Privacy Policy
Last updated: February 1, 2026
1. Introduction
Velosyti Inc. ("Velosyti," "we," "us," or "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our platform at velosyti.com and related services (the "Service").
By using the Service, you agree to the collection and use of information in accordance with this policy. If you do not agree with the terms, please do not use the Service.
2. Information We Collect
2.1 Account Information
When you create an account, we collect your name, email address, and password hash. If you sign up via OAuth (Google, GitHub), we receive your name, email, and profile picture from the provider. We do not receive or store your OAuth provider password.
2.2 Project Data
We store the code, files, database schemas, and configuration you create through the Service. This data is necessary to provide code generation, live preview, and deployment features. Your project data is stored in encrypted databases and is accessible only to you and your authorized team members.
2.3 Chat & AI Interactions
We store your chat messages and AI responses to provide continuity in your development sessions. Chat history may be used to improve AI generation quality in aggregate, but we never train AI models on individual user data without explicit opt-in consent.
2.4 Usage Data
We automatically collect information about how you interact with the Service, including pages visited, features used, generation credits consumed, deployment frequency, and error logs. This data is used to improve the Service and diagnose issues.
2.5 Payment Information
Payment processing is handled by Stripe. We do not store your full credit card number, CVC, or billing address. We receive and store only the last four digits of your card, card brand, and expiration date for display purposes.
3. How We Use Your Information
- To provide, operate, and maintain the Service
- To generate, preview, and deploy your applications
- To process payments and manage subscriptions
- To send account-related notifications (password resets, billing alerts, service updates)
- To improve AI generation quality and Service reliability
- To detect and prevent fraud, abuse, and security incidents
- To comply with legal obligations
4. Data Sharing & Disclosure
We do not sell your personal data. We share data only in the following circumstances:
- Service Providers: Stripe (payments), AWS (infrastructure), Anthropic (AI generation). These providers process data on our behalf under strict contractual obligations.
- Team Members: If you use team features, your project data is shared with members of your organization according to their role permissions.
- Legal Requirements: We may disclose data when required by law, court order, or to protect the rights, property, or safety of Velosyti and its users.
- Business Transfers: In the event of a merger, acquisition, or sale of assets, user data may be transferred as part of the transaction.
5. Data Security
We implement industry-standard security measures to protect your data:
- All data is encrypted in transit (TLS 1.3) and at rest (AES-256)
- Passwords are hashed using bcrypt with a work factor of 12
- Database access is restricted to the application layer via VPC isolation
- Secrets are managed via AWS Secrets Manager, never stored in code
- Regular security audits and automated vulnerability scanning
6. Your Rights
Depending on your jurisdiction, you may have the following rights regarding your personal data:
- Access: Request a copy of the personal data we hold about you.
- Correction: Request correction of inaccurate data.
- Deletion: Request deletion of your account and associated data.
- Portability: Export your project data in standard formats.
- Opt-out: Unsubscribe from marketing communications at any time.
To exercise any of these rights, contact us at privacy@velosyti.com.
7. Cookies
We use essential cookies for authentication and session management. We use analytics cookies (opt-in only) to understand usage patterns. We do not use third-party advertising cookies. You can manage cookie preferences in your browser settings.
8. Data Retention
We retain your account data for as long as your account is active. If you delete your account, we remove your personal data and project files within 30 days. Anonymized, aggregated data may be retained indefinitely for analytics purposes. Backups containing your data are purged within 90 days of account deletion.
9. Children's Privacy
The Service is not intended for children under 13 years of age. We do not knowingly collect personal data from children under 13. If you believe a child has provided us with personal data, contact us at privacy@velosyti.com and we will delete it promptly.
10. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by email or by posting a notice on the Service. Continued use of the Service after changes take effect constitutes acceptance of the updated policy.
11. Contact Us
If you have questions about this Privacy Policy or wish to exercise your data rights, contact us at:
Velosyti Inc.
Email: privacy@velosyti.com