Privacy Policy
Last updated: July 31, 2026
This document is under review by counsel; material changes will be noted here with a new date.
1. Who we are and what this covers
Velaris is operated by GenZ Technologies (Pvt) Ltd ("Velaris", "we", "us"). This policy explains what personal data we collect across this website, the waitlist, the community and the Velaris application (together, the "Service"), why we collect it, who processes it for us, and the rights and choices you have. Contact for anything in this policy: hello@velabios.com.
The short version: we collect what the Service needs to work, we don't run advertising trackers, we don't sell your data, and we don't use your private content to train AI models.
2. Information we collect
You give us
- Account and waitlist: your email address, an optional "how did you hear about us" answer, a referral code if you arrived through one, your marketing choice, and the version of the Terms and this policy you accepted (with a timestamp).
- Community content: your handle, profile, posts, comments and votes. Posts, comments and profiles are public — visible to anyone and indexable by search engines.
- Connected services: when you connect a third-party service (for example Gmail or Google Calendar), we access its data only within the permission scopes you grant, to carry out the tasks you ask for. Connection credentials are stored in an encrypted vault. See also Google user data.
- Content you bring to the app: prompts, files and other content you submit so agents can work on it.
- Support: messages you send us, and our replies.
Collected automatically
- Security and anti-abuse data: when you request a sign-in code we record your IP address and browser user-agent, and we use Cloudflare Turnstile to tell humans from bots. We use this to prevent abuse, not to profile you.
- Email delivery records: a log of the transactional emails we send you and their delivery status (delivered, bounced, complained), so sign-in codes and notifications can be debugged and bounce handling works.
- Essential cookies: session cookies that keep you signed in, described in the Cookie Policy. We currently run no analytics or advertising trackers on this website.
3. How we use information
- to provide the Service: accounts, sign-in, the community, agents and connectors;
- to secure it: verifying sign-ins, preventing spam, fraud and abuse, and debugging faults;
- to communicate: transactional email (sign-in codes, waitlist confirmations, referral updates) always; product news and launch updates only if you opted in, and every such email contains an unsubscribe link;
- to run the waitlist and referral program: positions, codes and early-bird benefits;
- to improve the Service, using aggregated or de-identified information where we can;
- to comply with legal obligations and enforce our Terms.
4. Lawful bases
Where GDPR or similar laws apply, we rely on:
- Contract — providing the Service you signed up for (account, waitlist, community, agents);
- Consent — marketing email and any future non-essential cookies; you can withdraw consent at any time;
- Legitimate interests — security, anti-abuse and service improvement, balanced against your rights;
- Legal obligation — where we must keep or disclose data by law.
5. AI processing
When you use AI features, the relevant content — your prompts, connected-service data within the scopes you granted, and context the agent needs — is sent to large-language-model providers (such as Anthropic, OpenAI or Google) to generate the response. These providers process it as service providers under agreements that do not permit them to use your content to train their models, and we don't use it to train models either. Your stored connector credentials are never shared with model providers.
We record metadata about AI runs — timing, token counts, errors and traces — to operate, debug and bill the Service.
6. Google user data
Velaris's use and transfer to any other app of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. In practice that means Google user data (such as Gmail or Calendar content) is used only to provide the features you ask for, is never sold, is not used for advertising, and is not used to train generalized AI models. Human access is limited to cases where you ask us for support, security requires it, or the law does. You can revoke Velaris's access at any time at myaccount.google.com/permissions.
8. International transfers
Our primary data store is in the EU (Supabase, eu-west region). Some providers above process data in other countries, including the United States. Where data moves across borders from the EU/UK, it is protected by recognized safeguards — standard contractual clauses or an adequacy mechanism such as the EU–US Data Privacy Framework, depending on the provider.
9. How long we keep data
- Account and waitlist data: for as long as your account exists.
- Sign-in codes: minutes — codes are single-use and expire shortly after being issued.
- Security and email-delivery logs: for as long as needed for anti-abuse and delivery diagnostics, then deleted or anonymized.
- Unsubscribe list: kept indefinitely — deleting it would risk emailing people who opted out.
- On account deletion: we delete or anonymize your personal data, except what we must keep for legal, security or accounting reasons. Public community posts are removed or disassociated from your identity, at your choice.
10. Security
Data is encrypted in transit (TLS) and at rest. Database access is governed by row-level tenant isolation; internal access follows least privilege. Connector credentials live in an encrypted vault and are never exposed to AI models, and agents must ask for your explicit approval before irreversible actions like sending or deleting. No system is perfectly secure — if we learn of a breach affecting your data, we will notify you and the relevant authorities as the law requires. We are candid about maturity: we do not currently hold certifications such as SOC 2 or ISO 27001.
11. Your rights and choices
Depending on where you live (including under GDPR and the CCPA), you can ask us to access, correct, delete, restrict or export your personal data, object to processing based on legitimate interests, and withdraw consent at any time without affecting prior processing. We do not sell or "share" personal data as the CCPA defines those terms, and we don't discriminate against you for exercising your rights.
- Marketing: every marketing email has an unsubscribe link, or use the unsubscribe page; transactional email (sign-in codes) continues while you have an account.
- Connectors: revoke any connection in Velaris or in the third-party service's security settings.
- Access or deletion: email hello@velabios.com from your account address; we verify the request and respond within the time the law sets (one month under GDPR).
- Complaints: you can also complain to the data-protection authority where you live; we'd appreciate the chance to resolve it with you first.
12. Children
The Service is not directed at children under 13 and we do not knowingly collect their data; users under 18 need a parent or guardian's permission (see the Terms). Where local law sets a higher age for consenting to data processing, that age applies. If you believe a child has provided us personal data, contact us and we will delete it.
13. Changes to this policy
We will update this policy as the Service evolves — for example when billing goes live. For material changes we give notice by email or in-product before they take effect. The "Last updated" date above always reflects the current version.
14. Contact
GenZ Technologies (Pvt) Ltd — hello@velabios.com for privacy questions, data requests and everything else in this policy.