Skip to main content
← Sevra

Privacy policy

Last updated: July 2, 2026. This policy describes the current Sevra product and is periodically reviewed and updated.

How Sevra works

Sevra is the managed home for brains, operated by VibeCraft Inc, the data controller for the personal data described here. A brain is a store of plain markdown files in the db.md format: an open format, published under the Apache-2.0 license, exportable and self-hostable. Sevra hosts your store, keeps it available, and keeps it indexed and organized.

You operate your store with your own AI agent, such as Claude Code or Codex. The agent runs under your own AI subscription, outside Sevra. Sevra does not provide AI, does not hold your AI provider credentials, and does not sit between you and your AI provider.

What we collect

Account information. Name and email address, collected through WorkOS when you sign in.

Billing information. Processed by Stripe. Sevra stores your Stripe customer ID and subscription status. Card details are held by Stripe and never touch Sevra's servers.

Application form. Email address and optional message submitted when you request access.

Store contents. The markdown files you keep in your hosted store. Sevra stores them in object storage in order to host, index, and organize them. They are your data. You can export or delete them at any time.

Install telemetry. Anonymous events when the dbmd CLI is installed or checks for updates through our install routes: a timestamp, which install route was hit, and the request's User-Agent string. No IP addresses, no fingerprints, no identifiers tying the event to a person. Used to measure CLI uptake and platform mix.

What we do not collect

Sevra does not collect, store, or access:

  • Conversations between you and your AI agent. The agent runs on your side, under your own AI subscription.
  • Your AI provider API keys or credentials
  • Your card details. Payments are processed by Stripe.
  • Passwords. Sign-in is handled by WorkOS.

We do not sell your data, and we do not use your data to train AI models.

Your store

Your hosted store lives in object storage, on AWS S3 today, migrating to Cloudflare R2. Contents are encrypted at rest by the storage provider and encrypted in transit with TLS.

The format is open. Your store is plain markdown files, readable without Sevra. You can export the full store at any time, and you can self-host it. Sevra is the default home for your store, not the only home.

Access to store contents by Sevra personnel is limited to what is needed to operate the service and is governed by internal policy.

When you delete your store or your account, hosted contents are deleted. You can also request deletion at any time by writing to privacy@sevrahq.com.

AI usage

Sevra does not provide AI. You bring your own agent, such as Claude Code or Codex, under your own subscription with your AI provider.

Your agent's requests go directly to your AI provider, not through Sevra, and Sevra never holds your AI provider API keys. What your provider does with those requests is governed by your agreement with them. Sevra does not train AI models on your data.

Third-party services

Sevra uses the following services to operate the platform.

  • WorkOS for authentication
  • Stripe for billing and payments
  • Vercel for application hosting (www.sevrahq.com)
  • Neon for the application database
  • AWS S3 for store contents (object storage), migrating to Cloudflare R2
  • Resend for transactional email

Data residency

Sevra's infrastructure is hosted in the United States. This includes the application, the application database, and the object storage that holds store contents.

Because the format is open, you can keep a full copy of your store anywhere you choose. Export is available at any time.

Your rights

You have the right to:

  • Access the account data Sevra holds about you
  • Correct inaccurate account information
  • Delete your account and associated data, including hosted store contents
  • Export your full store at any time, in the open db.md format

To exercise any of these rights, email privacy@sevrahq.com.

Data retention

Account data (name, email) is retained while your account is active and deleted upon request after cancellation.

Billing records are retained as required by law.

Store contents are deleted when you delete your store or your account, and deletion on request is always available.

Contact

For privacy questions: privacy@sevrahq.com