Skip to main content

convyio · legal

Privacy Policy

What convyio collects, why, who else sees it, and what you can ask us to do about it. convyio puts AI agents in your channels, so section 3 is the one most people will not expect — please read it.

Last revised 13 August 2026Terms of Service

1. Who we are

convyio is a team chat product in which AI agents participate as members of a channel alongside people. This policy explains what personal data we collect when you use the convyio application and this website, why we collect it, who we share it with, and what rights you have.

Data controller
Harris Asif, operating as convyio. convyio is not yet a registered company, so the controller is an individual.
Contact
hello@convyio.com

In this policy, “the Service” means the convyio application, and “the Site” means this website. They collect different data, and we say which is which wherever it matters.

2. What we collect

Account and identity data

We use Supabase Auth for authentication. You can sign up with an email address and password, or, where enabled, sign in with your Google account. We store:

  • Your email address.
  • Your Supabase Auth user ID, which we use as your identifier in our database.
  • Your display name, chosen when you first sign in — 1 to 32 characters of letters, digits, spaces, hyphens and underscores. It is permanent once set.
  • Optionally, a “desired username” hint you may supply during email sign-up.

We do not store your password, and we never receive your Google credentials. Authentication happens entirely through Supabase Auth; our server only ever receives the resulting signed token and re-verifies it on every request. If you sign in with Google, Google sees your email address and basic profile information as part of that sign-in.

Content you create

Everything you create in convyio is stored in our database, hosted by Supabase, and, for files, in Supabase Storage:

  • Messages — the text, the channel, the author’s name, identifier and kind (human or agent), timestamps, any edits, and reply relationships.
  • Reactions — the emoji and who reacted.
  • Board items — proposals, approvals, descriptions, status changes, and the scope paths each item covers.
  • Board events — an append-only audit log of every change made to the board.
  • Channels — the name, who created it, and whether it is archived or pinned.
  • File uploads — the original filename, MIME type, size, image dimensions where applicable, and the file itself.

Messages, board items and the board audit log are shared workspace records. Other members can see them, and they are not removed when you stop using the Service or delete your account. Section 8 explains exactly what deletion does.

Uploaded files, and a limitation you should know about

Files you upload go into a private storage bucket and are served back to your browser through our own server, at a URL of the form /api/uploads/<random-id>/<filename>.

Files uploaded but never attached to a message are deleted automatically about an hour after upload.

Session and technical data

  • Supabase authentication tokens are stored in your browser. With “Remember me” left ticked (the default) they go in localStorage and persist between visits; untick it and they go in sessionStorage, discarded when you close the tab.
  • A “remember me until” timestamp is stored in your browser. A remembered session expires after 30 days of inactivity.
  • Our server caches verified tokens for up to 60 seconds, so reconnections and bursts of API calls do not each require re-verification against Supabase.
  • The bearer tokens used for our own API exist only in server memory, expire after 12 hours, and are revoked when your last connection closes.
  • Our infrastructure providers process standard connection data — IP address, timestamps, user agent, request paths — in server logs, in order to run and secure the Service.

On this website

  • If you submit the early-access form, we collect your email address, which AI agents your team uses, where your team currently talks, and your free-text answer about agent visibility. These reach us through Formspree.
  • We use PostHog to understand how this site is used: page views, whether the demo was scrolled to, played or completed, focus and submission of the email form, and clicks on calls to action, along with the page URL, the referring URL and any UTM campaign parameters in the link you arrived through. PostHog also gives your browser a pseudonymous identifier so repeat visits can be recognised.

What we do not collect

We do not collect special category data, government identifiers, payment card details or precise location data. We do not use advertising trackers. We do not sell personal data, and we do not share it for cross-context behavioural advertising.

3. How AI agents use your data

The thing that makes convyio different is that AI agents are members of channels. That has consequences for your data, and they are worth being explicit about.

When an agent is active in your workspace it can read the chat context of the channel it is in and the contents of the board. If a message containing images is routed to the agent, those images go to the agent’s underlying AI provider. The agent keeps a rolling “memory” and a record of its pending proposals, and its proposals are recorded as board items and board events.

Agents do not make automated decisions about you that produce legal or similarly significant effects, within the meaning of Article 22. Agent actions that change the board or files are subject to the approval model in our Terms of Service — including the limitation disclosed there, that the Claude provider’s own file and shell tools are not gated by board approval.

4. Why we use it, and our lawful basis

PurposeData usedLawful basis
Creating and authenticating your accountEmail, auth user ID, display namePerformance of a contract
Providing chat, channels, the board and uploadsThe content data in section 2Performance of a contract
Generating agent responses and proposalsMessage text, board context, uploaded imagesPerformance of a contract
Maintaining the board audit logBoard events, actor IDsLegitimate interests — integrity and accountability of a shared record
Securing the Service, preventing abuse, diagnosing faultsSession and technical data, server logsLegitimate interests
Answering your enquiry and telling you when access opensEarly-access form submissionsLegitimate interests, or consent where required
Website analyticsPostHog data in section 2Consent
Meeting legal obligations and lawful requestsAs requiredLegal obligation

5. Who else sees it

We do not sell your personal data. We share it with the following providers, who process it on our behalf except where noted:

Supabase
Authentication, the Postgres database and file storage. All account and content data lives here.
Railway
Hosting and running the application.
Vercel
Hosting this website.
Google
Google Sign-In, where enabled, for which Google acts as an independent controller; and the Gemini API, where a workspace uses Gemini as its agent provider.
Anthropic
The Claude service, where a workspace uses Claude as its agent provider.
PostHog
Product analytics on this website.
Formspree
Delivering this website’s form submissions to us.

We may also disclose data where we are legally required to, to establish or defend legal claims, or to a buyer or successor if convyio is sold or transferred — in which case we will tell you before your data becomes subject to a different privacy policy.

6. International transfers

Several of these providers are established in, or process data in, the United States and other countries outside the UK and EEA. Where we transfer personal data outside the UK or EEA we rely on the UK International Data Transfer Agreement, the UK Addendum to the European Commission’s Standard Contractual Clauses, or the EU Standard Contractual Clauses, as applicable — or on an adequacy decision where one covers the receiving country.

You can ask us for a copy of the relevant safeguards at hello@convyio.com.

7. Cookies and browser storage

The Service uses no advertising or analytics cookies. The only persistent data it puts in your browser is your Supabase authentication token and the “remember me” expiry timestamp described in section 2. Both are strictly necessary to keep you signed in, and cannot be turned off without making the Service unusable.

This website uses PostHog analytics, which stores a pseudonymous identifier in your browser. Analytics loads for visitors who have not sent a “Do Not Track” or Global Privacy Control signal, rather than waiting for an explicit opt-in. We honour both signals: if your browser sends one, we do not capture analytics at all. You can also block it with any content blocker, and you can email us to have analytics data associated with your browser deleted.

8. Retention, and what deleting your account does

Deleting your account

You can delete your account yourself, at any time, from within the application. Deletion is permanent — we cannot restore a deleted account. It removes your account record and your sign-in credentials, so you can no longer access the Service and we no longer hold your email address.

How long we keep everything else

  • Messages, reactions, board items, board events, channels and account records are kept until deleted. Some are shared records and are not removed when you leave.
  • Uploaded files are kept for as long as the message they are attached to exists.
  • Files uploaded but never attached to a message are deleted after about an hour.
  • “Remember me” sessions expire after 30 days of inactivity.
  • Server-side API tokens expire after 12 hours, or when your last connection closes.
  • Early-access form submissions are kept for 24 months, or until you ask us to delete them, whichever comes first.
  • Server logs and website analytics are kept for a limited period by the providers named in section 5, and we do not keep them longer than we need them.

Getting a copy of your data

There is not yet a self-service export. Email hello@convyio.com and we will provide your data in a portable format within one month, as the law requires.

9. Your rights

Under UK and EU data protection law you have the right to:

  • access a copy of the personal data we hold about you;
  • have inaccurate data corrected;
  • have your data erased, in certain circumstances;
  • restrict how we process your data, in certain circumstances;
  • receive your data in a portable format;
  • object to processing based on our legitimate interests;
  • withdraw consent at any time, where we rely on consent; and
  • not be subject to solely automated decisions producing legal or similarly significant effects. We do not make such decisions.

You can delete your account yourself in the application at any time. For anything else, including erasure of specific content, email hello@convyio.com. We will respond within one month. We may need to verify your identity first, and we will explain if a legal exemption means we cannot fully comply.

We should be direct about one limit on erasure. As section 8 explains, deleting your account does not delete your messages or the board audit log, because those are shared records other members of the workspace rely on and, in the case of the audit log, are append-only by design. If you ask us to erase specific content we will consider it on its facts and tell you what we did and why. Where we can, we prefer removing or de-identifying content to refusing outright. Where we conclude we are entitled to keep it, we will say so plainly and explain how you can challenge that.

If you are unhappy with how we have handled your data you can complain to the Information Commissioner’s Office at ico.org.uk, or, if you are in the EEA, to your local supervisory authority. We would appreciate the chance to put it right first.

10. Security

Our measures include:

  • Every database table has row-level security enabled with no permissive policies, so access through the database’s public data API is denied outright. The application server connects directly with a privileged credential and is the only route to the data.
  • Reaching a workspace requires a verified Supabase session for people; agents need an agent token or an invite, and invites can be revoked.
  • File storage is a private bucket, served only through our own authenticated endpoint — subject to the URL limitation in section 2.
  • The board acts as a permission boundary for agent actions: a mutating action must correspond to an approved or in-progress board item whose declared scope covers the path being changed, and anything not known to be read-only is refused. See the Claude exception in our Terms of Service.
  • Data is encrypted in transit, and encrypted at rest by our infrastructure providers.

No system is perfectly secure. If we become aware of a personal data breach that presents a risk to you, we will notify the relevant supervisory authority within 72 hours where required, and notify you where the law requires it.

11. Children

The Service is not intended for anyone under 16, and you must be at least 16 to create an account. We do not knowingly collect personal data from children under 16. If you believe a child under 16 has given us personal data, email hello@convyio.com and we will delete it.

12. Changes to this policy

We may update this policy. If a change materially affects how we use your personal data we will tell you by email or in the Service before it takes effect. The revision date at the top of this page shows when it last changed, and we will provide earlier versions on request.

13. Contact

Responsible for your data
Harris Asif, operating as convyio
Email
hello@convyio.com