Privacy
Operator: Nisaba LLC · Patent application No. 64/124,027 · Contact: hello@velaru.xyz
Not legal advice. This notice describes what the public Velaru surfaces collect. Counsel-reviewed DPA lives at /procurement/dpa.
What we collect
- Work email and checkout metadata when you pay an Instant or deposit SKU (Stripe is the processor)
- Messages and metadata you submit for classify / fuse / verify (optional Privacy Mode stores a hash, not plaintext)
- Server logs (IP, user-agent, path, time) for abuse, uptime, and the support SLA
- API keys you create; BYOK public keys you register
What we do not
- Sell personal data
- Require a login to use
/verify
- Claim affiliation with DTCC, SWIFT, or any depository or messaging network
Retention
Signed receipts and hash-chain entries are the product — they persist for verification, billing, and dispute holds. Account-scoped PII deletion requests: hello@velaru.xyz.
Support SLA
- Liveness:
GET /healthz is the Render probe. First request after idle may take ~30s (cold start).
- Paid Instant: fulfillment at
/instant/welcome when the Stripe webhook lands — same calendar day, no later than one business day.
- Security reports: acknowledge within two business days at hello@velaru.xyz or security.txt.
- Enterprise: contracted uptime lives in the DPA / SOW — this public page is not a five-nines promise.