Legal
Privacy Policy
Last updated July 14, 2026
This Privacy Policy explains how Voyu, Inc. (“Voyu,” “we,” “us,” or “our”) collects, uses, discloses, and safeguards information when you visit our website or use the Voyu platform (the “Service”). Voyu is an AI-assisted compliance platform that helps organizations build and manage an Information Security Management System (ISMS) for standards such as ISO 27001 and SOC 2.
If you have questions about this policy or our privacy practices, contact us at info@voyu.io.
Who this policy covers
This policy applies to visitors of our website and to the users and organizations that register for and use the Service. Where an organization uses Voyu, that organization is the controller of the data it enters or connects, and Voyu processes that data on its behalf.
Information we collect
Account and organization information
When you create an account, we collect your name, email address, and authentication credentials (managed through our authentication provider). For your organization, we collect details such as organization name, industry, and geography, and the role assigned to each member (for example, admin, contributor, consultant, or auditor).
Compliance content you create
The Service stores the ISMS content you author, generate, or approve within it — including your scope definitions, interested parties, asset register, risks and risk owners, controls, policies and documents, evidence records, Statement of Applicability entries, corrective actions, and approval history.
Files you upload
Evidence and documents you upload (including PDFs we parse to extract text) are stored in private, access-controlled storage. Uploaded files are not publicly accessible.
Website and lead information
If you request a demo or sign up for updates, we collect the information you submit — such as name, email address, company, and job title — along with basic technical data like your browser user-agent and the page that referred you. We use this to respond to your inquiry and to operate the website.
How we use information
- To provide, maintain, and secure the Service and your account.
- To generate AI-assisted drafts (see AI processing below). Every AI-generated draft requires your review and approval before it becomes active — “AI drafts, you decide.”
- To send transactional messages such as member invitations and account notifications.
- To respond to demo requests, support inquiries, and other communications.
- To detect, prevent, and address security incidents, fraud, and abuse.
- To comply with legal obligations.
AI processing
Voyu uses Anthropic’s Claude API to generate compliance drafts and suggestions. When you use an AI feature, relevant organization context (for example, organization name, industry, headcount, geography, and the asset, risk, or control content you are working on) is sent from our servers to Anthropic to produce a draft. These requests are made server-side only; the Service never calls the AI provider directly from your browser. AI output is a starting point that a human must review and approve before it takes effect.
Third-party integrations and the data we access
You may optionally connect third-party systems so Voyu can automatically collect evidence about your security posture. These connections are initiated by an administrator in your organization and are read-only. Durable credentials (such as a Google refresh token or an AWS external identifier) are encrypted at rest using AES-256-GCM and are never exposed to browser clients.
- GitHub — organization, membership (including two-factor status), and repository settings such as visibility and branch protection.
- Amazon Web Services (AWS) — read-only security configuration (for example IAM password policy, S3 public-access settings, CloudTrail, and encryption status), accessed via a role you grant with the AWS-managed read-only security audit policy.
- Microsoft 365 / Entra ID — directory users, multi-factor registration state, conditional access policies, and directory roles.
- Google Workspace — see the dedicated disclosure below.
Google API Services — Limited Use disclosure
When an administrator connects Google Workspace, Voyu requests the following read-only OAuth scopes:
https://www.googleapis.com/auth/admin.directory.user.readonlyhttps://www.googleapis.com/auth/admin.directory.domain.readonlyopenidandemail— to identify the connecting administrator.
We use this access solely to read directory users and account domains in order to run automated security-posture checks — for example, whether 2-Step Verification is enrolled and enforced, how many super-administrators exist, and whether accounts are stale or suspended. We do not request or access Gmail, Drive, Calendar, or any message or file content. When you disconnect the integration, the stored refresh token is revoked.
Voyu’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We do not sell Google user data, do not use it for advertising, and do not use it to train generalized AI or machine-learning models.
Service providers (subprocessors)
We rely on a small number of vetted providers to operate the Service. They process data only to provide their service to us.
| Provider | Purpose |
|---|---|
| Supabase | Database, authentication, and file storage |
| Anthropic | AI generation (Claude API) |
| Netlify | Application hosting |
| Google Workspace (SMTP) | Sending transactional and notification email |
Systems you choose to connect (GitHub, AWS, Microsoft 365, Google Workspace) act as sources we read from at your direction; they are not recipients of your Voyu data.
How we share information
We do not sell your personal information. We share information only: with the service providers listed above; with auditors or other parties you grant access to (for example, through a token-based auditor link you generate); when required by law or to protect our rights and users; and in connection with a merger, acquisition, or sale of assets, subject to this policy.
Data security
The Service is multi-tenant, and every organization’s data is isolated using database row-level security. Durable integration credentials are encrypted at rest, uploaded files are held in private storage buckets, and AI and integration processing occurs server-side. No method of transmission or storage is completely secure, but we work to protect your information using appropriate technical and organizational measures.
Data retention and deletion
We retain account and organization data for as long as your account is active or as needed to provide the Service. You may request access to, correction of, or deletion of your data by contacting info@voyu.io. We will honor verified requests subject to our legal and operational obligations.
Your rights
Depending on your location, you may have rights to access, correct, delete, or port your personal information, or to object to or restrict certain processing. To exercise any of these rights, contact info@voyu.io. If your organization administers your account, we may direct your request to that organization.
International data transfers
We and our service providers may process information in countries other than the one in which you reside. Where required, we take steps to ensure that transfers are subject to appropriate safeguards.
Children’s privacy
The Service is intended for business use and is not directed to individuals under the age of 16. We do not knowingly collect personal information from children.
Changes to this policy
We may update this Privacy Policy from time to time. When we do, we will revise the “Last updated” date above and, where appropriate, provide additional notice.
Contact us
Voyu, Inc.
131 Continental Dr, Suite 305
Newark, DE 19713, United States
Email: info@voyu.io