Skip to main content
Velqa
← Back to home

Privacy Policy

Last updated: July 3, 2026

Data controller

The data controller is Quantyl Core LLC, Velqa's publisher, whose registered office is at 8 The Green, Suite B, Dover, Delaware 19901, United States. For any question about privacy or to exercise your rights, contact [email protected].

Data collected

Velqa collects the information necessary to operate the service: email address and account identifiers, minimal technical logs related to API requests (timestamp, model called, token volume), purchased credit amounts, and billing events. The content of requests and responses passing through the API (prompts and completions) is transmitted to the selected model's provider to generate the response, and is not retained by Velqa beyond processing the request.

Purposes and legal bases

This data is used to provide access to the gateway, secure accounts, track consumption, respond to support requests, and prevent abuse, on the basis of contract performance and our legitimate interest in ensuring the security of the service. We do not resell personal data.

Retention periods

  • Account data: until the account is deleted, which anonymizes personal data immediately;
  • Technical logs (request metadata): rolling 12 months;
  • Billing data: 10 years (accounting obligations);
  • Content of requests/responses sent to models: not retained by Velqa beyond processing the request, with the two exceptions listed below;
  • Sandbox agent conversations (messages, tool output): 30 days, then automatically deleted;
  • Media generated from the Playground (images, audio, video): 7 days on free accounts, up to 90 days on paid plans.

Sub-processors and recipients

Payments are processed by Stripe; Velqa does not store full card numbers. Hosting is provided by OVHcloud (France, EU). API requests are routed to the inference providers of the selected models — today DeepInfra and Novita — in passthrough mode: these providers process content solely to generate the response, without training a model on your data. Also involved: Resend (transactional email delivery), Sentry (application error reports), Google (Google Analytics 4 and reCAPTCHA) and Cloudflare R2 (storage of generated media). Details of roles and contractual guarantees are set out in our Data Processing Agreement (DPA).

International transfers

Some inference providers are located outside the European Union. The corresponding transfers rely on the European Commission's standard contractual clauses (EU 2021/914) or an equivalent mechanism.

Security

We apply reasonable security measures: encryption of data at rest (AES-256) and in transit (TLS 1.3), role-based access control, and immediate revocation of compromised keys from the dashboard. No system offers an absolute guarantee; each user remains responsible for the confidentiality of their credentials and API keys.

Your rights

In accordance with the GDPR (Articles 15 to 21) and, where applicable, Moroccan Law 09-08, you have a right of access, rectification, erasure, portability, objection, and restriction over your data. These rights can be exercised from your account settings or by writing to [email protected] (response within 30 days). You may also lodge a complaint with the CNIL (France, www.cnil.fr) or the CNDP (Morocco).

Cookies

Without consent, Velqa sets only the cookies the service needs: authenticated session, theme preference, language preference, and the cookie recording your choice below. Audience measurement (Google Analytics 4) loads only after you explicitly accept: until then no Google script is called and no measurement cookie is set. A refusal is remembered for six months. No third-party advertising cookie is set.

You can change your mind at any time: .

Page Agent: data and retention

When you enable Page Agent, selected DOM content and prompts are sent to the inference subprocessors required for the service. Session metadata is retained for up to 90 days, usage aggregates for 24 months, and the encrypted idempotency cache for no more than 15 minutes. Business-data masking is opt-in; passwords and card fields are masked by default.