VeloOpen workspace

Legal

TermsPrivacyAcceptable useCopyrightSubprocessors
Version
1
Effective
Aug 25, 2026
Publisher
Meridian Studios

Current policy

Privacy Policy

What Velo collects, why it is used, who receives it, and the choices available to you.

1. Scope and controller

This Privacy Policy explains how Meridian Studios (Meridian, we, us, or our) collects, uses, discloses, retains, and protects personal information when you use Velo, visit its public pages, create or review projects, connect an integration, or contact us. Meridian is the controller of personal information used to operate Velo. An organization using Velo may separately control the project material it asks you to review.

Privacy questions and rights requests may be sent to legal@meridianproject.studio. Product support is available at support@meridianproject.studio.

2. Information we collect

Account and identity information. We process your email address, username, display name, authentication subject, membership and role, invitations, verification state, locale, time zone, consent choices, and account lifecycle records.

Project and review information. We process project titles, source URLs, images, website snapshots, sanitized document representations, Brand Books, element maps, selected text or regions, comments, replies, tasks, decisions, blocks, release history, and contact-sharing choices. Review evidence may include a focused screenshot of the selected element and its nearby context.

Technical and device information. We process IP-derived request information, timestamps, browser and operating-system family, viewport, device pixel ratio, orientation, pointer class, source route, referrer controls, session and security events, capture diagnostics, checksums, queue attempts, and bounded error codes. We use this information to render the correct representation, preserve evidence, prevent abuse, and diagnose failures—not to make eligibility or authorization decisions from device characteristics.

Integration information. If you connect a service, we process provider type, endpoint, approved scopes and tools, public configuration, encrypted credentials or tokens, capability schemas, action previews, payload digests, delivery state, and external identifiers. We do not ask you to expose secrets in comments or project content.

Communications and legal records. We process support messages, transactional-email delivery events, legal-document versions and acceptances, copyright reports, account export and deletion requests, audit events, and security reports.

3. Sources of information

We receive information directly from you; from creators or organizations that invite you; from the websites and files you explicitly ask Velo to capture or publish; from your browser and device; from authentication, hosting, storage, email, and security providers; and from integrations you choose to connect. We do not buy personal-information profiles from data brokers.

4. How and why we use information

We use information to authenticate users; provision organizations and roles; create immutable releases; capture public websites; store and display images; anchor and attribute feedback; maintain private and community review boundaries; deliver content-minimal notifications; run approved integrations; export or delete data; prevent fraud, abuse, and security incidents; enforce agreements; comply with law; and maintain reliable operations.

Where European data-protection law applies, our legal bases are performance of a contract when we provide requested Velo functions; legitimate interests in securing, debugging, and improving a privacy-respecting service; consent for optional contact sharing or other choices where consent is appropriate; and legal obligation for records we must preserve. You may withdraw consent without affecting processing that occurred before withdrawal. We balance legitimate interests against user rights and do not use that basis for unrelated advertising.

5. Explicit publishing and local state

Velo does not silently publish every source edit. A creator explicitly uploads an image, requests a remote capture, or publishes a selected release. Browser-local drafts and pending operations may remain on the device until the creator publishes or clears them. A remote website capture necessarily sends the requested public URL and captured response data to Velo's capture infrastructure. Published review evidence is hosted so authorized reviewers can see the same release.

6. How we disclose information

We disclose information to the creator or organization responsible for a project; to reviewers authorized for the selected community or private session; to service providers listed in the Subprocessor Registry; to an integration only after an authorized user reviews and approves the action; to professional advisers under confidentiality duties; and to authorities or other parties when reasonably necessary to comply with law, protect rights and safety, investigate abuse, or complete a corporate transaction.

Private-review participants cannot use the product to read another reviewer's private conversation. Community feedback is visible to verified community participants. Notifications link back to Velo and are designed not to include private feedback text. Mutual contact sharing reveals an email address only after both participants opt in and stops new disclosure after withdrawal.

We do not sell personal information. We do not share personal information for cross-context behavioral advertising. Velo does not enable advertising analytics, third-party session replay, or AI processing of project content by default.

7. Service providers and international transfers

Velo uses Neon for PostgreSQL and authentication, Vercel for the web application, Cloudflare for private object storage and delivery controls, Render for background capture and delivery workers, and Resend for transactional email. GitHub and user-configured MCP or HTTP services are optional. The current registry identifies each provider's purpose and whether it is required or optional.

Providers may process information in the United States or other countries where they or their subprocessors operate. Those countries may have different data-protection rules. Where required, we rely on legally recognized transfer mechanisms and contractual safeguards available from the provider. Contact us for information relevant to a particular transfer.

8. Retention and deletion

Account, project, release, review, and integration records remain while the account or organization uses Velo or until an authorized user deletes them or submits a verified deletion request. Revoked and expired links stop access but do not automatically delete the underlying release. Disconnected credentials are removed from active use; the external provider may retain data already sent to it under its own policy.

When we complete a verified deletion request, we remove eligible information from active systems and allow encrypted backups to age out through their normal rotation. We may retain minimal audit, security, legal acceptance, fraud-prevention, dispute, and transaction records where reasonably necessary or legally required. Copyright reports and related correspondence may be retained to administer repeat-infringer and legal processes. We do not promise deletion where another user or organization independently controls the same record, but we will explain the applicable boundary.

Exports are generated for the requester and may be deleted from temporary delivery storage after delivery or expiration. Capture attempts and delivery logs contain bounded diagnostics rather than full page bodies or credentials.

9. Security

We use organizational and technical measures designed to protect information, including encrypted transport, private object storage, short-lived signed URLs, credential encryption, hashed review and invitation tokens, tenant-scoped database authorization, append-only legal and audit records, bounded capture egress, redirect and private-network blocking, idempotent operations, and least-privilege provider access. No system is perfectly secure. Report suspected vulnerabilities or unauthorized access to legal@meridianproject.studio; do not exploit or expose another user's data while testing.

10. Your choices and rights

Velo provides controls to export account or project data, request account deletion, revoke review links, block participants, disconnect integrations, withdraw mutual contact sharing, and close review sessions. Depending on where you live, you may also have rights to know or access personal information, correct it, delete it, receive a portable copy, object to or restrict processing, withdraw consent, and complain to a supervisory authority.

California residents may request the categories and specific pieces of personal information collected, sources, purposes, and disclosures; request correction or deletion subject to exceptions; and receive equal service for exercising privacy rights. Velo does not sell or share personal information for cross-context behavioral advertising, so it does not offer a sale/share opt-out workflow for a practice it does not perform. We honor legally valid browser signals where they apply to an enabled practice.

To exercise a right, use Velo's export or deletion controls or email legal@meridianproject.studio. We may verify identity and authority before acting. An authorized agent must provide proof of authority. We will respond within the period required by applicable law and explain any denial or limitation.

11. Cookies and similar storage

Velo uses session cookies and browser storage needed for authentication, security, review-link exchange, local drafts, cached projections, pending operations, receipts, and interface preferences. Review tokens are exchanged for protected receipts and removed from the visible URL where supported. We do not use advertising cookies. Blocking essential storage may prevent authentication, local recovery, or review access from working.

12. Children

Velo is not directed to children and is limited to people age 18 or older. We do not knowingly collect personal information from children under 13. If you believe a child has provided information, contact legal@meridianproject.studio so we can investigate and delete it where appropriate.

13. Changes to this policy

We may update this Policy when Velo, its providers, or applicable requirements change. The current page identifies the version and effective date. We will provide additional notice or request renewed acceptance when a material change requires it. Earlier accepted versions remain recorded so the applicable notice can be reconstructed.

14. Contact

Privacy and legal requests: legal@meridianproject.studio

Product and account support: support@meridianproject.studio