Privacy Policy
1. Scope
This Privacy Policy applies to Velo's marketing website, web application, Chrome extension, Stripe-powered payment flows, third-party integrations, public share links, uploaded files and imports, avatar and voice features, and related services we operate.
2. Information We Collect
We collect information you provide directly to us, information collected automatically when you use the Services, and information generated through your use of product features.
- Account and profile information, including your name, email address, company name, login credentials, and onboarding details.
- Billing and transaction information connected to subscriptions and payments processed through Stripe or other payment service providers.
- Project content and user-generated content, including prompts, scripts, edits, comments, reactions, form submissions, videos, recordings, screenshots, images, audio, uploaded files, and imported materials.
- Media inputs such as microphone audio, system audio, face images, likeness materials, and voice samples used in avatar, voice, or related AI features.
- Support and communications data, including messages sent to support or through product communication tools.
- Technical and usage data, including IP address, browser type, device information, operating system, timestamps, referral URLs, crash logs, performance logs, analytics events, and cookie data.
- Public page interaction data, such as access logs and viewer-submitted comments, reactions, or forms on public pages.
3. How We Use Information
- Provide, operate, maintain, and improve the Services.
- Create and manage user accounts and authenticate access.
- Process uploads, recordings, prompts, scripts, avatar data, voice data, and generated outputs.
- Enable public sharing, comments, reactions, forms, and related publishing features.
- Process subscriptions, payments, and billing administration.
- Provide support, communicate service updates, and respond to inquiries.
- Monitor performance, troubleshoot issues, investigate abuse, and protect the security of the Services.
- Enforce our Terms, policies, and legal rights, and comply with applicable law.
4. AI Features and Third-Party Providers
Velo uses third-party providers to power parts of the Services, including infrastructure, payments, analytics, communications, and AI processing. These providers may include Fal, ElevenLabs, Gemini, OpenAI, Anthropic, Stripe, Google Analytics, PostHog, and Intercom.
We do not currently state that we use customer content to train our own models. However, because some features rely on third-party providers, we cannot guarantee how every provider may use or retain data except as described in that provider's own terms, policies, or technical documentation.
5. Avatar, Voice, and Likeness Data
If you use avatar, synthetic voice, or likeness-based features, you understand that the materials you upload may include your face image, likeness, voice recording, or other identifying media. We use these materials to provide the requested feature and related outputs.
You are solely responsible for ensuring that you have all rights, permissions, notices, and consents necessary for any face, voice, likeness, image, audio, or personal data that you upload or use through the Services.
6. Confidential, Internal, and Regulated Content
Velo is a user-directed creation tool. We do not control what users choose to record, upload, import, generate, or publish through the Services. You are solely responsible for determining whether you are authorized to use any content, including confidential, proprietary, internal, sensitive, or regulated material.
We do not intentionally request sensitive personal data. If you choose to submit such material, you do so at your own risk and responsibility.
7. Cookies and Similar Technologies
We use cookies and similar technologies to keep users signed in, remember preferences, support analytics, improve performance and reliability, measure advertising and attribution, and maintain security.
You can control cookies through your browser settings. Disabling cookies may affect the availability or performance of parts of the Services.
8. How We Share Information
- With vendors, processors, and service providers that help us operate the Services.
- With payment processors, billing providers, analytics providers, communications providers, hosting providers, and infrastructure vendors.
- With third-party integrations or services that you choose to connect or use.
- When you publish content or create public share links.
- To comply with law, regulation, legal process, or valid governmental request.
- To protect the rights, property, safety, users, or security of Velo, our company, or others.
- In connection with a merger, financing, acquisition, reorganization, bankruptcy, or sale of assets.
9. Public Links and Interactive Pages
If you create or distribute a public or shareable link, the content available through that link may be accessed, forwarded, reposted, embedded, or otherwise viewed by others. We do not intentionally index these links for search engines, but if you or others post them on publicly indexed websites, they may become discoverable outside Velo.
If public pages allow comments, reactions, or forms, information submitted by viewers may be processed through the Services.
10. Legal Basis for Processing, and Retention
Under GDPR, we only process personal data where we have a valid legal basis. The table below sets out the basis for each use of data, and how long we keep it.
| Use of Data | Legal Basis | Retention Period |
|---|---|---|
| Creating and managing your account | Contractual Necessity: to provide the service you signed up for | Duration of active account, plus 12 months after closure |
| Responding to contact form / support enquiries | Legitimate Interests: to respond to enquiries and support users | Up to 24 months from last contact |
| Demo bookings and sales follow-up | Legitimate Interests / Contractual Necessity (pre-contract steps) | Up to 24 months, or duration of the sales relationship |
| Product usage and platform security logs | Legitimate Interests: to secure the platform, detect misuse | Up to 12 months |
| Marketing communications (email, newsletters) | Consent: opted in via marketing checkbox | Until you unsubscribe or withdraw consent, plus 24 months for suppression records |
| Analytics and non-essential cookies | Consent: via cookie banner | Per cookie category; see Cookie Notice |
| Essential/security cookies | Legitimate Interests: required for the site to function | Session or as specified in Cookie Notice |
| Compliance, billing, and legal records | Legal Obligation: tax, accounting, regulatory requirements | As required by applicable law |
| Investigating misuse or unauthorized access | Legitimate Interests: protecting the platform and other users | Up to 12 months, longer if part of an active investigation |
When data is no longer needed for these purposes, we securely delete or anonymize it. We do not sell personal data to third parties.
11. Security
We use reasonable administrative, technical, and organizational measures designed to protect information. No system is completely secure, and we cannot guarantee absolute security.
12. International Data Transfers
Velo is operated by Flowframe, Inc., based in the United States. If you are located in the European Economic Area (EEA), the United Kingdom, or another jurisdiction outside the US, your personal data will be transferred to and processed in the United States, and potentially other countries where our service providers and AI processing partners operate. We rely on the following safeguards to ensure your data receives an equivalent level of protection:
- EU-U.S. Data Privacy Framework (DPF): relying on DPF certification where applicable for transfers to the United States
- Standard Contractual Clauses (SCCs): the European Commission's approved contractual terms, incorporated into our agreements with vendors and sub-processors
- Supplementary technical and organizational measures: including encryption in transit and at rest, access controls, and data minimization, applied on top of the SCCs where required
- Vendor due diligence: assessing the security practices and data protection commitments of our infrastructure and AI processing partners (including Stripe, Google Analytics, PostHog, Intercom, and our AI providers) before transferring data to them
A list of our sub-processors and their locations is available on request at support@usevelo.ai. You may object to a specific transfer or request more information about the safeguards in place for your data.
13. Your Privacy Rights
If you are located in the European Economic Area (EEA), UK, or another jurisdiction where data protection law gives you these rights, you may:
- Access the personal data we hold about you
- Correct inaccurate or incomplete data
- Delete your data (“right to be forgotten”), subject to legal or contractual retention requirements
- Restrict or object to our processing of your data
- Port your data: receive it in a structured, machine-readable format, or have it transferred to another provider
- Withdraw consent at any time, where processing is based on consent, without affecting the lawfulness of processing before withdrawal
- Lodge a complaint with your local data protection supervisory authority
- Opt out of marketing communications at any time, using the unsubscribe link in any email or by contacting us directly
If you are a California resident, you may have additional rights under the CCPA/CPRA, including the right to know, access, correct, and delete certain personal information, subject to exceptions.
To exercise any of these rights, contact us at support@usevelo.ai. We may ask you to verify your identity before acting on a request, and we will respond within the timeframe required by applicable law (generally 30 days under GDPR).
14. Children
The Services are intended only for individuals who are at least 18 years old. We do not knowingly collect personal information from children.
15. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. If we make changes, we will post the updated version and update the Last updated date. Your continued use of the Services after the revised policy becomes effective means you accept the revised Privacy Policy.
16. Data Protection Officer
Sourav Sanyal
Flowframe, Inc.
131 Continental Dr, Suite 305
Newark, Delaware 19713
United States
Email: support@usevelo.ai
17. Contact
Flowframe, Inc.
131 Continental Dr, Suite 305
Newark, Delaware 19713
United States
Email: support@usevelo.ai