Skip to content
Verolith
Safe ChatYour corpusAligned ChatProvenanceSee itHow it worksPricingFAQ
Request a demo

Privacy Policy

Version 1.0.0 · Effective: Pending

Draft — pending final legal review. This document is provided for transparency and is not yet in force. The binding version will be published here and presented in-app once finalized.

[LEGAL ENTITY NAME] (“we,” “us”) operates Verolith (the “Service”). This Privacy Policy explains what information we process, why, and how we protect it. It is incorporated into our Terms of Service and End-User Terms.

This Service is provided to organizations (churches and ministries) as the “Subscriber.” For most data we process, the Subscriber is the controller and we are the processor acting on its instructions.

1. Information We Process

  • Account & identity data: name, email, organization, role, and authentication identifiers, received through your organization’s single sign-on (WorkOS) or issued credentials.
  • Usage & audit metadata: actions taken in the Service, timestamps, token-usage counts, and similar operational logs — used for security, access review, cost attribution, and billing true-up. This is metadata about actions, not the content of your prompts or responses.
  • Agreement-acceptance records: when you accept the Terms of Service or End-User Terms in the Service, we record who accepted, which document and version, when, and — as evidence of the acceptance — the IP address the request came from and your browser’s user-agent string. These records are append-only (see Section 5) and are kept within your organization’s isolated tenant.
  • Abuse-prevention signals: requests to the public provenance-verification endpoint — which anyone holding a bundle can use, with no account — are rate-limited per IP address. The address is used only as a short-lived counter key that expires within a minute; it is not written to any tenant’s records and is not used to identify the visitor.
  • Subscriber content you submit: prompts, uploaded documents, sermon media and transcripts, confessional/doctrinal materials, and corpus content.
  • Connected-source data: content from third-party accounts you connect, such as Google Drive files and YouTube captions (see Section 6).
  • Saved chat history (on by default): so you can reload past conversations, the Service saves each chat turn — your prompt and the model’s response — as submitted, or as tokenized text on turns where the Privacy Airlock is enabled, stored within your organization’s isolated tenant. On turns where the optional Privacy Airlock is enabled (see Section 3), the stored prompt is the scrubbed version (the personally-reconstituted version shown on your screen is not stored); on turns where the Airlock is off, the turn is stored as submitted. Saving is on by default. Any member can turn it off for their own account in Settings, and an organization owner can disable it or require it for the whole organization. Administrators see session metadata rather than the content, and saved chats are never used to train foundation models.
  • Provenance content (opt-in attestation): separately, when a user explicitly starts a provenance/attestation session, the content of that session as processed (scrubbed on Airlock-enabled turns) is recorded into a tamper-evident, exportable bundle so the user can later prove how they used AI. Outside a saved-chat session (above) or an opt-in attestation session, prompt/response content is not retained.

2. How We Use Information

We use information to: provide and secure the Service; route AI requests as you direct; generate retrieval, audit, translation, and provenance features; meter usage for cost attribution and billing; provide support; and comply with law. We do not use your content to train foundation models, and we do not sell personal information.

3. AI Processing & the Privacy Airlock

AI requests are routed to external Foundation Model Providers under data-processing agreements, using zero-data-retention (ZDR) endpoints where we have contracted for them, so that providers do not retain or train on your content. These contractual protections apply to every AI request and are the primary safeguard for your content.

The Privacy Airlock is an additional, optional scrubbing control — off by default — that a user (or an organization-wide policy) can enable per surface in Settings. When enabled for a surface, it is designed to detect and remove identifying information from prompts before routing — such as email addresses, phone numbers, government identifiers, and network addresses. Detection is automated and not a guarantee that every item of personal or sensitive content is removed; in particular, free-text details such as personal names or narrative descriptions may not be detected. When the Airlock is not enabled for a surface, prompts are routed as submitted, under the contractual protections above. Use judgment about what you submit.

Search indexing (embeddings). To make your corpus searchable, text is converted into numerical embeddings. This is done locally, on our own infrastructure, with no egress — the deployed default since 2026-07-20. A remote embedding backend exists as a dormant, fail-closed configuration lever; it is not engaged in the deployed Service, and engaging it would require an explicit, attested configuration change and a corresponding subprocessor disclosure below.

4. Subprocessors

We use the following categories of subprocessors to provide the Service.

Subprocessor Purpose Notes
Google Cloud Platform Application hosting + PostgreSQL database (Cloud SQL, tenant-isolated) + object storage + secrets + foundation-model inference (Claude and Gemini on Vertex AI; prompt/response text sent transiently) All environments; [region/notes]
WorkOS Identity / SSO / directory sync Account & identity data
Google (Drive / YouTube Data API) Optional content connectors See Section 6

There is no embedding subprocessor. Search indexing runs on our own infrastructure with no egress (Section 3), so no third party receives your corpus text for that purpose.

A current list is available on request and will be published with the finalized policy. We will give notice of material changes to subprocessors as required by the Terms of Service or any Data Processing Addendum.

5. Data Retention & Deletion

  • Subscriber content is retained for the subscription term and deleted after termination as described in the Terms of Service §7.3 (export window, then deletion of content and derived transcripts/chunks/embeddings, excluding expiring backups and legally-required retention).
  • Saved chat history (Section 1), where enabled, is retained within your tenant until the member deletes the conversation or turns chat history off, the organization disables it, or Subscriber Data is deleted on termination (§7.3 of the Terms of Service). It is stored scrubbed on Airlock-enabled turns and as submitted when the Airlock is off (Section 1).
  • Agreement-acceptance records (Section 1), including the IP address and user-agent captured at acceptance, are append-only: they are deliberately never modified, and nothing currently expires or prunes them.
  • Connected-source data is retained only while the connection is active and is deleted on disconnect, on token revocation, and on termination (see Section 6).
  • Audit metadata is retained for [PERIOD] for security and contractual purposes.
  • You may request deletion of personal data through your administrator or at [PRIVACY EMAIL], subject to the Subscriber’s instructions and our legal obligations.

6. Third-Party Connectors — Google & YouTube Disclosures

This section satisfies the disclosure obligations of the YouTube API Services Terms of Service and Google API Services User Data Policy, which apply because the Service can connect to a Subscriber’s own Google Drive and YouTube channel.

6.1 YouTube

The Service includes features that use YouTube API Services. By connecting your YouTube channel, you are also agreeing to be bound by the YouTube Terms of Service. Google’s handling of data is described in the Google Privacy Policy.

What we access. When an authorized owner connects their own YouTube channel, the Service uses the YouTube Data API (v3) with OAuth (youtube.force-ssl, own-channel only) to retrieve:

  • the list of the channel’s own uploaded videos and their metadata (title, publish time, video identifiers); and
  • official caption text for those videos.

What we do not do. We do not download, store, or redistribute video or audio media via the YouTube API; we access caption text only. We do not access videos or data of channels you do not own, and we do not use scraping.

Why. Captions are ingested into your private theological corpus so the Service can provide search, retrieval, citations, and (for entitled tiers) deep links back to the original video on YouTube.

How long we keep it & how it’s deleted. Caption data and anything derived from it (transcripts, chunks, embeddings) is treated as Authorized Data: stored only while your authorization remains active, re-confirmed on a cadence of no more than 30 days, and deleted when you disconnect the source, when your authorization/token is revoked, when the underlying video is removed on YouTube, or on termination of the Service or our API access.

How to revoke access. You can revoke the Service’s access to your Google/YouTube account at any time via the Google security settings page: https://myaccount.google.com/permissions. Revoking access triggers deletion of the associated stored caption data and derived data as described above.

6.2 Google Drive

If you connect Google Drive, the Service uses the Google Drive API (read-only, drive.readonly) to read files from the specific folder(s) you designate, in order to ingest their content into your corpus. We access only what you designate, store derived data as described in Section 5, and delete it on disconnect, revocation, or termination. Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. You may revoke access via https://myaccount.google.com/permissions.

7. Security

We use tenant isolation (schema-per-tenant), encrypted transport, fail-closed authorization, sealed per-tenant credentials, audit logging, and encryption at rest for stored corpus documents and media (the object store — Google Cloud Storage — encrypts every object at rest by default, verified). No system is perfectly secure; we cannot guarantee absolute security.

8. International Transfers

The Service and its subprocessors may process data in the United States and other locations. Where required, transfers are made under appropriate safeguards.

9. Children’s Privacy

The Service is a workplace tool intended for organizational staff and is not directed to children. Do not use it to submit children’s personal information except as your organization is lawfully permitted and instructs.

10. Your Rights

Depending on your jurisdiction, you may have rights to access, correct, delete, or port your personal data, or to object to or restrict processing. Because the Subscriber is usually the controller, please direct requests to your organization; we will assist the Subscriber in responding. You may also contact us at [PRIVACY EMAIL].

11. Changes to This Policy

We may update this Privacy Policy. We will post the updated version with a new effective date and, for material changes, provide notice through the Service and/or by email. The current version is always available from the “Legal” link in the Service and at https://verolith.co/privacy.


Privacy contact: [PRIVACY EMAIL] · [LEGAL ENTITY NAME], [ADDRESS]

Verolith

An AI-native operating system for the church.

Safe ChatYour corpusAligned ChatProvenanceSee itHow it worksPricingFAQContact

Verolith is in active development. Statements about zero-data-retention routing and SOC 2 describe our architecture and contractual design, not a completed certification; current status is disclosed on request.

© 2026 Verolith. All rights reserved.

Privacy PolicyTerms of ServiceAcceptable Use Policy