entitlement and plan records, connected-account tokens, and hosted-AI usage. On the desktop app it also clears the workspace stored on your computer. This cannot be undone.
- Disconnecting one account: Disconnecting a connected account from Settings deletes the tokens we hold for it, without affecting anything else.
- Security and audit records are the one exception. We keep the record of what happened, but the identity attached to it is removed when you delete your account, so the entry no longer identifies you. We may also need to retain limited information where required for security, legal compliance, fraud prevention, or legitimate operational records.
- For anything else — including waitlist entries — email support@vexlynk.app from the address associated with your request.
Data Retention
- Waitlist entries: kept until launch or until you ask us to remove them.
- Account and entitlement records: kept while your account is active, and removed when you delete your account.
- Hosted-AI usage: kept as monthly totals used for billing and plan limits, and removed when you delete your account.
- Cloud board snapshots: kept until you delete the board, delete your cloud data, or delete your account.
- Security and audit records: kept for security and legal purposes; the identity attached to them is removed when you delete your account.
- Diagnostic logs on your own device: size-capped and rotated automatically; they are not uploaded to us.
Changes To This Policy
We may update this Privacy Policy as Vexlynk evolves. The effective date above will change when material updates are made.