Privacy

What we collect, and what we never touch.

Vexo posts under your company’s name and sends email from your address, so it asks for more than most tools do. This says exactly what that means, in the order somebody actually wants to know it.

Last updated 24 September 2026.

What Vexo collects

Everything in the database, grouped by the thing that puts it there. Nothing here is collected in the background: each row exists because you connected something or asked Vexo to make something.

Your account

Name, email address and the workspace you belong to. If you sign in with Google, LinkedIn or X we receive your name, email and profile picture from them and hold no password of yours at all.

What your company sells

Your website address, the products you add, who you say buys them, and anything Vexo read off your own site when you asked it to. This is what drafts and prospect lists are written from.

What Vexo writes and publishes

Drafts, posts, images, videos, courses and ads, and the numbers the networks report back about them.

Connected accounts

Access and refresh tokens for the networks, mailboxes and calendars you connect, sealed with AES-256-GCM under a key held outside the database.

People you choose to contact

Companies Vexo suggests, business email addresses it found published on those companies’ own websites, and the messages sent to and received from them. The page each address was published on is stored beside it.

Billing

Your plan, your trial dates and a Stripe customer reference. Card details go to Stripe directly and never reach Vexo.

Google account data

Vexo asks for four Google permissions and only when you use the feature that needs one. Signing in never carries calendar or mail access.

openid, email, profile
Signing in. Vexo learns your name, email and picture, and nothing else about your Google account.
calendar.freebusy
Reading when you are busy so an email can offer a real time. It returns only that you are busy — never the title, the attendees or anything else about the meeting.
calendar.events
Creating the one meeting somebody books with you. Asked for separately from the one above, so a workspace that only wants times offered never grants it.
gmail.send
Sending an email you asked Vexo to send. It is send-only: it cannot read, search, list or delete anything in your mailbox, and Vexo never requests a scope that could.

Limited Use

Vexo’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically: we do not use Google user data to serve advertising, we do not sell it, we do not use it to train generalised artificial intelligence or machine learning models, and no human reads it except where you have explicitly asked us to, where it is necessary for security or to comply with the law, or where the data has been aggregated and made anonymous.

Who else sees it

Every third party that receives customer content, including the model provider — which is the one most products leave off.

Google Cloud
Hosting and the database.
OpenAI
Writing drafts and generating images. Receives your brand description, products and post topics.
Stripe
Payments. Card details go to Stripe directly.
Netlify
Serves the website in front of the application.
The networks and mailboxes you connect
They receive what you publish or send through them, under their own terms.
Canva and Slack
Only if you connect them, and only what those features need.

Your content is not sold and is not used to train anyone’s models. We do not share it with anybody not on this list except where the law requires it.

People you contact through Vexo

Vexo finds business email addresses by reading the company’s own public website and keeping the page each address was published on. It will not write to an address it only guessed at from a naming pattern, and it stores the lawful basis it is relying on alongside every contact. An opt-out is honoured before anything else happens to a reply: the check runs first, by pattern match, on a path with no model and no network call in it, so it can stop mail going out and can never start it. If you are on a list somebody built with Vexo and want to be removed, reply with “unsubscribe” and you will be suppressed for that workspace immediately, or write to us and we will remove you everywhere.

Keeping it, and taking it back

Data is kept while your workspace exists. Disconnecting a network, mailbox or calendar deletes the stored tokens for it and Vexo stops being able to reach that account at all; you can also revoke Vexo from your Google account directly, at any time, without telling us. Deleting a workspace removes everything belonging to it — drafts, connected accounts, analytics, prospects, contacts, uploaded media and the audit trail — by database constraint rather than by a cleanup job somebody has to remember. Posts already published stay on the networks, because they belong to the network now and are deleted there.

You can ask us for a copy of what we hold about you, ask us to correct it, or ask us to delete it. Write to the address below and we will answer within 30 days.

Contact

TouchBase Technologies, which operates Vexo. Questions about this page, or a request about your own data: support@touchbasetechnologies.com.

The mechanisms behind all of this are described on the security page, including what Vexo does not have yet.