Privacy Policy
Last updated: July 10, 2026
Verlo, Inc. ("Verlo", "we", "us", or "our") provides an AI-assisted collaborative whiteboard platform. This Privacy Policy explains what personal data we collect, how we use it, who we share it with, how long we keep it, and the choices and rights you have. It applies to verlo.in, our web application, and any related services (together, the "Service").
In short
- We collect account, board, voice, payment, and usage data needed to run a real-time AI whiteboard — never more than that, and we never sell your data.
- You can export or permanently delete your data yourself: Account settings has a self-service "Delete account" flow, and you can request a full data export at hello@verlo.in.
- We share data only with the processors that run the Service on our behalf (Clerk, Google Cloud/Firebase, Razorpay, OpenAI, Sentry) and with people you invite to your boards — never with data brokers or advertisers.
- Board data and audit logs are kept only as long as your account is active, plus a bounded retention window for security logs; deleting your account deletes the rest.
- If GDPR, the DPDP Act, CCPA, or a similar law applies to you, Section 8 lists your specific rights and how to exercise them.
1. Definitions
- "Personal data" means any information relating to an identified or identifiable individual.
- "Board" means a Verlo canvas and its contents (shapes, text, widgets, files, comments).
- "Processor" or "sub-processor" means a third party that processes personal data on our behalf, under our instructions.
- "You" means the individual or organization using the Service; where you use the Service on behalf of a team, your team admin may also control certain settings and data described here.
2. Data we collect
We collect data in three ways: what you give us directly, what is created as you use the Service, and what our service providers generate on our behalf.
- Account data — name, email address, phone number (for OTP sign-in), and profile details you provide through our authentication provider, Clerk, including social sign-in profile information (Google, GitHub, or Microsoft) if you use it.
- Board content — the shapes, text, widgets, uploaded files, and other content you create or upload on a board, stored in Firestore and Firebase Storage.
- Voice and audio — if you use voice chat or Talkreels voice notes, we process short-lived audio streams for real-time transmission and, where you request a transcript, send the audio to our transcription provider to generate text.
- Collaboration metadata — presence, cursor position, comments, chat messages, hand-raise state, and canvas lock status, exchanged over our WebSocket connection while a board session is active.
- Payment data — plan selection, billing cycle, and transaction status. Card, UPI, and bank details are collected and processed directly by our payment processor, Razorpay; we do not store full payment card numbers on our servers.
- Device and usage data — device tokens for push notifications, browser/OS metadata, IP address, approximate location derived from IP, and product usage events (for example, boards created, features used, AI credits consumed).
- Audit and security logs — for every write action on your account (board changes, sharing, AI feature use, subscription and admin changes), we log who performed it, when, what action, which entity it affected, and the before/after values, together with context such as board ID, session ID, IP address, and user agent.
- Support and communications — messages you send to hello@verlo.in or through in-product support flows.
3. How we use your data
- To provide, operate, and maintain the Service, including real-time canvas sync, voice chat, and collaboration features.
- To authenticate you and secure your account.
- To process payments, manage subscriptions, and send billing-related communications.
- To power AI features you explicitly trigger, such as voice transcription and AI-assisted board generation, and to enforce your plan's AI credit quota.
- To send service notifications, such as a board being shared with you or a session starting.
- To monitor, debug, and improve the Service, including error and crash reporting.
- To detect, investigate, and prevent fraud, abuse, and security incidents.
- To comply with legal obligations and enforce our Terms and Conditions.
4. Legal basis for processing
Where the Digital Personal Data Protection Act, 2023 (India), the EU/UK GDPR, or an equivalent data protection law applies, we process your personal data on the basis of: your consent (for example, when you sign up or enable voice features); the performance of a contract with you (providing the Service you subscribed to); and our legitimate interests in securing, operating, and improving the Service, balanced against your rights. Where we rely on consent, you may withdraw it at any time without affecting the lawfulness of processing before withdrawal.
6. International data transfers
Our infrastructure providers operate data centers in multiple regions, including the United States. Where your data is transferred outside your country of residence, we rely on our providers' contractual and technical safeguards — including standard contractual clauses where applicable — to protect it consistently with this Policy and applicable law.
7. Data retention
We retain account and board data for as long as your account is active or as needed to provide the Service. Audit and security logs are retained for up to 24 months to support security investigations and compliance, after which they are deleted or anonymized on a rolling basis. Voice audio is processed transiently for real-time transmission and is not stored beyond what is needed to generate a transcript you requested.
You can permanently delete your account and all associated data at any time from Account settings. Deletion is immediate and irreversible: it cancels any active subscription, deletes every board you own, removes you from all team memberships, and deletes your account record and authentication identity. We may retain a minimal record of the deletion itself, and any data we are legally required to keep (for example, financial records), for the period required by law.
8. How we protect your data
We use encryption in transit (TLS) and at rest, role-based access controls, and audit logging for all write operations on user data. Access to production systems is restricted to authorized personnel. No method of transmission or storage is 100% secure, and we cannot guarantee absolute security. If we become aware of a security incident that compromises your personal data, we will notify affected users and, where legally required, the relevant supervisory authority, without undue delay.
9. Your rights and choices
Subject to applicable law, you have the following rights over your personal data. To exercise any of them, use the relevant in-product control where available, or contact us at hello@verlo.in — we will respond within the timeframe required by applicable law.
- Access — request a copy of the personal data we hold about you, including your profile, boards, comments, and recent audit log entries.
- Correction — update inaccurate account details directly in Account settings.
- Deletion — permanently delete your account and associated data at any time via the self-service "Delete account" flow in Account settings.
- Portability — request an export of your data in a structured, machine-readable (JSON) format.
- Restriction and objection — ask us to limit certain processing, or object to processing based on our legitimate interests.
- Withdraw consent — turn off optional features (such as voice transcription) at any time; this does not affect processing that already occurred.
- Lodge a complaint — if you believe we have not handled your data lawfully, you may lodge a complaint with your local data protection authority.
10. Additional notice for California residents
If you are a California resident, the CCPA gives you the right to know what personal data we collect, request its deletion, correct inaccuracies, and opt out of the "sale" or "sharing" of personal data. We do not sell or share personal data for cross-context behavioral advertising. You can exercise your CCPA rights using the same contact channel described in Section 9, and we will not discriminate against you for exercising them.
12. Children's privacy
The Service is not directed to children under 18. We do not knowingly collect personal data from children under 18. If you believe a child has provided us with personal data, contact us at hello@verlo.in and we will delete it.
13. Grievance officer
In accordance with applicable Indian data protection and information technology regulations, you may direct privacy questions, complaints, or grievances to our Privacy Team at hello@verlo.in. We aim to acknowledge grievances within 48 hours and resolve them within the timeframe required by applicable law.
14. Changes to this policy
We may update this Privacy Policy from time to time. If we make material changes, we will notify you by email or an in-product notice before the changes take effect. The "Last updated" date above reflects the most recent revision.
15. Contact us
For any questions about this Privacy Policy or our data practices, contact us at hello@verlo.in.