Vennio by The Boat OÜ

Privacy Policy

Last updated: August 2026 — applies to all users of venn.theboat.dev

1. Who we are

The Boat OÜ (Sepapaja tn 6, 15551 Tallinn, Harju Maakond, Estonia) is the data controller for Vennio. Vennio is an AI-powered thought partner that helps you explore decisions by surfacing tension forces through voice and text conversation.

Contact for privacy matters: support@theboat.dev

2. What data we collect and why

DataWhy we collect itLegal basis
Email address Authentication, sending magic links, service notifications, waitlist management Contract / legitimate interest
Voice audio Streamed in real time to AI providers for transcription and response. Not stored by us - audio is discarded once the session ends. Consent (you initiate each session)
Conversation transcripts Stored so your topics persist across sessions and devices Contract
Personal profile data Self-described traits extracted from your voice sessions, used to personalise tension analysis when you enable personal mode on a topic Contract / consent
Topic structure (tensions, labels, key points) Core service output - stored and synced across devices Contract
Usage metrics (AI spend, voice seconds, request counts) Enforcing fair-use limits, preventing abuse, cross-device usage display Legitimate interest
Error and diagnostic data Bug fixing and reliability. Conversation content is explicitly stripped from error reports before they leave your browser. Legitimate interest
Anonymous analytics (page views, feature usage) Understanding how the product is used Legitimate interest
Invite records (inviter email, invitee email, topic title, optional note) Managing access, notifying us of pending approvals Legitimate interest / contract
Billing and payment data (subscription plan, billing status, Stripe customer ID, transaction history) Processing subscription payments, managing plan entitlements, issuing invoices and receipts. Payment card details are processed exclusively by Stripe and are never stored on our servers. Contract

3. Third-party processors

We use the following sub-processors to deliver the service. All receive only the minimum data necessary for their function and are bound by EU-compliant data processing agreements (Standard Contractual Clauses where applicable).

ProcessorLocationPurpose
OpenAI US (OpenAI Ireland Ltd for EU) Primary AI: conversation extraction, chat, voice (fallback)
Google US/EU Voice AI: Gemini Live real-time voice sessions (Paid Services tier)
Anthropic US Backup AI: conversation extraction
Supabase US/EU Authentication, database (topics, usage records, invite lists)
Sentry US Error monitoring (user ID and email, no conversation content)
Vercel US/EU Hosting, edge delivery, anonymous web analytics
Stripe US/EU Payment processing and subscription management for Plus and Pro plans. Stripe handles all payment card data under PCI DSS certification. Vennio never receives or stores raw card details.

4. How your data is shared

We do not sell your data. Your topic content is only shared with others when you choose to share it:

5. Data retention

Data typeRetention period
Topics, transcripts, profile data Kept while your account is active. If you have not signed in for 12 months, we will email you a warning. Data is deleted 30 days after that warning if you do not sign in.
Usage records (AI spend, voice seconds) 2 years from the date of the record
Waitlist and invite records 24 months from submission, or until you request deletion
Error telemetry (Sentry) 90 days
Voice audio Not stored - discarded at session end
Anonymous analytics Aggregated only; no personal data retained
Billing records (invoices, transaction history, subscription status) 7 years from the transaction date, as required for tax and accounting obligations under Estonian law. Stripe retains its own records independently under their data retention policy.

6. Your rights under GDPR

As a resident of the EU (or anyone whose data we hold), you have the following rights:

To exercise any of these rights, email support@theboat.dev. We will respond within 30 days. We may ask you to verify your identity before acting on a request.

7. Security

All data is transmitted over HTTPS/WSS. Database access uses row-level security enforced by Supabase. Conversation content is explicitly excluded from error reports. We do not log or store raw voice audio on our servers.

Payment card data is processed exclusively by Stripe under PCI DSS certification. Card details are entered directly on Stripe's servers and are never transmitted to or stored on our infrastructure.

Despite these measures, no system is completely secure. If you become aware of a security issue, please contact us at support@theboat.dev.

8. Cookies and local storage

Vennio uses browser localStorage to store your topics and settings locally on your device. This is part of the core service functionality, not tracking. We do not use advertising cookies. Supabase sets a session cookie for authentication.

9. Supervisory authority

If you believe we are not handling your personal data lawfully, you have the right to lodge a complaint with the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon):

10. Changes to this policy

We will notify you by email before making material changes to this policy. The "last updated" date at the top of this page always reflects the current version. For minor clarifications, we may update without notice.


The Boat OÜ — Sepapaja tn 6, 15551 Tallinn, Harju Maakond, Estonia

support@theboat.dev  ·  Terms of Service