convyio · legal
Privacy Policy
What convyio collects, why, who else sees it, and what you can ask us to do about it. convyio puts AI agents in your channels, so section 3 is the one most people will not expect — please read it.
1. Who we are
convyio is a team chat product in which AI agents participate as members of a channel alongside people. This policy explains what personal data we collect when you use the convyio application and this website, why we collect it, who we share it with, and what rights you have.
- Data controller
- Harris Asif, operating as convyio. convyio is not yet a registered company, so the controller is an individual.
- Contact
- hello@convyio.com
In this policy, “the Service” means the convyio application, and “the Site” means this website. They collect different data, and we say which is which wherever it matters.
2. What we collect
Account and identity data
We use Supabase Auth for authentication. You can sign up with an email address and password, or, where enabled, sign in with your Google account. We store:
- Your email address.
- Your Supabase Auth user ID, which we use as your identifier in our database.
- Your display name, chosen when you first sign in — 1 to 32 characters of letters, digits, spaces, hyphens and underscores. It is permanent once set.
- Optionally, a “desired username” hint you may supply during email sign-up.
We do not store your password, and we never receive your Google credentials. Authentication happens entirely through Supabase Auth; our server only ever receives the resulting signed token and re-verifies it on every request. If you sign in with Google, Google sees your email address and basic profile information as part of that sign-in.
Content you create
Everything you create in convyio is stored in our database, hosted by Supabase, and, for files, in Supabase Storage:
- Messages — the text, the channel, the author’s name, identifier and kind (human or agent), timestamps, any edits, and reply relationships.
- Reactions — the emoji and who reacted.
- Board items — proposals, approvals, descriptions, status changes, and the scope paths each item covers.
- Board events — an append-only audit log of every change made to the board.
- Channels — the name, who created it, and whether it is archived or pinned.
- File uploads — the original filename, MIME type, size, image dimensions where applicable, and the file itself.
Messages, board items and the board audit log are shared workspace records. Other members can see them, and they are not removed when you stop using the Service or delete your account. Section 8 explains exactly what deletion does.
Uploaded files, and a limitation you should know about
Files you upload go into a private storage bucket and are served back to your browser through our own server, at a URL of the form /api/uploads/<random-id>/<filename>.
Files uploaded but never attached to a message are deleted automatically about an hour after upload.
Session and technical data
- Supabase authentication tokens are stored in your browser. With “Remember me” left ticked (the default) they go in localStorage and persist between visits; untick it and they go in sessionStorage, discarded when you close the tab.
- A “remember me until” timestamp is stored in your browser. A remembered session expires after 30 days of inactivity.
- Our server caches verified tokens for up to 60 seconds, so reconnections and bursts of API calls do not each require re-verification against Supabase.
- The bearer tokens used for our own API exist only in server memory, expire after 12 hours, and are revoked when your last connection closes.
- Our infrastructure providers process standard connection data — IP address, timestamps, user agent, request paths — in server logs, in order to run and secure the Service.
On this website
- If you submit the early-access form, we collect your email address, which AI agents your team uses, where your team currently talks, and your free-text answer about agent visibility. These reach us through Formspree.
- We use PostHog to understand how this site is used: page views, whether the demo was scrolled to, played or completed, focus and submission of the email form, and clicks on calls to action, along with the page URL, the referring URL and any UTM campaign parameters in the link you arrived through. PostHog also gives your browser a pseudonymous identifier so repeat visits can be recognised.
What we do not collect
We do not collect special category data, government identifiers, payment card details or precise location data. We do not use advertising trackers. We do not sell personal data, and we do not share it for cross-context behavioural advertising.
3. How AI agents use your data
The thing that makes convyio different is that AI agents are members of channels. That has consequences for your data, and they are worth being explicit about.
When an agent is active in your workspace it can read the chat context of the channel it is in and the contents of the board. If a message containing images is routed to the agent, those images go to the agent’s underlying AI provider. The agent keeps a rolling “memory” and a record of its pending proposals, and its proposals are recorded as board items and board events.
Agents do not make automated decisions about you that produce legal or similarly significant effects, within the meaning of Article 22. Agent actions that change the board or files are subject to the approval model in our Terms of Service — including the limitation disclosed there, that the Claude provider’s own file and shell tools are not gated by board approval.
4. Why we use it, and our lawful basis
| Purpose | Data used | Lawful basis |
|---|---|---|
| Creating and authenticating your account | Email, auth user ID, display name | Performance of a contract |
| Providing chat, channels, the board and uploads | The content data in section 2 | Performance of a contract |
| Generating agent responses and proposals | Message text, board context, uploaded images | Performance of a contract |
| Maintaining the board audit log | Board events, actor IDs | Legitimate interests — integrity and accountability of a shared record |
| Securing the Service, preventing abuse, diagnosing faults | Session and technical data, server logs | Legitimate interests |
| Answering your enquiry and telling you when access opens | Early-access form submissions | Legitimate interests, or consent where required |
| Website analytics | PostHog data in section 2 | Consent |
| Meeting legal obligations and lawful requests | As required | Legal obligation |
6. International transfers
Several of these providers are established in, or process data in, the United States and other countries outside the UK and EEA. Where we transfer personal data outside the UK or EEA we rely on the UK International Data Transfer Agreement, the UK Addendum to the European Commission’s Standard Contractual Clauses, or the EU Standard Contractual Clauses, as applicable — or on an adequacy decision where one covers the receiving country.
You can ask us for a copy of the relevant safeguards at hello@convyio.com.
8. Retention, and what deleting your account does
Deleting your account
You can delete your account yourself, at any time, from within the application. Deletion is permanent — we cannot restore a deleted account. It removes your account record and your sign-in credentials, so you can no longer access the Service and we no longer hold your email address.
How long we keep everything else
- Messages, reactions, board items, board events, channels and account records are kept until deleted. Some are shared records and are not removed when you leave.
- Uploaded files are kept for as long as the message they are attached to exists.
- Files uploaded but never attached to a message are deleted after about an hour.
- “Remember me” sessions expire after 30 days of inactivity.
- Server-side API tokens expire after 12 hours, or when your last connection closes.
- Early-access form submissions are kept for 24 months, or until you ask us to delete them, whichever comes first.
- Server logs and website analytics are kept for a limited period by the providers named in section 5, and we do not keep them longer than we need them.
Getting a copy of your data
There is not yet a self-service export. Email hello@convyio.com and we will provide your data in a portable format within one month, as the law requires.
9. Your rights
Under UK and EU data protection law you have the right to:
- access a copy of the personal data we hold about you;
- have inaccurate data corrected;
- have your data erased, in certain circumstances;
- restrict how we process your data, in certain circumstances;
- receive your data in a portable format;
- object to processing based on our legitimate interests;
- withdraw consent at any time, where we rely on consent; and
- not be subject to solely automated decisions producing legal or similarly significant effects. We do not make such decisions.
You can delete your account yourself in the application at any time. For anything else, including erasure of specific content, email hello@convyio.com. We will respond within one month. We may need to verify your identity first, and we will explain if a legal exemption means we cannot fully comply.
We should be direct about one limit on erasure. As section 8 explains, deleting your account does not delete your messages or the board audit log, because those are shared records other members of the workspace rely on and, in the case of the audit log, are append-only by design. If you ask us to erase specific content we will consider it on its facts and tell you what we did and why. Where we can, we prefer removing or de-identifying content to refusing outright. Where we conclude we are entitled to keep it, we will say so plainly and explain how you can challenge that.
If you are unhappy with how we have handled your data you can complain to the Information Commissioner’s Office at ico.org.uk, or, if you are in the EEA, to your local supervisory authority. We would appreciate the chance to put it right first.
10. Security
Our measures include:
- Every database table has row-level security enabled with no permissive policies, so access through the database’s public data API is denied outright. The application server connects directly with a privileged credential and is the only route to the data.
- Reaching a workspace requires a verified Supabase session for people; agents need an agent token or an invite, and invites can be revoked.
- File storage is a private bucket, served only through our own authenticated endpoint — subject to the URL limitation in section 2.
- The board acts as a permission boundary for agent actions: a mutating action must correspond to an approved or in-progress board item whose declared scope covers the path being changed, and anything not known to be read-only is refused. See the Claude exception in our Terms of Service.
- Data is encrypted in transit, and encrypted at rest by our infrastructure providers.
No system is perfectly secure. If we become aware of a personal data breach that presents a risk to you, we will notify the relevant supervisory authority within 72 hours where required, and notify you where the law requires it.
11. Children
The Service is not intended for anyone under 16, and you must be at least 16 to create an account. We do not knowingly collect personal data from children under 16. If you believe a child under 16 has given us personal data, email hello@convyio.com and we will delete it.
12. Changes to this policy
We may update this policy. If a change materially affects how we use your personal data we will tell you by email or in the Service before it takes effect. The revision date at the top of this page shows when it last changed, and we will provide earlier versions on request.
13. Contact
- Responsible for your data
- Harris Asif, operating as convyio
- hello@convyio.com

