Verbatm

Privacy Policy

Version 2026-07-13 · Effective July 13, 2026

This Privacy Policy explains how Verbatm (“Verbatm,” “we,” “us”) collects, uses, shares, and protects information when you use the Verbatm service (the “Service”) — a voice-first AI assistant for your CRM and connected business systems. It applies to individual users and to the workspaces (organizations) they belong to. By using the Service you agree to this Policy.

1. Information we collect

  • Account information. Your email, name (if provided), authentication identifiers, and — for Google sign-in — the basic profile Google returns.
  • Workspace information. Workspace names, membership, and role assignments (owner, admin, member).
  • Voice and command data. Audio you record to issue a command, the transcript produced from it, the command you type, and the results and AI responses generated in return.
  • Connected-system data. Data fetched on your behalf from systems you connect (for example, Salesforce records, contacts, opportunities, or accounting data) to answer a command or propose a change.
  • Connector credentials. OAuth access and refresh tokens for the systems you authorize, stored encrypted (see §5).
  • Billing information. Subscription plan and status. Payment card details are handled by Stripe; we do not store card numbers.
  • Usage, audit, and technical data. Audit log entries for privileged actions (CRM/accounting writes, OAuth events, ownership transfers), usage counts for plan limits, and standard technical logs (IP address, timestamps, error diagnostics).
  • Acceptance records. The version and time you accepted these terms.

2. Voice and AI processing

When you speak a command, your audio is sent to our transcription subprocessor (Groq Whisper) and converted to text. Verbatm does not retain the audio after transcription — it is processed in transit and discarded. The resulting transcript is then processed by a large language model to understand your intent and, where a change is proposed, to draft it for your confirmation.

We log command transcripts and their results (in our voice_sessionsrecords) so the Service can be operated, debugged, secured, and audited, and so you can review your own history. These records are retained per your workspace's settings and its plan.

3. How we use your information

We use the information above to operate and secure the Service, transcribe and interpret your commands, execute the actions you confirm against your connected systems, enforce plan limits, provide support, process payments, and meet legal obligations. We do not sell your personal information, and we do not use your data or your connected-system data to train AI models.

4. AI subprocessors

Transcripts and the minimum context needed to fulfil a command are sent to the AI provider configured for your workspace. Transcription always uses Groq. Language-model processing uses Groq by default, and — depending on your workspace configuration — may use Google, Anthropic, OpenAI, or DeepSeek. Text-to-speech replies, when enabled, are generated by a speech provider (such as Cartesia, Microsoft Azure, or OpenAI). These providers process data to return a result to us; we instruct them not to use it to train their models, subject to their own terms.

5. Connected systems & data minimization

You can connect Salesforce, HubSpot, QuickBooks, Gmail, Outlook, Slack, and Google Calendar. The OAuth tokens for these connectors are encrypted at rest with AES-256-GCM and decrypted only in-memory on the server when a command needs them. We fetch data from connected systems on demand to answer your commands — we do not maintain a bulk copy of your CRM. Before any data is included in a prompt to an AI provider, it is capped and minimized to what the command requires.

6. Confirm-before-write

Verbatm does not silently change your systems. Every write is presented to you as a field-by-field preview and executed only after you confirm it. You remain responsible for the changes you confirm to your own systems.

7. Infrastructure & other subprocessors

  • Vercel — hosts the application front end and server functions.
  • Railway — hosts our Postgres database, authentication, and Redis cache.
  • Stripe — processes subscription billing.
  • Resend — sends transactional email.
  • Sentry — error and performance monitoring (when enabled).
  • PostHog — first-party product analytics (when enabled).
  • Groq and the AI/speech providers listed in §4.

8. Cookies

We use only the cookies needed to keep you signed in and to remember your active workspace. We do not use advertising cookies or cross-site tracking, and we do not sell cookie data.

9. Data retention

Recorded audio is discarded after transcription. Command transcripts, results, workspace data, and audit records are retained for the life of your account and your workspace's configured retention, and are deleted within 30 days of account or workspace deletion, except records we are required to keep for legal, security, or accounting reasons.

10. Security

We encrypt connector tokens at rest (AES-256-GCM), serve all traffic over TLS, scope data access by workspace and role, and log privileged actions to an append-only audit trail. No system is perfectly secure, but we work to protect your information using industry-standard measures.

11. Workspace roles & member controls

Data in a workspace is shared with that workspace according to member roles. Workspace owners and admins can manage membership, connectors, and settings, and can request export or deletion of workspace data. If you joined a workspace created by your employer or team, that organization administers your use of the Service within it.

12. Your rights

Subject to applicable law, you may request access to, correction of, deletion of, or a portable copy of your personal data, and you may object to or ask us to restrict certain processing. To exercise these rights, or to delete your account, contact us at hello@verbatm.ai. We honor these requests regardless of where you live.

13. International users

Verbatm serves users in India and around the world. Your information may be processed in countries other than your own, including by the subprocessors named above. We apply this Policy wherever your data is processed.

14. Children

The Service is intended for business use by adults. It is not directed to anyone under 18, and we do not knowingly collect their data.

15. Changes to this Policy

We may update this Policy. When we make material changes we will post the new version here with a new version identifier and effective date, and — where the changes are significant — ask you to re-accept before you continue using the Service.

16. Contact

Questions or requests? Email us at hello@verbatm.ai.