VNTR OS — Privacy Policy

Effective date: June 8, 2026 Last updated: July 7, 2026


0. About this policy

This Privacy Policy explains how VNTR OS ("VNTR OS", "the Platform", "we", "us", "our") collects, uses, shares, and protects personal data when you use the Platform — the web dashboard, the command-line / MCP interface, the Telegram bot, and any related services and websites (together, the "Services").

VNTR OS is agentic software infrastructure for private capital. Each account (an investor, a founder/startup, or a fund) gets a private workspace — a "Brain" — consisting of a knowledge base, a complete history of every action, and a personal orchestrator agent that directs specialist sub-agents to source, screen, and coordinate deal flow. Because the Platform is agentic, it processes your content with AI agents and, to do so, transmits some content to third-party language-model providers. The way this works, and the safeguards around it, are described in Section 6 (AI processing and third-party language models) — please read it carefully.

Positioning note (for context, not a legal representation): VNTR OS is permissioned software infrastructure for analysis, workflow coordination, relationship intelligence, documents, reporting, and human-approved communications. It is not a broker, not an investment adviser, and not an autonomous decision-maker. Decisions, signatures, and the movement of money remain under explicit human control.


1. Who we are (data controller and contact)

The data controller responsible for your personal data is:

  • Legal entity: VNTR Circle LLC
  • Registered / business address: c/o its registered agent, Agents and Corporations, Inc., 1207 Delaware Ave #3808, Wilmington, DE 19806, USA
  • Privacy / data-protection contact: info@vntr.vc
  • Data Protection Officer (DPO): we have not appointed a Data Protection Officer; privacy enquiries go to info@vntr.vc

If you are in the EEA or the UK and we are required to appoint a representative under Article 27 GDPR / UK GDPR, their details will be listed here: we have not currently appointed one.


2. Scope — who and what this policy covers

This policy applies to personal data we process about:

  • Investors (private investors, angels, family offices, and fund/GP users) and their team members;
  • Founders / startups and their team members;
  • Fund users and their team members;
  • Developers / operators who connect external agentic clients (Claude Code, Codex, any MCP client) to the Platform via CLI/MCP;
  • Visitors to our marketing site and people who request access or join a waitlist;
  • Third parties named or described in materials that a user uploads or forwards to the Platform — for example, founders, companies, co-investors, or contacts mentioned in a pitch deck, email, or document (see Section 3(g) and Section 5).

It does not govern the privacy practices of third parties whose services or sites you may reach through the Platform; their own policies apply.


3. The personal data we collect

We collect the following categories of personal data. Not every category applies to every user.

(a) Account and identity data. Name, email address, and the identifiers returned when you sign in with email one-time code or Google sign-in (e.g. your Google account email and the OAuth identifiers Google provides). Authentication is provided through Supabase Auth.

(b) Profile and mandate data. The information that defines your workspace and goals — for an investor this includes your thesis (sectors, stages, geographies, ticket size, ownership, exclusions, "the bar"), your goal/mission, and your allocation plan (the coming year's allocation and how much is already invested); for a founder, your company, round, and founder details; for a fund, fund-level allocation and pacing data. This data is often versioned, and the version history is retained.

(c) Uploaded and forwarded materials, and their extracted contents. Pitch decks, documents, and other files you upload, forward, or share — and the content our agents parse and extract from them (structured facts, entities, figures, summaries, and embeddings/vector representations generated for search and matching). Decks and forwarded materials are treated as untrusted input and as confidential (see Section 8).

(d) Communications data. Messages and chats with your orchestrator and agents; scheduling and follow-up data; emails you forward into the Platform; and voice notes you send via Telegram, together with the text transcripts we generate from them. Telegram messages may include text, documents, emails, and voice.

(e) Activity and agent logs (the audit history). The Platform keeps a complete history of every action taken in your workspace — by you, by your team members, and by every agent — including logins, document access, agent runs and their inputs/outputs, decisions you record, and every disclosure, access, and action across access levels. This audit log is a core feature of the Brain and is used for security, accountability, attribution, and to help the Brain learn. Parts of the audit log are append-only by design (see Sections 10, 11 and 12).

(f) Usage, telemetry, device, and technical data. Log data, IP address, approximate location derived from IP, browser and device information, timestamps, feature usage, performance and error data (collected via our error-monitoring and observability tooling), and similar technical data.

(g) Cookies and similar technologies. See Section 13.

(h) Data about third parties contained in your materials. Materials you upload or forward, and the communications you bring into the Platform, frequently contain personal data about other people — e.g. founders, employees, co-investors, advisers, or contacts named in a deck, email thread, or document. We process this data on your behalf to provide the Services. By submitting such materials you confirm you have the right to share them and that doing so does not breach any third party's rights or any non-disclosure obligation (consistent with our offer terms). See Section 5 on roles.

(i) Connected calendar data (optional Google Calendar integration). If you choose to connect your Google Calendar, we access — through Google's APIs, under the OAuth permission you grant — your calendar events and free/busy availability, so your agent can help you schedule and coordinate meetings and follow-ups you initiate in the Platform (creating, reading, and updating those events) and avoid double-booking. This access is initiated by you, is limited to the scopes you approve (calendar.events and calendar.freebusy), and can be revoked at any time in the Platform (Settings → Calendar → Disconnect) or at myaccount.google.com/permissions. We do not use Google Calendar data for advertising and we do not sell it — see the Google API Services — Limited Use statement at the end of Section 6.

We do not intentionally collect special-category data (e.g. health, biometric, or sensitive personal data). Voice notes and their transcripts are processed to provide the Service and are not used to create biometric voiceprints or to uniquely identify a person by voice.


4. How we collect personal data

  • Directly from you — when you create an account, set up your Brain, type or speak to your orchestrator, upload or forward materials, or contact us.
  • Automatically — through your use of the Services (telemetry, log, device, and cookie data).
  • Through integrationsemail forwarding, the Telegram bot (text, voice, documents, email), a connected Google Calendar (only if you enable it), and the CLI / MCP interface, including when an external agentic client you authorize calls the Platform on your behalf.
  • Through the network — via invitations (e.g. an investor invites a founder to pitch into their Brain using a single-use link/token) and via shared or distributed deals (materials a founder distributes to fitting investor agents, subject to access settings).

5. How and why we use personal data, and our legal bases (GDPR)

We use personal data for the purposes below. Where the GDPR / UK GDPR applies, the lawful basis for each purpose is shown.

#PurposeWhat this coversLegal basis (GDPR Art. 6)
1Providing the agentic ServicesRunning your Brain, orchestrator, and hired agents — intake, screening, diligence, memos, matching, portfolio, reporting, scheduling and meeting coordination (incl. a connected calendar), and human-approved communicationsContract (Art. 6(1)(b)) for the account holder; legitimate interests (Art. 6(1)(f)) for processing within materials, where contract does not apply
2Accounts, teams, and access controlManaging accounts, teams, roles, permissions, and the access-level model (Public / Qualified / NDA / Restricted / Internal)Contract (Art. 6(1)(b))
3Security, fraud prevention, and audit loggingProtecting the Services and users; the append-only audit history; attribution of deal access; abuse detectionLegitimate interests (Art. 6(1)(f)); legal obligation (Art. 6(1)(c)) where applicable
4Billing and paymentsSubscriptions, distribution fees, success-fee attribution and invoicingContract (Art. 6(1)(b)); legal obligation (Art. 6(1)(c)) for tax/accounting records
5Service improvement and analyticsDiagnosing errors, measuring usage, and improving features (using aggregated/de-identified data where feasible)Legitimate interests (Art. 6(1)(f))
6Communications with youService messages, support, and (where permitted) updates and marketingContract, legitimate interests, or consent (Art. 6(1)(a)) for marketing where required
7Legal compliance and defenceComplying with law, responding to lawful requests, and establishing/exercising/defending legal claimsLegal obligation (Art. 6(1)(c)); legitimate interests (Art. 6(1)(f))
8Optional model improvementUsing your content to improve the Service's own quality only where you have opted in / agreedConsent (Art. 6(1)(a))

Controller / processor note. For the account holder's own account, profile, and activity data we generally act as controller. For third-party personal data contained in materials a user uploads or forwards, we generally act as a processor on that user's behalf, and the user is the controller of that data.


6. AI processing and third-party language models

The Platform is agentic: it processes your content with AI agents (your orchestrator and the specialist sub-agents you hire). To generate analysis, the Platform transmits relevant content to third-party large-language-model (LLM) providers that act as sub-processors.

What we send. Depending on the task, we send the content needed to perform it — for example, the text and extracted contents of a deck or document, your thesis and mandate context, message text, or a voice-note transcript — to a provider's API so it can return a screen, a diligence output, an investment memo, a transcript, a summary, an embedding, or a matching/confidence score. We send the minimum reasonably necessary to perform the requested task.

Current LLM sub-processors. Anthropic, OpenAI, and Perplexity (see the table in Section 16). This list may change; we will keep it current.

Training. We do not permit these providers to use your content to train their foundation models, and we do not use your content to train our own or third parties' models, except to the limited extent you have separately opted in or agreed. We rely on each provider's enterprise/API data-handling terms (which, for these providers, generally exclude API content from model training by default) to support this position. Where any provider's default differs, we will configure opt-outs or stop using that provider for user content.

Safeguards. Content is transmitted over encrypted connections; we use providers' API/enterprise tiers rather than consumer products; we limit what is sent to what the task requires; and we apply the access-level model so that an agent only operates on content the requesting user is entitled to see.

Automated processing, profiling, and human-in-the-loop. The Platform scores, ranks, screens, and matches deals and produces draft memos and communications — this involves automated processing and a degree of profiling. However, the Platform is designed so that a human makes every decision with legal or similarly significant effect: agents prepare, surface, and coordinate; humans decide, sign, and move money. We do not make decisions producing legal or similarly significant effects about you solely by automated means within the meaning of Article 22 GDPR. Outputs are presented with sources and confidence and are intended to support, not replace, human judgement.

Google API Services — Limited Use. VNTR OS's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Concretely, data obtained from Google Calendar (via the calendar.events and calendar.freebusy scopes) is used only to provide and improve the in-product scheduling and meeting-coordination features you invoke; it is not transferred to others except as necessary to provide those user-facing features, to comply with applicable law, or as part of a merger, acquisition, or sale of assets; it is not used for advertising; and it is not used to develop, improve, or train generalized AI/ML models. Our LLM sub-processors are not sent your Google Calendar data, and our staff do not read it except with your consent, for security, or to comply with law.


7. How we share and disclose personal data

We share personal data only as described here. We do not sell your personal data.

(a) Sub-processors and service providers. We use the vendors listed in Section 16 to host, secure, and operate the Services — including Supabase (database, auth, storage), Upstash Redis (queue/cache), Cloudflare (CDN, DNS, email/edge), the LLM providers above, Google (for Google sign-in), our payment provider (e.g. Stripe). They process data on our instructions under appropriate terms.

(b) Sharing controlled by your access levels. Sharing of materials and deal data within the network is governed by the access-level model — Public / Qualified / NDA / Restricted / Internal — enforced at the database (row-level security) and API layers. Other participants see only what your chosen access level, block lists, and settings permit.

(c) Private sends. When a deal is sent privately to a single recipient, it is delivered via a unique single-use token with a limited lifetime (TTL). Other users cannot access it, and it is not indexed or discoverable in search.

(d) Distribution to investor agents. Where a founder chooses to distribute a deal, the relevant materials are made available to the agents of fitting investors in the network according to the founder's access settings and block lists.

(e) Team and account sharing. Within an investor/founder/fund account, data is shared with the account's team members according to the roles and access rights configured by the account.

(f) Legal, safety, and compliance disclosures. We may disclose data where required by law, to respond to lawful requests, to enforce our terms, or to protect the rights, property, or safety of users, the public, or VNTR OS.

(g) Corporate transactions. If we are involved in a merger, acquisition, financing, or sale of assets, personal data may be transferred as part of that transaction, subject to this policy.


8. Confidentiality of materials

Pitch decks, forwarded documents, and private sends are treated as confidential and are access-scoped. For a private send, our trust guarantees are: a single intended recipient, a single-use token, and expiry (TTL) — the deal is not shown to other users and is not indexed for discovery. Every disclosure, access, and action on a deal is recorded in the audit log, supporting deal-access attribution.

Messages — a two-tier promise. We treat your two kinds of conversation differently:

  • Direct messages (person-to-person). Your DMs with other members are private between the participants. They are encrypted (application-level AES-256-GCM, key held by us) and our staff do not read them — they do not appear in our internal console, which shows only metadata (who, when, and that a thread exists). The only exception is an audited emergency process (suspected abuse, a legal request, or an extreme support need): a reveal requires an elevated role and a recorded reason, and the who / why / when is written to our append-only audit log before the text is shown. This is not end-to-end encryption — we hold the key, so a lost device never destroys your message history and we can still act on abuse.

  • Conversations with the assistant (your Brain/agent). These are processed to operate and improve the assistant (see Section 6). Staff access is restricted and logged, used to review and correct the agent's answers. We don't sell this data, and our AI provider doesn't train on it.


9. International data transfers

We and our sub-processors may process personal data in countries outside your own, including outside the EEA / UK. In particular, the LLM providers and cloud providers listed in Section 16 may process data in the United States and other locations. VNTR Circle LLC is based in the United States.

Where personal data is transferred out of the EEA / UK, we rely on a lawful transfer mechanism — such as the EU Standard Contractual Clauses and the UK International Data Transfer Addendum, an adequacy decision, or a provider's certification under an applicable data-transfer framework.


10. Data retention

We retain personal data for as long as needed to provide the Services, comply with legal obligations, resolve disputes, and enforce our agreements.

  • Account, profile, and mandate data — for the life of the account and a reasonable period afterwards.
  • Materials and their extracted contents — for the life of the account or until you delete them, subject to backups and legal holds.
  • Audit / activity log — retained for security, accountability, and attribution, and is append-only by design (entries are not edited or deleted in the ordinary course).
  • Billing and tax records — for the period required by law.

When data is no longer needed, we delete or de-identify it. Note the interaction between the append-only audit log and erasure requests, explained in Section 12.


11. Security

We use technical and organisational measures appropriate to the risk, including:

  • Authentication via email one-time code and Google sign-in (Supabase Auth).
  • Access controls enforced at the database (row-level security) and API layers, implementing the Public / Qualified / NDA / Restricted / Internal access-level model.
  • Encryption in transit, and at rest as provided by our hosting/storage providers.
  • Comprehensive audit logging of user and agent actions.
  • Vendor due diligence and least-privilege access for our team.

No method of transmission or storage is completely secure; we cannot guarantee absolute security.


12. Your privacy rights

Subject to applicable law, you may have the rights below. For third-party personal data contained in a user's materials, the user is generally the controller, and such requests should be directed to that user; we will assist them as their processor.

For individuals in the EEA / UK (GDPR / UK GDPR):

  • Access — obtain a copy of your personal data.
  • Rectification — correct inaccurate or incomplete data.
  • Erasure — request deletion of your personal data.
  • Restriction — limit how we process your data.
  • Portability — receive certain data in a portable, machine-readable format.
  • Objection — object to processing based on legitimate interests, and to direct marketing.
  • Withdraw consent — where processing is based on consent, withdraw it at any time.
  • Complain to a supervisory authority (Section 15).

For California residents (CCPA / CPRA):

  • Know / access the categories and specific pieces of personal information collected.
  • Delete personal information, subject to exceptions.
  • Correct inaccurate personal information.
  • Opt out of "sale" or "sharing" of personal information. We do not sell personal information.
  • Limit the use of sensitive personal information (to the extent we process any).
  • Non-discrimination for exercising your rights.

How to exercise your rights. Contact us at info@vntr.vc. We will verify your identity and respond within the time limits required by law (generally one month under GDPR and 45 days under CCPA, extendable as permitted).

Audit-log immutability vs erasure. Our audit log is append-only for security, accountability, and attribution. This can limit our ability to delete or alter certain log entries even after an erasure request, where retaining them is necessary for the establishment, exercise, or defence of legal claims, for compliance with a legal obligation, or for overriding legitimate security interests (recognised exceptions to erasure under Article 17(3) GDPR). Where this applies, we will restrict further processing rather than delete, and explain the basis to you.


13. Cookies and similar technologies

We use cookies and similar technologies for authentication and session management, security, and to understand and improve usage of the Services. Where required by law, we obtain consent for non-essential cookies and provide controls.


14. Children

The Services are intended for business users and are not directed to individuals under 18. We do not knowingly collect personal data from children. If you believe a child has provided us personal data, contact us and we will delete it.


15. Changes, contact, and complaints

Changes. We may update this policy from time to time. We will post the updated version with a new "Last updated" date and, where appropriate, notify you of material changes.

Contact. Questions or requests: info@vntr.vc, or by post at c/o its registered agent, Agents and Corporations, Inc., 1207 Delaware Ave #3808, Wilmington, DE 19806, USA.

Complaints / supervisory authority. If you are in the EEA or the UK, you have the right to lodge a complaint with your local data-protection supervisory authority (in the UK, the Information Commissioner's Office). We ask that you contact us first so we can try to resolve your concern.


16. Sub-processor list

The following is the current/expected list of sub-processors and service providers. It is provided for transparency and must be confirmed against our live contracts; locations are indicative and subject to provider configuration.

Sub-processorPurposeLocation (indicative)
SupabaseDatabase (Postgres), authentication, and file storageUnited States (US/EU)
Upstash RedisQueue and cacheUnited States
CloudflareCDN, DNS, edge, and email routingGlobal edge (US-based company)
AnthropicLLM provider — agent analysis, memos, summariesUnited States
OpenAILLM provider — agent analysis, transcripts, summariesUnited States
PerplexityLLM provider — research/enrichmentUnited States
GoogleGoogle sign-in; and, if you connect it, Google Calendar (read availability, create/update meeting events)United States / global
TelegramConversational bot interface (text, voice, documents, email)
Payment provider (e.g. Stripe)Billing, subscriptions, and fee processingStripe
Error-monitoring / observability (e.g. Sentry, LangSmith)Diagnostics and service quality