Privacy Policy
Version 2.0 · Effective August 2, 2026
This Privacy Policy explains what personal data Veloris (“we”, “us”) collects through Veloris (the “Platform”), why we collect it, who else processes it, how long we keep it, and what you can require us to do with it. It forms part of the Terms of Service.
We are the data controller for the personal data described here. Contact: privacy@veloris.health.
The short version
- We collect what is needed to run an account, verify you are a medical professional, and show you your own study progress.
- Your AI tutor messages are sent to a third-party model provider to generate a reply. They are only stored if you leave chat history on.
- We never see your card details. Stripe handles those.
- We do not sell your data, and we do not train models on it.
- You can delete your account yourself, immediately, from Settings.
- Never put real patient information into this Platform.
1. Information we collect
1.1 Account information
- First name and last name
- Date of birth — collected to confirm you meet the minimum age of 16, and used by administrators to match your account against the credential document you upload
- Email address
- Password, stored only as a bcrypt hash — we never hold the password itself and cannot recover it
- Your selected role (student, physician, institution administrator) and subscription plan
- Account state: whether your email is verified, whether you accepted the current Medical Disclaimer, and your notification and privacy preferences
1.2 Identity and credential verification information
To confirm you are a medical student, resident or physician we collect your institution name, degree or programme, and a student ID number and/or medical licence number, together with a supporting document you upload (typically a student ID, enrolment letter or licence).
Do not upload documents containing patient information, and do not upload anyone’s documents but your own. Credential documents are encrypted at rest and are visible only to you and to platform administrators carrying out verification review.
1.3 Educational and study information
- AI tutor conversations — your messages and the model’s replies. Storage is optional. Chat history is on by default and can be turned off at any time in Settings. With it off, your message is still transmitted to a model provider to generate a reply — that is unavoidable — but it is not retained by us afterwards.
- Question bank attempts — which questions you answered, what you chose, whether it was correct, and how long you took.
- Mock exam results — exam configuration, answers, timing, pause and resume events, and scores.
- Flashcards — cards you create or generate, and your review grades and scheduling state.
- Study plans — the plans generated for you and your progress through them.
- Study analytics — metrics derived from the above, such as accuracy by subject and weak-area breakdowns. These are computed from your own activity and are shown only to you.
- Files you upload to the AI tutor — held for the time needed to process your request.
1.4 Payment information
Subscriptions are processed by Stripe. We do not receive or store your card number, security code, or full billing address. Those are submitted directly to Stripe. We store the Stripe customer and subscription identifiers, your plan, and its status and renewal date.
1.5 Technical, device and log data
- IP address, recorded against security-relevant events: sign-in, failed sign-in, account lockout, password reset, credential submissions and decisions, disclaimer acknowledgements, administrative actions, and AI queries blocked by the safety classifier.
- Server logs generated in the ordinary course of operating a web service — request paths, response codes, timestamps and errors.
- Device and browser information sent by your browser with each request, such as the user-agent string.
- Authentication cookies — see section 4 and the Cookie Policy.
We do not use advertising trackers, cross-site tracking, device fingerprinting, or session replay.
1.6 Information we do not want and do not ask for
We do not ask for, and you must not provide, information about identifiable patients, your own medical history, or any other special-category health data about a living individual. The AI safety classifier refuses queries that appear to concern real patient care, but it is a safeguard rather than a guarantee.
2. Why we process it, and our legal basis
Where UK or EU data protection law applies, we rely on the following legal bases under Article 6 of the (UK) GDPR:
| Purpose | Data | Legal basis |
|---|---|---|
| Create and operate your account | Account information | Performance of a contract |
| Confirm you are a medical professional | Identity and credential information | Performance of a contract; legitimate interests (restricting a clinical-education tool to trained users) |
| Confirm you meet the minimum age | Date of birth | Legal obligation; legitimate interests |
| Provide tutoring, question bank, exams, flashcards, plans | Educational and study information | Performance of a contract |
| Retain AI conversation history | Chat messages | Consent — withdrawable at any time in Settings |
| Take payment and manage subscriptions | Billing identifiers | Performance of a contract |
| Secure the Platform; detect abuse and credential fraud | Audit logs, IP addresses | Legitimate interests (security of the service and its users) |
| Send transactional email | Email address, first name | Performance of a contract |
We do not send marketing email. If we ever do, it will be on the basis of separate, specific consent with a one-click unsubscribe.
3. Third-party processors
We use the following categories of processor. Each processes personal data on our instructions under a data processing agreement.
- AI model providers — OpenAI, Anthropic, Google, Groq. Depending on the type of request, your AI tutor messages and any attached file are transmitted to one of these providers to generate a reply. Which provider handles a given request, and what we do and do not know about their retention, is set out in the AI Usage Policy.
- Stripe — payment processing and subscription management. Stripe is an independent controller for the payment data you give it directly.
- Email delivery (SMTP) — transactional messages only: address verification, password reset, credential decisions, and security alerts.
- Cloud object storage (Amazon S3 or Cloudflare R2), where configured — encrypted storage of uploaded credential documents. Where it is not configured, documents are stored encrypted on our own server disk.
- Malware scanning (ClamAV), where configured — uploaded files are scanned before being stored.
- Hosting and infrastructure — the provider running our application servers and database.
We also disclose personal data where we are legally required to, or where it is necessary to establish, exercise or defend legal claims. If we are ever party to a merger or acquisition, data may transfer to the successor entity, subject to this Policy.
We do not sell personal data, and we do not share it for advertising.
4. Cookies
We set two cookies, both strictly necessary: an access token and a refresh token, which keep you signed in. Both are httpOnly (unreadable by JavaScript) and SameSite=Lax, and are marked Secure in production. We set no analytics or advertising cookies. Full detail is in the Cookie Policy.
5. How we protect your data
Measures actually implemented on this Platform — described more fully in Security & Privacy Practices:
- Passwords are hashed with bcrypt and are never stored or recoverable in plain text.
- Session tokens are held in
httpOnlycookies, are short-lived, rotate on refresh, are revocable individually at sign-out, and are invalidated everywhere on password reset. - Credential documents are encrypted at rest.
- Uploaded files are validated against their actual file signature rather than their filename, are size-limited, and can be scanned for malware before storage.
- Access to credential documents is restricted to the submitting account and to platform administrators performing review; administrative actions are recorded in an audit log.
- Rate limiting is applied to authentication, AI and upload endpoints.
- Traffic runs over HTTPS in production, with a Content-Security-Policy and related security headers on every response.
No system is perfectly secure and we cannot guarantee absolute security. If a breach affecting your personal data occurs, we will notify the relevant supervisory authority and affected users as and when applicable law requires.
6. Data retention
- Account and study data — kept while your account is active, and deleted when you delete your account.
- AI conversations — kept while your account is active if chat history is enabled; deleted immediately when you delete a conversation or your account. Not retained at all if chat history is off.
- Credential documents — kept while your account is active, as the record supporting your verified status.
- Security audit logs — retained after account deletion for security and fraud-prevention purposes, but anonymised: the reference to your account is removed and the event is kept without it.
- Billing records — retained by Stripe, and by us in identifier form, for the period required by tax and accounting law.
- Credential review decisions you made as an administrator — the decision is preserved on the reviewed user’s record for their accountability; only the reference identifying you as reviewer is removed.
7. What account deletion actually does
Deleting your account from Settings is immediate, self-service and permanent. It deletes your profile and login credentials; all chat sessions, folders and messages; submitted credential documents and verification records; question bank and mock exam attempt history; flashcards, study plans, CME records, disclaimer acknowledgement history and notifications; and your subscription record.
Two categories are anonymised rather than deleted, as described in section 6: security audit entries, and — only if you were a platform administrator — the reviewer reference on other users’ credential submissions.
Deleting your account does not cancel an active Stripe subscription. Cancel it from the billing portal first, or you may continue to be charged.
8. Your rights
Subject to your location and to applicable law, you may have the right to access your data; to correct it; to erase it; to restrict or object to processing; to data portability; to withdraw consent where processing is based on consent; and not to be subject to solely automated decisions with legal or similarly significant effects.
How to exercise them:
- Access and portability — email privacy@veloris.health; we will respond within 30 days.
- Correction — update what you can in Settings; email us for anything else.
- Erasure — delete your account in Settings, which takes effect immediately.
- Withdraw consent to chat history — toggle it off in Settings at any time.
We do not charge for these requests unless they are manifestly unfounded or excessive. We may ask you to confirm your identity before acting on one.
8.1 UK and EU (GDPR / UK GDPR)
If you are in the UK or the EEA, the rights above arise under Articles 15–22 of the (UK) GDPR, and our legal bases are set out in section 2. You also have the right to complain to a supervisory authority — in the UK, the Information Commissioner’s Office; in the EEA, your national data protection authority. We would appreciate the chance to resolve the matter first.
We do not carry out automated decision-making producing legal or similarly significant effects. Credential verification is decided by a human administrator; the AI safety classifier restricts the subject matter of a query but does not decide anything about you as a person.
8.2 California (CCPA / CPRA)
If you are a California resident you have the right to know what personal information we collect and for what purpose, to request deletion, to request correction, and not to be discriminated against for exercising those rights. The categories we collect are listed in section 1 and the purposes in section 2.
We do not sell personal information, and we do not share it for cross-context behavioural advertising as those terms are defined by the CCPA. We therefore do not offer a “Do Not Sell or Share My Personal Information” link, because there is nothing for it to switch off. To make a request, email privacy@veloris.health.
8.3 A note on HIPAA
Veloris is an educational platform. It is not a HIPAA covered entity and not a business associate, we do not enter into Business Associate Agreements, and the Platform must not be used to store, transmit or process protected health information. Do not put patient data into it.
9. Children’s privacy
The Platform is intended for medical students, residents and physicians and is not directed at children. You must be at least 16 years old to register, and we collect a date of birth to check this. We do not knowingly collect personal data from anyone below that age. If we learn we have, we will delete the account and its data promptly. If you believe a child has registered, contact privacy@veloris.health.
10. International data transfers
Our infrastructure and processors may be located outside your country, including in the United States. The AI providers in section 3 are US-based, so an AI tutor request is processed in the United States regardless of where you are.
Where we transfer personal data out of the UK or EEA, we rely on an appropriate safeguard under Article 46 of the (UK) GDPR — typically the European Commission’s Standard Contractual Clauses together with the UK International Data Transfer Addendum, or an adequacy decision where one applies.
11. Changes to this Policy
We may update this Policy. The version and effective date at the top of this page will change, and material changes affecting how we use your data will be notified by email or in-app notice before they take effect.
12. Contact
Veloris
[Registered address to be inserted before launch]
Privacy enquiries and rights requests: privacy@veloris.health
Security reports: security@veloris.health