Last updated: 2026-07-24
This Privacy Policy describes how Team Veto ("Veto," "we," "us," or "our") collects, uses, and protects information when you use the Veto iOS app, web app at app.get-veto.app, browser extension (Chrome, Safari), or MCP connector at mcp.get-veto.app (used by third-party AI assistants you authorize). By using Veto, you agree to the practices described here.
1. Surfaces & Shared Account
Veto is one account across multiple surfaces. Your Purchase Considerations, Gauntlet conversations, Veto Pro entitlement, and Advisor Allowance are tied to your signed-in Veto account — not to a particular device, browser, or assistant host. Backend processors (Firebase, Anthropic, and the other services listed below) are the same regardless of entry surface; what differs is how data enters and any local or temporary state on that surface.
- iOS app: Primary mobile surface. May store an Expo push notification token for reminders. Apple in-app purchases are available here.
- Web app (app.get-veto.app): Same Firebase Authentication and Firestore account model in the browser. Does not read shopping-site pages. This is where you manage AI assistant (MCP) connections. The marketing site at get-veto.app may store a theme preference in your browser’s local storage; it is not used for advertising or cross-site tracking.
- Browser extension (Safari, Chrome): Locally detects product details on supported store pages so you can review them before a Gauntlet. Backend sync happens only after you choose to begin (see Section 3).
- MCP / AI assistants (mcp.get-veto.app): Assistants you authorize via OAuth can submit tool arguments to create Purchase Considerations and run Gauntlets. Results return to the host (see Section 4).
We do not use advertising SDKs or request an Advertising Identifier (IDFA) on any surface. We do not track you across other apps or websites for advertising.
2. Data We Collect
We collect information you actively provide or that is created when you use the Service:
- Account information: Email address and display name created at sign-up via Firebase Authentication.
- Purchase considerations: Item names, prices, descriptions, photos, product URLs, merchant names, variants, and source platform details you submit or review before analysis — including details submitted via the browser extension or MCP tools.
- Financial profile: Monthly discretionary budget, estimated income, hours worked per week, and birth year — entered optionally to personalise cost analysis. This data is never verified or linked to any financial account.
- Conversation history: Your Gauntlet conversations with the AI advisor, including messages, verdicts, and per-turn analysis.
- Preferences: Advisor tone, app theme, notification settings, and the version of any browser-extension privacy disclosure you acknowledged.
- MCP connection metadata: When you authorize an AI assistant host, we store connection and OAuth-related records such as client/host identity, granted scopes, and timestamps, so you can review and disconnect that host.
- Device identifiers: Your Expo push notification token, stored to deliver reminders. On iOS, this is a pseudonymous device identifier managed by Apple.
- Support & feedback: When you contact us through the website form or the in-app feedback feature, we collect your name, email address, and message. In-app feedback also includes your account identifier, app version, and device OS version to help us diagnose issues.
Account-linked data is stored in Google Firebase Firestore under your authenticated user ID. Authentication credentials are handled by Firebase Authentication. The browser extension’s temporary recovery state is stored locally as described in Section 3. MCP access and refresh tokens for authorized hosts are stored so those hosts can call Veto on your behalf until you disconnect them or delete your account.
3. Browser Extension
On supported Amazon pages, the Veto browser extension locally detects and reads available product details so it can offer the Veto button; it does not place a product draft in extension storage until you invoke it. On Shopify, Veto detects and reads product details only after you choose to grant the exact store origin, and it may keep that draft temporarily ready for review. Shopify access is optional and can be removed from the extension.
Before a Gauntlet begins, you can review and edit the product fields. Veto sends reviewed product details to your account and backend only after you choose to begin. It does not save the rest of the page, your browsing history, cart, checkout details, passwords, or payment-card information. The extension does not run ads or track you across websites.
The extension temporarily stores the active product draft and, when necessary, an interrupted Gauntlet answer in local extension storage so your work can recover. This temporary browser state is cleared when it is no longer needed or when you sign out.
On Chrome, the use of information received from Google APIs will adhere to the Chrome Web Store User Data Policy, including the Limited Use requirements.
4. MCP / AI Assistants
Veto provides a remote Model Context Protocol (MCP) connector at mcp.get-veto.app. After you authorize a host on the Veto consent screen, supported AI assistants (for example Claude, Cursor, Codex, or VS Code Copilot Chat) may call Veto tools to create Purchase Considerations and walk them through the Gauntlet inside your account.
- Authorization: Connection uses an OAuth 2.1-style flow with PKCE. You sign in with your Veto Firebase account on the web consent screen and grant scopes. Hosts receive MCP access and refresh tokens — not your password. We do not issue user API keys for MCP.
- What Veto receives: Tool arguments only — for example item name, price, optional context, product URL, merchant, Gauntlet responses, and decision choices. Hosts are instructed not to send full chat transcripts; Veto does not scrape the host’s conversation.
- What Veto stores: The same Purchase Consideration and conversation records under your user ID as other surfaces. Items created via MCP appear in your normal Veto library across iOS, web, and the extension.
- AI analysis: Gauntlet turns use the same Cloud Functions → Anthropic path described in Section 5. Your name and email are not included in those API calls.
- Host-side boundary: Advisor text and consideration metadata returned in tool results may be retained in the assistant host’s chat history or logs under that host’s privacy policy. Veto does not control how long a host keeps that copy.
- Connection lifecycle: You authorize each host separately. View and disconnect hosts in Settings → AI assistant connections on the web app. Disconnecting revokes refresh tokens for that host. Deleting your account clears MCP connections and tokens.
- Channel telemetry: Our MCP Cloud Function may log operational events such as a hashed account key, OAuth client id, tool name, latency, and status codes. These logs do not include tool argument content (item names, prices, or messages). Channel telemetry stays in Cloud Logging.
- Product analytics: When you have not opted out of product analytics in Settings, selected MCP product milestones (for example creating a Purchase Consideration or completing a Gauntlet) may also be sent to PostHog as described in Section 10 — using your Firebase user ID and allowlisted metadata only, never tool argument content.
5. AI Analysis
When you run a Gauntlet conversation from any surface — including iOS, web, the browser extension, or MCP — the following data is sent server-side to Anthropic's Claude API via Firebase Cloud Functions:
- The item name, price, and conversation history.
- Your financial profile context: discretionary budget, monthly outgoings, approximate age (derived from birth year), and advisor tone preference. This allows the AI to tailor its assessment to your financial situation.
Your name and email address are never included in API calls. Anthropic processes these requests under its commercial API terms and does not train its models on API data. Your conversation data is not retained by Anthropic beyond the scope of the individual request.
6. Visual Scouting
If you use Visual Scouting, the item name is sent to Serper (a Google Image Search proxy operated by Serper LLC) to retrieve publicly available product images. The item name is the only data transmitted. Product images are then stored in Firebase Storage linked to your item record. Image analysis uses Anthropic Claude server-side.
7. Sharing
We do not sell, trade, or rent your personal information. We do not share data with advertisers, data brokers, or marketing platforms. Data is processed by the following third-party services:
- Google Firebase (Auth, Firestore, Storage, Cloud Functions, Cloud Run) — core infrastructure provider. Data is stored in the United States. MCP operational telemetry is written to Cloud Functions logs as described in Section 4.
- Anthropic — AI analysis, server-side only, under commercial API terms (see Section 5).
- Serper — image search for Visual Scout product identification. Item names are transmitted as search queries (see Section 6).
- Expo — push notification delivery. Your device push token and notification content (item name and price) are transmitted to Expo's push service to send reminders.
- Sentry — crash reporting and diagnostics on surfaces where it is integrated (see Section 10).
- PostHog (EU Cloud) — product analytics on the iOS app, web app, browser extension side panel, and (when you have not opted out) selected MCP product milestones (see Section 10). Behavioural events are stored in the European Union.
- Apple — in-app purchase processing and payment management (see Section 9).
- RevenueCat — subscription management and Pro Entitlement verification. We share a pseudonymous app user identifier (your Firebase user ID) and receive your subscription status; RevenueCat does not receive your payment card details (see Section 9).
- Cloudflare — operates the proxy that receives contact form and in-app feedback submissions, and hosts our website. Cloudflare receives the name, email address, and message you submit, and processes it under Cloudflare's Data Processing Addendum and Standard Contractual Clauses.
- Resend — delivers contact form and in-app feedback submissions to our support inbox by email. Resend receives the name, email address, and message you submit, processed under Resend's Data Processing Agreement and Standard Contractual Clauses.
- MCP hosts you authorize — third-party AI assistants you connect receive tool results (Advisor text and consideration metadata) as part of providing the Service to you. Those hosts process that information under their own terms and privacy policies.
We may disclose information if required by law or to protect the rights, property, or safety of Veto, its users, or the public.
8. Purchases
Veto offers Veto Pro through Apple's in-app purchase system and a RevenueCat-hosted web purchase flow linked from the browser extension. We do not store or have access to your payment card details. RevenueCat receives your Firebase user ID and, for the web flow, your account email so it can associate the purchase with the same Pro Entitlement across extension, web, and mobile. Manage or cancel a subscription through the channel where you purchased it.
9. Analytics & Crash Reporting
Where integrated, we use Sentry to collect crash reports and diagnostic information when a Veto surface encounters an error. Each report is associated with a pseudonymous account identifier (your Firebase user ID) so we can investigate and fix issues affecting specific users. Reports include device type, OS version, app version, and a stack trace. Your name, email address, item data, and conversation content are never included.
Where integrated, we use PostHog (hosted in the EU) for first-party product analytics so we can understand activation and feature usage across iOS, web, the browser extension side panel, and MCP. Events are associated with your Firebase user ID and may include coarse metadata such as surface (web / mobile / extension / mcp), Gauntlet step or Verdict enum, merchant platform enum, and app environment. We do not send item names, prices, product URLs, conversation text, tool arguments, or email addresses to PostHog. We do not use session replay, advertising SDKs, or the Advertising Identifier (IDFA). We do not track you across other apps or websites for advertising. The extension does not send analytics from merchant product pages — only from the Veto side panel after you use it. MCP ops/channel telemetry (Section 4) remains in Cloud Logging and is separate from PostHog product milestones.
You can opt out of PostHog product analytics in Settings on iOS or web (or contact us). Opting out is stored on your account and stops further event capture on client surfaces and MCP product milestones; existing PostHog records can be deleted on request.
MCP channel telemetry (Section 4) is separate from Sentry and PostHog and does not include tool argument content.
If you would like your Sentry diagnostic data or PostHog analytics data deleted, contact us and we will submit the deletion request on your behalf.
10. Legal Bases for Processing (GDPR)
If you are in the European Economic Area (EEA) or United Kingdom, we process your data under the following legal bases:
- Performance of contract (Art. 6(1)(b)): Account creation, storing purchase considerations, delivering AI analysis, MCP connections you authorize, sending reminders.
- Legitimate interests (Art. 6(1)(f)): Crash reporting and diagnostics (our interest: maintaining stable and secure surfaces); product analytics via PostHog across iOS, web, the extension side panel, and MCP product milestones (our interest: understanding how the Service is used so we can improve it); MCP operational telemetry without tool content (our interest: reliability and abuse prevention). These interests do not override your rights — you can opt out of product analytics in Settings, disconnect MCP hosts, and request Sentry or PostHog data deletion.
- Consent (Art. 6(1)(a)): Push notifications (you grant permission through the iOS system prompt; you may withdraw at any time in your device Settings); authorizing an MCP host on the consent screen.
11. Data Retention
We retain data for as long as your account is active. Specific retention windows:
- Account data, purchase history, conversations, and MCP connection records: Retained until you delete your account or, for MCP, until you disconnect a host (which revokes that host’s tokens).
- Sentry crash reports: 90 days (Sentry's default retention period).
- PostHog product analytics: Up to 1 year on our current PostHog plan (or shorter if we configure a lower retention).
- Push notification logs: Approximately 30 days.
- AI feedback reports: If you use the in-app feature to report a poor AI response, that report is stored to help improve the advisor. It is automatically deleted when you delete your account.
- Support & feedback correspondence: Contact form and in-app feedback messages delivered to our support inbox are retained for up to 24 months, then deleted.
12. International Data Transfers
Your data is stored and processed in the United States by Google Firebase (region: us-central1). Serper and Expo are also US-based. Product analytics events sent to PostHog are stored in the European Union. If you are located in the EEA or UK, transfers to US processors are made under appropriate safeguards:
- Google Firebase: Covered by Google's Standard Contractual Clauses (SCCs) and Google's Data Processing Addendum.
- Anthropic: Covered by Anthropic's Data Processing Agreement and SCCs.
- Serper and Expo: Transfers made on the basis of SCCs.
- Cloudflare and Resend: Transfers made on the basis of SCCs (see Section 7).
- PostHog: EU Cloud hosting under PostHog's Data Processing Agreement.
13. Children
Veto is not directed at children under 13. We do not knowingly collect personal information from anyone under 13. If we learn that a child under 13 has provided personal information, we will delete it promptly. If you believe a child has submitted data, contact us via our support form.
14. Your Rights
Depending on your location, you may have the following rights regarding your personal data. To exercise any of them, use the controls below or contact us — we will respond within 30 days.
- Access (Art. 15): Request a copy of the data we hold about you, including the categories of data, processors involved, and retention periods.
- Rectification (Art. 16): Correct inaccurate data directly in Settings → Profile (iOS or web), or ask us to update it.
- Erasure (Art. 17): Delete your account and all associated data from Settings → Account → Delete Account on iOS or web. This removes your Firestore data, stored images, and MCP connections immediately. You can also disconnect individual MCP hosts without deleting your account.
- Restriction (Art. 18): Ask us to pause processing of your data while a dispute is resolved.
- Portability (Art. 20): Export your purchase history and notifications as a JSON file from Settings → Export Data where available.
- Object (Art. 21): Object to processing based on legitimate interests, including product analytics. Disable product analytics in Settings, or contact us and we will disable it for your account.
- Withdraw consent: Disable push notifications at any time in your device Settings. Disconnect MCP hosts in Settings → AI assistant connections.
- Lodge a complaint: You have the right to lodge a complaint with your national data protection authority — for example, the ICO (UK), the CNIL (France), or the DPC (Ireland).
California residents (CCPA): You have the right to know what personal information is collected (see Section 2), the right to delete (see Erasure above), the right to correct, and the right to opt out of the sale or sharing of your personal information. We do not sell or share personal information. To exercise your rights, contact us via our support form or at support@get-veto.app.
15. Changes to This Policy
We may update this policy as Veto evolves. Material changes will be reflected in the "Last updated" date above. The browser extension asks you to acknowledge a new disclosure version before beginning another Gauntlet when a material extension data-use change requires it. Material changes to MCP data use are reflected in this policy and may require you to re-consent or reconnect an assistant host before that host can continue using Veto tools.
16. Contact
Questions about this policy or requests to exercise your rights:
A Data Protection Officer (DPO) is not currently designated. Under
GDPR Article 37, a DPO is required only where: (a) processing is
carried out by a public authority; (b) core activities consist of
large-scale systematic monitoring of individuals; or (c) core
activities consist of large-scale processing of special category data.
None of these conditions currently apply to Veto. If the user base
grows to a scale where condition (b) or (c) is triggered, or if
features involving explicit medical data or systematic behavioural
tracking are introduced, this policy will be updated and a DPO
appointed accordingly.