Privacy Policy

Privacy at a Glance

Velaris collects only the information needed to provide our mental wellness services, including your account details and, for professional users, therapy-related research interactions. We use your data to deliver and improve our services — we never sell your personal information. Only you and authorized Velaris staff can access your data. You have the right to access, correct, or delete your information at any time through your account settings. For questions, contact our Chief Privacy Officer at privacy@velaris.app.

Version 1.0Effective Date: April 6, 2026

1. Introduction

Velaris ("we," "our," or "us") is an AI-powered mental wellness platform. We take your privacy seriously, especially because our services involve sensitive mental health topics.

This Privacy Policy explains what personal information we collect, why we collect it, how we use and protect it, and what choices you have. It applies to all users of our website and platform, including public visitors and licensed professionals.

We follow Canada's Personal Information Protection and Electronic Documents Act (PIPEDA) and its ten privacy principles. This policy is designed to be clear and easy to understand — no legal jargon.

Back to top

2. Accountability

We have appointed a Chief Privacy Officer (CPO) who is responsible for making sure we follow this policy and all privacy laws.

Chief Privacy Officer

Name: [CPO Name — To Be Designated]

Email: privacy@velaris.app

Phone: [Phone Number — To Be Designated]

Address: [Mailing Address — To Be Designated]

Our CPO oversees all privacy practices, responds to your questions or concerns, and ensures our team is trained on handling personal information properly.

Back to top

3. What We Collect

We collect different types of information depending on how you use Velaris. Here is what we may collect:

Identity Information

Your name, email address, and professional credentials (for licensed therapists). We need this to create and manage your account.

Health and Therapy Information

For professional users: therapy research interactions, saved documents, AI-assisted analysis results, and notes. This is the most sensitive information we handle and receives our highest level of protection.

Usage Information

How you interact with our platform, including which features you use and how often. We use this to improve our services.

Financial Information

Payment details for subscriptions. We do not store your full credit card number — our payment processor (Stripe) handles this securely.

Zero-Footprint Public Sessions

If you use Velaris as a public visitor without creating an account, we use ephemeral (temporary) sessions that automatically expire after 30 minutes. No personal data is stored. Once your session ends, all interaction data is permanently deleted. We cannot recover it.

Back to top

4. Why We Collect Your Information

We only collect information when there is a clear reason. Here are our purposes:

  • Providing our services: Creating your account, delivering AI-powered wellness features, and processing subscriptions.
  • AI processing: Using your inputs to generate personalized insights, research analysis, and therapeutic resource recommendations (with your explicit consent).
  • Professional verification: Confirming licenses and credentials for therapists using our professional portal.
  • Improving our platform: Understanding usage patterns (using anonymized data only) to make Velaris better.
  • Safety and security: Detecting and preventing fraud, abuse, and security threats.
  • Legal compliance: Meeting our obligations under Canadian privacy law and, where applicable, health data regulations.
Back to top

5. How We Collect Information

We collect information in the following ways:

  • Directly from you: When you create an account, fill out your profile, use our AI features, or contact us.
  • Automatically: Basic usage data like pages visited and features used, collected through standard web technologies.
  • From third parties: License verification services (for professional users) and payment processing confirmations from Stripe.
Back to top

7. Limiting Collection

We only collect information that is necessary for the purposes we have identified. We do not collect extra data "just in case" or for unrelated reasons.

For public visitors using our anonymous sessions, we collect no personal information at all. For registered users, we collect only what is needed to provide and improve the specific services you use.

Back to top

8. Use and Disclosure

We use your information only for the purposes described in this policy. We share your data with the following categories of service providers, and only as needed:

CategoryProviderPurpose
Payment ProcessingStripeProcessing subscription payments securely
Error TrackingSentryIdentifying and fixing technical problems (anonymized data only)
AnalyticsPostHogUnderstanding usage patterns to improve our services (anonymized data only)
AI ProcessingGoogle, OpenAIPowering AI features (with your explicit consent)
HostingSupabase, VercelHosting our platform and database securely

We never sell your personal information to advertisers or any third party. We never share therapy-related content for marketing purposes.

Back to top

9. How Long We Keep Your Data

We keep your information only as long as necessary. Here are our retention periods:

Data TypeRetention PeriodAfter Deletion
Public sessions (anonymous)30 minutesPermanently erased
AI conversations30 daysPermanently deleted
Account dataWhile account is activeDeleted within 30 days of account closure
Professional research interactionsUser-controlled (90-day default maximum)Permanently deleted
Inactive public accounts24 months of inactivityAutomatically deleted
Inactive professional accounts12 months of inactivityAutomatically deleted
Audit logs7 yearsArchived, then deleted

We run automated checks weekly to enforce these retention periods. When data is deleted, it is permanently removed from our systems, including backups, within 90 days.

Back to top

10. Accuracy

We want to make sure your information is accurate and up to date. You can review and update your personal information at any time:

  • Update your profile details through your account settings
  • Contact our CPO at privacy@velaris.app if you find any inaccuracies
  • Request a correction and we will update our records within 30 days
Back to top

11. How We Protect Your Information

We use multiple layers of security to protect your data:

  • Encryption in transit: All data sent between your device and our servers is encrypted using TLS 1.3, the latest security standard.
  • Encryption at rest: Sensitive data stored in our database is encrypted using AES-256, a military-grade encryption standard.
  • Field-level encryption: Therapy-related content receives an additional layer of encryption at the individual field level.
  • Access controls: Row Level Security (RLS) ensures you can only access your own data. Staff access is strictly limited and audited.
  • Regular security audits: We regularly review our security practices and test for vulnerabilities.
Back to top

12. Your Rights

Under PIPEDA, you have the following rights regarding your personal information:

Right to Access

You can request a copy of all personal information we hold about you. Submit a Data Subject Access Request (DSAR) through your account settings or by contacting our CPO. We will respond within 30 days.

Right to Correction

If any of your information is inaccurate or incomplete, you can update it through your account settings or request a correction from our CPO.

Right to Deletion

You can request deletion of your account and all associated data. After your request, we provide a 30-day verification period during which you can cancel. After 30 days, all your data is permanently removed.

Right to Data Portability

You can export your data in machine-readable formats (JSON or CSV) through the DSAR portal in your account settings.

Right to Withdraw Consent

You can withdraw consent for any optional data processing at any time through your account settings. Withdrawing consent does not affect the lawfulness of processing done before withdrawal.

Back to top

13. Children's Privacy

Velaris is designed for adults aged 18 and older. We do not knowingly collect personal information from anyone under 18 years of age.

If we learn that we have collected personal information from someone under 18, we will delete that information as quickly as possible. If you believe a minor has provided us with personal information, please contact our CPO immediately at privacy@velaris.app.

Back to top

14. Changes to This Policy

We may update this Privacy Policy from time to time. When we make changes, here is what you can expect:

  • Advance notice: We will notify you by email and through an in-app banner at least 30 days before any material changes take effect.
  • Version tracking: Each version of this policy is numbered and dated so you can track changes.
  • Your choice: If you disagree with changes, you can close your account before the new policy takes effect.
Back to top

15. Questions and Complaints

We welcome your questions and feedback about our privacy practices. Here is how to reach us and what to expect:

Step 1: Contact Us

Send your question or complaint to our Chief Privacy Officer at privacy@velaris.app. We will acknowledge your inquiry within 48 hours.

Step 2: Investigation

We will investigate your concern and provide a response within 45 days.

Step 3: Escalation (If Needed)

If you are not satisfied with our response, you have the right to file a complaint with the Office of the Privacy Commissioner of Canada:

Office of the Privacy Commissioner of Canada
30 Victoria Street
Gatineau, Quebec K1A 1H3
Phone: 1-800-282-1376
Website: www.priv.gc.ca
Back to top

AI Processing Disclosure

Velaris uses artificial intelligence to provide wellness insights, research analysis, and therapeutic resource recommendations. Important things to know about our AI:

  • AI features require your explicit consent before activation.
  • AI-generated content is clearly labeled and is not a substitute for professional mental health care.
  • Your inputs to AI features are processed by third-party AI providers (Google, OpenAI) under strict data processing agreements.
  • We do not use your data to train AI models. Your interactions are used only to generate responses for you.
Back to top

International Data Handling

Velaris is hosted in Canada. Your data is primarily stored and processed within Canadian borders, subject to Canadian privacy law.

Some of our service providers (listed in Section 8) may process data in other countries. When this happens, we ensure that appropriate safeguards are in place through data processing agreements that require the same level of protection as Canadian law provides.

Back to top