Legal
Privacy Policy
This policy explains the information handled by the Velora website, account service, billing system, support flow, and desktop product. It also explains how connected AI providers affect where your content is processed.
Effective September 29, 2026
Who is responsible for your information
Velora is the service responsible for the personal information described in this policy. The operator, postal address and contact email are listed at the bottom of this page; privacy requests may be sent there or through the support page. We may need to verify that a request comes from the account holder before acting on it.
Information we collect
Account information. When you create an account, Supabase Auth processes your email address, password credentials in protected form, account identifiers, confirmation status, and session information. Velora does not receive your password in readable form.
Billing information. Stripe processes payment-card details. Velora receives customer and subscription identifiers, plan status, billing dates, and transaction status needed to provide paid access. Velora does not store your full payment-card number.
Contact requests. The contact form stores your name, email, category, message, reference number, and delivery status. Proposal requests also include your organization and team size. We retain a hashed network identifier to limit abuse. Notifications are sent through Resend and forwarded through ImprovMX to the business inbox. These details are used to respond to your request.
Legacy feedback. We receive the category, message, optional email address you submit, and the browser and operating system your request came from — the last so a reported bug can be reproduced. If you choose to send screenshots, recordings, logs, or diagnostic details, those materials may contain information about your device, workspace, prompts, file paths, models, and errors. Review attachments and remove secrets or unrelated personal information before sending them.
Technical information. Our hosting and security providers may process IP address, device and browser type, request time, requested route, referral information, and service logs needed to deliver, secure, and diagnose the service.
Desktop workflows and connected services
The desktop app processes the instructions, files, workspace context, and tool results that you choose to place in a workflow. Where that content is processed depends on your configuration. Content routed to a cloud model or connected tool is transmitted to that provider and is governed by its terms, privacy policy, account settings, and retention controls. Eligible work routed to a local runtime such as Ollama may remain on your device, subject to the runtime and model you select.
Desktop sign-in happens in the Velora website. The website returns a short-lived, one-use encrypted sign-in proof to a local callback on the same device. The desktop app exchanges that proof with Supabase Auth; your password is not passed to the app. The app keeps its access token in memory and stores its refresh credential in the operating system’s secure credential vault.
Do not place sensitive personal information, credentials, confidential customer material, or regulated data into a workflow unless you have authority to do so and have confirmed that every selected provider is appropriate for that information.
Private Business and mail
If you connect IMAP/SMTP, the desktop communicates directly with your configured mail provider. Your credential stays in the operating system vault. Mail references and action receipts retain selected message/draft identifiers, timestamps, reviewed fields, and submission outcomes. Selected mail content can be sent to the AI provider you choose and retained in its conversation or saved document; review that provider’s privacy controls.
Business profile facts and follow-up Records stay local and are not automatically published to an organization or room. Deliberately sharing a reviewed summary creates a separate audience-controlled copy. Optional encrypted history sync remains governed by the choices described below.
External sends require the exact approval preview. An uncertain submission is retained for reconciliation and is not automatically retried. Disconnect removes local credentials and blocks future mailbox retrieval and queued mail actions; it does not delete mail already stored by your provider or erase prior local documents and receipts. Google provider revocation failures are shown explicitly. Mail clients load on demand; only explicitly enabled IMAP triggers poll, and disabling or disconnecting stops that polling.
Google Workspace connections
Google Workspace remains a restricted pilot for named testers. Approved pilot accounts can select the Drive, Docs, Sheets, and Calendar surfaces offered in Settings → Connections. Connecting Google is optional; review the exact account and scopes on Google’s consent screen. Drive uses per-file access to files created by or opened with Velora.
When an approved workflow needs Google data, Velora retrieves the selected file, document or spreadsheet content, or calendar information needed for that request. It uses that information to answer your prompt or perform the requested operation. Retrieved content can be processed by the AI provider you select and can appear in your conversation or saved artifacts. Review the provider’s privacy and retention controls before using confidential information. Velora does not build a background index of your Google account or use Google Workspace data to train its own general-purpose AI models. Gmail browser consent remains restricted to approved pilot testers pending Google review and live acceptance. It requests identity, read-only mail access, and draft/send access for implemented operations; it does not request mailbox modification permission.
Persistent Google refresh credentials are stored in the desktop’s OS-backed credential vault. Velora’s authenticated token broker processes authorization codes and refresh tokens transiently to exchange them with Google; it does not intentionally store them in a server database or application logs. Local connection records retain the account identity, granted permissions, connection health, and an opaque credential reference. Task and audit records can retain resource identifiers, revisions, timestamps, and requested actions.
Your Google credentials are not shared with other team members. Publishing selected content creates a separate room snapshot under the room’s access controls; it does not grant room members access to your Google account. Disconnect a connection to stop using it in Velora, and use Revoke to remove the stored grant. You can also remove Velora’s access directly from your Google Account connections. Revocation does not automatically delete published room snapshots or previously saved conversations and artifacts; use the room’s Forget control or remove those items separately.
How and why we use information
We use information to create and secure accounts, maintain sessions, provide and synchronize Pro access, process billing events, operate desktop and website features, answer support requests, investigate abuse, prevent fraud, diagnose failures, comply with law, and improve product reliability. Where applicable law requires a legal basis, these activities are performed to provide the service you request, pursue legitimate interests in security and improvement, comply with legal obligations, or act with your consent.
Velora does not sell personal information. Velora does not use personal information for cross-context behavioral advertising.
When information is shared
We share information with vendors only as needed to operate the service. Current core vendors include Vercel for hosting, Supabase for authentication, shared rooms, selected source snapshots, Records, and account data, and Stripe for billing. We may also disclose information when required by law, to protect users or the service, in connection with a business reorganization, or with your direction. Model providers, local runtimes, and coding tools you connect may act independently under their own policies.
Cookies, local storage, and session data
The website sets one cookie, and only after you sign in: it keeps you signed in. There is no analytics, advertising, session recording, or third-party script on this site, and no cookie is set at all while you are signed out. The Cookie Policy names that cookie, its purpose and its lifetime, and lists what we deliberately do not use. If a nonessential technology is added later, this policy and the Cookie Policy will be updated and consent requested before it is enabled.
Syncing between your devices
Velora can synchronise your task history, the instructions you write, and the results agents produce between devices signed in to the same account. This is off unless you turn it on, and you are asked before anything is uploaded for the first time.
When it is on, that content is encrypted on your device with a key derived from a passphrase you choose. What our servers hold is ciphertext plus the minimum routing information needed to deliver it to your other devices — a record identifier, a device identifier, a sequence number, and a timestamp. We do not hold your passphrase and cannot read the content. The consequence is deliberate and worth stating plainly: if you lose the passphrase, we cannot recover your synchronised history, because we never had the means to. Workspace file contents, provider API keys, and your credentials are never synchronised.
Retention and deletion
We keep account information while an account is active and for a reasonable period afterward for security, dispute, and legal purposes. Billing records are retained as required for accounting, fraud prevention, and legal compliance. Support messages and operational logs are retained only as long as reasonably needed for the purpose collected. Backup copies may remain for a limited period before deletion cycles complete.
Security and international processing
We use access controls, encrypted network connections, restricted server credentials, and service-provider safeguards appropriate to the information handled. No system can guarantee complete security. Vendors may process information in countries other than the one where you live. Where required, we use legally recognized transfer mechanisms or vendor terms intended to protect that information.
Your privacy choices and rights
If you are in the United States. Residents of California and of other states with comprehensive privacy laws — including Colorado, Connecticut, Virginia, Utah, Texas, Oregon and Montana — may request access to the personal information we hold, a portable copy of it, correction of inaccuracies, and its deletion. You may also appeal a decision we make on such a request. We do not use sensitive personal information for any purpose requiring a right to limit it.
We do not sell or share your personal information. Velora does not sell personal information, does not share it for cross-context behavioural advertising, and has no advertising or analytics technology on this site to do so with. There is therefore nothing to opt out of, and no “Do Not Sell or Share” mechanism is offered because none would do anything.
If you are elsewhere. Depending on where you live, you may have rights to access, correct, delete, restrict, or receive a copy of personal information, object to certain processing, withdraw consent, or appeal a denied request — including under the UK GDPR and the EU GDPR. You may also have the right to complain to a data protection authority.
Submit a request to the contact address at the bottom of this page, or through the support page, using the email connected to your account. We do not charge for a request and do not treat anyone differently for making one. You may sign out at any time and can avoid providing optional support contact details.
Children
Velora is not directed to children under 13, and we do not knowingly collect personal information from them. Users who are not old enough to consent to data processing in their location should not create an account without authorization from a parent or legal guardian.
Changes and contact
We may update this policy as the product, vendors, or legal requirements change. Material changes will be identified through the effective date and, when required, through an additional notice. Privacy questions and requests can be sent to the contact address below or through the support page.
Who to contact
- Service
- Velora
- Operated by
- Utsav Das, trading as Velora. Velora is an independent sole proprietorship, not an incorporated company.
- Contact
- support@runvelora.app
- Postal address
- 4601 Marshall Hall Lane, Fairfax, VA 22033
- Governing law
- Virginia, United States
Privacy requests, legal notices, and billing questions can be sent to the address above. Support questions are usually answered faster through the support page.