Myromyro

Privacy Policy

Last updated: June 13, 2026

Myro is an autonomous work assistant operated by VDR Tech Limited (“VDR Tech”, “we”, “us”). This policy explains what data Myro accesses, how it is used, stored and protected, and the choices you have. It applies to myro.vdrtech.net and the Myro service.

1. Data we access

With your explicit authorization, Myro accesses data only from the services you choose to connect, and only within the permissions you grant. Connectable services include, and will expand over time:

  • Google — Gmail, Calendar, Drive, Docs/Sheets/Slides, Tasks, Contacts, Meet.
  • Microsoft 365 — Outlook mail, calendar and files (Microsoft Graph).
  • Cloud platforms — Amazon Web Services, Oracle Cloud, Cloudflare.
  • Developer tools — GitHub, Bitbucket.
  • Messaging & productivity — Slack, Jira, and other providers as we add them.

Myro accesses only the scopes you authorize for each connected service, only to perform the tasks you request, and only within the project (namespace) you connect it to.

2. How we use it

Connected data is used solely to provide the assistant features you ask for — reading and summarizing messages, drafting and (with your approval) sending communications, managing calendars and files, and related productivity tasks. Every consequential action is tied to an explicit human instruction and recorded.

3. Google user data — Limited Use

Myro’s use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:

  • We use Google user data only to provide and improve the user-facing features you request.
  • We do not transfer or sell Google user data for advertising, resale, or credit purposes.
  • We do not use Google user data to train generalized AI/ML models.
  • Humans do not read your Google data except with your explicit consent for support, for security, or as required by law.

4. Knowledge bases (optional, curated)

Myro does not automatically index or copy your connected accounts. If you choose, you may add specific documentsto a project’s Knowledge base. Only those documents you explicitly select are read, split into passages, and converted into a private search index. This indexing — including the embedding step — runs on VDR Tech’s own hardware; the document content is not sent to any third-party indexing or embedding service. The index is scoped to a single project, is used only to provide relevant context to your own requests, and is deleted when you remove the document.

5. How we protect and store it

Credentials and access tokens are encrypted at rest and held only by Myro’s control plane — never exposed to the AI model or to arbitrary code. The agent that reasons over your data has no direct internet access and cannot read stored credentials. Every action is written to a tamper-evident, hash-chained log. Data is isolated per project.

6. Sharing

We do not sell your data. We share it only with subprocessors strictly necessary to run the service (e.g. the AI model provider you have configured and cloud hosting), and only to the extent required to perform your requested tasks.

7. Retention & deletion

You can disconnect any integration at any time, which revokes Myro’s stored access and deletes the associated tokens. You may request deletion of your account and associated data by contacting us. Conversation history and logs are retained until you delete them or your account is closed.

8. Your choices

You control which services Myro connects, which projects they apply to, and which actions require your approval. Outbound or irreversible actions are gated behind explicit approval.

9. Contact

VDR Tech Limited — privacy@vdrtech.net. To revoke Google access directly, visit your Google account permissions.