Data We Collect
During pre-launch, Vexlynk collects waitlist information so we can contact people who ask to hear about the product.
- Waitlist data: email address, selected language, source, signup timestamp, and confirmation status.
- Optional form data: if a future form asks for a name or similar field, it will be used only to personalize Vexlynk communication.
- Technical data: basic request information may be processed by hosting, security, analytics, or email delivery systems to keep the service reliable.
Future Account Data
When Vexlynk accounts become available, we may collect account details such as name, email, authentication status, workspace settings, preferences, and product activity needed to provide the service.
We will use that data to operate Vexlynk, secure accounts, support users, improve the product, and communicate important service updates.
Google OAuth And Google User Data
When you choose to connect a Google account, Vexlynk requests — through Google's OAuth consent screen — only the narrowest access needed for the feature you enable, and only when you enable it. Most access is read-only; the one write permission (Google Calendar event editing) is requested separately, at the moment you first use event editing — never up-front. Vexlynk also receives your basic Google profile (name and email) to identify the connected account. The Google data Vexlynk can access today is:
- YouTube data (youtube.readonly): Vexlynk reads, read-only, your channel's title, subscriber count, total views, video count, and your recent uploads' titles and view, like, and comment counts. For competitor and trending features it reads the same kind of public channel and video data for the channels or regions you specify. This is shown to you in Vexlynk and used by your in-app assistant to summarize your channel and content. Vexlynk never posts, modifies, or deletes anything on your YouTube account.
- YouTube Analytics (yt-analytics.readonly): For your own channel, Vexlynk reads, read-only, your analytics for the date range you choose: views, watch time, average view duration, and subscribers gained and lost. This is shown to you as performance cards and used by your in-app assistant to summarize how your channel is performing.
- Google Analytics (analytics.readonly): If you connect a Google Analytics account, Vexlynk reads, read-only, the GA4 property reports you choose — sessions, users, and page metrics for the date range you select. This is shown to you as analytics cards and used by your in-app assistant to summarize your site's performance. Vexlynk never changes anything in your Google Analytics account.
- Gmail (gmail.readonly): If you connect Gmail, Vexlynk reads, read-only, your recent inbox metadata — sender, subject, date, and Gmail's own short snippet — to show an inbox overview card and let your in-app assistant produce a brief of your inbox. Vexlynk never fetches full message bodies or attachments, and never sends, modifies, deletes, or labels email. Replying opens Gmail itself.
- Google Calendar (calendar.readonly): If you connect Google Calendar, Vexlynk reads, read-only, your upcoming events — titles, times, and attendees — to display them in calendar cards on your workspace and let your in-app assistant summarize your schedule.
- Google Calendar event editing (calendar.events): Only if you use event editing in the Calendar Sync card does Vexlynk ask for this additional permission, at that moment — never up-front. It is used solely to create, update, or delete the specific events you act on in Vexlynk, mirrored to your own Google Calendar. If you never edit events, this permission is never requested.
- Google Business Profile (business.manage): If you connect a Google Business Profile, Vexlynk reads your business locations, ratings, and reviews to display them in your workspace. Google offers no read-only permission for this data, so its management scope is required — but Vexlynk uses it strictly read-only and never edits, posts to, or deletes anything on your Business Profile.
- Access: Vexlynk accesses this data only after you grant permission through Google's OAuth consent screen, and only while your account stays connected. You can disconnect at any time.
- Use: Vexlynk uses Google data only to provide the features you enable — displaying it in your workspace and letting your in-app assistant summarize it — plus account connection, support, and security. Vexlynk does not use Google data for advertising and does not sell it.
- Storage: Vexlynk stores your Google connection tokens encrypted on its server and keeps only the connection metadata needed to operate the features you enabled.
- Sharing: Vexlynk does not sell Google user data. We do not share it except as needed to provide the service, comply with law, protect users, or follow your direction.
- Compliance: Vexlynk's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
How We Use Data
- To manage the Vexlynk waitlist and send launch updates.
- To provide, secure, maintain, and improve Vexlynk.
- To support account access, product workflows, and future integrations that users choose to enable.
- To prevent abuse, investigate issues, and comply with legal obligations.
Analytics
Vexlynk may use privacy-conscious analytics, including Google Analytics, to understand how the public launch pages are used and how the waitlist flow performs.
Analytics may help us understand page visits, general traffic sources, approximate geographic region, waitlist conversion, language preference, and site performance.
- No email addresses: Vexlynk does not send waitlist email addresses to analytics.
- No verification tokens: Vexlynk does not send Turnstile tokens or raw form payloads to analytics.
- No sale of personal data: Vexlynk does not sell personal data.
Security Verification
Vexlynk uses Cloudflare Turnstile to help verify waitlist submissions and reduce automated abuse.
Turnstile may run in invisible mode, which means verification can happen silently without a visible challenge or widget on screen.
- Cloudflare Turnstile: Turnstile verification is processed by Cloudflare, and Vexlynk references Cloudflare's Turnstile Privacy Addendum for that processing.
- Purpose: Vexlynk uses Turnstile for bot prevention, abuse protection, and waitlist security.
- No analytics sharing: Vexlynk does not send Turnstile tokens to analytics or marketing systems.
How Data Is Stored And Protected
Waitlist data is stored in Vexlynk's Supabase project. Future account and integration data will be stored in systems selected for the production Vexlynk service.
We use practical security controls such as server-side secrets, access restrictions, validation, and abuse protection. No system can be guaranteed perfectly secure, but we design Vexlynk to limit unnecessary access and reduce risk.
Sharing And Service Providers
Vexlynk may use trusted service providers for hosting, database storage, email delivery, security, analytics, and product operations. These providers process data only as needed to support Vexlynk.
We do not sell personal data or Google user data.
Data Deletion Requests
To request deletion of waitlist, account, or connected Google data, email support@vexlynk.app from the email address associated with your request.
We may need to retain limited information when required for security, legal compliance, fraud prevention, or legitimate operational records.
Changes To This Policy
We may update this Privacy Policy as Vexlynk evolves. The effective date above will change when material updates are made.