Privacy Policy
Last Updated: June 2026
1. Introduction
This Privacy Policy explains how Velona ("Velona", "we", "our", or "us") collects, uses, stores, processes, and protects information when you access or use our website, APIs, applications, and related services (collectively, the "Service").
By creating an account or using the Service, you acknowledge that you have read and understood this Privacy Policy.
2. Information We Collect
We may collect the following categories of information:
Account Information
- Name
- Email address
- Organization or company name (if provided)
- Account credentials
Billing Information
- Transaction records
- Wallet balances
- Payment references and invoices
- Tax-related information where required
Usage Information
- API requests and responses
- Model selections
- Token usage
- Request timestamps
- Rate-limit and quota information
- IP addresses
- Device and browser metadata
Content Submitted to the Service
We may process prompts, inputs, files, messages, and generated outputs submitted through the Service where necessary to provide, secure, maintain, troubleshoot, and improve the Service.
3. How We Use Information
We use information for purposes including:
- Providing and operating the Service.
- Authenticating users and securing accounts.
- Processing payments and maintaining wallet balances.
- Preventing fraud, abuse, and unauthorized activity.
- Monitoring service performance and reliability.
- Providing customer support.
- Complying with legal and regulatory obligations.
- Generating analytics and usage insights.
- Improving features, reliability, and user experience.
4. AI Models and Third-Party Providers
Velona provides access to third-party AI models and infrastructure providers.
Prompts, requests, inputs, and generated outputs may be transmitted to the selected model provider in order to process your requests.
The handling of such data may also be subject to the privacy policies and practices of the relevant provider.
5. Payment Processing
Payments are processed through third-party payment processors, including Razorpay and other providers that may be introduced from time to time.
Velona does not store complete card numbers, CVV codes, or other sensitive payment credentials.
Payment processors handle payment information according to their own privacy policies and security standards.
6. Data Retention
We retain information for as long as reasonably necessary to provide the Service, comply with legal obligations, resolve disputes, enforce agreements, and protect our legitimate interests.
Velona may retain prompts, inputs, generated outputs, request metadata, usage logs, IP addresses, billing records, and operational logs for security, abuse prevention, fraud detection, billing verification, debugging, compliance, analytics, service improvement, and operational purposes.
- Account and billing records may be retained as required by law.
- Usage logs may be retained for security and operational purposes.
- Support communications may be retained for service improvement.
Retention periods may vary depending on legal, security, operational, and business requirements.
7. Cookies and Local Storage
We use cookies, session tokens, and similar technologies to operate and secure the Service.
These technologies may be used for:
- User authentication.
- Session management.
- Security and fraud prevention.
- User preferences and settings.
We may also use browser local storage to save user preferences such as theme settings.
8. Sharing of Information
We do not sell or rent personal information to third parties.
We may share information with:
- Payment processors.
- Cloud hosting providers.
- Email and communication service providers.
- Analytics and monitoring providers.
- AI model providers selected by users.
- Government authorities where legally required.
Such sharing is limited to what is reasonably necessary to provide and operate the Service.
9. Security
We implement reasonable technical, organizational, and administrative safeguards designed to protect information from unauthorized access, disclosure, alteration, or destruction.
Security measures may include:
- Password hashing.
- Encrypted communications using HTTPS/TLS.
- Access controls and monitoring.
- API key protection mechanisms.
- Infrastructure security controls.
No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
10. International Transfers
Depending on the model provider or infrastructure used, information may be processed or stored outside India.
By using the Service, you acknowledge that information may be transferred to jurisdictions that may have different data protection laws than your own.
11. Your Rights
Subject to applicable law, you may request:
- Access to your personal information.
- Correction of inaccurate information.
- Deletion of your account and personal data.
- Withdrawal of consent where applicable.
Certain information may be retained where required by law, regulatory obligations, fraud prevention requirements, or legitimate business interests.
12. Children's Privacy
The Service is not intended for individuals under the age of 18.
We do not knowingly collect personal information from children.
13. Changes to this Privacy Policy
We may update this Privacy Policy from time to time.
Updated versions will be posted on this page with a revised "Last Updated" date.
Continued use of the Service after changes become effective constitutes acceptance of the revised Privacy Policy.
14. Data Breach Notification
In the event of a personal data breach that is likely to result in a high risk to the rights and freedoms of affected individuals, Velona will:
- Notify affected users within 72 hours of becoming aware of the breach, where feasible.
- Send notification to the registered email address on file for each affected account.
- Include in the notification: (a) a description of the nature of the breach. (b) the categories and approximate number of individuals and records concerned. (c) the likely consequences of the breach. (d) the measures taken or proposed to address the breach, including steps to mitigate its possible adverse effects.
- Where required by applicable law (including the Digital Personal Data Protection Act, 2023 and GDPR), notify the relevant supervisory authority without undue delay.
If you believe your account has been compromised, please contact us immediately at the address below.
15. Grievance Officer
In accordance with the Information Technology Act, 2000 and the Digital Personal Data Protection Act, 2023 (India), the details of the Grievance Officer are provided below.
Name: Kaustav Maji
Designation: Grievance Officer
Organisation: Velona (nCircle Tech)
Email: [email protected]
Response time: We will acknowledge your grievance within 48 hours and resolve it within 30 days of receipt.
You may raise a grievance regarding the processing of your personal data, any perceived violation of your data protection rights, or any other privacy-related concern by writing to the Grievance Officer at the email address above.
16. Contact
For general privacy-related questions, requests, or concerns, please contact us through the support channels listed on the Velona website, or write to the Grievance Officer listed above.
Related policies: Terms of Service · Cookie Policy · Refund Policy