Privacy Policy

Ultimo aggiornamento: July 15, 2026

This Privacy Policy explains how Verli (“we”, “us”) collects, uses, and shares information when you use the Verli browser app, Chrome extension, desktop app, and related services (the “Service”). By using Verli, you agree to the practices described here.

Information we collect

Account information

When you create an account we collect the identifiers you provide to our authentication provider (Clerk), such as your email address, name, and authentication credentials. We do not see or store your password directly.

Audio you capture

Verli processes microphone and system audio in real time to produce transcripts and translations. After you choose Continue, captured audio, language settings, and any preferred terms or context notes you enabled are streamed to our transcription partner (Soniox) solely to generate transcripts and translations. Verli does not store raw audio on our servers after the session ends.

When speaker voice matching is available, Verli sends one short audio clip per detected speaker to the Verli voice-classifier service hosted by Fly.io. The clip is used only to choose an appropriate translated voice, is deleted as soon as classification finishes, and is not retained by Verli or Fly.io.

Audio and video file translator

When you use the public audio and video file translator, your browser processes the original file locally and creates a compressed audio excerpt of no more than three minutes. Verli uploads only that excerpt to Soniox for temporary transcription and translation processing, not the complete original file. Verli deletes the Soniox transcription and its uploaded audio before delivering a result. We retain the bilingual text result and limited job metadata in MongoDB Atlas for no more than 24 hours so you can recover the result in the same browser tab. We do not retain the source media or original filename.

Chrome extension

When you use the Chrome extension guest side panel, Chrome asks you to choose a browser tab and explicitly share its audio. The extension streams only that selected-tab audio directly to Soniox for live transcription and translation. Verli does not collect the tab title or URL, does not retain raw audio, and keeps the guest transcript only in temporary browser-session storage so you can copy it after the trial. We store a hashed installation identifier, language choices, guest-session timestamps, trial status, duration bucket, outcome, extension version, and an opaque handoff identifier to enforce the one-time allowance, prevent abuse, measure reliability, and attribute an optional continuation into the full Verli product. Our hosting infrastructure also processes the request IP address to enforce the per-IP guest reservation limit and prevent abuse; the extension does not request GPS data or derive precise location.

When you sign in and open full Verli in the extension, you may also authorize microphone audio and use your Verli account minutes. Selected-tab and microphone audio are streamed to Soniox as described under Audio you capture, and usage-session records and deducted minutes are associated with your account. If you choose to save a meeting, generate a summary, or share a transcript, the account-linked storage and third-party processing described below apply. Purchase and subscription-management actions leave the extension and open RevenueCat or Stripe checkout and billing pages in a browser tab. Payment card details are not sent to or stored by the extension.

Verli's use of information received from Google APIs will adhere to the Chrome Web Store User Data Policy, including the Limited Use requirements.

Transcripts and share sessions

If you create a share session, the transcript text, language settings, and session metadata are stored temporarily so viewers can follow along. Share sessions expire and are deleted automatically. If you generate an AI summary, transcript text and optional context notes are sent to Google Gemini. If you use Read aloud, translated transcript text is sent to the selected text-to-speech provider, which may be Google Gemini, xAI Grok, Lemonfox, or Google Cloud Text-to-Speech.

If you enable Save meeting transcripts in Settings, completed transcript text, language settings, timestamps, and speaker labels are stored in your Verli account so you can view them in History. Raw audio is not saved with the meeting. This setting applies only to new recordings and can be turned off at any time.

Knowledge-base presets and settings

If you save a knowledge-base preset, we store its name, preferred terms and translations, replacement pairs, background notes, enabled state, timestamps, and account identifier so you can reuse it across devices. We also store service settings and state needed to provide features you choose, such as your saved-meeting preference and onboarding state. Privacy-consent choices for recording and AI summaries are stored locally on your device.

Billing and subscription data

If you purchase a subscription or minutes, RevenueCat manages product and entitlement information, Stripe processes web payments, and Apple processes Apple App Store purchases. We receive subscription status, remaining minutes, and a customer identifier. Payment card details are handled by Stripe or Apple and are not sent to Verli.

Usage and diagnostic data

We collect limited usage and diagnostic data through PostHog, Sentry, Axiom, and our hosting infrastructure to keep the Service reliable and understand which parts of the product are used. This may include IP address, browser or device type, operating system, account or device identifiers, pages you visit in the Verli web product, selected product-interaction events, crash reports, performance information, and structured request and application logs. Chrome extension analytics do not include selected-tab URLs, tab titles, audio, or transcript text. PostHog may use cookies and browser or app storage; we disable autocapture and session recording.

Communications and privacy requests

For transactional messages, privacy requests, and content reports, we process the contact information and message content you submit, along with the report category, content type, non-content reference identifier, and timestamp needed to review and act on the request. Do not include private transcript or summary text in a content report. For product-education and lifecycle emails, we process your email address, first name when available, account identifier, preferred locale, platform and operating system, activation and product-usage milestones, subscription plan, signup status, and inactivity status.

How we use information

  • To provide real-time transcription and translation.
  • To authenticate you and keep your account secure.
  • To operate subscriptions, minutes, and promo codes.
  • To diagnose bugs and improve reliability.
  • To communicate important service notices.
  • To send product education and lifecycle emails after you activate the Service. You can unsubscribe from marketing emails at any time without affecting transactional or account-related messages.

Third parties we share with

We share the minimum data needed with the following processors, each under a data processing agreement:

  • Clerk — authentication and account management.
  • Soniox — real-time speech-to-text and translation using captured audio, including audio from a browser tab you explicitly select in the Chrome extension, language settings, and optional context notes or preferred terms; and temporary batch processing of the compressed audio excerpt created by the public audio and video file translator. File-translator resources are deleted before the result is delivered.
  • MongoDB Atlas — database hosting for account-linked service data, including billing and usage records, share sessions and transcript segments, saved meetings and preferences, knowledge-base presets, desktop authentication credentials, lifecycle-marketing records, and Chrome extension guest-session and handoff metadata. It also temporarily stores public file-translator job metadata and bilingual text results for up to 24 hours. Chrome guest transcript text, file-translator source media, and raw audio are not stored in MongoDB Atlas.
  • Ably — real-time delivery of transcripts to viewers.
  • RevenueCat, Stripe, and Apple — subscription and purchase processing.
  • Vercel — web hosting.
  • Sentry, Axiom, and PostHog — error and crash reports, performance and structured request logs, and selected product analytics. PostHog may use cookies and browser or app storage.
  • Google Gemini, xAI Grok, Lemonfox, and Google Cloud Text-to-Speech — optional transcript summaries and Read aloud speech generation.
  • Fly.io — hosting for Verli's speaker voice-classifier service, which processes short audio clips only for the duration of a classification request.
  • Plunk — product-education and lifecycle email delivery using your email address, first name when available, account identifier, preferred locale, platform and operating system, subscription plan, and events for activation, web activation, reaching the free limit, signup nudges, subscription starts, and inactivity. Plunk does not receive audio, transcripts, knowledge-base content, or meeting content.
  • Resend — transactional email delivery, including account welcome messages, privacy-request notifications and confirmations, and content-report notifications. Resend receives the recipient email address and the content and delivery metadata of those messages; a privacy request or content report may include the contact information, context, category, reference identifier, and timestamp you submit.

We require each processor that receives personal data to provide the same or equivalent protection described in this policy, use the data only to provide the contracted service, and delete or return it when it is no longer needed.

We do not sell your personal information. We do not use your audio or transcripts to train machine-learning models.

How we secure information

Verli uses encrypted HTTPS and secure WebSocket connections when data moves between your device and hosted services. Account-linked data is stored with managed providers that protect stored data using encryption and access controls. Access to production systems and personal information is limited to authorized operators and service roles that need it to run or support the Service. Desktop refresh credentials are encrypted with Electron safeStorage, which uses operating-system protected storage such as Windows DPAPI or the macOS Keychain. We review access and delete or restrict data according to the retention and user-control commitments below. No system can be guaranteed completely secure, so contact support@verli.app if you believe your account or data has been compromised.

Retention

Account data is kept for as long as your account is active. Marketing contact data is retained while your account is active or until you unsubscribe, and is deleted when your account is deleted. A minimal suppression record may be retained when necessary to honor an unsubscribe request. Transcripts in share sessions are retained only while the session is live and for a short period after. Public audio and video file translator bilingual text results and job metadata are retained for no more than 24 hours; the source media is not retained by Verli, and Soniox resources are deleted before result delivery. Chrome extension guest-session and handoff metadata is retained for up to 90 days during the pilot; the guest transcript remains only in browser-session storage and is cleared when that browser session ends. Billing records are retained as required for tax and accounting purposes.

Saved meeting transcripts remain in your account until your account is deleted. Turning off Save meeting transcripts prevents future meetings from being saved but does not delete meetings already in History. You can request access, export, or deletion through the privacy-request and account-deletion links below.

Your privacy rights

You can access, correct, port, and delete the personal data we hold about you. Delete your account at any time via account deletion; submit other requests (or download a copy of your data) at privacy requests; or email support@verli.app. Depending on where you live, the rights below may also apply.

European Economic Area, Switzerland, and the United Kingdom (GDPR / UK GDPR)

You have the right to access, rectify, erase, restrict the processing of, and port your personal data, and to object to processing based on legitimate interest or direct marketing. Where processing is based on consent, you have the right to withdraw it. Our legal bases for processing are: (1) performance of the contract to provide the Service, (2) our legitimate interest in operating, securing, and improving the Service, and (3) consent where required by law. You have the right to lodge a complaint with your local data-protection supervisory authority. We do not currently offer automated decision-making with legal or similarly significant effects. We have not designated a representative under GDPR Article 27 (or its UK equivalent); you can exercise your rights directly with us at the contact above.

California (CCPA / CPRA)

California residents have the right to know what personal information we collect, the right to delete it, the right to correct it, the right to opt out of the sale or sharing of personal information, the right to limit use of sensitive personal information, and the right not to be discriminated against for exercising these rights. Verli does not sell personal information and does not share personal information for cross-context behavioral advertising. California residents under 18 may also request removal of content they posted; contact us as described above. The "Shine the Light" law (Civil Code §1798.83) gives California residents the right to request information about disclosure of personal information to third parties for direct-marketing purposes — we do not engage in such disclosures.

Brazil (LGPD)

Data subjects in Brazil have the right to confirmation of processing, access, correction of incomplete or inaccurate data, anonymization or deletion of unnecessary or excessive data, portability, information about entities with which we share data, and revocation of consent. Submit requests via the contact above.

Canada (PIPEDA)

Individuals in Canada have the right to access and challenge the accuracy of personal information we hold about them. Complaints may be directed to the Office of the Privacy Commissioner of Canada (priv.gc.ca).

Australia (Privacy Act / Australian Privacy Principles)

Australian residents have the right to access and seek correction of personal information. Complaints may be directed to the Office of the Australian Information Commissioner (oaic.gov.au).

To delete your account, see account deletion. To download a copy of your data or submit any other privacy request, see privacy requests. We aim to respond within 30 days for GDPR / UK GDPR / LGPD / PIPEDA / Australia requests and within 45 days for CCPA / CPRA requests, with shorter timelines where law requires. Because privacy requests on these pages are submitted while signed in, no further identity verification is needed.

Children

Verli is not directed to children under 13 (or the equivalent minimum age in your jurisdiction). We do not knowingly collect information from children.

International transfers

Your data may be processed in the United States and other countries where our processors operate. Where required, we rely on standard contractual clauses for cross-border transfers.

Changes to this policy

We may update this policy from time to time. Material changes will be posted on this page with an updated “Last updated” date.

Contact

Questions about this policy? Email support@verli.app.