Legal

Privacy Policy

Last updated July 14, 2026

This Privacy Policy explains how Voyu, Inc. (“Voyu,” “we,” “us,” or “our”) collects, uses, discloses, and safeguards information when you visit our website or use the Voyu platform (the “Service”). Voyu is an AI-assisted compliance platform that helps organizations build and manage an Information Security Management System (ISMS) for standards such as ISO 27001 and SOC 2.

If you have questions about this policy or our privacy practices, contact us at info@voyu.io.

Who this policy covers

This policy applies to visitors of our website and to the users and organizations that register for and use the Service. Where an organization uses Voyu, that organization is the controller of the data it enters or connects, and Voyu processes that data on its behalf.

Information we collect

Account and organization information

When you create an account, we collect your name, email address, and authentication credentials (managed through our authentication provider). For your organization, we collect details such as organization name, industry, and geography, and the role assigned to each member (for example, admin, contributor, consultant, or auditor).

Compliance content you create

The Service stores the ISMS content you author, generate, or approve within it — including your scope definitions, interested parties, asset register, risks and risk owners, controls, policies and documents, evidence records, Statement of Applicability entries, corrective actions, and approval history.

Files you upload

Evidence and documents you upload (including PDFs we parse to extract text) are stored in private, access-controlled storage. Uploaded files are not publicly accessible.

Website and lead information

If you request a demo or sign up for updates, we collect the information you submit — such as name, email address, company, and job title — along with basic technical data like your browser user-agent and the page that referred you. We use this to respond to your inquiry and to operate the website.

How we use information

  • To provide, maintain, and secure the Service and your account.
  • To generate AI-assisted drafts (see AI processing below). Every AI-generated draft requires your review and approval before it becomes active — “AI drafts, you decide.”
  • To send transactional messages such as member invitations and account notifications.
  • To respond to demo requests, support inquiries, and other communications.
  • To detect, prevent, and address security incidents, fraud, and abuse.
  • To comply with legal obligations.

AI processing

Voyu uses Anthropic’s Claude API to generate compliance drafts and suggestions. When you use an AI feature, relevant organization context (for example, organization name, industry, headcount, geography, and the asset, risk, or control content you are working on) is sent from our servers to Anthropic to produce a draft. These requests are made server-side only; the Service never calls the AI provider directly from your browser. AI output is a starting point that a human must review and approve before it takes effect.

Third-party integrations and the data we access

You may optionally connect third-party systems so Voyu can automatically collect evidence about your security posture. These connections are initiated by an administrator in your organization and are read-only. Durable credentials (such as a Google refresh token or an AWS external identifier) are encrypted at rest using AES-256-GCM and are never exposed to browser clients.

  • GitHub — organization, membership (including two-factor status), and repository settings such as visibility and branch protection.
  • Amazon Web Services (AWS) — read-only security configuration (for example IAM password policy, S3 public-access settings, CloudTrail, and encryption status), accessed via a role you grant with the AWS-managed read-only security audit policy.
  • Microsoft 365 / Entra ID — directory users, multi-factor registration state, conditional access policies, and directory roles.
  • Google Workspace — see the dedicated disclosure below.

Google API Services — Limited Use disclosure

When an administrator connects Google Workspace, Voyu requests the following read-only OAuth scopes:

  • https://www.googleapis.com/auth/admin.directory.user.readonly
  • https://www.googleapis.com/auth/admin.directory.domain.readonly
  • openid and email — to identify the connecting administrator.

We use this access solely to read directory users and account domains in order to run automated security-posture checks — for example, whether 2-Step Verification is enrolled and enforced, how many super-administrators exist, and whether accounts are stale or suspended. We do not request or access Gmail, Drive, Calendar, or any message or file content. When you disconnect the integration, the stored refresh token is revoked.

Voyu’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We do not sell Google user data, do not use it for advertising, and do not use it to train generalized AI or machine-learning models.

Service providers (subprocessors)

We rely on a small number of vetted providers to operate the Service. They process data only to provide their service to us.

ProviderPurpose
SupabaseDatabase, authentication, and file storage
AnthropicAI generation (Claude API)
NetlifyApplication hosting
Google Workspace (SMTP)Sending transactional and notification email

Systems you choose to connect (GitHub, AWS, Microsoft 365, Google Workspace) act as sources we read from at your direction; they are not recipients of your Voyu data.

How we share information

We do not sell your personal information. We share information only: with the service providers listed above; with auditors or other parties you grant access to (for example, through a token-based auditor link you generate); when required by law or to protect our rights and users; and in connection with a merger, acquisition, or sale of assets, subject to this policy.

Data security

The Service is multi-tenant, and every organization’s data is isolated using database row-level security. Durable integration credentials are encrypted at rest, uploaded files are held in private storage buckets, and AI and integration processing occurs server-side. No method of transmission or storage is completely secure, but we work to protect your information using appropriate technical and organizational measures.

Data retention and deletion

We retain account and organization data for as long as your account is active or as needed to provide the Service. You may request access to, correction of, or deletion of your data by contacting info@voyu.io. We will honor verified requests subject to our legal and operational obligations.

Your rights

Depending on your location, you may have rights to access, correct, delete, or port your personal information, or to object to or restrict certain processing. To exercise any of these rights, contact info@voyu.io. If your organization administers your account, we may direct your request to that organization.

International data transfers

We and our service providers may process information in countries other than the one in which you reside. Where required, we take steps to ensure that transfers are subject to appropriate safeguards.

Children’s privacy

The Service is intended for business use and is not directed to individuals under the age of 16. We do not knowingly collect personal information from children.

Changes to this policy

We may update this Privacy Policy from time to time. When we do, we will revise the “Last updated” date above and, where appropriate, provide additional notice.

Contact us

Voyu, Inc.
131 Continental Dr, Suite 305
Newark, DE 19713, United States
Email: info@voyu.io