Privacy Policy - VeLens
Last updated: September 28, 2026
Applies to: VeLens Cloud, and VeLens for Marketing Cloud v1.3.0 and later, and any earlier version still in use.
VeLens adds productivity and AI-assisted features to Salesforce Marketing Cloud (SFMC). This policy describes what data VeLens accesses, how it is stored, who it is shared with, and your rights.
Who is responsible for your data. VeLens, Inc., a Delaware corporation, is the data controller for the account data described in section 5, and acts as a processor when VeLens reads data from your own SFMC account on your instruction. Legal bases and international transfers are in section 10, and contact details are in section 13.
VeLens for Marketing Cloud was previously published as MC Lens. This policy covers that installation too; the product was renamed, not replaced.
1. The two VeLens surfaces
- VeLens Cloud - the web app at
app.velens.cloud. The same web app also opens inside Marketing Cloud from SFMC's app menu; that is the same application in an iframe, not a separate product. - VeLens for Marketing Cloud - the Chrome extension that adds UI directly to the SFMC interface.
Both surfaces share the same backend, the same account, and the same data handling described below. "VeLens" on its own refers to the company and platform.
2. How VeLens reaches your SFMC data
2.1 The extension, using your existing browser session
Some extension features call SFMC's own in-application endpoints from the SFMC page you already have open, using the session you are already signed in with (a same-origin request that carries your existing SFMC cookies). The extension does not capture, read, store, or transmit your SFMC session token or any other SFMC credential, and no data from these calls is sent to VeLens servers. The responses stay in your browser.
Features that work this way include the Command Palette and in-page navigation, Data Extension listings and schemas, query and data-filter listings, the Query Studio overlay, the Dependency Mapper, and Journey and Automation listings (including the Automation Health Monitor).
2.2 A connected account, using OAuth
When you choose "Connect SFMC", you are taken through Salesforce Marketing Cloud's own OAuth sign-in for the VeLens Installed Package. VeLens never asks you for your SFMC username or password, and you do not enter any client secret. After you approve, SFMC issues VeLens tokens that are stored on VeLens's servers (see section 5). When the extension is connected, it also requests a short-lived access token from VeLens for the Business Unit you are viewing, keeps it in memory, and uses it to call SFMC's APIs directly from your browser. The refresh token stays on VeLens's servers.
A connection is required for anything that uses SFMC's SOAP API or the VeLens backend, including Subscriber Lookup and Cross-BU Subscriber Search, the Error Log, Send Performance, the Engagement Hub, the Admin Dashboard, and all AI features. Without a connection these features do not run; they show a "Connect SFMC" prompt instead.
When the web app is opened from Marketing Cloud's app menu, Marketing Cloud posts a signed single-sign-on request to the VeLens login endpoint. VeLens does not read or store the contents of that request; the browser is redirected into the same OAuth sign-in described above.
2.3 First-run consent
On first run the extension shows a privacy disclosure and will not process data until you accept it. Until consent is recorded, the extension processes no data; deleting your account is never blocked. If this policy changes materially, the stored consent is invalidated and you are asked again.
3. What data is processed
- SFMC metadata - names, keys, IDs, folder paths, schemas and statuses of Data Extensions, Journeys, Automations, Lists, Emails, Query Activities, Data Filters and Content Builder assets.
- Send and event data - send metrics, automation run status, bounce, not-sent, unsubscribe, complaint and forward events, and import results, for the Business Units you have access to in SFMC.
- Subscriber data - subscriber keys, email addresses, list memberships and event history, retrieved only when you run a subscriber lookup, and never sent to an AI model (see section 7).
- SQL and email content - the SQL you author in Query Studio, and email subject lines, preheaders and HTML when you use an AI email feature.
- Account information - your SFMC user ID, enterprise ID, Business Unit IDs, and (best effort, from SFMC) your SFMC name and email address.
VeLens does not read Data Extension row data on your behalf, and no Data Extension row data is sent to VeLens servers.
4. Data stored on your device
The extension stores the following on your machine, in chrome.storage and, for the search index and the dependency graph, in the extension's own IndexedDB database. None of it is transmitted to VeLens servers.
| Data | Retention |
|---|---|
| Cached SFMC metadata, kept separately for each Business Unit you open, including the search index and the dependency graph | Refreshed from SFMC once it is older than its refresh interval (from a few minutes up to 7 days, depending on the data type). Kept on your device until it is replaced, until older Business Units are removed to free space, or until you use "Clear All Cache" or remove the extension |
| Automation health snapshot | Until the next poll |
| Local bookmarks | Until you remove them |
| Toolbar and feature settings | Until you change them |
| Query Studio tabs and recent queries | Until you clear them |
| Privacy consent record (version and timestamp) | Until you uninstall or re-consent |
| Your VeLens sign-in session (when connected) | Until you disconnect or uninstall |
The web app stores your VeLens sign-in session, your selected Business Unit, and a few interface preferences (whether the sidebar and the conversation list are collapsed, which organization a launch from Marketing Cloud opened, and a question picked on the Home page until AI Chat opens it) in your browser's local and session storage. VeLens does not hold your SFMC refresh token in the browser in either surface.
5. Data stored on VeLens servers
Stored in Supabase. The database denies all direct client access, including over its API; only the VeLens server can reach it, and the server enforces the isolation between users and organizations. Every time limit below is enforced by a daily scheduled purge.
| Data | Retention | Notes |
|---|---|---|
| User identity | Until you delete your account | From your SFMC sign-in, plus your SFMC name and email where SFMC returns them |
| Organization and Business Unit records | Until you delete your account | Scopes features per Business Unit |
| Team invitations | Deleted 90 days after the invitation is accepted, revoked or expires, or when the organization is deleted | Created when an owner or admin invites a colleague: the email address they entered, the role assigned, who sent it, and, once accepted, the Marketing Cloud address that was used to accept. Only a one-way hash of the invite link is stored, never the link itself |
| Organization AI context | The current version until an owner or admin clears it, or until the organization is deleted; previous versions deleted after 90 days | A short document (up to 10,000 characters) that an owner or admin writes in VeLens Cloud to describe how the organization works, for example naming conventions and brand rules, with who last changed it and when. Every member of the organization can read it. It is sent to the AI model with every AI Chat message for that organization (section 7) |
| SFMC OAuth tokens | Until you disconnect or delete your account | AES-256-GCM encrypted at rest |
| Conversations and messages | Deleted after 90 days | Lets you resume past chats |
| Images attached to AI Chat messages | Image deleted after 30 days | Stored with the conversation so a follow-up question can refer back to the image; the conversation itself follows the 90-day rule above |
| Tool invocation records | Deleted after 30 days; undo snapshots after 7 days | What each AI tool call requested and returned, and, for a change you can undo, a snapshot of the object as it was before the change |
| Activity log (audit log) | Deleted after 30 days | Every tool execution; for support and security. Email addresses in audit entries are redacted |
| AI Chat work plans and approval records | Deleted after 365 days | Multi-step plans you approve in AI Chat: the plan's title, goal and steps, the tool arguments each step proposes, and for each confirmation who approved it and when. Members of your organization can view plans; only the person who created a plan can run or cancel it. Deleted with the account of the person who created the plan |
| AI usage telemetry | Deleted after 400 days (per-call token records after 365 days), or when you delete your account | Model, token counts, latency, status, and size/count summaries - not prompt or response text |
| AI conversation credits | Until you delete your account; the organization's allowance until the organization is deleted | How many AI Chat conversations each member has been granted and has used, and the organization's overall allowance. Counts only |
| Subject-line scores | Until you remove them, or until you delete your account | The subject line you scored, its score and suggestions |
| Cloud-synced saved queries and bookmarks | Until you remove them, or until you delete your account | Only items you explicitly save to the cloud |
| Cached SFMC metadata (server-side) | Per-record expiry | Deleted by the same daily purge once expired |
| Organization health snapshots | Deleted after 400 days, or when the organization is deleted | Daily aggregate counts only (contacts, sends, automation failures, journey counts) - no personal data |
| Terms of Service acceptance | Until you delete your account | Recorded when you connect Marketing Cloud after agreeing to the Terms: which version of the Terms you accepted, when, your IP address, and your browser's user-agent string. Kept so both sides can establish what was agreed and when, including after the Terms are revised. Not used for analytics, profiling or marketing |
| Email preferences and sign-up sync record | Until you delete your account; the history of preference changes for 365 days; each sync message 30 days after it is sent (90 days if it failed) | Your product-email choices (product updates, tips) and the record that syncs your sign-up to VeLens' own CRM (see "Emails from VeLens" below) |
| Server error reports | Deleted after 30 days | Diagnostic records written when a VeLens endpoint fails unexpectedly, for fixing the fault. Email addresses are masked |
| Rate-limit counters | Deleted after 1 day | Short-lived counters that limit how often sign-in and other endpoints can be called, keyed by IP address (or by organization). Only the count is stored. Used only to block abuse |
| Deletion receipt | Deleted after 3 years; the Marketing Cloud identity match is removed after 12 months | Created only when an account is deleted. Irreversible hashes of the account identifiers, a one-way match key for the Marketing Cloud user, date, record counts and prior AI credit usage - no personal data. See section 11 |
Backups. The table above is backed up twice a day so the service can be restored after a failure. Each backup is encrypted by the backup job before it is stored with Cloudflare (section 6), and deleted automatically after 30 days. The backups are encrypted with a key held only by VeLens - neither Cloudflare nor the automated job that writes them can read their contents. Backups are opened only to recover from a disaster or to test that recovery works; they are never searched or read in normal operation. See section 11 for what this means when you delete your account.
Emails from VeLens. When you first connect Marketing Cloud, VeLens records you as a contact in its own Salesforce CRM (your SFMC name and email address, your SFMC enterprise id, your VeLens role and which surface you signed up from) and sends you a welcome email from its own Marketing Cloud account. After that, VeLens may send occasional product updates and tips, and service messages about your account (for example, that your SFMC connection needs re-authorizing). Every marketing email carries a preference link that lets you turn product updates and tips off individually or unsubscribe from all marketing email in one click, without signing in; service messages are sent only when your account needs attention. These accounts belong to VeLens and are entirely separate from your Marketing Cloud tenant: nothing from your SFMC data, your conversations or your tokens is ever sent there. The CRM contact and the subscriber record are deleted when you delete your account (section 11).
6. Sub-processors
| Sub-processor | Purpose | Data shared | Location |
|---|---|---|---|
| Vercel, Inc. | Hosts the VeLens web app and API | All VeLens backend traffic | United States |
| Supabase, Inc. | Database and authentication | User identity, organization, encrypted SFMC tokens, conversation history and images attached to AI Chat messages, the organization AI context, AI Chat work plans and approval records, audit log, scoring history, saved queries and bookmarks | United States (AWS us-east-2, Ohio) |
| Cloudflare, Inc. | Stores the twice-daily encrypted backups (section 5) | The same data as Supabase, but encrypted before it is sent - Cloudflare stores an unreadable file and holds no key to it | Eastern North America |
| GitHub, Inc. (a Microsoft company) | Runs the scheduled backup job (section 5). The job reads the database and encrypts the backup before upload; the runner is ephemeral and the key that decrypts the backups is not stored on GitHub | The same data as Supabase, held on the job's temporary runner only while the backup is written, then discarded | United States |
| Salesforce, Inc. (VeLens' own Sales Cloud and Marketing Cloud accounts) | VeLens' own customer records and the emails VeLens sends you (section 5, "Emails from VeLens") | Your SFMC name and email address, SFMC enterprise id, VeLens role and sign-up surface, and your email preferences. No data from your Marketing Cloud tenant, your conversations or your tokens | United States |
| Vercel, Inc. (AI Gateway) | LLM routing | Conversation messages, system prompts and tool results - routed to the model providers below | United States |
| Model providers: OpenAI, Inc.; Anthropic, PBC; Google LLC (Google Cloud); Microsoft Corporation (Azure); Amazon Web Services, Inc. (Amazon Bedrock) | AI models for all AI features, including text and image generation (AI Chat, Query Studio AI, the Subject Scorer, the AI Email Editor and AI Data Extension descriptions). VeLens uses OpenAI, Anthropic and Google models, reached only through the Vercel AI Gateway. The sub-processor for a request is the company that runs it, which can be the model's developer or a cloud provider serving that model. Each request runs on one of these providers, bound to zero data retention, selected by the gateway | Your prompts and instructions, any images you attach to an AI Chat message, system prompts, conversation history and tool results (SFMC metadata only), email subject, preheader and HTML content, and Data Extension field names and types | United States; the gateway selects the provider per request |
The model providers receive data only through the Vercel AI Gateway; VeLens has no direct integration, and there is no alternative model route in the code. Every request is sent with the gateway's zero-data-retention option enabled, configured to fail closed: the gateway restricts routing to zero-data-retention-capable providers and returns an error rather than falling back to a provider that would retain the request. The gateway executes each request on a provider it holds a zero-data-retention agreement with; that is one of the providers listed above, selected by the gateway per request. VeLens does not choose or pin the executing provider; the retention guarantee, not the provider, is the control. Using the Service constitutes your general written authorisation for these sub-processors to process your data for the purposes above. We will update this table and give notice through the Service or by email at least 30 days before we add or replace one, as set out in the Data Processing Addendum.
7. Data sent to AI models
- Subject Scorer - the subject line, the preheader, and the email's HTML body as context.
- AI Email Editor - the email's HTML body and your natural-language instruction.
- AI Data Extension descriptions - the Data Extension name, its field names and types, and the names of objects that depend on it. No row data.
- AI Chat and Query Studio AI - your prompt, the system prompt, conversation history, and the results of any tools the model calls, and any image you attach to a message in AI Chat (downscaled in your browser before it is sent). Tool results contain SFMC metadata only, for example automation names, Data Extension schemas, send metrics and bounce category counts. An organization owner or admin can also save a short context document describing how their organization works, for example naming conventions and brand rules, and that text is sent with every AI Chat message for that organization.
- Query Studio Explain & Optimize - the SQL you submit for analysis.
Subscriber data and AI
The Service is designed so that subscriber contact details do not reach the model. The subscriber lookup tools that return email addresses and profile attributes, and the tool that changes a subscriber's status, are on a denylist applied to every AI surface before any tool list is built, and again when a write is confirmed. Any tool that returns subscriber-row data is stripped from every AI surface by a second, independent check.
One narrower capability is available only if an organization owner or admin switches it on (it is off by default): the AI can check a single subscriber's engagement history, meaning current journey membership and sent, clicked, bounced or unsubscribed events, looked up by a SubscriberKey or ContactKey that the user types in. The result contains email, journey, and list names, dates, statuses, and bounce categories only: no email addresses, no profile attributes, no Data Extension row values, and the identifier itself is masked in everything sent to the model.
Where a permitted tool can still surface an identifier - for example an email address quoted inside an SMTP bounce reason - VeLens masks it in its own backend, at the point the tool result is produced, before that result is sent to the model or written to storage. To be precise: this masking happens inside VeLens's backend after the data has been read from your SFMC account, not before the data leaves your SFMC account.
Content sent to the Vercel AI Gateway and its model providers is subject to their privacy policies (vercel.com/legal/privacy-notice and the privacy terms of each model provider listed in section 6).
8. Extension permissions
| Permission | Why |
|---|---|
storage | Cache SFMC data locally and store your preferences |
activeTab | Inject the toolbar and UI into the active SFMC tab |
notifications | Desktop alerts when automations enter an error state (opt-in) |
alarms | Background polling and service worker keepalive |
tabs | Detect SFMC navigation and route messages between tabs |
webNavigation | Detect when the SFMC OAuth sign-in redirect completes, to finish connecting your account |
Host access to *.exacttarget.com, *.marketingcloudapis.com | SOAP and REST API calls to your SFMC tenant |
Host access to *.marketingcloudapps.com | Detect Data Extension and email context inside Contact Builder and Content Builder iframes |
Host access to querystudio.herokuapp.com | Inject Query Studio enhancements into SFMC's hosted Query Studio iframe |
Host access to app.velens.cloud | API calls to the VeLens backend, including refreshing and ending your VeLens sign-in session, and reading and writing the bookmarks, saved queries and subject-line scores you choose to save to the cloud. These requests carry your VeLens session, never an SFMC credential, and no subscriber data. Versions 2.0.4 and earlier sent the sign-in and saved-item requests directly to VeLens' database host (ftppzkvbqsvlxyyjtqbn.supabase.co, not a host permission) |
9. Privacy protections
- No credential capture - VeLens does not capture, store or transmit SFMC session tokens. Server-side OAuth tokens are the only SFMC credential VeLens holds, and the browser never holds the refresh token.
- Consent gate - the extension processes no data until you accept the first-run disclosure.
- Email masking - subscriber email addresses are masked in the Error Log, in AI tool results, in the audit log, and in server error reports.
- Shadow DOM isolation - all injected UI is encapsulated in closed Shadow DOM, so the SFMC page cannot read it.
- No direct database access - the database denies all direct client access; isolation between users and organizations is enforced by the VeLens server.
- Encrypted secrets - SFMC tokens are encrypted at rest with AES-256-GCM using a key held outside the database.
- Enforced retention - a daily scheduled job deletes every record in section 5 that has a time limit once that limit passes, including aged conversations, images attached to AI Chat messages, tool invocations, audit entries, AI Chat work plans and approval records, AI usage telemetry, server error reports, and expired cache rows.
- No analytics or telemetry in the product - the extension, VeLens Cloud and the in-Marketing-Cloud view include no analytics SDKs, page-view tracking or behavioral telemetry. The public pages at velens.cloud (home, features, pricing, docs and similar) use Vercel Web Analytics, which counts page views in aggregate without cookies or cross-site identifiers; Vercel is already listed as a sub-processor in section 6.
Security incidents. If VeLens becomes aware of a personal data breach affecting your data, VeLens will notify affected customers without undue delay and no later than 72 hours after becoming aware of it, with what is known at that time and updates as the investigation proceeds. Where VeLens is the controller and the GDPR applies, VeLens will also notify the competent supervisory authority within 72 hours where required.
10. Legal bases for processing (EU, UK and Swiss users)
This section applies where the GDPR, the UK GDPR or the Swiss Federal Act on Data Protection (FADP) applies to your personal data. It sets out why VeLens processes each kind of data and the legal basis it relies on.
| Purpose | Data | Legal basis |
|---|---|---|
| Providing the Service | Your account, organization membership, SFMC connection and encrypted tokens | Performance of a contract, GDPR Art. 6(1)(b) |
| Your content in the Service | Conversations, saved queries, bookmarks, work plans, and what you submit to AI features | Performance of a contract, Art. 6(1)(b). Where your organization is the controller of this content, VeLens processes it on the organization's instruction under the Data Processing Addendum |
| Security, abuse prevention and reliability | Audit log, error records, rate-limit counters and backups | Legitimate interests, Art. 6(1)(f): keeping the Service secure and recoverable |
| Evidencing your acceptance of the Terms | The Terms acceptance record, including your IP address and browser user agent | Legitimate interests, Art. 6(1)(f): establishing what was agreed and when; and legal obligation, Art. 6(1)(c), where applicable |
| Welcome and service emails about your account | Your SFMC name and email address, enterprise id and VeLens role | Performance of a contract, Art. 6(1)(b) |
| Product updates and tips | Your name, email address and email preferences | Legitimate interests, Art. 6(1)(f), with an opt-out in every email and a preference page. Where the law that applies to you requires prior consent for these emails, let us know and we will not send them until you opt in |
| Marketing-site analytics | Aggregate page-view counts at velens.cloud, without cookies or cross-site identifiers (section 9) | Legitimate interests, Art. 6(1)(f): understanding which public pages are useful |
| Data VeLens reads from your Marketing Cloud account on your instruction | SFMC metadata, send and event data, and subscriber data when you run a lookup (section 3) | VeLens acts as a processor. Your organization is the controller and determines the legal basis. See the Data Processing Addendum |
International transfers. VeLens is established in the United States and its sub-processors store data there (section 6). For personal data protected by the GDPR, the UK GDPR or the Swiss FADP, transfers to VeLens rest on the European Commission's Standard Contractual Clauses (Decision (EU) 2021/914, Module Two, controller to processor) and the UK International Data Transfer Addendum, both incorporated in the Data Processing Addendum at velens.cloud/dpa. VeLens is not certified under the EU-US Data Privacy Framework. Onward transfers to sub-processors are covered by each sub-processor's own data processing terms and Standard Contractual Clauses.
Automated decisions. VeLens makes no decisions about you based solely on automated processing that produce legal or similarly significant effects. AI features produce suggestions and drafts; every change to your Marketing Cloud account requires a person to confirm it (section 7).
Children. The Service is for business users aged 18 or over and is not directed to children; VeLens does not knowingly collect data from anyone under 18.
11. Your rights
Wherever you are, you can ask VeLens about the personal data it holds about you. If the GDPR, the UK GDPR or the Swiss FADP applies to you, you have the following rights, and VeLens extends the same rights to anyone else who asks:
- Access - a copy of the personal data VeLens holds about you.
- Rectification - correction of personal data that is inaccurate or incomplete.
- Erasure - deletion of your personal data, which you can do yourself or ask us to do (see the deletion routes below).
- Restriction - limiting how VeLens uses your data while a concern is resolved.
- Portability - email info@velens.cloud and we will send a machine-readable export of the data VeLens holds about you, such as your conversations and saved queries.
- Objection - to processing based on legitimate interests (section 10), including product-update emails.
- Withdrawal of consent - where processing rests on your consent, at any time, without affecting processing before you withdrew.
- Complaint - you may lodge a complaint with your local supervisory authority: in the EU, the data protection authority of your member state; in the UK, the Information Commissioner's Office; in Switzerland, the Federal Data Protection and Information Commissioner (FDPIC).
Requests are free. VeLens answers within one month, which can be extended by two further months for complex requests, in which case we will tell you. We may need to verify your identity before acting on a request. Requests about data VeLens processes on your organization's behalf, meaning the data read from your Marketing Cloud account, should go to your organization, which is the controller for it; VeLens will assist your organization under the Data Processing Addendum.
You can also act on your data directly:
- Disconnect at any time - use "Disconnect" in the extension popup's Settings tab. Disconnecting revokes the server-side SFMC credentials and stops API access.
- Delete your account and data, in product - the extension popup offers "Delete my account & data". You are shown a count of exactly what will be removed and must type
DELETEto confirm. VeLens then revokes the SFMC session, deletes the stored SFMC tokens first, and deletes your account, which cascades your conversations, messages, tool invocations, AI Chat work plans you created, bookmarks, saved queries, subject scores, usage records, credits, memberships and your Terms acceptance records. If you were the only member of an organization, that organization and its data are deleted too. VeLens also deletes the contact record and email-subscriber entry it created about you in VeLens' own customer systems. The same deletion is available on the Account page in VeLens Cloud ("Delete my account and data"). The deletion cannot be undone. - Proof of erasure - VeLens keeps one deletion receipt containing irreversible hashes of the deleted account's identifiers, a one-way match key for the Marketing Cloud user, the date, record counts, and how many AI credits the account had used. The hashes cannot be reversed to identify you, the receipt contains no personal data, and it is never used to contact you or to rebuild anything that was deleted. It exists for two reasons: so an erasure can be evidenced, and so that free AI credits cannot be reset by deleting an account and reconnecting the same Marketing Cloud user. If the same Marketing Cloud user reconnects within 12 months, the earlier credit usage carries over to the new account. After 12 months the Marketing Cloud match key is removed, so the receipt is no longer matched to a reconnecting user. The receipt, with its other one-way hashes, is deleted after 3 years.
- Delete by email - if you do not use the extension, or cannot use the in-product flow, email support@velens.cloud with the subject "VeLens account deletion" and all server-side data tied to your user will be purged.
- Deletion and backups - deletion removes your data from the live service immediately. Copies inside backups taken before you deleted remain until those backups expire, which is at most 30 days (section 5), after which no copy of your data exists anywhere. Backups are never searched, queried or partially restored to look anything up; they are only ever opened in full to recover the service.
- Clear local cache - use "Clear All Cache" in the extension popup at any time.
- Remove the extension - uninstalling removes all browser-stored data. Server-side data is unaffected and requires one of the deletion routes above.
12. Changes to this policy
Material changes will be reflected in the "Last updated" date above, and will re-trigger the extension's first-run consent prompt.
13. Contact
For questions about this policy or about your data:
VeLens, Inc.
131 Continental Dr Ste 305, Newark, DE 19713-4324, United States
General and privacy enquiries: info@velens.cloud
Security reports and vulnerability disclosure: security@velens.cloud
VeLens, Inc. is the data controller. Data protection contact: info@velens.cloud.
VeLens has no establishment in the European Union or the United Kingdom and has not appointed a representative under Article 27 of the GDPR or the UK GDPR. Direct all data protection requests to the contact above.
VeLens is not affiliated with, endorsed by, or sponsored by Salesforce, Inc.