Privacy Policy
Draft — pending final legal review. This document is provided for transparency and is not yet in force. The binding version will be published here and presented in-app once finalized.
[LEGAL ENTITY NAME] (“we,” “us”) operates Verolith (the “Service”). This Privacy Policy explains what information we process, why, and how we protect and delete it. For most data, the subscribing organization is the controller and we act as its processor.
The canonical, full version of this policy is maintained with our other legal documents and finalized with legal counsel before it takes effect.
Information We Process
- Account & identity — name, email, organization, role, and authentication identifiers received via your organization’s single sign-on.
- Usage & audit metadata — actions, timestamps, and token-usage counts for security, access review, and billing — metadata about actions, not the content of prompts/responses.
- Content you submit — prompts, uploaded documents, sermon media/transcripts, and corpus content.
- Connected-source data — content from accounts you connect, such as Google Drive files and YouTube captions (see below).
How We Use It
To provide and secure the Service, route AI requests as you direct, generate retrieval/audit features, and meter usage for billing. We do not use your content to train foundation models, and we do not sell personal information.
The Privacy Airlock
The Service is designed to scrub personal and sensitive pastoral content from prompts before routing requests to external AI providers, and to use zero-data-retention endpoints where contracted. This strongly reduces — but does not guarantee elimination of — exposure of sensitive content. We never store your raw, un-scrubbed input, and your content is never used to train AI models.
Saved Chat History
So you can revisit past conversations, the Service saves each chat — your Airlock-scrubbed prompt and the AI response, stored as scrubbed text within your organization’s private tenant (the on-screen, personally-restored version is not stored). This is on by default. Any member can turn it off in Settings, and an organization owner can disable it or require it for everyone. Administrators see session metadata rather than content.
Google & YouTube Data
The Service uses YouTube API Services. By connecting your YouTube channel you also agree to the YouTube Terms of Service. Google’s handling of data is described in the Google Privacy Policy.
What we access. When an authorized owner connects their own YouTube channel, we use
the YouTube Data API (v3) with OAuth (youtube.force-ssl, own-channel only) to read the
channel’s own video list/metadata and official caption text. We do not download,
store, or redistribute video or audio via the API — caption text only — and we do not access
channels you do not own or use scraping. If you connect Google Drive, we use the Drive API
(read-only) to read files from the folder(s) you designate. Our use of information received
from Google APIs adheres to the
Google API Services User Data Policy,
including its Limited Use requirements.
Why. To ingest your own content into your private corpus for search, retrieval, citation, and deep-linking back to the original source.
Retention & deletion. Connected-source data and everything derived from it (transcripts, chunks, embeddings) is Authorized Data: kept only while your authorization is active, re-confirmed regularly, and deleted when you disconnect the source, when your authorization is revoked, when the underlying item is removed at the source, or on termination.
Revoking access. Revoke our access to your Google/YouTube account anytime via the Google security settings page: https://myaccount.google.com/permissions. Revoking access triggers deletion of the associated stored data as described above.
Subprocessors
We use service providers for hosting, database, identity, AI model access, and the optional Google connectors. A current list is available on request and will be published with the finalized policy.
Data Retention & Your Rights
Content is retained for your subscription term and deleted afterward (excluding expiring backups and legally required retention). Depending on your jurisdiction you may have rights to access, correct, delete, or port your data; because your organization is usually the controller, direct requests to it, or contact us at [PRIVACY EMAIL].
Changes
We may update this policy and will post the updated version with a new effective date and, for material changes, provide notice.
Privacy contact: [PRIVACY EMAIL] · [LEGAL ENTITY NAME]