VERSOCloud

Privacy Policy

Effective 30 August 2026

VERSO Cloud is a private workspace for running a business. It reasons only over the information you put in or connect. This policy explains exactly what we hold, why, and what you control — in plain language, and limited to what the product actually does today.

1Who we are

VERSO Cloud (“VERSO”, “we”) is operated by VERSO and served at app.versolab.ai. For any privacy question, correction or deletion request, contact contact@versolab.ai. A person reads that address.

2What we collect

Account information

The work email address and password you register, and the company or workspace name you choose. Passwords are stored only as a scrypt hash — never in a readable form. We also store a session record so you stay signed in.

What you put into your workspace

Everything you enter: business facts, attention flags, goals, projects, clients, team and budget entries, ventures and workspace settings. This is your content. VERSO stores it so it can show it back to you and answer questions from it.

Data from Google, if you connect it

Nothing from Google reaches VERSO unless you explicitly connect an account. Section 3 describes this in full.

Operational records

Ordinary server logs and request records needed to run and secure the service, and a usage record of AI requests made by your workspace so allowances can be enforced. We do not run advertising or third-party analytics trackers in the product.

3Google user data

Connecting Google is optional and per-service. You can connect Gmail without Calendar, or Calendar without Gmail; each is a separate consent. VERSO requests read-only access only and never requests permission to send, modify or delete anything in your Google account.

gmail.readonly
Message metadata and snippets
To build Your Desk — who is waiting on you, what they asked, and who owes the next move — and to ground search and your daily brief.
calendar.readonly
Event times, titles and attendees
To show your day and to reconcile what was already handled in a meeting against what you still owe someone.
openid · email
The email address of the Google account you connected
Only to show you which account is connected and to attach the connection to the right service.

What we store from Gmail — and what we do not

VERSO stores an index of message metadata and short snippets: sender, recipients, subject, date, thread and the preview line Gmail itself provides. This index covers roughly the last six months and is capped in size. VERSO does not store the full text of your emails and does not copy your mailbox. Gmail remains the source of truth; the index exists so VERSO can reason about who is waiting on you without re-reading your mailbox on every request. Attachments are not downloaded or stored.

How the connection is secured

Google access and refresh tokens are encrypted at rest with AES-256-GCM under a dedicated key, kept apart from your workspace content. Tokens are never displayed anywhere in the product, never returned by any API the browser can call, and never written to logs.

Disconnecting

You can disconnect any connected Google account at any time from the Integration Hub. Disconnecting revokes the grant with Google, deletes the stored tokens, and stops all further access. To be clear about what it does not do: information VERSO had already derived and stored before you disconnected — for example an attention flag you kept, or the message index built while connected — remains in your workspace until it is deleted. To have that removed as well, ask us at contact@versolab.ai.

4Google API Services User Data Policy

VERSO’s use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

  • We use Google user data only to provide and improve the user-facing features described in this policy.
  • We do not transfer Google user data to others except as necessary to provide those features, to comply with applicable law, or as part of a merger or acquisition — and never to a party that is not bound by equivalent restrictions.
  • We do not use Google user data for advertising of any kind.
  • We do not allow humans to read Google user data, except with your explicit consent, where necessary for security purposes such as investigating abuse, to comply with applicable law, or where the data has been aggregated and anonymised.

5AI processing

Some VERSO features generate written answers using a large language model provided by Anthropic. When you ask VERSO a question, relevant content from your own workspace — which may include business facts you entered and email metadata or snippets, where those are what the question is about — is included in the request so the model can answer from your data and cite it.

VERSO does not train any model on your data. Anthropic processes these requests as our service provider under its commercial API terms; we do not control and do not make representations here about Anthropic’s own practices beyond that relationship.

6Where your data lives and how tenants are separated

VERSO Cloud runs on Fly.io in the United States. Workspace content is stored in a PostgreSQL database in which every row carries its tenant and is protected by database-enforced row-level security, alongside a persistent volume for file-backed stores. Each customer’s workspace is isolated from every other customer’s.

We describe our architecture here, not a certification. VERSO holds no third-party security or compliance certification at this time, and this page makes no such claim.

7Who else touches your data

We keep this list short on purpose. Today it is:

  • Google — only if you connect it, as the source of the Gmail and Calendar data described above.
  • Fly.io — hosting, application servers and the managed database.
  • Anthropic — the AI provider described in section 5.

We do not sell your data, and we do not share it for advertising.

8Retention and deletion

We keep your workspace content for as long as your account is active, because it is the material VERSO reasons over. You can delete individual records in the product at any time. To close your account or have your workspace deleted, write to contact@versolab.ai and we will action it and confirm when it is done. Backups and ordinary server logs may persist for a period after deletion as part of normal operation.

We are a small team and we would rather be honest than impressive: we do not publish a guaranteed deletion SLA, because we are not yet in a position to commit to one.

9Your choices

  • Connect or disconnect Google at any time, per service, from the Integration Hub.
  • Enable or disable capabilities in Settings, which changes what VERSO surfaces.
  • Ask us for a copy of your workspace data, a correction, or deletion, at contact@versolab.ai.

10Children

VERSO Cloud is a business product and is not directed to children under 16.

11Changes

If this policy changes we will update this page and its effective date. If a change materially affects how we handle Google user data, we will tell affected customers directly.