Privacy notice
Privacy at Vythos
Last updated 7 October 2026
Vythos is an AI workspace for agencies and consultants. It keeps your rules — rates, terms, brand, process — and your own knowledge, and gives them to you and your AI tools when you need them. This page says what personal data that involves, why, where it goes, and what you can do about it.
Who we are
VYTHOS TECH LIMITED, a company registered in England and Wales, company number 17470263. Registered office: 2 Twyford Avenue, London, England, W3 9QA. Write to us about privacy at michael@vythos.tech.
Our representative in the European Union under Article 27 GDPR is being appointed; until then, write to us directly.
Two roles
- Your account, sign-in, billing and our security records: we decide how these are used. We are the controller.
- What you put in your workspace — the documents and sources you connect, your rules, clients, questions and answers: your business decides. We process it on your behalf as a processor, under our Data Processing Agreement. If your employer or client gave you access to their workspace, questions about that content go to them first.
What we collect, and why
| What | Why | Legal basis |
|---|---|---|
| Your name, email address and password (stored only as a one-way hash) — or, if you sign in with Google, your name, email address and Google account ID from Google, and no password | To give you an account and sign you in | Contract |
| A record of sign-ins and failed attempts, and of changes you make (neither with your IP address) | To keep accounts and workspaces secure and investigate problems | Our legitimate interest in security |
| Server logs, which include your IP address | Security and fixing faults | Our legitimate interest in security |
| Billing details — held by Stripe, not by us; we keep only Stripe's reference numbers | To take payment and meet tax law | Contract; legal obligation |
| Whether a question in Ask was answered (never the question) | To improve answers | Our legitimate interest in improving the service |
| Emails you send us, and what you send from Help & feedback in the app: what you write, the page you were on if you leave that ticked, and a question and its answer only if you choose to include them | To help you, and to decide what to build next | Contract; legitimate interest |
| Your name and email, if you join the waitlist (through a Tally form) | To tell you when you can sign up | Your consent, which you can withdraw by writing to us |
| On this website (vythos.tech), only if you press Accept: the pages you visit, how you arrived, your device and browser, and your rough location (Google Analytics) | To see how people find and use this website | Your consent, which you can withdraw at any time with Cookie settings at the foot of each page |
| Workspace content | To provide the service you asked for | Processed for your business, on its instructions |
We do not sell personal data, show advertising, use analytics cookies without asking you first, send marketing email, make automated decisions about you, or use your content to train AI models.
How the AI works with your content
When you connect a source or upload a file, its text is stored in your own memory, which only you can search — not your colleagues, and not the workspace owner. Credentials found in documents, such as API keys and tokens, are removed before anything is stored. Documents your team names as rules are shared with the workspace by category and client.
When you ask a question, the question, the relevant passages from your own memory and the rules you can see are sent to an AI model — Microsoft's Azure OpenAI service, in the European Union — to write the answer. Microsoft does not use them to train models or share them with OpenAI. Microsoft reviews requests its systems flag as possible abuse, automatically by default; if one needs a person to look, it is stored in the EU and reviewed by Microsoft staff in the European Economic Area.
What we read from a connected source is only what you select: chosen folders, pages, channels or labels. We never read Slack direct messages or Microsoft Teams private chats. You can disconnect a source at any time, and erase what it put in your memory.
Information Vythos receives from Google APIs is used and transferred in line with the Google API Services User Data Policy, including the Limited Use requirements.
Who else handles it
Only the providers we use to run Vythos, each under a data protection agreement:
- Microsoft Azure — hosting, database, AI and email, in the EU (Sweden).
- Stripe — payments.
- Google Workspace — our email, if you write to us.
- Tally — the waitlist form, in the EU.
- Amazon Web Services — hosting for this website.
- Google Analytics — visits to this website, only if you accept.
The full list, with locations and safeguards, is on our sub-processors page. We tell workspace owners 30 days before adding one that handles workspace content.
Where it is
Your account and workspace data are stored and processed in the European Union (Microsoft Azure, Sweden). Stripe may process billing data, and Google website analytics data if you accept, in the United States, under the EU–US Data Privacy Framework and its UK Extension, and standard contractual clauses. The UK and the EU recognise each other's data protection as adequate, so data can pass between them.
How long we keep it
| What | Kept |
|---|---|
| Workspace content: memory, rules, conversations, clients | While the workspace exists; erased when you or the owner delete it |
| Your account | Until you delete it |
| Sign-in records | 180 days |
| Records of changes | 90 days |
| Server logs | 30 days |
| Invitations | 30 days after they expire |
| Encrypted backups of deleted data | Up to 14 days |
| Billing records (at Stripe) | As UK tax law requires: 6 years |
| Waitlist | Until you sign up or ask us to remove you |
| Website analytics (Google Analytics, if you accept) | Up to 14 months |
The time limits are applied automatically, every day.
Your rights
You can ask for a copy of your data, have it corrected or erased, ask us to restrict or stop processing it, object to processing based on our legitimate interests, and take your data elsewhere. Much of this you can do yourself, in Vythos under Your data, in the menu under your initials:
- Download your data: one file with everything your workspace holds about you.
- Forget a source: erase what one connected source put in your memory.
- Erase yourself: leave a workspace and erase everything it holds about you — and your account, if no other workspace holds it.
- Delete a workspace (owners): everything in it, and optionally your account.
For anything else, write to michael@vythos.tech. We reply within a month. If your request is about a workspace that belongs to someone else, we may pass it to them, because it is their data to decide about.
If you are unhappy with how we handle your data, tell us first and we will try to put it right. You can also complain to the Information Commissioner's Office at ico.org.uk or on 0303 123 1113, or, in the EU, to your local data protection authority.
Cookies and storage in your browser
The Vythos app uses no cookies for tracking or analytics. It keeps your sign-in session, your light or dark theme, and a short-lived marker while you connect a source in your browser's storage — all strictly necessary for what you asked it to do. This website and our documentation load fonts from Google, which sees your IP address when it sends them.
On this website, vythos.tech, we use Google Analytics only if you press Accept in the cookie banner. It then sets two cookies, _ga and _ga_PN01SNN93H, which last up to two years, and Google sees your IP address and uses it to work out your rough location. If you press Decline, or choose nothing, Google Analytics isn't loaded and no cookie is set. Your choice is kept in your browser's storage. You can change it at any time with Cookie settings at the foot of each page; declining then removes the Google Analytics cookies.
Security
Every workspace is separated from every other at the database level; data is encrypted in transit and at rest; connected-account tokens are encrypted, and passwords and keys are stored only as hashes. More in our security documentation.
Children
Vythos is a business service for adults. It is not meant for anyone under 18.
Changes
We will update this page when what we do changes, and tell account holders by email about anything significant.