Security and privacy

How access, credentials, and control work when AI does real work in your accounts.

Handing work to AI employees means handing over some access, so it's worth knowing exactly how that access is held and bounded. This page is the plain language version; the privacy policy and terms are the formal one.

Your account

Sign in with Google, Microsoft, or email and password. Password changes and sign in security live under Settings, then Authentication. Your workspace is yours alone: employees, memory, runs, and connections are scoped to your account.

App credentials

  • Apps connect through their own sign in pages (OAuth) wherever supported. Verse receives a scoped token, never your password.
  • Tokens are stored encrypted on the server and used only to run work you set in motion. Nobody, including your employees in chat, can read them back.
  • Disconnecting a connector revokes what Verse holds, and you can always also revoke from the app's side. See Managing connections.

What keeps employees bounded

  • Autonomy levels decide how much gets done without you. See Employee settings.
  • Hard limits: daily spend caps, outbound message rates, and email domain rules apply no matter the autonomy level.
  • Approvals fail closed. A request you never answer expires as declined. The failure mode is inaction, not action. See Approvals.
  • Everything is auditable. Every run keeps its timeline, tool calls, credits, and, for browser and computer work, a visual replay.

Isolation

  • Each employee's cloud computer is an isolated machine, separate from other employees and from you.
  • Miniapps run in a sandbox with no network access; the only actions they can trigger are ones you own, brokered and permissioned by Verse.
  • Access to your own machine never happens implicitly: it exists only in the desktop app, per employee, behind a toggle you set, with native confirmation on risky commands. See Verse Desktop.

Your content

What your employees produce for you is yours. Deleting an employee permanently removes their activity, memory, chat, and connections. For account level questions or a full account deletion, email hello@useverse.ai and a human will handle it.

Important

One habit worth keeping: connect apps with the least account that does the job. A support employee needs the support inbox, not the founder's personal Gmail.

© 2026 Verse. All rights reserved.

Privacy Policy and Terms of Service