Legal

Privacy Policy

Your readings are yours. Last updated: September 2026.

Who is in control of your data

Shefa Group, trading as Velora, is the data controller for the personal data described in this notice. We are responsible for deciding how and why your data is used.

What we collect

Account data: email address, optional first name, and authentication details.

Reading data: the topic, deck, spread, question, optional context, and the generated reading content you create.

Journal data: notes, favourites, and any content you add to your readings.

Membership data: subscription status, payment history, and Paddle customer identifiers.

Technical data: device type, browser, approximate location, pages visited, and aggregate usage data.

Why we collect it and the legal basis

To provide the service: create your account, generate and store readings, and save your journal (contract performance).

To process your membership: billing, renewals, cancellations, and support (contract performance and legitimate interests in running the business).

To improve the product: understand which features are used and fix issues (legitimate interests, kept in aggregate where possible).

To keep the service secure: detect fraud, abuse, and unauthorised access (legitimate interests and legal obligation).

To communicate with you: important service updates, replies to support, and optional product news (contract performance and consent for marketing, where required).

What we never do

We do not sell your data. We do not share the content of your readings with advertisers or third parties. We do not use the personal details inside your questions for marketing.

Who processes data on our behalf

Hosting and database provider: stores your account and readings.

Paddle.com: acts as the Merchant of Record for all orders, processing payments, billing, tax, invoicing, subscription management, and refunds. Paddle is a data processor for transaction-related data.

AI provider: processes the text of a reading request in order to generate it. That text is not used to train public models.

Analytics and support tooling: help us understand aggregate usage and respond to your questions.

Professional advisers: legal and accounting professionals, bound by confidentiality, when required.

Authorities: where we are required by law to disclose information.

International transfers

Some of our providers are based outside the UK/EEA. Where data is transferred internationally, we rely on appropriate safeguards such as Standard Contractual Clauses or adequacy decisions approved by relevant regulators.

How long we keep it

Your account and readings are kept until you delete them or close your account. When you close your account, personal data is removed or anonymised within 30 days, except where we must keep records for tax, legal, or fraud-prevention reasons. Backup copies may be retained for a limited period beyond that.

Your rights

You may request access to, correction of, or deletion of your data at any time through your account settings or by contacting us. If you are in the UK or EEA you also have the right to restrict processing, object to processing, request data portability, withdraw consent, and complain to your local data protection authority. We respond to requests within one month.

Cookies

We use only the cookies required to keep you signed in and to measure aggregate usage. No advertising trackers.

Security

Access to your readings is enforced at the database level so only your account can read them. Connections are encrypted in transit. We review access controls regularly.

Contact

Privacy questions can be sent through our contact page and are answered within two working days.