Privacy Policy
Last updated: August 2026
Verso is an AI writing studio that drafts LinkedIn posts grounded in your own work. This policy explains what we collect, why, who we share it with, and how you stay in control. We have written it to be read, not to hide behind.
Who we are
Verso is operated by Wasim Asghar, a sole trader established in the United Kingdom, trading as “Verso”. Wasim Asghar is the data controller responsible for your personal data under the UK GDPR. You can contact us by post at Lytchett House, 13 Freeland Park, Wareham Road, Poole, Dorset, BH16 6FA, United Kingdom or by email at privacy@versovoice.com.
What we collect
- Account data: your name, email and authentication credentials (passwords are hashed with scrypt; we never store them in plain text), plus optional Google or LinkedIn sign-in identifiers.
- Content you create or upload: chat messages, generated posts, and the documents you add to your knowledge base.
- Speech, if you use it: when you dictate or hold a live voice call, your microphone audio is processed to turn it into text. It is streamed to the speech providers named under “Who we share it with” below, and is never stored by Verso; what we keep is the resulting text, saved as ordinary content exactly as if you had typed it.
- Derived data: a writing voice profile and durable memory (preferences, corrections, facts) distilled from your content to personalize generations. (“Voice profile” here means your writing style, not a recording of your speech.)
- Usage and cost records: per-request token counts and cost, used for your dashboard and quotas.
- Technical and security data: your IP address is recorded in a security audit log for specific actions: uploading, deleting or retrying a knowledge-base document (including one built from a guided interview), connecting, disconnecting, syncing or rescoping a connector or overriding what it may sync, uploading a guardrails document, and a payment-webhook request that fails our signature check. Signing in itself is tracked in your session record instead, which is deleted along with your account rather than kept in this log. Audit log entries about a deleted account are de-identified rather than deleted (the link to you is removed, the entry itself stays), so we can still investigate abuse and defend the account afterwards if we ever need to. We rely on our legitimate interest in keeping the service secure for this.
How we use it
We use your data to operate the product: generating drafts in your voice, grounding them in your knowledge base, metering cost, and securing your account. We do not sell your data, and we do not use your content to train our own models.
Legal basis for processing
UK GDPR asks us to say which legal basis covers each use of your data. Delivering the product itself, generating drafts, storing your content, running your dashboard, rests on performance of our contract with you. Keeping the service secure, preventing abuse, and improving the product, including the security audit log above, rests on our legitimate interests, weighed against your right to privacy. Where we ask for it separately, for example the launch updates described below, we rely on your consent, which you can withdraw at any time without affecting the rest of your account.
Encryption
Your most sensitive fields, knowledge-base content, voice profile, learned memory and conversation summaries, are encrypted with AES-256-GCM on our server before they are written to the database, using a key that is not stored in that database. Transport is protected with TLS.
Who we share it with
We rely on a small set of sub-processors to deliver the service. They receive only what is needed to perform their function. See the full list on our sub-processors page. In short: your prompts and relevant context are sent to our AI provider to generate text; text is sent to an embeddings provider to make your knowledge base searchable; billing details are handled by our payments provider; and transactional email is sent through our email provider. If you dictate or use a voice call, the audio you speak, its transcript, and the reply spoken back to you are sent to our speech provider; and because live dictation uses your browser’s own speech recognition, your browser vendor (Google in Chrome, Microsoft in Edge) also receives that audio directly from your device. If you contact us, through the public contact form or the in-app feedback widget, your message is also shared with our AI provider so it can be sorted automatically before a person reads it.
Most of the providers on our sub-processors list operate in the United States. Where that is the case, the transfer is covered by the UK International Data Transfer Addendum (or the UK Extension to the EU Standard Contractual Clauses), the standard safeguard for sending personal data outside the UK, which each of those providers has agreed to. This does not cover your browser vendor: when live dictation sends audio straight from your device to Google or Microsoft, as described above, that happens outside our control, under that vendor’s own privacy policy rather than ours.
Retention and deletion
We keep your data for as long as your account is active. You can export a full copy at any time, and you can permanently delete your account from Account settings. Deleting your account erases your personal data and any workspace where you are the only member; cost-ledger rows kept for accounting are de-identified. Encrypted fields become unrecoverable once their rows are removed.
Cookies and local storage
Verso sets only first-party cookies that are strictly necessary to run the service. There is no advertising cookie, no third-party tracker and nothing that follows you to other websites, which is why the notice you see on your first visit tells you what we do rather than asking you to opt in: under the Privacy and Electronic Communications Regulations, strictly necessary storage does not need your consent, but you are still entitled to be told about it. Here is everything we put on your device.
- Sign-in cookies: set by our authentication library when you log in, so the site knows it is still you as you move between pages. Deleting them signs you out. Without them you cannot use an account at all.
- Preference storage: small values kept in your browser's local storage to remember choices you made yourself, such as light or dark theme, whether interface sounds are on, and which one-off notices you have dismissed. These never leave your browser and we never read them on our servers.
- Audience measurement: we count page views through Vercel Web Analytics, which does not use cookies, does not store an identifier on your device and cannot follow you across other sites. It tells us how many people visited a page, not who they were.
You can clear or block all of this in your browser settings at any time. Blocking the sign-in cookies will stop you being able to log in; nothing else here is needed for the site to work.
Your rights
Depending on where you live (including under GDPR and CCPA), you have the right to access, export, correct and delete your personal data, and to object to certain processing. You can exercise access, export and deletion yourself from Account settings; for anything else, contact us at privacy@versovoice.com. You also have the right to complain to the UK’s data protection regulator, the Information Commissioner’s Office (ICO), at ico.org.uk or through their helpline, though we would rather have the chance to put things right first.
Launch updates
The footer on our site lets you leave your email for occasional launch updates. We only use it for that, and only if you tick the box to opt in when you leave your address; visiting the site or reading a page never signs you up on its own. The legal basis is your consent, which you can withdraw at any time by emailing privacy@versovoice.com and asking to be removed.
Connecting your LinkedIn account is optional. If you connect it, we store the access token LinkedIn issues (encrypted at rest) and use it for one purpose: publishing the posts you explicitly choose to publish, through LinkedIn's official API. Verso never posts without your action and does not scrape LinkedIn. You can disconnect your LinkedIn account at any time from Settings, and you are responsible for what you choose to post.
Changes
If we make material changes to this policy we will update the date above and, where appropriate, notify you. Questions: privacy@versovoice.com.