Vernais
How it worksWorkflowPricingDocsChangelog
Book a demo
Platform

One system that replaces your whole stack.

See how it works
CorvexInstant answers and root cause from your dataIntegrationsEvery tool you run, unified in one graphCodexLiving docs and knowledge your team can trustWireReal time chat your agents work insideBeamMeetings with an AI that remembers everythingForgeTickets that move themselves forwardTrawlFresh research gathered from across the web

Product

CorvexInstant answers and root cause from your dataIntegrationsEvery tool you run, unified in one graphCodexLiving docs and knowledge your team can trustWireReal time chat your agents work insideBeamMeetings with an AI that remembers everythingForgeTickets that move themselves forwardTrawlFresh research gathered from across the web

Explore

How it worksWorkflowPricingDocsChangelog
Book a demo

Legal

Privacy Policy

How Vernais collects, uses, shares, and protects information, and the choices and rights you have. We built the product to be grounded in your data, with nothing invented, and we hold our data handling to the same standard.

Effective 9 July 2026
Last updated 9 July 2026
Applies to atmosphor.com and the Vernais application
Privacy contact privacy@atmosphor.com

Contents

1 Overview and our two roles 2 Information we collect 3 How we collect it 4 How we use information 5 AI and hosted models 6 Legal bases for processing 7 Cookies and analytics 8 How we share information 9 Subprocessors 10 International data transfers 11 Data retention 12 How we protect information 13 Your privacy rights 14 United States state privacy rights 15 Europe, UK, and Switzerland 16 Children 17 Third-party links and services 18 Changes to this policy 19 How to contact us

This Privacy Policy explains how Atmosphor, Inc. ("Vernais," "we," "us," or "our") handles information in connection with the Vernais application and the atmosphor.com website. It is part of our Terms of Service.

1 Overview and our two roles

Vernais is a business product. The information we handle falls into two categories, and our role and responsibilities differ between them.

Data we control

For our website, marketing, account administration, and billing, we act as a controller. This Privacy Policy describes how we handle that information, such as the details of the people who sign up for, administer, and pay for the Service.

Data we process for a customer

When a customer connects tools, uploads data, or runs Trawl, the Service processes that Customer Data on the customer's behalf. For Customer Data, the customer is the controller and we act as a processor, following the customer's instructions and our agreement with them. If your personal data appears in a customer's workspace because you work with or interact with that customer, that customer is responsible for it as controller. Please direct your requests to them, and we will support them in responding. Our processing of Customer Data as a processor is also governed by our Data Processing Agreement, available on request at privacy@atmosphor.com.

2 Information we collect

Account and contact information

Name, work email, company, role, and the credentials you use to sign in, including identifiers from Google Sign-In if you choose it. If you contact us or book a demo, we keep the details you provide.

Billing information

Plan, seats, usage, and billing contact details. Card and bank details are collected and processed by our third-party payment processor, not stored by us in full. We receive limited information such as the last digits, card type, and transaction status.

Usage, device, and log data

Information generated when you use the Service, such as pages and features used, actions taken, timestamps, approximate location derived from IP address, browser and device type, and diagnostic and performance logs. We keep audit logs of activity in a workspace and a separate administrative trail for security.

Customer Data (processed for the customer)

Data a customer connects or submits, including data synced from Integrations such as Stripe, GitHub, Jira, Slack, Notion, Salesforce, Snowflake, Zendesk, Sentry, and Amplitude, material gathered by Trawl from public sources the customer directs, and chat, questions, and content created in the workspace. Customer Data may contain personal data about the customer's own employees, users, or customers. We handle it as a processor as described above.

Communications

Messages you send us for sales, support, or security, and our responses.

3 How we collect it

  • Directly from you when you create an account, configure the Service, communicate with us, or make a payment.
  • Automatically through your use of the Service, using cookies and similar technologies and server logs.
  • From Integrations you or your organization connect, using the permissions granted at connection time.
  • From public sources through Trawl, but only for the sources a user confirms and instructs the Service to gather.
  • From service providers such as our payment processor, cloud hosting, and analytics providers.

4 How we use information

We use information that we control to:

  • provide, operate, maintain, and secure the Service, and authenticate users;
  • process payments, manage subscriptions, and send service and administrative messages;
  • provide support, respond to requests, and communicate about the Service;
  • monitor, analyze, and improve the Service, develop new features, and ensure reliability;
  • detect, investigate, and prevent fraud, abuse, security incidents, and violations of our Terms; and
  • comply with legal obligations and enforce our agreements.

We process Customer Data only to provide and support the Service and as instructed by the customer under our agreement with them. We do not sell personal data, and we do not use Customer Data for our own advertising.

5 AI and hosted models

The Service uses artificial intelligence and machine-learning models, including models hosted by third-party providers, to generate answers grounded in your data. To produce an Output, relevant content may be sent to these model providers as subprocessors so they can return a result.

  • We do not use your Customer Data to train third-party public or foundation models, and we require our model providers, by contract, not to use your content to train their general models.
  • We may use de-identified and aggregated information, and operational metadata, to evaluate and improve the quality, safety, and reliability of the Service.
  • The Service is designed to ground answers in your data, cite sources, and decline when it lacks evidence. Outputs are still generated by automated systems and should be reviewed, as described in our Terms of Service.
  • The Service does not make decisions that produce legal or similarly significant effects about a person without human involvement. Outputs are advisory and a person reviews them before any decision. Where profiling rules apply, you can ask us about the logic involved and request human review.

6 Legal bases for processing

Where the European Union General Data Protection Regulation, the UK GDPR, or a similar law applies to data we control, we rely on one or more of these legal bases:

  • Contract: to provide the Service to you and to administer your account and billing.
  • Legitimate interests: to secure, analyze, and improve the Service and to run our business, balanced against your rights.
  • Consent: where we ask for it, such as certain cookies or marketing, which you can withdraw at any time.
  • Legal obligation: to comply with law, including tax, accounting, and lawful requests.

For Customer Data, the customer as controller is responsible for establishing a legal basis and providing any required notices to individuals.

7 Cookies and analytics

We use cookies and similar technologies that are strictly necessary to run the Service, such as keeping you signed in with a secure session cookie, and, where permitted, cookies that help us understand and improve how the website and product are used. Where required by law, we set non-essential cookies only after you give consent through our cookie banner or preference manager, and you can withdraw that consent at any time there. You can also control cookies through your browser settings, though blocking strictly necessary cookies may break parts of the Service.

8 How we share information

We do not sell your personal data and we do not share it for cross-context behavioral advertising. We disclose information only as follows:

  • Within your organization: Customer Data is available to the Authorized Users and administrators of the relevant workspace, according to the roles and permissions the customer sets.
  • Service providers and subprocessors: vendors who process information on our behalf to run the Service, such as cloud hosting, model providers, payment processing, email delivery, and analytics, under contracts that limit their use of the information.
  • Legal and safety: when we believe disclosure is reasonably necessary to comply with law or valid legal process, to enforce our Terms, or to protect the rights, property, or safety of Vernais, our users, or the public. Where lawful, we will notify the affected customer of a request for Customer Data.
  • Business transfers: in connection with a merger, acquisition, financing, or sale of assets, subject to this policy and appropriate confidentiality.
  • With your direction or consent: when you ask us to share information or otherwise consent.

9 Subprocessors

We use a limited set of subprocessors to deliver the Service, including cloud infrastructure, hosted AI model providers, payment processing, and communications. We maintain a current list of subprocessors, which is available on request at privacy@atmosphor.com, and we require each to protect information consistent with this policy and our customer agreements.

10 International data transfers

We operate in a single hosting region, the United States, today. Depending on where you and our service providers are located, information may be processed in a country other than your own, including the United States. Where a cross-border transfer of personal data requires legal safeguards, we put in place appropriate mechanisms, such as the Standard Contractual Clauses approved by the European Commission and the UK International Data Transfer Addendum, which are available on request as part of our Data Processing Agreement. You can request more detail about our transfer safeguards at privacy@atmosphor.com.

11 Data retention

We keep information for as long as needed to provide the Service, and after that for as long as we have a legitimate business or legal reason, such as to comply with law, resolve disputes, and enforce agreements. Customer Data is retained for the customer's subscription term and handled at termination as described in our Terms of Service: on request we make it available for export for a limited period, then delete it in the ordinary course, subject to legal retention requirements and routine backups that expire on a rolling basis. Retention varies by category: account information for the life of your account plus a limited period after closure; billing and tax records for the period required by law; logs and audit records for a limited security window; and Customer Data for the subscription term plus the export and deletion window described in the Terms. Our processing of Customer Data as a processor is also governed by our Data Processing Agreement.

12 How we protect information

Security is built into how the Service works. Our measures include:

  • encryption in transit, and encryption at rest with AES-256-GCM for integration credentials and stored chat content;
  • a separate pair of databases per workspace, so one customer's data is isolated from another's, with membership re-checked on every request;
  • passwords hashed with Argon2id, opaque session tokens stored only as a hash, and hardened OAuth 2.0 with OIDC for Google Sign-In;
  • a defined, workspace-configurable role and permission model, per-request membership checks, audit logging, and least-privilege internal access; and
  • continuous internal security review, with independent testing planned.

You can read more on our Security and Compliance page. If we become aware of a personal data breach that affects your information, we will notify affected customers without undue delay and provide the information reasonably needed to respond, with detailed timelines for Customer Data set out in the Data Processing Agreement. No method of transmission or storage is completely secure, so we cannot guarantee absolute security. You are responsible for protecting your credentials and for the access you grant within your workspace.

13 Your privacy rights

Depending on where you live, you may have rights to access, correct, delete, or receive a copy of your personal data, to object to or restrict certain processing, and to withdraw consent. To exercise a right regarding data we control, email privacy@atmosphor.com. We will verify your request and respond within the time required by law. You may also have the right to appeal a decision or to complain to a regulator.

If your personal data is part of a customer's workspace, we handle it as a processor. Please send your request to that customer, who is the controller, and we will help them respond.

14 United States state privacy rights

If you are a resident of California or another state with a comprehensive privacy law, you may have rights to know, access, correct, delete, and receive a portable copy of your personal information, and to appeal our decision.

  • No sale or sharing: we do not sell personal information and do not share it for cross-context behavioral advertising, as those terms are defined under California law.
  • Categories: in the past 12 months we have collected identifiers, commercial information, internet and network activity, approximate location, professional information, and the contents of communications, as described in the sections above, for the business purposes described above.
  • Sensitive personal information: we collect account login credentials, including identifiers from Google Sign-In, which are sensitive personal information under California law. We use them only to authenticate you and secure your account, a purpose that does not trigger the right to limit, and we do not use or disclose sensitive personal information to infer characteristics about you.
  • No discrimination: we will not discriminate against you for exercising your rights.
  • Authorized agents: you may use an authorized agent to submit a request, with proof of authorization.

Residents of Virginia, Colorado, Connecticut, and other states with comprehensive privacy laws have equivalent rights. If we deny a request, you may appeal by replying to our decision or emailing privacy@atmosphor.com, and we will respond within the time your state's law allows.

To exercise these rights, email privacy@atmosphor.com. Much of the personal information in the Service is Customer Data that we process on behalf of a business customer; for that data, please contact the customer.

15 Europe, UK, and Switzerland

If you are in the European Economic Area, the United Kingdom, or Switzerland, the controller of data we control is Atmosphor, Inc. We process personal data on the legal bases in the section above, transfer it with the safeguards described above, and honor the rights described above. You have the right to lodge a complaint with your local data protection authority. If you are in the EEA or the United Kingdom and wish to reach our data protection contact, email privacy@atmosphor.com and we will direct your request to the right place.

16 Children

The Service is a business product intended for organizations and is not directed to children. We do not knowingly collect personal data from anyone under 16. If you believe a child has provided us personal data, contact privacy@atmosphor.com and we will delete it.

17 Third-party links and services

The Service integrates with and may link to third-party products and websites. Their handling of your information is governed by their own privacy policies, not this one. We encourage you to review the policies of any third-party service you connect or visit. We are not responsible for the practices of third parties.

18 Changes to this policy

We may update this Privacy Policy from time to time. If we make a material change, we will provide notice by a reasonable means, such as posting the updated policy with a new effective date or notifying you in the Service or by email. Your continued use of the Service after the update takes effect means you accept the revised policy.

19 How to contact us

For any privacy question or request, reach our team. We will route it to the right people and respond as required by law.

Atmosphor, Inc.

Privacy: privacy@atmosphor.com

Security: security@atmosphor.com

Legal and notices: legal@atmosphor.com

This Privacy Policy was last updated on 9 July 2026.

Vernais

Company brain

purpose-built

for product teams.

Book a demo

Product

CorvexIntegrationsCodexWireBeamForgeTrawl

Solutions

How it worksWorkflowPricing

Company

Contact

Resources

DocsChangelogBook a demoSecurity & Compliance
© 2026 Vernais
TermsPrivacy