VIERLO

Version 1.1

Privacy Policy

Effective date: August 29, 2026

1. Scope and controller

This Policy explains how the operator of VIERLO processes personal data when individuals visit, register for, purchase, or use the VIERLO AI workspace. It applies to personal accounts, Business workspaces, manual and Enterprise access, support, billing, websites, and related services. For an organization’s internal content, the organization may also act as controller and VIERLO may process data on its instructions.

Privacy requests can be submitted through the authenticated Feedback & Ideas area. The operator’s full legal identification and dedicated privacy contact must also be made available in the commercial contracting or company-identification channel applicable to the customer.

2. Data we collect

  • Account data: name, e-mail, password hash, e-mail verification, authentication method, recovery and two-factor status, preferences, and account status.
  • Organization data: company name, memberships, roles, invitations, plan, member limits, workspace settings, Access Key hash and related security status. Complete Access Keys are not stored for display.
  • Workspace content: prompts, conversations, responses, projects, tasks, documents, images, research, memories, knowledge, feedback, reports, automation instructions, and content selected for integrations.
  • Billing data: plan, interval, currency, subscription and customer identifiers, payment status, renewal and cancellation information. Payment-card details are processed by the payment provider and are not stored by VIERLO.
  • Usage and technical data: request time, feature, model routing metadata, token and cost estimates where available, latency, errors, IP-derived security signals, browser and device information, session identifiers, audit events, cookies, and diagnostic logs.
  • Communications: support requests, feedback, reports, optional contact e-mail, and service or security e-mail delivery status.
  • Integration data: provider, connection status, permissions and encrypted credentials when a user explicitly connects an external service. Secrets are not sent to the AI model as ordinary prompt context.

3. Sources of data

We receive data directly from users and organization administrators; from activity within the service; from authorized integrations; from payment, e-mail, hosting, database, and AI providers; and from public sources that a user specifically asks VIERLO to research. Administrators must have authority to provide member data and invitations.

4. Why we process data and legal bases

Depending on the context and applicable law, processing is necessary to perform a contract or pre-contract request, comply with legal obligations, exercise legal rights, prevent fraud and protect users, pursue legitimate interests that do not override fundamental rights, or act on valid consent when consent is required.

  • create and authenticate accounts, verify e-mail, manage sessions, recover passwords, provide two-factor authentication, and switch authorized workspaces;
  • provide chat, AI, memory, projects, documents, research, images, agents, integrations, automations, exports, notifications, and administration;
  • process subscriptions, enforce plan limits, reconcile signed webhooks, support direct contracts, and maintain legally required financial records;
  • protect tenant isolation, investigate abuse, apply rate limits, detect suspicious activity, resolve errors, maintain audit trails, and secure infrastructure;
  • respond to support, privacy, feedback, and legal requests and send essential service, billing, and security notices;
  • measure reliability and improve the service using minimized or aggregated telemetry where reasonably possible.

5. AI processing

When a user requests an AI feature, the relevant prompt, selected conversation context, authorized memories, project or document excerpts, images, research material, and tool results may be transmitted to contracted AI and infrastructure providers to generate the response. Context is selected according to feature scope and permissions; unrelated organization data and application secrets must not be included.

AI output and routing telemetry may be stored with the conversation and usage records. Users should avoid submitting unnecessary sensitive data and must have authority to process third-party data. VIERLO does not use AI output as the sole basis for legal or similarly significant decisions about individuals.

6. Sharing and service providers

We do not sell personal data. Data may be shared only as necessary with: authorized members and administrators of the relevant workspace; contracted providers for frontend hosting, backend hosting, databases, AI processing, e-mail delivery, payments, monitoring, and user-authorized integrations; professional advisers under confidentiality; authorities or counterparties when legally required; and a successor in a legitimate corporate transaction subject to appropriate safeguards.

Current provider categories may include Vercel for frontend hosting, Render for backend hosting, Neon for PostgreSQL infrastructure, specialized infrastructure supporting VIERLO Intelligence, Resend for transactional e-mail, and Paddle for payment processing. Providers may change as the service evolves. Each provider processes data under its own contractual role, security controls, and applicable privacy terms.

7. International data transfers

Some providers and systems may process data outside Brazil. Where required, international transfers use mechanisms recognized by applicable data-protection law, contractual safeguards, security measures, and provider assessments appropriate to the transfer. Requests for information about relevant transfer safeguards may be made through the privacy channel.

8. Organization access and tenant isolation

Workspace data is scoped to the authorized organization. Owners and administrators may manage memberships and access organizational activity and content according to their role and the organization’s policies. A member leaving an organization does not automatically delete content owned by that workspace. Backend authorization is designed to prevent access to another tenant by changing an identifier, URL, or payload; no security control can be guaranteed infallible, and suspected access must be reported promptly.

9. Cookies, local storage, and sessions

VIERLO uses essential authentication cookies and limited browser storage to maintain secure sessions, navigation state, preferences, and fraud protection. Authentication cookies are configured with security attributes appropriate to the production environment. Browser storage must not be treated as the authoritative source of identity or organization permissions. Optional analytics or marketing technologies, if introduced, will be disclosed and consent controls will be provided where required.

10. Retention

Data is retained only for the period reasonably necessary for the purpose described, considering account status, workspace instructions, contractual needs, security, dispute resolution, backup rotation, and legal obligations. Conversation, project, document, and memory data generally remain while the account or workspace is active or until an authorized user deletes them. Temporary chat images are designed to expire after a short period and may disappear earlier after infrastructure restart.

Verification codes, password-reset tokens, challenges, and export links expire automatically. Sessions, security events, telemetry, system errors, and audit records follow configured retention windows. Billing, transaction, consent, fraud-prevention, and legal records may be retained for the period required to comply with law or exercise rights. Deletion from active systems may not immediately remove encrypted backups, which are isolated and expire through controlled rotation.

11. Security

Measures include hashed passwords and Access Keys, encrypted integration credentials when a dedicated key is configured, revocable sessions, role-based authorization, tenant-scoped queries, rate limiting, upload validation, signed billing webhooks, audit and security events, secret redaction, and restricted administrative routes. No internet service is completely secure. Users are responsible for protecting credentials, reviewing active sessions, using two-factor authentication when available, and reporting suspected compromise.

12. Your rights

Subject to identity verification, legal exceptions, and the applicable controller relationship, a data subject may request confirmation and access; correction; information about sharing; anonymization, blocking, or deletion of unnecessary or unlawfully processed data; portability where regulated and technically applicable; deletion of data processed on consent; information about consent consequences; withdrawal of consent; opposition to processing; and review of decisions made solely by automated processing.

Requests are free through the privacy channel. We may request proportionate information to verify identity and authority, especially for organization data, and will respond within applicable legal time limits. A request cannot require disclosure of another person’s data, trade secrets, security-sensitive material, or deletion of records that must lawfully be retained. Data subjects may also contact the Brazilian National Data Protection Authority or competent consumer-protection bodies.

13. Data deletion, export, and account closure

Available settings may allow users to edit profile data, manage memories, export authorized data, revoke sessions, disconnect integrations, and request account deletion. Exports and deletion are scoped to the authenticated user and workspace permissions. Organization-owned content, financial records, immutable audit records, fraud-prevention data, and legal holds may remain when there is a lawful reason. Account deletion does not automatically cancel a separate paid subscription; billing cancellation must be confirmed through the appropriate flow.

14. Email and communications

Transactional e-mails may include verification, password recovery, invitations, billing events, and security alerts. We record delivery status and technical failure information without intentionally logging verification codes, reset tokens, passwords, Access Keys, or provider API keys. Product communications, if introduced, will include preference or opt-out controls where required; essential security and contractual notices may still be sent.

15. Children and sensitive data

VIERLO is not directed to children. Do not submit children’s data or sensitive personal data unless there is a lawful basis, the use is strictly necessary, appropriate safeguards are in place, and any required authorization has been obtained. The service is not designed as a regulated health-record, banking, or government-classified information system.

16. Security incidents

We investigate suspected incidents and take containment, remediation, and notification measures appropriate to risk and applicable law. Notices to affected individuals or authorities will describe relevant facts without exposing secrets or creating additional risk. Users and administrators must promptly report suspicious sessions, unexpected Access Key use, unauthorized integration activity, or cross-workspace access.

17. Changes to this Policy

Material changes will be shown through a new version and effective date and may require renewed acceptance. Earlier acceptance records are preserved for accountability. Continued use after a notified effective date may constitute acceptance where permitted, but consent-based processing will not be materially expanded without the notice or consent required by law.

18. Contact

Submit privacy, security, deletion, access, or correction requests through the authenticated Feedback & Ideas area. Do not place passwords, Access Keys, payment-card details, verification codes, recovery codes, API keys, or sensitive document content in the request.