Versine
PlatformsPersonalDocumentation
Book a demo
PlatformsPersonalDocumentation
Book a demo

Privacy policy

  • Who we are
  • What we collect
  • Why we use it
  • Who receives it
  • Cookies and local storage
  • Retention and deletion
  • Your choices and rights
  • Security
  • International processing
  • Children
  • Changes and contact

Legal · updated draft

Privacy policy

How the current Versine implementation handles your information. Updated September 23, 2026. Effective date pending approval; existing rights and commitments are not withdrawn by this review draft.

Who we are

Oversine, Inc. (“we”, “us”, “our”) operates Versine. We are a Delaware corporation at 2261 Market Street STE 68058, San Francisco, CA 94114, United States, and the controller for the personal information described here. Contact privacy@oversine.com.

Platforms you sign into, their authentication providers and your assistant hosts separately control their own services and subsequent use of information they receive. Their privacy policies apply to those activities.

What we collect

Account identity

Clerk handles authentication for separate Console and My realms; Mobile shares My. We receive identity identifiers, names, email and verification state, and Console organization membership/roles. Google login is mediated by Clerk. We do not store your password, Google password or Google session credentials. Optional existing phone values and their verification state may be retained; phone verification is not required.

Companies, projects and logos

We store company/project names, ownership, uploaded logos, broker configuration, connection names, redirect/webhook/legal URLs and encrypted project credentials. Logos identify the company/platform in the service and on authentication screens; do not upload confidential images. Authorized company administrators can view their project's user identity and acceptance history.

Authentication and legal history

We store platform/user/connection identifiers, request state and timestamps, authorization and revocation records, blacklist entries, and document URLs, version and acceptance times when you approve platform Terms/Privacy. Browser interaction, code/token and grant records support secure completion and replay protection. A token expiring does not mean its associated audit record is erased.

Assistant connections and onboarding

We store your named MCP connection's owner, creation/expiry/revocation times and a hash of its bearer credential. The plaintext credential is returned once when created. You may provide platform-specific first/last name, email, optional phone, company and job title. These submitted values are encrypted and scoped to the user, platform and field. Pending/completed information requests are also recorded.

Webhooks and notifications

Authorization webhook records contain a stable event ID, platform and user identity, authorization ID and applicable legal acceptance. We keep delivery state, attempt times and response/error codes. Payloads do not include passwords, one-time codes, bearer credentials, device tokens or onboarding values.

If you enable mobile notifications, we store an encrypted Expo push token, a token hash, platform and device-registration state. Messages identify the pending platform and opaque request/project IDs and contain a deep link. They do not contain login codes, credentials or onboarding answers. A lock-screen preview may reveal the platform name; you can control previews and permission in device settings.

Technical and support records

The current backend records redacted error codes and request identifiers and uses connection information for abuse prevention/rate limiting. It intentionally excludes raw authentication headers, cookies, authorization codes, tokens and user profile values from request logs. Hosting/network providers necessarily process connection metadata; their exact production logging and retention configuration must be confirmed before launch. Information you send to support is used to address the request.

Why we use it

We use this information to authenticate accounts, manage organizations, authorize assistant sign-ins, present and record human decisions, supply requested onboarding details, deliver signed events and optional notifications, enforce revocation/blacklists, secure the service and handle support and legal obligations.

Where applicable data-protection law requires a legal basis, our purposes may rely on providing the requested service, legitimate interests in security and operation, compliance with legal obligations, or consent where required. The applicable bases and assessments must be approved before launch. Notification permission can be withdrawn; declining notifications does not block the approval screen.

We do not sell personal information or operate advertising profiles. The current marketing/docs implementation has no advertising or analytics integration. We do not use this workflow to make decisions with legal or similarly significant effects about you; external platforms may make their own eligibility or access decisions.

Who receives it

  • Clerk processes authentication and account/organization data. Google processes its own login when you choose that method.
  • A platform and its Auth0 broker receive a stable identity and scoped name/email claims. The platform's registered webhook additionally receives the identity, authorization and legal-acceptance fields described above. They never receive your Versine account password, browser cookies or MCP bearer credential.
  • Your connected assistant can retrieve permitted profile/onboarding fields for an active, non-blacklisted platform. The assistant host's policy governs its handling.
  • AWS S3 stores company/project logos in the configured private bucket. Other production hosting and database providers/regions require confirmation before launch.
  • When mobile push is configured and enabled, Expo and Apple's APNs or Google's FCM process device-routing data and notification payloads. These credentials and a physical-device delivery check are still part of launch setup.
  • Authorized staff and operational service providers may access data as needed for support, security and service operation. Secret-management services hold runtime credentials, not a general copy of users' profiles.

We may disclose data when legally required, to protect rights and safety, or in a corporate transaction involving Oversine, Inc., subject to applicable law and notice. No unrestricted transfer to unrelated recipients is authorized by an agent handshake.

Cookies and local storage

OIDC interaction/session cookies bind the initiating browser and use Secure, HttpOnly and SameSite protections. Clerk manages its own session mechanisms in Console/My. Mobile uses secure device storage for authentication and registration data. Interface preferences may use local storage or cookies. Do not assume every SDK cookie is HttpOnly or that every Versine surface is cookie-free.

Blocking necessary storage can prevent authentication. We do not add marketing tracking cookies in this implementation. Any future non-essential tracking requires an updated assessment and appropriate disclosures/choices.

Retention and deletion

Current protocol validity is 60 seconds for an authorization code, 300 seconds for OIDC access/ID tokens, 600 seconds for interactions/provider sessions/grants, and 90 days for MCP bearer connections unless revoked earlier. These are security lifetimes—not complete data-retention periods.

Account, project, authorization, legal, audit, webhook and onboarding records can remain stored after expiry or revocation. This implementation does not yet provide a comprehensive automated retention/deletion schedule or self-service account deletion/export. Do not rely on revocation to erase previously shared data.

Contact privacy@oversine.com to request access, a copy, correction or deletion. We verify requests and apply applicable legal requirements and retention exceptions. Before launch, we must adopt specific retention periods and backup/deletion procedures; we do not claim an automated 30-day deletion system that is not implemented. Previously applicable commitments and mandatory deadlines remain unaffected by this draft.

Your choices and rights

You can accept/reject pending legal requests, choose onboarding values, revoke a platform, blacklist/unblock it, disconnect an assistant and disable notifications. Use platform controls separately to end external sessions or delete external accounts.

Depending on your location, you may have rights to access, correct, delete, export, restrict or object to processing, withdraw consent and complain to a supervisory authority. Contact privacy@oversine.com; we may need proportionate identity verification. Rights may be subject to legal exceptions. We do not retaliate for exercising applicable rights.

Security

Controls include HTTPS, separate identity realms, organization-scoped authorization, encrypted project/onboarding/device secrets, hashed MCP credentials, short-lived codes, exact callbacks, PKCE or explicit nonce protections, redacted logging and signed webhooks.

No system is perfectly secure. Versine cannot prove the approving agent controls the browser that started a request; only complete codes from the trusted interaction page reached through your platform. Human legal approval is never inferred from push delivery.

International processing

Oversine, Inc. is based in the United States. Providers may process data in other jurisdictions under their applicable configurations and agreements. Production hosting, processor contracts and required cross-border safeguards must be verified before launch. We do not represent that a particular transfer agreement is in place without verification. Contact privacy@oversine.com for the applicable arrangements.

Children

Versine is not directed to children under 16 or a higher applicable age of digital consent. Contact us if you believe an ineligible child's information is held so we can investigate and take appropriate action.

Changes and contact

Adopted revisions will have an effective date and any notices required by law or existing commitments. Automated change-notice/reacceptance workflows are not yet implemented. This review draft is not a notice withdrawing prior rights.

Oversine, Inc.
2261 Market Street STE 68058, San Francisco, CA 94114, United States
privacy@oversine.com

Versine

Let agents sign up and log in to your platform autonomously.

Product

For platformsFor personal useBook a demo

Resources

Integration guideConnect your agentDocumentationContact us

Legal

Privacy policyTerms of servicePlatform agreement
© 2026 Oversine, Inc. · Versine