Legal

Privacy Policy

We don't want your data. Here's exactly what we collect and why.

Last updated: 2026-07-24

This Privacy Policy describes how Team Veto ("Veto," "we," "us," or "our") collects, uses, and protects information when you use the Veto iOS app, web app at app.get-veto.app, browser extension (Chrome, Safari), or MCP connector at mcp.get-veto.app (used by third-party AI assistants you authorize). By using Veto, you agree to the practices described here.


1. Surfaces & Shared Account

Veto is one account across multiple surfaces. Your Purchase Considerations, Gauntlet conversations, Veto Pro entitlement, and Advisor Allowance are tied to your signed-in Veto account — not to a particular device, browser, or assistant host. Backend processors (Firebase, Anthropic, and the other services listed below) are the same regardless of entry surface; what differs is how data enters and any local or temporary state on that surface.

We do not use advertising SDKs or request an Advertising Identifier (IDFA) on any surface. We do not track you across other apps or websites for advertising.

2. Data We Collect

We collect information you actively provide or that is created when you use the Service:

Account-linked data is stored in Google Firebase Firestore under your authenticated user ID. Authentication credentials are handled by Firebase Authentication. The browser extension’s temporary recovery state is stored locally as described in Section 3. MCP access and refresh tokens for authorized hosts are stored so those hosts can call Veto on your behalf until you disconnect them or delete your account.

3. Browser Extension

On supported Amazon pages, the Veto browser extension locally detects and reads available product details so it can offer the Veto button; it does not place a product draft in extension storage until you invoke it. On Shopify, Veto detects and reads product details only after you choose to grant the exact store origin, and it may keep that draft temporarily ready for review. Shopify access is optional and can be removed from the extension.

Before a Gauntlet begins, you can review and edit the product fields. Veto sends reviewed product details to your account and backend only after you choose to begin. It does not save the rest of the page, your browsing history, cart, checkout details, passwords, or payment-card information. The extension does not run ads or track you across websites.

The extension temporarily stores the active product draft and, when necessary, an interrupted Gauntlet answer in local extension storage so your work can recover. This temporary browser state is cleared when it is no longer needed or when you sign out.

On Chrome, the use of information received from Google APIs will adhere to the Chrome Web Store User Data Policy, including the Limited Use requirements.

4. MCP / AI Assistants

Veto provides a remote Model Context Protocol (MCP) connector at mcp.get-veto.app. After you authorize a host on the Veto consent screen, supported AI assistants (for example Claude, Cursor, Codex, or VS Code Copilot Chat) may call Veto tools to create Purchase Considerations and walk them through the Gauntlet inside your account.

5. AI Analysis

When you run a Gauntlet conversation from any surface — including iOS, web, the browser extension, or MCP — the following data is sent server-side to Anthropic's Claude API via Firebase Cloud Functions:

Your name and email address are never included in API calls. Anthropic processes these requests under its commercial API terms and does not train its models on API data. Your conversation data is not retained by Anthropic beyond the scope of the individual request.

6. Visual Scouting

If you use Visual Scouting, the item name is sent to Serper (a Google Image Search proxy operated by Serper LLC) to retrieve publicly available product images. The item name is the only data transmitted. Product images are then stored in Firebase Storage linked to your item record. Image analysis uses Anthropic Claude server-side.

7. Sharing

We do not sell, trade, or rent your personal information. We do not share data with advertisers, data brokers, or marketing platforms. Data is processed by the following third-party services:

We may disclose information if required by law or to protect the rights, property, or safety of Veto, its users, or the public.

8. Purchases

Veto offers Veto Pro through Apple's in-app purchase system and a RevenueCat-hosted web purchase flow linked from the browser extension. We do not store or have access to your payment card details. RevenueCat receives your Firebase user ID and, for the web flow, your account email so it can associate the purchase with the same Pro Entitlement across extension, web, and mobile. Manage or cancel a subscription through the channel where you purchased it.

9. Analytics & Crash Reporting

Where integrated, we use Sentry to collect crash reports and diagnostic information when a Veto surface encounters an error. Each report is associated with a pseudonymous account identifier (your Firebase user ID) so we can investigate and fix issues affecting specific users. Reports include device type, OS version, app version, and a stack trace. Your name, email address, item data, and conversation content are never included.

Where integrated, we use PostHog (hosted in the EU) for first-party product analytics so we can understand activation and feature usage across iOS, web, the browser extension side panel, and MCP. Events are associated with your Firebase user ID and may include coarse metadata such as surface (web / mobile / extension / mcp), Gauntlet step or Verdict enum, merchant platform enum, and app environment. We do not send item names, prices, product URLs, conversation text, tool arguments, or email addresses to PostHog. We do not use session replay, advertising SDKs, or the Advertising Identifier (IDFA). We do not track you across other apps or websites for advertising. The extension does not send analytics from merchant product pages — only from the Veto side panel after you use it. MCP ops/channel telemetry (Section 4) remains in Cloud Logging and is separate from PostHog product milestones.

You can opt out of PostHog product analytics in Settings on iOS or web (or contact us). Opting out is stored on your account and stops further event capture on client surfaces and MCP product milestones; existing PostHog records can be deleted on request.

MCP channel telemetry (Section 4) is separate from Sentry and PostHog and does not include tool argument content.

If you would like your Sentry diagnostic data or PostHog analytics data deleted, contact us and we will submit the deletion request on your behalf.

10. Legal Bases for Processing (GDPR)

If you are in the European Economic Area (EEA) or United Kingdom, we process your data under the following legal bases:

11. Data Retention

We retain data for as long as your account is active. Specific retention windows:

12. International Data Transfers

Your data is stored and processed in the United States by Google Firebase (region: us-central1). Serper and Expo are also US-based. Product analytics events sent to PostHog are stored in the European Union. If you are located in the EEA or UK, transfers to US processors are made under appropriate safeguards:

13. Children

Veto is not directed at children under 13. We do not knowingly collect personal information from anyone under 13. If we learn that a child under 13 has provided personal information, we will delete it promptly. If you believe a child has submitted data, contact us via our support form.

14. Your Rights

Depending on your location, you may have the following rights regarding your personal data. To exercise any of them, use the controls below or contact us — we will respond within 30 days.

California residents (CCPA): You have the right to know what personal information is collected (see Section 2), the right to delete (see Erasure above), the right to correct, and the right to opt out of the sale or sharing of your personal information. We do not sell or share personal information. To exercise your rights, contact us via our support form or at support@get-veto.app.

15. Changes to This Policy

We may update this policy as Veto evolves. Material changes will be reflected in the "Last updated" date above. The browser extension asks you to acknowledge a new disclosure version before beginning another Gauntlet when a material extension data-use change requires it. Material changes to MCP data use are reflected in this policy and may require you to re-consent or reconnect an assistant host before that host can continue using Veto tools.

16. Contact

Questions about this policy or requests to exercise your rights:

A Data Protection Officer (DPO) is not currently designated. Under GDPR Article 37, a DPO is required only where: (a) processing is carried out by a public authority; (b) core activities consist of large-scale systematic monitoring of individuals; or (c) core activities consist of large-scale processing of special category data. None of these conditions currently apply to Veto. If the user base grows to a scale where condition (b) or (c) is triggered, or if features involving explicit medical data or systematic behavioural tracking are introduced, this policy will be updated and a DPO appointed accordingly.