Velo
ProductUse casesPricingResources
Sign inStart a review

Legal

TermsPrivacyAcceptable useCopyrightSubprocessors
Version
2
Effective
Aug 25, 2026
Publisher
Meridian Studios

Current policy

Subprocessor Registry

The required and optional providers that process data while operating Velo.

1. About this registry

Meridian Studios uses a limited set of service providers to operate Velo. A subprocessor processes personal information on Meridian's behalf. This registry describes the providers currently built into Velo, their purpose, the data involved, and whether the provider is required or optional. Questions about a provider or transfer may be sent to legal@meridianproject.studio.

Velo's provider interfaces are deliberately narrow so core records remain portable. Changing a provider does not change the creator-reviewer authorization model, immutable release history, attribution contract, or export format.

2. Core providers

Neon
Purpose
PostgreSQL and authentication
Requirement
Required
Data involved
Neon hosts Velo's authoritative relational records and managed authentication for the hosted deployment. Data may include account identity, organization and project membership, invitations, releases, review authorization, comments, tasks, decisions, consent, audit, integration configuration, and legal records. Velo uses restricted roles and PostgreSQL row-level authorization rather than relying on interface visibility alone.
neon.tech/privacy-policy
Vercel
Purpose
Web application and private worker hosting
Requirement
Required
Data involved
Vercel serves Velo's Next.js application, request-time functions, Queue triggers, recovery cron, and private container worker. Data may include request metadata, session traffic, rendered responses, queued job payloads, bounded application logs, and information submitted to web endpoints. PostgreSQL outbox rows remain the durable job authority.
vercel.com/legal/privacy-policy
Cloudflare
Purpose
Private object storage and delivery controls
Requirement
Required for hosted review assets
Data involved
Cloudflare stores source assets, review representations, focused evidence, and exports in private object storage and may process request metadata when delivering authorized objects. Velo uses non-public buckets and short-lived signed access rather than permanent public asset URLs.
cloudflare.com/privacypolicy
Resend
Purpose
Transactional email
Requirement
Required when email delivery is enabled
Data involved
Resend sends invitations, authentication-related messages where configured, review notifications, consent updates, resolution notices, and operational messages. Email bodies are designed not to contain private feedback text. Resend processes recipient and sender addresses, message metadata, content-minimal templates, and delivery events.
resend.com/legal/privacy-policy

3. Optional user-connected providers

GitHub
Purpose
Issue export
Requirement
Optional
Data involved
An authorized user may connect a repository-scoped GitHub App and explicitly export a selected thread, task, or Brand Book finding to an issue. GitHub receives the reviewed payload and repository context. Disconnecting prevents new actions but does not remove issues already created.
docs.github.com/site-policy/privacy-policies/github-general-privacy-statement
Remote MCP servers
Requirement
User selected and optional
Data involved
An authorized user may configure an HTTPS MCP endpoint, approve tools and scopes, review a redacted action payload, and execute the action. The endpoint operator receives only the information included in that approved call, but its own terms and logging practices apply. Velo does not treat an arbitrary MCP server as trusted merely because it is reachable.
Bounded HTTP services
Requirement
User selected and optional
Data involved
An authorized user may configure an HTTPS base URL and specific schema-validated operations. The selected operator receives the approved request data. Velo does not permit arbitrary JavaScript, shell execution, unrestricted URL substitution, private-network destinations, or unbounded responses through this connection type.

4. Provider controls

Velo keeps credentials outside client-readable records, encrypts hosted integration credentials, records approval and execution state, redacts payload previews, limits tools and operations, validates webhook signatures where supported, deduplicates deliveries, and avoids provider-token passthrough. A provider may use its own subprocessors and process data in countries where it operates. Refer to each linked policy for current locations, subprocessors, transfer terms, and retention practices.

Organizations should connect only providers they have reviewed and are authorized to use. Removing an optional connection stops new Velo-authorized disclosures; deletion of data already held by that provider must be requested from the provider or performed through its own controls.

5. Changes

We update this registry before or when a new provider begins materially processing Velo personal information. The page version and effective date identify the applicable registry. If a provider change materially affects required processing or user rights, we will provide additional notice where required. A deployment may replace a core infrastructure provider with an equivalent adapter, but the current hosted provider must be accurately disclosed before handling user data.

6. Contact

Provider, transfer, and privacy questions: legal@meridianproject.studio

Product and account support: support@meridianproject.studio

Product

  • Home
  • Overview
  • Use cases
  • Website feedback
  • Pricing

Resources

  • Help
  • Docs
  • Downloads
  • Extension
  • Security
  • Privacy
  • Accessibility
  • Support

Legal

  • Terms
  • Acceptable use
  • Copyright
  • Subprocessors

Company

  • About
  • Contact
  • Changelog
Velo© 2026 Meridian