Vennio by The Boat OÜ
The Boat OÜ (Sepapaja tn 6, 15551 Tallinn, Harju Maakond, Estonia) is the data controller for Vennio. Vennio is an AI-powered thought partner that helps you explore decisions by surfacing tension forces through voice and text conversation.
Contact for privacy matters: support@theboat.dev
| Data | Why we collect it | Legal basis |
|---|---|---|
| Email address | Authentication, sending magic links, service notifications, waitlist management | Contract / legitimate interest |
| Voice audio | Streamed in real time to AI providers for transcription and response. Not stored by us - audio is discarded once the session ends. | Consent (you initiate each session) |
| Conversation transcripts | Stored so your topics persist across sessions and devices | Contract |
| Personal profile data | Self-described traits extracted from your voice sessions, used to personalise tension analysis when you enable personal mode on a topic | Contract / consent |
| Topic structure (tensions, labels, key points) | Core service output - stored and synced across devices | Contract |
| Usage metrics (AI spend, voice seconds, request counts) | Enforcing fair-use limits, preventing abuse, cross-device usage display | Legitimate interest |
| Error and diagnostic data | Bug fixing and reliability. Conversation content is explicitly stripped from error reports before they leave your browser. | Legitimate interest |
| Anonymous analytics (page views, feature usage) | Understanding how the product is used | Legitimate interest |
| Invite records (inviter email, invitee email, topic title, optional note) | Managing access, notifying us of pending approvals | Legitimate interest / contract |
| Billing and payment data (subscription plan, billing status, Stripe customer ID, transaction history) | Processing subscription payments, managing plan entitlements, issuing invoices and receipts. Payment card details are processed exclusively by Stripe and are never stored on our servers. | Contract |
We use the following sub-processors to deliver the service. All receive only the minimum data necessary for their function and are bound by EU-compliant data processing agreements (Standard Contractual Clauses where applicable).
| Processor | Location | Purpose |
|---|---|---|
| OpenAI | US (OpenAI Ireland Ltd for EU) | Primary AI: conversation extraction, chat, voice (fallback) |
| US/EU | Voice AI: Gemini Live real-time voice sessions (Paid Services tier) | |
| Anthropic | US | Backup AI: conversation extraction |
| Supabase | US/EU | Authentication, database (topics, usage records, invite lists) |
| Sentry | US | Error monitoring (user ID and email, no conversation content) |
| Vercel | US/EU | Hosting, edge delivery, anonymous web analytics |
| Stripe | US/EU | Payment processing and subscription management for Plus and Pro plans. Stripe handles all payment card data under PCI DSS certification. Vennio never receives or stores raw card details. |
We do not sell your data. Your topic content is only shared with others when you choose to share it:
| Data type | Retention period |
|---|---|
| Topics, transcripts, profile data | Kept while your account is active. If you have not signed in for 12 months, we will email you a warning. Data is deleted 30 days after that warning if you do not sign in. |
| Usage records (AI spend, voice seconds) | 2 years from the date of the record |
| Waitlist and invite records | 24 months from submission, or until you request deletion |
| Error telemetry (Sentry) | 90 days |
| Voice audio | Not stored - discarded at session end |
| Anonymous analytics | Aggregated only; no personal data retained |
| Billing records (invoices, transaction history, subscription status) | 7 years from the transaction date, as required for tax and accounting obligations under Estonian law. Stripe retains its own records independently under their data retention policy. |
As a resident of the EU (or anyone whose data we hold), you have the following rights:
To exercise any of these rights, email support@theboat.dev. We will respond within 30 days. We may ask you to verify your identity before acting on a request.
All data is transmitted over HTTPS/WSS. Database access uses row-level security enforced by Supabase. Conversation content is explicitly excluded from error reports. We do not log or store raw voice audio on our servers.
Payment card data is processed exclusively by Stripe under PCI DSS certification. Card details are entered directly on Stripe's servers and are never transmitted to or stored on our infrastructure.
Despite these measures, no system is completely secure. If you become aware of a security issue, please contact us at support@theboat.dev.
Vennio uses browser localStorage to store your topics and settings locally on your device. This is part of the core service functionality, not tracking. We do not use advertising cookies. Supabase sets a session cookie for authentication.
If you believe we are not handling your personal data lawfully, you have the right to lodge a complaint with the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon):
We will notify you by email before making material changes to this policy. The "last updated" date at the top of this page always reflects the current version. For minor clarifications, we may update without notice.
The Boat OÜ — Sepapaja tn 6, 15551 Tallinn, Harju Maakond, Estonia