01 Overview
Verabase provides a self-healing knowledge platform that helps support teams ingest their knowledge, detect gaps, and deliver verified answers. We designed the product around a simple principle: your knowledge — and your customers' data — belongs to you.
This Privacy Policy applies to the Verabase website, web application, and related services (together, the "Services"). It describes the personal information we process as a business and, where you use Verabase to handle data on behalf of your own customers, how we act as a processor on your instructions.
The short version: We don't train AI models on your content, we don't mark up or resell your data, and you can export or delete your knowledge base at any time.
02 Information we collect
We collect only what we need to provide and improve the Services.
Information you provide
- Account details — name, work email, organization name, and authentication credentials when you create an account.
- Billing information — plan selection and payment details, processed by our payment provider. We do not store full card numbers.
- Content you ingest — documents, URLs, and connected sources (such as Notion or Google Drive) you choose to add to your knowledge base.
- Support communications — messages you send us and the context you share when you contact our team.
Information collected automatically
- Usage data — feature interactions, query volumes, and diagnostic logs used to operate and improve the Services.
- Device & connection data — IP address, browser type, and similar technical information.
03 How we use information
We use the information we collect to:
- Provide, maintain, and secure the Services and your knowledge base.
- Authenticate users, manage seats and agents, and process billing.
- Detect knowledge gaps, cluster similar questions, and draft answers within your own workspace.
- Respond to your requests and provide customer support.
- Monitor performance, prevent abuse, and protect the integrity of the platform.
We do not use your ingested content, queries, or generated answers to train our own models or those of any third party.
04 Bring Your Own Keys & providers
Verabase operates on a Bring Your Own Keys (BYOK) model. Language, voice, and messaging capabilities run on API accounts you connect, such as OpenAI, Anthropic, Azure, Gemini, and Deepgram.
- Your prompts and inference traffic flow between your workspace and your provider accounts. We do not store or inspect your raw model traffic.
- Usage costs are billed directly by your providers — Verabase adds no markup.
- Each connected provider processes data under its own terms. We encourage you to review the privacy practices of any provider you connect.
Before queries leave your workspace, our real-time PII masking detects and redacts sensitive personal information so it is not transmitted unprotected.
06 Data retention & deletion
We retain personal information for as long as your account is active or as needed to provide the Services. You remain in control of your content:
- You can export your knowledge base at any time.
- You can delete individual documents, sources, or your entire workspace from within the product.
- When you close your account, we delete or anonymize associated personal data within 30 days, except where retention is required by law.
07 How we protect your data
Security is built into the platform, not bolted on afterward:
- Encryption — TLS 1.3 in transit and AES-256 at rest.
- PII masking — sensitive data is redacted in real time before any query reaches a language model.
- Access controls — enterprise SSO via Okta, Azure AD, and OIDC, with role-based permissions.
- Auditability — a complete security audit ledger records access and changes.
- Compliance modes — GDPR and HIPAA configurations are available for teams with regulatory obligations.
No system is perfectly secure, but we work continuously to safeguard your data and to notify affected users promptly in the unlikely event of a breach.
09 International transfers
Verabase offers regional data residency so you can choose where your data is hosted. Where personal data is transferred across borders, we rely on appropriate safeguards — such as Standard Contractual Clauses — to protect that information consistent with applicable law.
10 Your privacy rights
Depending on where you live, you may have the right to:
- Access the personal information we hold about you.
- Correct inaccurate or incomplete information.
- Delete your personal information.
- Object to or restrict certain processing.
- Receive a portable copy of your data.
- Withdraw consent where processing is based on consent.
To exercise any of these rights, contact us at privacy@verabase.io. If Verabase processes data on behalf of your organization, we will direct your request to the relevant account administrator.
11 Children's privacy
Verabase is a business product not directed to children. We do not knowingly collect personal information from anyone under 16. If you believe a child has provided us personal information, please contact us so we can remove it.
12 Changes to this policy
We may update this Privacy Policy as our Services evolve or as required by law. When we make material changes, we will update the "Last updated" date above and, where appropriate, notify you through the product or by email. Your continued use of the Services after an update means you accept the revised policy.
13 Contact us
If you have questions about this policy or how we handle your data, we'd be glad to help.