Privacy policy
Last updated 12 September 2026
vaOS is a tool for virtual assistants to run their client work. This explains what it holds about you, what it holds about your clients, and what you can do about either.
Who this is about
vaOS is operated by Rory Manning, trading as Virtually Rory, of Suite 45, 4 Blenheim Court, Peppercorn Close, Peterborough, Cambs PE1 2DU, registered with the Information Commissioner's Office under ZB747045.
There are two sorts of people in here and the law treats them differently.
You, as a vaOS customer. We decide what to collect about you and why, so we are the data controller.
Your clients. You decide what to record about them and why. You are their controller and we are your processor: we hold their details because you asked us to, and we do not use them for anything of our own.
What we hold about you
- Your name, email address and password, which is stored hashed and cannot be read back by anyone including us.
- Your business name, logo, colour and working hours, because the product uses them.
- Your billing details if you are on a paid plan. Card numbers go to Stripe and never reach our servers.
- A log of actions taken in your account, so that a question about what happened has an answer.
What you put in about your clients
Whatever you choose: names, contact details, requests and the messages on them, notes, time entries, invoices and files. We hold it, back it up and keep it available to you. We do not read it, mine it, sell it, or use it to train anything.
Your clients reach their own portal through a private link rather than an account, so we hold no password for them.
Google Calendar
If you connect Google Calendar, vaOS lists your calendars so you can choose which ones it watches and which one it adds events to, reads events on the chosen calendars so it can show them and notice when somebody you have invited books a call, and writes the events you create here.
vaOS's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
In plain terms: your calendar data is used to provide the calendar feature to you and nothing else. It is not sold, not used for advertising, not used to train any model or any artificial intelligence feature, and no human at vaOS reads it except where you have asked us to help with a specific problem, where it is needed for security purposes, or where the law requires it.
Who we share Google user data with
We do not share, transfer, sell, rent or disclose Google user data to any third party. It is not passed to advertisers, data brokers, analytics services or model trainers, and no other vaOS customer can reach it.
Three parties are unavoidably involved in holding it for you, and no others:
- Google, who hold the data in the first place and who receive our requests to read and write your events.
- Hostinger, who host the server and database where the small amount of stored Google data below sits. They act on our instructions and do not use it for anything of their own.
- Google Drive, again Google, where our backup copies are kept. Google user data in a backup returns to Google rather than going anywhere new.
We would also disclose it if the law required us to, which has not happened.
What Google user data we store, and for how long
Your events are fetched from Google each time a page needs them and are not copied into our database, so there is nothing to retain.
Four small things are stored so that the feature can work at all: the connection tokens Google gives us, encrypted before they are written; the identifiers of the calendars you chose to watch and to write to; and, when vaOS notices that a lead has booked a call with you, that event's title, its identifier, its calendar and its start time, kept on that lead so the booking can be shown to you.
All four are deleted as follows:
- Disconnect at any time from Settings. We ask Google to revoke the grant, so it disappears from your own Google account page too, and we delete the tokens and the stored calendar identifiers immediately.
- Booking details are deleted when you delete or erase the lead they belong to, and in any case are deleted with the account below.
- Close your account and everything above is deleted within 30 days.
- Backups. Because the system is copied hourly and copies are kept for 30 days before being deleted automatically, a copy of stored Google user data can persist in a backup for up to 30 days after it has gone from the live system. It is not visible or searchable there, and nothing reads it.
You can also revoke our access yourself at any time from your Google account's security settings, at which point vaOS stops being able to read or write anything.
If you add your own mail settings, notifications to your clients are sent through your mail provider under your own address. We store your mail password encrypted so that we can send on your behalf.
Backups
The whole system is copied automatically every hour and the copy is stored away from the server that runs vaOS, so that a failure of that server does not take your work with it. Copies are encrypted in transit and at rest, are held in an account controlled by us, and are reachable by nobody else.
Backups exist to restore the system after a failure. They are never used to look anything up, and we do not read them.
Who else is involved
- Hostinger, who host the servers and the database.
- Stripe, for payments, if you are on a paid plan.
- Google, for calendar access if you connect one, and for backup storage. Backups are held in a Google Workspace account controlled by us, in a location set by our Workspace region.
- Your own mail provider, if you configure one.
We do not use advertising networks, analytics services or tracking tools.
How long it is kept
Your account data stays while your account is open. Close it and we delete it within 30 days, except anything we have to keep for tax or accounting, which is six years.
Client records stay until you delete them. Erasing a client from within vaOS removes their personal details from the live system immediately.
Backups are the exception to "immediately". Because the system is copied hourly and those copies are kept for 30 days before being deleted automatically, something you have erased can still sit inside a backup for up to 30 days after it has gone from the live system. It is not visible or searchable there, and nothing reads it. If we ever do restore from a backup, anything you deleted stays deleted.
What you can ask for
You can ask for a copy of what we hold, for it to be corrected, or for it to be deleted. Any client's full record can be exported from their page as a zip without asking us at all, which is usually faster than a request.
Ask at support@vaos.uk. If you are unhappy with the answer you can complain to the Information Commissioner's Office at ico.org.uk.
Security
Traffic is encrypted in transit. Passwords are hashed. Credentials such as mail passwords and calendar tokens are encrypted before they are stored. Each account's data is separated at the database level, so one customer cannot reach another's.
The system is backed up automatically to storage separate from the live server, encrypted in transit and at rest, and reachable only by us.
Changes
If this changes materially we will tell you in the app rather than quietly updating the date at the top.
See also our cookie policy.