Policies
Privacy Policy.
Last updated September 1, 2026 · Draft version 2026-09-01 · Intended effective date pending launch review
What we collect
We process account and identity details, authentication records, learning level and goals, instructor preferences, bookings, attendance, credit ledger and payment references, support and safety records, and device or security metadata needed to operate Vervalio.
Payment card details are handled by our payment provider and should not be entered into Vervalio forms or review notes. We store provider order references, amounts, currencies, and credit ledger records needed for fulfillment, refunds, audit, and fraud prevention.
When you follow a referral link, we store the referral code in a limited-duration, HTTP-only cookie. If you then create a new account, we retain the inviter relationship and any qualifying reward record for program operation, audit, and abuse prevention.
Google sign-in, Calendar, and Meet
Google sign-in and Google Calendar access are separate. When you use Google sign-in, Google provides an account identifier and verified email address and may provide a display name and profile image when available so Vervalio can create, link, and authenticate your account. Vervalio stores that identifier and those available account profile fields, but does not store the Google OAuth access token or refresh token received by the sign-in flow.
An existing student may instead link Google sign-in from account settings through a narrower openid and email flow. Vervalio uses the verified Google email only to confirm that it matches the current Vervalio account and stores the Google provider and account-identifier association. The linking access token is transient; no Google access token or refresh token is stored, and no Calendar permission is requested.
If you separately connect Google Calendar, Vervalio requests openid to identify the Google account and https://www.googleapis.com/auth/calendar.events.owned. That Calendar scope can see, create, change, and delete events on Google calendars you own. Vervalio limits its actual use to checking, creating, and deleting lesson events at deterministic event identifiers generated by Vervalio in the connected primary calendar; it does not list, inspect, or change your other Calendar events.
For an instructor, Vervalio sends the lesson time and internal booking and lesson identifiers to Google and requests a Google Meet conference on the instructor-owned event. There is no separate Google Meet OAuth scope; Vervalio creates the conference through that Calendar event. For a student who chooses the optional Calendar connection, Vervalio creates a separate ordinary event containing the lesson time, internal booking, lesson, and student identifiers, and the instructor-owned Meet URL in the description and location. The student copy does not create or own a conference. A student can receive and use the instructor's Meet link without connecting Google Calendar.
For a Calendar connection, Vervalio stores the Google account identifier, granted scopes, the primary-calendar reference, an AES-256-GCM encrypted refresh token, connection status and version, and connection, reauthorization, creation, and update timestamps. Access tokens are used transiently during the OAuth callback or Calendar worker request and are not stored in the Calendar connection record. During authorization, encrypted short-lived OAuth state and PKCE data are kept in an HTTP-only cookie.
To operate the lesson events it creates, Vervalio also stores the linked provider account and Calendar references, Vervalio and Google event identifiers, the Meet conference request and provider conference identifiers, and the instructor Meet join URL. Operational metadata includes provisioning generation, delivery status, attempt counts, failure codes, and ready, provider-deletion, creation, and update timestamps. A student-copy record also links the student and lesson to that copy's provider account, primary-calendar, and event identifiers. These records do not contain or mirror the contents of other Calendar events.
Vervalio's use and transfer of information received from Google Workspace APIs adheres to the Google API Services User Data Policy and the Google Workspace API User Data and Developer Policy, including the Limited Use requirements. Vervalio does not sell Google user data; use it for advertising, retargeting, creditworthiness, or lending decisions; or use it to train or improve a general-purpose or shared AI or machine-learning model. Google Calendar data is not sent to the AI lesson-review workflow.
Vervalio currently has no in-app Google disconnect control. You can stop future access by removing Vervalio in Google Account connections. Revoking Google access does not automatically delete Vervalio's local account or Calendar connection metadata, or events already created in Google Calendar. You can delete those events in Google Calendar. To request deletion of Vervalio-held data, contact [email protected].
Lessons, transcripts, and AI
Before booking, the optional AI review choice starts unchecked. Selecting it authorizes transcript creation from an otherwise permitted source and AI review processing for that lesson, or for each lesson in the selected series. Recording is a separate permission and remains disabled, and retention of raw transcript text after processing remains disabled, unless separately enabled later.
When transcript storage is disabled, raw transcript text is removed after processing or a terminal failure. You can later delete a stored transcript or withdraw AI processing consent from the lesson review. A structured review already produced from a consented transcript may remain available unless law requires otherwise.
AI review input is sent only for the requested review workflow, and Vervalio's OpenAI review-generation request uses store: false. This setting is not a blanket promise about storage or abuse-monitoring practices for speech-to-text, meeting, storage, or other providers. AI output can be inaccurate and is presented as learning content rather than a factual profile of you.
Why we use data
We use data to authenticate users, recommend instructors, provide and secure lessons, process bookings and payments, create consented reviews, send transactional messages, answer support requests, prevent abuse, keep financial and administrative audit records, and improve reliability.
The legal basis depends on location and purpose and may include performance of a contract, consent, legal obligations, and legitimate interests such as fraud prevention and service security.
Providers and international processing
We may use configured providers for Google authentication, Calendar and Meet, FastSpring payments, OpenAI-assisted review generation and speech-to-text, hosting, databases, storage, observability, and transactional email. Data may be processed in countries other than your own. Provider terms, retention practices, and any required international-transfer safeguards must be confirmed before launch and are not asserted by this draft.
We do not sell personal information. We disclose data when you direct us, when a provider needs it to deliver the service, to protect users and the service, or when legally required.
Retention, security, and your choices
Retention depends on purpose. Security, payment, credit, refund, and audit records may be kept for legal and fraud-prevention periods. Lesson transcript retention follows your consent setting. Operational logs are limited and secrets are not intentionally written to logs.
Depending on your location, you may request access, correction, deletion, restriction, portability, or objection, and may withdraw consent without affecting earlier lawful processing. [email protected] is the privacy request contact.
Launch notice
This privacy policy is a product and policy draft. The operating entity, contacts, retention schedules, provider terms, international-transfer requirements, and region-specific notices must be configured where applicable and reviewed by qualified counsel before public launch.

