Legal
Privacy Policy
Effective date: June 29, 2026 · Versa Pro AI, LLC
At Versa Pro AI, LLC ("Versa," "we," "us," or "our"), your privacy is foundational — not an afterthought. This Privacy Policy explains what information we collect, how we use it, who we share it with, and the controls you have over your data. It applies to the Versa web application, API, and related services (collectively, the "Service").
1. Information We Collect
We collect information in the following categories:
Account and identity information
- Name, email address, and password (or social login credentials via Google, Microsoft, GitHub, Facebook, or Apple)
- Billing information — handled by Stripe; Versa stores only subscription status and a Stripe customer reference, never your full card number, CVV, or bank credentials
- Profile preferences you set, such as communication preferences, tone settings, and trusted contacts
Usage and assistant data
- Conversations and messages exchanged with your AI assistant
- Actions you approve or reject, and the context surrounding those decisions
- Research queries and results retrieved on your behalf
- Files and attachments you share within the Service
- Assistant memory items you create or that are generated during your sessions
Connected account data
- OAuth tokens for accounts you connect (e.g., Google Calendar, Microsoft 365). These tokens are stored in an encrypted vault and never stored in plain text. We access only the permissions you explicitly grant.
- Calendar events, email metadata, and other data from connected accounts, accessed only to fulfill your instructions
Communications data
- Inbound and outbound SMS messages and voice call metadata processed through your Versa phone number (Plus and Pro plans). Call transcripts are stored under encrypted references and are accessible only to you.
- Communication consent preferences and opt-in records
Technical and device data
- IP address, browser type, operating system, and device identifiers
- Log data such as request timestamps, error reports, and feature usage patterns
- Session cookies and authentication tokens
What we do NOT collect
- Raw payment card numbers, CVV codes, or bank account credentials
- Biometric data
- Data from connected accounts beyond what is necessary to execute your instructions
2. How We Use Your Information
We use the information we collect to:
- Provide the Service — operate your assistant workspace, process instructions, execute approved actions, and deliver responses
- Authentication and security — verify your identity, protect your account, and detect fraudulent activity
- Billing and subscriptions — manage your subscription, process payments through Stripe, and send billing communications
- AI assistant memory — store contextual information you provide so your assistant can recall your preferences and history
- Communications — send transactional emails (account verification, password reset, receipts) and, where you have consented, SMS or voice notifications
- Service improvement — analyze anonymized, aggregated usage patterns to improve reliability, performance, and features. We do not use your individual conversations or personal data to train foundational AI models.
- Legal compliance — meet obligations under applicable law, respond to lawful requests, and maintain audit records
- Support — diagnose issues and respond to customer service requests
We do not sell your personal information. We do not share your data with advertisers or use it for behavioral advertising.
3. How We Share Your Information
We share your information only in the following circumstances:
Service providers (subprocessors)
We engage trusted third-party service providers who process data on our behalf under confidentiality and data processing agreements. Current key subprocessors include:
- Stripe — payment processing
- Twilio — SMS and voice communications
- OpenAI — AI model inference (for responses generated by your assistant)
- Cloud infrastructure providers — hosting and storage
- HashiCorp Vault — secure credential storage
When your instructions require it, we send necessary context to AI model providers (such as OpenAI) to generate responses. We apply redaction and data minimization policies to limit what is transmitted. We do not permit subprocessors to use your data for their own purposes.
Legal requirements
We may disclose your information if required by law, subpoena, court order, or a lawful request by government or law enforcement authorities. We will notify you where permitted by law before disclosing.
Business transfers
If Versa is involved in a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction. We will notify you via email or prominent Service notice before your data becomes subject to a materially different privacy policy.
With your consent
We may share information in other ways if you have given explicit consent.
4. Data Isolation and Security Architecture
Each Versa account is isolated at the database level using row-level security policies. Your conversations, memory, connected account tokens, files, assistant settings, and action records are technically inaccessible to other users. Versa staff can access your data only when required for support, security, or legal purposes, and such access is logged in our audit system.
Your personal context, preferences, and conversation history are treated as your data — they do not influence the platform's AI policies, admin controls, or other users' experiences.
5. Data Retention
We retain your personal data for as long as your account is active and for a reasonable period thereafter to comply with legal obligations, resolve disputes, and enforce our agreements.
- Active accounts: Data is retained for the duration of your subscription and the 30-day period following cancellation, during which your account enters a soft-deletion phase.
- Post-cancellation: After 30 days, personal data is deleted or anonymized except where retention is required by law or necessary to maintain audit integrity.
- Audit logs: Certain audit records may be retained longer to comply with legal, regulatory, or security requirements, in anonymized or minimized form.
- Backups: Encrypted backup copies may be retained for a limited period after deletion requests are processed; these are purged on a rolling schedule.
You may request deletion of your account and associated data at any time through your account settings or by contacting us at billing@versapro.ai.
6. Cookies and Tracking Technologies
Versa uses session cookies to maintain your authenticated session. We do not use third-party tracking cookies, advertising pixels, or behavioral tracking technologies. The cookies we set are:
- pa_session — an encrypted, HTTP-only session cookie that identifies your authenticated session. It does not contain readable personal data.
- pa_oidc_state / pa_oidc_verifier — short-lived authentication state cookies used during the login flow; they expire after 15 minutes.
You can configure your browser to reject cookies, but doing so will prevent you from logging in to the Service.
7. Your Privacy Rights
Depending on where you live, you may have the following rights regarding your personal data. To exercise any of these rights, contact us at billing@versapro.ai. We will respond within 30 days (or the period required by applicable law).
- Access. Request a copy of the personal data we hold about you.
- Correction. Request correction of inaccurate or incomplete data.
- Deletion. Request deletion of your personal data, subject to legal retention obligations.
- Portability. Request your data in a structured, machine-readable format.
- Restriction. Request that we limit processing of your data in certain circumstances.
- Objection. Object to processing based on legitimate interests.
- CCPA (California residents). California residents have the right to know what personal information is collected, to opt out of sale (we do not sell your data), and to non-discrimination for exercising privacy rights.
- GDPR (EEA/UK residents). EEA and UK residents may have additional rights under GDPR, including the right to lodge a complaint with a supervisory authority.
8. Security Measures
We implement industry-standard security measures to protect your information, including:
- TLS encryption for all data in transit
- AES-256 encryption for session data and secrets at rest
- Encrypted vault storage for connected account OAuth tokens and sensitive credentials
- Row-level security policies preventing cross-account data access at the database layer
- Audit logging of all privileged and data-modifying operations
- Regular security reviews of platform architecture
No system is perfectly secure. While we take significant steps to protect your data, we cannot guarantee absolute security. If we become aware of a security breach affecting your data, we will notify you in accordance with applicable law.
9. AI Model Data Handling
When you use the AI assistant, relevant context from your session is sent to AI model providers to generate responses. We apply the following safeguards:
- Sensitive personal identifiers are redacted before being sent to model providers where technically feasible
- Raw payment card data, credentials, and secrets are never included in model prompts
- We do not use your personal conversations or data to train third-party foundational models; this is governed by our agreements with model providers
- Model calls are limited to the minimum context necessary to fulfill your request
- All model interactions are logged in our audit system with references and hashes, not raw content
10. Children's Privacy
The Service is not directed to children under 18 years of age, and we do not knowingly collect personal information from anyone under 18. If we learn that we have collected information from a child under 18 without parental consent, we will delete it promptly. If you believe a child under 18 has provided us with their personal information, contact us at billing@versapro.ai.
11. International Data Transfers
Versa is operated in the United States. If you are accessing the Service from outside the US, your information may be transferred to, stored, and processed in the United States, where data protection laws may differ from those in your country. By using the Service, you consent to this transfer.
For users in the European Economic Area (EEA) or United Kingdom, we ensure that transfers to the US are conducted with appropriate safeguards, such as Standard Contractual Clauses, where required.
12. Third-Party Links
The Service may contain links to third-party websites or integrate with third-party services. We are not responsible for the privacy practices of those third parties and encourage you to review their privacy policies before sharing any personal information with them.
13. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by email to your registered address or by posting a notice within the Service at least 14 days before changes take effect. Your continued use of the Service after the effective date constitutes acceptance of the updated policy.
14. Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy or your personal data, please contact us at:
- Email: billing@versapro.ai
- Website: versapro.ai
We will acknowledge your request within 5 business days and respond fully within 30 days (or the period required by applicable law).
This Privacy Policy was last updated on June 29, 2026.