Privacy Policy

Last updated: July 2026

Vayme ("we", "us") operates Nayf, an AI assistant for macOS. This Privacy Policy describes what data we collect, how we use it, and the rights you have under the EU General Data Protection Regulation (GDPR).

1. Data We Collect

  • Account data — your email address, used to authenticate your account and deliver receipts.
  • Usage and token data — aggregated counts of interactions and tokens consumed, used for billing and abuse prevention.
  • Screenshots — captured only when you explicitly press the screenshot hotkey, sent to the AI provider for that single request, and never stored on our servers.
  • Connected-service data — if you connect a third-party account such as Google Calendar, the data needed to carry out the requests you make (see "Google User Data" below).

2. Third-Party Services

Nayf relies on the following processors to deliver its features. Your data is shared with them strictly as needed:

  • Supabase — authentication and account storage.
  • Anthropic (Claude) — large language model inference.
  • AssemblyAI — voice transcription.
  • ElevenLabs — text-to-speech.
  • Cloudflare — backend proxy that holds our API keys and brokers requests.
  • Paddle — payment processing.
  • PostHog — anonymous product analytics.
  • Google — provides the Google Calendar API when you choose to connect it.

3. Google User Data

When you connect Google Calendar, Nayf requests the https://www.googleapis.com/auth/calendar.events scope so it can read your upcoming events and create events at your explicit request — for example, "what's on my calendar tomorrow?" or "schedule lunch Friday at noon."

  • Access — only when you ask Nayf to read or change your calendar. Nayf never accesses your calendar in the background.
  • Use — to generate your answer, the relevant event details are processed transiently by our AI provider (Anthropic) and then discarded. Your calendar content is not retained beyond the session, not sold, not used for advertising, and not used to train AI or ML models.
  • Storage — your Google authorization tokens are stored securely on our backend and are never exposed to the Nayf app or any third party. The app reads or writes your calendar only by asking our backend, which uses the stored token on your behalf.
  • Revoking access — you can disconnect Google at any time in Nayf (Connect apps → Disconnect), which deletes the stored tokens and revokes the grant. You can also revoke access at myaccount.google.com/permissions.

Nayf's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

4. Data Security

We apply the following measures to protect your data, including sensitive data such as your connected-service (Google) authorization tokens and any calendar content processed to fulfil your requests:

  • Encryption in transit — all data exchanged between the Nayf app, our backend, and third-party services is transmitted over encrypted HTTPS/TLS connections.
  • Encryption at rest — sensitive data, including OAuth access and refresh tokens, is stored in our managed database (Supabase / PostgreSQL), which encrypts data at rest.
  • Restricted access and isolation — OAuth tokens are stored server-side only and are never exposed to the Nayf desktop app or any third party. They are accessible solely to our backend proxy via a privileged service-role key, and the tokens table has row-level security enabled so it cannot be read with client credentials.
  • Secret management — all third-party API keys and OAuth client secrets are held exclusively on our backend (Cloudflare Workers) and are never shipped in the app or exposed to clients.
  • Data minimization — we request the narrowest scopes needed, access data only in response to your explicit requests, and process sensitive content (such as calendar events) transiently to answer you rather than storing it.
  • Revocation — you can disconnect a connected account at any time, which deletes the stored tokens and revokes the third-party grant.

5. Memory Stored On Your Device

Nayf can remember durable facts and preferences to personalize its help. This memory is stored locally on your Mac and is not uploaded to our servers; relevant facts are included in a request to the AI provider only when needed to answer you. You can view and delete this memory at any time from within Nayf.

6. Legal Basis

We process your data on the basis of (a) the contract you enter when using Nayf, and (b) our legitimate interest in operating, securing, and improving the service.

7. Data Retention

Account and billing data are retained for as long as your account is active and as required by Swedish bookkeeping law. Screenshots, prompts, and connected-service data are not retained beyond the duration of the request. Integration tokens are retained until you disconnect the integration or delete your account.

8. Your Rights

Under GDPR you have the right to access, rectify, export, and erase your personal data, and to object to or restrict processing. To exercise these rights, contact us at hey@vayme.io.

9. International Transfers

Some of our processors are located outside the EU/EEA. When data is transferred internationally, we rely on Standard Contractual Clauses or equivalent safeguards.

10. Contact

For any privacy-related questions, email hey@vayme.io.