Legal
Privacy Policy
This policy explains what data Verso Studio ("Verso", "we", "us") collects when you use the Verso AI content studio, why we collect it, who we share it with, and the choices you have. We keep it deliberately plain: we collect what the product needs to work, we don't sell your data, and we don't train AI models on your content.
1.Who we are & scope
Verso Studio is the controller of the personal data described in this policy. The policy covers our websites and the Verso application, including all verticals (Content, Booking, Legal). It does not cover third-party sites we link to, or content you publish elsewhere using drafts made in Verso.
2.Data we collect
We collect three broad categories of data:
| Category | Examples | Source |
|---|---|---|
| Account data | Name, email address, password (stored only as a salted hash), plan, workspace membership, billing country. | You, at registration and in settings. |
| Content data | Briefs and prompts you submit, chat messages, generated drafts, template and vertical selections, saved history. | You, while using the studio. |
| Usage & technical data | Credit balance and consumption, feature usage events, approximate location derived from IP, device and browser type, error logs. | Collected automatically. |
Payment card details are collected and stored by our payment processor, not by us; we receive only a payment token, the card brand, and the last four digits for your invoices.
3.How we use it
- To provide the service — generating your drafts, keeping your history, metering credits, operating workspaces (performance of contract).
- To bill you — processing subscriptions, invoices, and taxes (performance of contract; legal obligation).
- To keep the service safe — preventing abuse, enforcing rate limits, investigating incidents (legitimate interest).
- To improve the product — analyzing aggregated, de-identified usage patterns such as which templates are used most (legitimate interest). This never involves reading your briefs or drafts for product research without your explicit consent.
- To communicate — service emails such as receipts, credit warnings, and security notices (contract), and optional product news you can opt out of at any time (consent).
- To comply with law — tax, accounting, and responding to valid legal requests (legal obligation).
We do not sell your personal data, and we do not use your content for advertising.
4.AI processing
Verso's drafting is powered by third-party large-language-model providers. When you generate a draft or send a chat message, the relevant brief, thread context, template, and vertical are transmitted to an AI provider to produce the output, together with a pseudonymous request identifier — never your name or email.
Output is generated by statistical models and may be inaccurate; Section 7 of our Terms of Service explains your review responsibilities. If we ever introduce optional features that would use your content to improve models, they will be strictly opt-in and off by default.
7.Retention
- Account data — kept while your account is active, deleted within 30 days of account deletion.
- Content data — drafts and chat history follow your plan's history settings; on account deletion, all content is deleted within 30 days of the export window closing.
- Billing records — retained for the period required by tax and accounting law (typically 7 years), then deleted.
- Logs — technical and security logs are retained for up to 90 days, then deleted or fully anonymized.
Residual copies may persist in encrypted backups for up to 35 additional days before rotating out.
8.Security
All traffic is encrypted in transit (TLS) and stored data is encrypted at rest. Passwords are stored only as salted hashes. Access to production data is restricted to a small number of engineers, on a need-to-access basis, with audit logging. We test our defenses regularly and patch promptly.
No system is perfectly secure. If a breach affects your personal data, we will notify you and the relevant authorities without undue delay, as required by law, and tell you plainly what happened and what we are doing about it.
9.International transfers
Our processors may store or process data outside your country, including in the United States and the European Union. Where data protection law requires it, transfers are protected by recognized safeguards such as Standard Contractual Clauses or an applicable adequacy decision.
10.Your rights
Depending on where you live (including under the GDPR, UK GDPR, and CCPA/CPRA), you may have the right to:
- Access a copy of the personal data we hold about you;
- Export your content — draft and history export is built into account settings;
- Correct inaccurate data;
- Delete your data — account deletion is self-serve in settings;
- Restrict or object to certain processing, including direct marketing (every marketing email has an unsubscribe link);
- Not be discriminated against for exercising these rights, and
- Complain to your local data-protection authority.
To exercise a right that isn't self-serve, email privacy@verso.studio from your account address. We respond within 30 days (or sooner where the law requires). We do not "sell" or "share" personal information as defined by the CCPA/CPRA.
11.Children
Verso is not directed at children and may not be used by anyone under 16 (or the higher age of digital consent in your jurisdiction). We do not knowingly collect data from children; if you believe a child has created an account, contact us and we will delete it.
12.Changes
We will update this policy as the product and the law evolve. Material changes will be announced by email or an in-product banner at least 30 days before they take effect, alongside the updated effective date above. Earlier versions are available on request.
13.Contact
Privacy questions and requests: privacy@verso.studio. General support: support@verso.studio. Postal contact details for formal notices are provided on your invoice and on request.