Legal
Privacy policy
How Oversine, Inc. handles your information when you use Versine. Effective October 3, 2026.
Who we are
Oversine, Inc. (“we”, “us”, “our”) operates Versine. We are a Delaware corporation at 2261 Market Street STE 68058, San Francisco, CA 94114, United States, and the controller for the personal information described here. Contact privacy@oversine.com.
Platforms you sign into, their authentication providers and your assistant hosts separately control their own services and subsequent use of information they receive. Their privacy policies apply to those activities.
What we collect
Account identity
Clerk handles authentication for separate Console and Mobile realms. We receive identity identifiers, names, email and verification state, and Console organization membership/roles. Google login is mediated by Clerk. We do not receive your Google password or Google session credentials. We retain each address's actual verification state rather than marking unverified addresses as verified. A phone number is optional for signup. If you choose to share one from your passport, Clerk verifies it and we receive the number and verification state. Without the identity information required for account creation, we cannot provide an authenticated account.
Companies, projects and logos
We store company/project names, ownership, uploaded logos, broker configuration, connection names, redirect/webhook/legal URLs and encrypted project credentials. Logos identify the company/platform in the service and on authentication screens; do not upload confidential images. Authorized company administrators can view their project's user identity and acceptance history.
Authentication and legal history
We store platform/user/connection identifiers, request state and timestamps, authorization and revocation records, blacklist entries, and document URLs, version and acceptance times when you approve platform Terms/Privacy. Browser interaction, code/token and grant records support secure completion and replay protection. A token expiring does not mean its associated audit record is erased.
Assistant connections and onboarding
We store your named MCP connection's owner, creation/expiry/revocation times and a hash of its bearer credential. The plaintext credential is returned once when created. You may provide first/last name, email, company and job title in a general passport shared with your connected assistants. Submitted passport values are encrypted and scoped to user and field, not platform. Optional phone ownership is verified through Clerk SMS before the account number is made available to assistants. Legacy platform-scoped values are retained separately without automatic merging. Information request states, requesting assistant, expiry and decision times are also recorded.
Webhooks and notifications
Authorization webhook records contain a stable event ID, platform and user identity, authorization ID and applicable legal acceptance. We keep delivery state, attempt times and response/error codes. Payloads do not include passwords, one-time codes, bearer credentials, device tokens or onboarding values.
If you enable mobile notifications, we store an encrypted Expo push token, a token hash, platform and device-registration state. Legal-approval messages identify the pending platform and opaque request/project IDs and contain a deep link. Passport prompts contain a request ID and deep link without requested field names or values. They do not contain login codes, credentials or onboarding answers. A lock-screen preview may reveal the platform name; you can control previews and permission in device settings.
Technical and support records
The current backend records redacted error codes and request identifiers and uses connection information for abuse prevention/rate limiting. It intentionally excludes raw authentication headers, cookies, authorization codes, tokens and user profile values from request logs. Hosting and network providers process connection metadata, such as IP addresses, request times and device/browser information, to deliver and protect the service. We use the contact details, messages and attachments you send to support to address your request. Please do not send passwords, verification codes or access tokens.
Platform directory searches
We process the search text, keywords, tags, names and URLs your assistant submits to find directory entries. The current directory uses sample platform metadata and lexical matching; it does not send searches to an embedding provider or retain a directory-search history in your account. Directory searches do not access your passport. Avoid including personal or confidential information in search text or URLs.
Why we use it
We use this information to authenticate accounts, manage organizations, authorize assistant sign-ins, present and record human decisions, supply requested onboarding details, deliver signed events and optional notifications, enforce revocation/blacklists, secure the service and handle support and legal obligations.
Where applicable data-protection law requires a legal basis, we process account, authentication and requested passport information to provide the service under our agreement with you. We rely on legitimate interests in operating and securing the service for fraud prevention, troubleshooting and support, subject to your rights. We also process information to comply with legal obligations and rely on consent where required for optional processing. You can withdraw consent without affecting prior lawful processing. Disabling notifications does not block the approval screen.
We do not sell personal information or share it for cross-context behavioral advertising. We do not operate advertising profiles, and our marketing and documentation sites have no advertising or analytics integration. We do not use this workflow to make decisions with legal or similarly significant effects about you; external platforms may make their own eligibility or access decisions.
Who receives it
- Clerk processes authentication and account/organization data. Google processes its own login when you choose that method.
- A platform and its Auth0 broker receive a stable identity and scoped name/email claims. The platform's registered webhook additionally receives the identity, authorization and legal-acceptance fields described above. They never receive your Versine account password, browser cookies or MCP bearer credential.
- Your connected assistant can retrieve your general passport fields independently of platform authorization or blacklist status. It can use them to fill browser onboarding under your instructions. Disconnect the assistant to revoke its MCP access. The assistant host's policy governs its handling.
- Amazon Web Services provides application hosting, database, storage and network infrastructure. This includes storing account and service records and company/project logos.
- When mobile push is configured and enabled, Expo and Apple's APNs or Google's FCM process device-routing data and notification payloads. Delivery depends on your device settings and the availability of those services.
- Authorized staff and operational service providers may access data as needed for support, security and service operation. Secret-management services hold runtime credentials, not a general copy of users' profiles.
We may disclose data when legally required, to protect rights and safety, or in a corporate transaction involving Oversine, Inc., subject to applicable law and notice. No unrestricted transfer to unrelated recipients is authorized by an agent handshake.
Retention and deletion
Current protocol validity is 60 seconds for an authorization code, 300 seconds for OIDC access/ID tokens, 600 seconds for interactions/provider sessions/grants, and 90 days for MCP bearer connections unless revoked earlier. These are security lifetimes—not complete data-retention periods.
We retain account, project and passport information as needed to provide your account and requested services. Retention of authorization, legal-acceptance, security, webhook and support records depends on their purpose, the duration of our relationship, applicable legal requirements, dispute-resolution needs and abuse prevention. Expiry or revocation does not automatically erase associated records or copies already received by an assistant or external platform.
To request access, a copy, correction or deletion, contact privacy@oversine.com. We handle requests after proportionate identity verification, subject to applicable deadlines and legal retention exceptions. Backup copies may remain until the applicable backup cycle ends and are subject to the same access restrictions. This policy does not remove retention or deletion commitments already owed to you under an applicable agreement or law.
Your choices and rights
You can accept/reject pending legal requests, choose onboarding values, revoke a platform, blacklist/unblock it, disconnect an assistant and disable notifications. Use platform controls separately to end external sessions or delete external accounts.
Depending on your location, you may have rights to access, correct, delete, export, restrict or object to processing, withdraw consent and complain to a supervisory authority. Contact privacy@oversine.com; we may need proportionate identity verification. Rights may be subject to legal exceptions. We do not retaliate for exercising applicable rights. Where permitted by law, you may use an authorized agent; we may require proof of authority. If we deny a request, you may contact us to appeal where applicable.
Security
Controls include HTTPS, separate identity realms, organization-scoped authorization, encrypted project/onboarding/device secrets, hashed MCP credentials, short-lived codes, exact callbacks, PKCE or explicit nonce protections, redacted logging and signed webhooks.
No system is perfectly secure. Versine cannot prove the approving agent controls the browser that started a request; only complete codes from the trusted interaction page reached through your platform. Human legal approval is never inferred from push delivery.
International processing
Oversine, Inc. is based in the United States. Providers may process data in the United States and other jurisdictions where they operate. Those countries may have different data-protection laws from your country. International processing is subject to applicable legal requirements. Contact privacy@oversine.com for information about the locations and safeguards applicable to your information. This policy is not a waiver of your rights or a request for blanket consent to international transfers.
Children
Versine is not directed to children under 16 or a higher applicable age of digital consent. Contact us if you believe an ineligible child's information is held so we can investigate and take appropriate action.
Changes and contact
We may update this policy to reflect changes to the service or our practices. We will post the revised policy with its effective date and provide additional notice or obtain consent where required by law or existing commitments. Changes do not retroactively remove your rights. For general product questions, visit our support page.
Oversine, Inc.
2261 Market Street STE 68058, San Francisco, CA 94114, United States
privacy@oversine.com