Privacy policy
Last updated: 19 September 2026 · Version 2026-09-19
Vesqo holds two kinds of personal data: yours, as the person with an account, and your customers', which your tools send us on your instruction. This notice covers both, in plain language.
Who is responsible
Carlos Soares (MotionKeys), Rua de Santo Antonio 654, Penafiel Porto, tax id PT260967114, runs Vesqo. Privacy questions and rights requests: privacy@vesqo.app. Anything else: hello@vesqo.app.
For your account, your workspace settings and your billing, we are the controller. For the data your connected tools send about your customers (a Stripe customer, a support conversation, an analytics group, a CRM company) you are the controller and we are your processor: we act only on your instructions, which are the terms and the settings you choose in the product. The data processing terms in the terms of service are the Article 28 contract between us.
Data about you
Account: name, email address, password hash, timezone, notification choices, the workspaces you belong to and your role in each, sign-in sessions with IP address and browser details, and email verification state. Billing: the plan, the Stripe customer and subscription ids; card details go to Stripe and never reach us. Use of the product: an audit log of what was done in a workspace and by whom, kept so a team can see what changed, including the questions asked of Ask Vesqo and the answers given.
Data about your customers
Only what the tools you connect send, read with the credentials you give: customers and subscriptions from your billing provider, error reports and who they reached from your error tracker, usage counts from your analytics, conversations from your support inbox, companies and deals from your CRM, releases from your code host, and public news or job listings about the companies you sell to. Vesqo keeps these as events and joins them into accounts by company domain or email address. It never sends anything to your customers and never sells or shares their data.
You decide what is connected and can disconnect a source, delete a workspace, or export everything at any time. Ask Vesqo answers from this data; the question and the data it read are sent to Anthropic's API only when you ask, and only for your workspace.
Why, and on what basis
Contract (GDPR Article 6(1)(b)): running your account and workspace, reading your sources, finding signals, sending the daily brief and the notifications you chose, billing. Legitimate interests (Article 6(1)(f)): keeping Vesqo secure and working, preventing abuse, minimal technical logs. Legal obligation (Article 6(1)(c)): tax and accounting records, lawful requests. For your customers' data we process on your documented instructions as your processor; the lawful basis is yours to establish, and the terms ask you to have it.
Who else touches the data
Hetzner Online GmbH hosts Vesqo and its database in European Economic Area (Falkenstein, Germany). Cloudflare, Inc. serves the domain's DNS, forwards mail sent to our published addresses, and stores the encrypted nightly backups in the EU. Stripe runs checkout and payment for Vesqo's own plans. Resend sends the emails Vesqo writes to you. Anthropic answers Ask Vesqo questions, under its commercial API terms, which state that inputs and outputs are not used to train its models and are normally deleted within 30 days. Your connected tools receive only the requests needed to read your data, and, when you set an automation to do so, the note or message you asked Vesqo to write.
Where a provider processes data outside the EEA, we rely on an adequacy decision or the European Commission's Standard Contractual Clauses. Write to privacy@vesqo.app for the safeguard in force for a given provider.
How long
Your account and workspace data stay while the workspace exists, with one exception: the hourly and daily series read from your sources (error counts, activity, key events, hiring) are kept for 90 days unless a longer window is agreed for your workspace; your customers' history (subscriptions, issues, conversations, deals, releases) is not pruned. Deleting a workspace removes its events, accounts, signals, conversations, automations and audit log from active systems immediately; encrypted backups keep a copy for up to 30 days. Deleting your user account removes your profile and sessions. Sign-in sessions expire after 30 days of inactivity. Provider credentials are encrypted at rest and deleted the moment a source is disconnected. Invoices are kept for the Portuguese legal period, normally 10 years.
Your rights, and your customers'
You can see, export, correct and delete your account and workspace data from the product. For anything else, or to object or restrict, write to privacy@vesqo.app; we answer within one month. You may complain to the Comissão Nacional de Proteção de Dados (cnpd.pt) or the authority where you live or work.
If one of your customers exercises a right against you, we help: their data can be found by account in the product and deleted or exported there, and we assist with anything the product does not cover.
Security and changes
Every workspace's data is isolated at the database level, provider credentials and API keys are encrypted, connections use TLS, access by us is limited to what running the service needs (plan, sources, members, and the like), we open a workspace's contents only to provide support or fix a fault, read-only and for a limited time, with the reason written in your audit log and mailed to the owners, who can end it at any time; and everything done or read in a workspace, by you or by us, is logged. Should a breach put your rights or your customers' at risk we notify you without undue delay so you can meet your own duties. We post changes to this notice here and tell account holders by email when they matter.