Last updated · April 25, 2026
Privacy
Varity is a workflow tool. We collect the minimum required to run that workflow for you, and we never sell your data — to anyone, ever.
What we collect
We collect three buckets of data, and only those three.
- Account data: name, email, organization, role, and any teammates you invite.
- Workspace data: drafts, schedules, brand profile, connected-account tokens, analytics snapshots, AI tool runs, and event logs that you create or trigger inside Varity.
- Operational data: anonymized request logs, error reports, billing events, and aggregate product metrics needed to keep the service up.
How we use it
We use your data only to operate Varity on your behalf — to publish posts, render clips, run AI tools, deliver analytics, and bill you. We do not sell, rent, or share your data with advertisers, data brokers, or training partners.
- We do not train any third-party model on your content.
- We use no-training inference endpoints (OpenAI, Anthropic, Replicate) wherever the provider offers them — which they currently do across our default model set.
- We process content in-region where supported by the provider.
Sub-processors
We use a small, vetted set of sub-processors. We list them below; we update this list at least 30 days before adding a new sub-processor that handles workspace content.
- Hosting and database: Vercel and Supabase (US/EU regions).
- Object storage: Cloudflare R2 / AWS S3 (configurable per workspace on Agency+ plans).
- Email: Resend (transactional only).
- AI inference: OpenAI, Anthropic, Replicate, ElevenLabs (no-training endpoints, configurable per workspace).
- Payments: Stripe (we never see or store full card details).
- Error reporting: Sentry (PII scrubbed before send).
Storage, encryption, and retention
All data is encrypted in transit (TLS 1.2+) and at rest (AES-256). Connected-account tokens and bring-your-own-key secrets are stored in an envelope-encrypted vault and only decrypted at the moment they are needed by a worker.
Drafts, schedules, analytics, and brand data live for the life of your workspace. Job logs and event logs are retained for 90 days. Deleted workspaces are purged from primary storage within 30 days and from backups within a further 60.
Your rights
You can export, correct, or delete any data you put into Varity at any time, from inside the product. If you want an account and its data removed entirely, get in touch and we will take care of it.
Children
Varity is a B2B tool. It is not directed at children under 16 and we do not knowingly collect data from anyone under 16.
Contact
Questions about privacy, your data, or anything else on this page: see the contact page at varity.pro/contact.
This page is informational and reflects how Varity currently operates. It is not legal advice and does not replace a customer agreement; enterprise customers receive a signed DPA and order form alongside these public terms.