Skip to main content

Privacy Policy

Last updated: July 3, 2026

1. Introduction

This Privacy Policy explains how Verslay — a product operated by its founders ("Verslay," "we," "us," or "our") — collects, uses, stores, shares, and protects your personal data when you use the website at verslay.com, the dashboard at hub.verslay.com, and the Verslay MCP server (together, the "Service").

Verslay is a platform that lets you run AI agents against your own connected tools. For the personal data we process about you, Verslay acts as a Data Fiduciary and you are a Data Principal under India's Digital Personal Data Protection Act, 2023 (the "DPDP Act"). Please read this policy carefully. If you do not agree with it, please do not use the Service.

Important: Verslay does not operate its own AI models. The AI assistant you use (currently Anthropic's Claude, via claude.ai) is a separate service governed by its own privacy policy. Verslay is the mechanical layer that stores your business context, resolves your credentials, and executes the tools you enable.

2. Information We Collect

Account Information

  • Email address and, optionally, your name
  • Authentication identifiers from our authentication provider (including any social sign-in you use, and passkey/authenticator settings)

Billing Information

If you subscribe to a paid plan, payment is processed by Razorpay. We receive and store subscription metadata (your plan, status, billing cycle, and a payment-processor reference ID). We do not collect or store your full card or bank details — those are handled directly by the payment processor.

Business Memory

To personalize agent behavior, the Service stores business context you provide — company information, team structure, preferences, milestones, and agent activity logs (which agents ran, when, and general outcomes). This is kept in your isolated memory space and is never shared with other users.

Connected-Service Credentials

When you connect a third-party account, we store the access tokens or API keys needed for agents to act on your behalf. We access your connected data (for example, an email or a CRM record) in real time only to perform the task you request; we do not keep standing copies of that data.

Usage & Technical Data

  • Agent and feature usage (deployments, invocations, pages used)
  • Technical data such as browser type, device type, and IP address, used for security and diagnostics
  • Communications you send us (for example, support requests)

3. How We Use Your Information

We process your personal data for these specified purposes:

  • Providing the Service — operating the platform, running the agents and tools you enable, and maintaining your business memory.
  • Personalization — giving agents the context they need to act usefully for your business.
  • Security & fraud prevention — protecting your account, detecting misuse, and enforcing our Terms.
  • Improvement — analyzing aggregated, de-identified usage to improve the Service. We do not use your business memory or connected-service data to train third-party AI models.
  • Communication — sending essential service messages (security alerts, billing notices, changes to terms). We send marketing only where you have consented, and you can opt out at any time.

We process this data on the basis of the consent you give when you sign up and connect services, and to provide the Service you have requested. You can withdraw consent as described below.

4. Your Consent & How to Withdraw It

When you sign up, you give free, specific, informed, and unambiguous consent to the processing described in this policy, through a clear affirmative action. When you connect a third-party account, you separately authorize the specific access (scopes) required.

You may withdraw your consent at any time — for example, by disconnecting a service from your dashboard, deleting your business memory, or closing your account. Withdrawing consent does not affect processing already carried out, and may mean parts of the Service can no longer function. To withdraw consent for anything you cannot control from the dashboard, contact legal@verslay.com.

5. AI Processing & Your AI Assistant

Verslay runs no AI models of its own. When you use an agent, your AI assistant (currently Anthropic's Claude, via claude.ai) processes the conversation and decides which Verslay tools to call. That processing happens on the AI provider's systems under the AI provider's own terms and privacy policy — not on Verslay's servers. Verslay receives the specific tool calls your assistant makes and executes them against your connected services. You should review the privacy policy of the AI assistant you use.

6. Connected Services & Your Credentials

You may connect your own accounts — such as Google (Gmail, Calendar, Drive), Microsoft, HubSpot, Slack, Stripe, and many others. Some connections use Verslay's own OAuth or an API key you provide; others are established through our managed-authentication provider (Composio). In every case:

  • Access tokens are encrypted at rest with AES-256-GCM; API keys are stored only as irreversible hashes.
  • Agents access connected data in real time to complete the task you request; we do not store standing copies of your emails, files, calendar, or CRM records.
  • Each connected service processes your data under its own terms and privacy policy.
  • You can disconnect any service at any time, which revokes Verslay's stored authorization for it.

7. How We Share Information

We do not sell your personal or business data. We share it only with the sub-processors that run the Service, each processing only what its function requires:

  • Supabase — database, authentication data, and file storage (your account and business memory).
  • Clerk — authentication and session management (email, name, authentication identifiers).
  • Vercel — hosting for the website and dashboard (web traffic and server rendering).
  • Railway — hosting for the MCP server (tool-execution requests).
  • Anthropic (Claude / claude.ai) — the AI assistant that processes your conversation context on its own systems.
  • Composio — managed authentication that brokers connections to a large catalog of third-party services and, for some providers, proxies your authorized requests.
  • Razorpay — subscription billing (subscription metadata and payment reference IDs; no full card details).
  • Apify — powers certain research and data-retrieval tools (the queries and public data you request; no account data).

We may also disclose information where required by law, to enforce our Terms, or to protect the rights, safety, and security of Verslay, our users, or the public.

8. Data Storage, Security & Location

  • All data is encrypted in transit using TLS/HTTPS.
  • Connected-service access tokens are encrypted at rest using AES-256-GCM.
  • API keys are stored as SHA-256 hashes; the original key is never retained.
  • Passwords are hashed by our authentication provider and never stored in plaintext.
  • Row-level security isolates your data from other users at the database level; elevated (service-role) access is limited to specific server operations, and administrative actions are logged.

Location & cross-border transfer: our infrastructure and sub-processors (including Supabase, Vercel, Railway, Anthropic, Composio, and others) may store and process your data on servers located outside India. Where we transfer personal data across borders, we do so in accordance with the DPDP Act and using providers that apply appropriate safeguards. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

9. Data Retention

  • Active accounts: we retain your data for as long as your account is active and the purposes above apply.
  • Closed accounts: we delete or de-identify your personal data within 90 days of account closure, except where we must retain certain records to meet legal, tax, or security obligations.
  • Connected-service tokens: deleted promptly when you disconnect a service.
  • Logs: retained for a limited period for security, diagnostics, and legal compliance.

10. Your Rights as a Data Principal

Under the DPDP Act, you have the right to:

  • Access a summary of the personal data we process about you and how we process it.
  • Correct or complete inaccurate or incomplete data, and update it — much of this is available directly in your dashboard.
  • Erase your personal data where it is no longer needed for the purpose it was collected.
  • Grievance redressal — raise a complaint about our handling of your data (see below).
  • Nominate another individual to exercise your rights in the event of your death or incapacity.
  • Withdraw consent and opt out of marketing at any time.
  • Export your data — contact us and we will provide it in a portable format.

To exercise any of these rights, use your dashboard or contact legal@verslay.com. We will respond within a reasonable period and in any case within the timelines required by law.

11. Cookies

We use strictly necessary cookies for authentication (secure, HTTP-only session cookies set by our authentication provider across verslay.com) and short-lived cookies for security during connection flows. We do not use third-party advertising cookies. For details, see our Cookie Policy.

12. Children's Privacy

The Service is intended for users aged 18 and over. We do not knowingly process the personal data of children. If you believe a child has provided us with personal data, contact legal@verslay.com and we will delete it.

13. Data-Breach Notification

If a personal-data breach affecting you occurs, we will notify the Data Protection Board of India and affected users as required under the DPDP Act, 2023 and the rules made under it (as and when those provisions come into force), and — as a matter of policy — we will act promptly to contain and mitigate the impact.

14. Grievance Redressal

If you have a concern or complaint about how we handle your personal data, contact our grievance channel at legal@verslay.com. We will acknowledge and address your grievance promptly, and within the timelines prescribed under the DPDP Act, 2023 and its rules as they come into force. If you are not satisfied with our response, you may escalate the matter to the Data Protection Board of India.

15. Changes to This Policy

We may update this Privacy Policy from time to time. If we make material changes, we will notify you by email or a prominent notice on the Service at least 14 days before they take effect, and update the "Last updated" date above.

16. Contact

For privacy questions, data requests, or grievances, contact us at: