Skip to content
Vyrelio
How it worksTrustAboutFAQ
Sign inJoin Vyrelio

Legal

Privacy Policy

Effective: 10 October 2026Last updated: 10 October 2026Governing law: India
On this page
  1. Who we are
  2. What we collect
  3. Why we collect it
  4. Service providers
  5. No sale, no advertising
  6. International transfers
  7. How long we keep data
  8. Your rights
  9. India: DPDP Act
  10. California: CCPA and CPRA
  11. Children and age
  12. Security
  13. Changes to this policy
  14. Contact and complaints

1. Who we are

Soner Private Limited runs Vyrelio and decides how your data is used. This one policy applies to everyone, wherever you live.

2. What we collect

  • Account: your email, username, name, password (stored only as a one-way hash), member type, profile photo, and your email preferences.
  • Profile: what you add as a founder, builder or venture, such as company or firm details, headline, interests and links.
  • Verification evidence: the links, numbers and work email you send for a badge, and the result of the review, including the AI model's assessment.
  • Content: posts, media, community activity, needs, bookmarks, connections, admires and the messages you send.
  • Safety records: reports, blocks, warnings, strikes and suspensions.
  • Sign-in and device: the time and IP address of your last sign-in, two-factor settings, and a push notification token if you use the app.
  • Activity: notifications and who viewed your profile.

If you sign in with Google or LinkedIn, we receive the basic details those services share, such as your name, email and photo.

3. Why we collect it

Each purpose has a legal basis. This is the reason the law lets us use the data.

Purpose and legal basis
What we doData usedLegal basis
Run your account and give you the serviceAccount, profile, content, connections, messagesContract
Check evidence for badgesVerification evidence and the review resultContract, and legitimate interests in keeping the network trustworthy
Keep members safe and handle reportsReports, blocks, warnings, strikes, contentLegitimate interests, and legal obligations where they apply
Protect sign-in and prevent abuseLast sign-in time and IP address, two-factor settingsLegitimate interests
Send notices about your accountEmail address, notification settings, push tokenContract
Send optional emails you choseEmail address, email preferencesConsent
Follow the law and handle disputesRecords needed for the matterLegal obligation, and legitimate interests

Where India's DPDP Act applies, we rely on your consent or on the legitimate uses it allows.

4. Service providers

These companies process data for us.

  • Microsoft Azure: hosting, and Azure OpenAI for content and verification checks.
  • Amazon Web Services: S3 file storage for photos and uploaded media.
  • Soner Mail: our main mail service, which sends account and security emails. It is run by Soner Private Limited, our own company.
  • Resend: a backup email service, used only if our main mail service is unavailable.
  • Cloudflare: DNS for our domain.
  • Expo push, with Apple and Google: to deliver push notifications to the app.
  • Google and LinkedIn: if you choose to sign in with them.
  • Have I Been Pwned: when you set a password, we send only a small fragment of its hash to check if it has leaked. Your password is never sent.

5. No sale, no advertising

We never sell your data and we never share it for advertising. We do not use an outside identity-check vendor. The site sets no analytics or advertising cookies (see cookies).

6. International transfers

Our service providers may process data outside your country, including in the United States. Where the law requires it, we use safeguards such as contracts with those providers.

7. How long we keep data

How long each kind of data is kept
DataHow long
Account, profile, posts, messages and connectionsUntil you delete your account.
Verification evidence30 days after a decision, then removed. This is our proposed period and may change before launch.
Strikes and warningsStrikes stop counting after 90 days.
Sign-in detailsOnly the latest sign-in is kept, with your account.
Accounts that never finish verificationWe may close accounts that have not completed verification within 30 days of sign-up. The app shows how many days you have left.
Copies in backupsOverwritten as backups rotate.

8. Your rights

Under GDPR, UK GDPR, CCPA/CPRA and India's DPDP Act, you have these rights. Here is how to use each one.

  • Access: ask for a copy of the data we hold about you. Email privacy@vyrelio.com from the address on your account.
  • Correction: change most details yourself by editing your profile. For anything else, email us.
  • Deletion: use Settings in the Vyrelio app, or email us. See data deletion for the steps.
  • Export: ask us by email for your data in a common file format.
  • Objection: if you do not want us to use your data for a purpose based on legitimate interests, email us and tell us why.
  • Withdraw consent: where we rely on consent, such as optional emails, you can withdraw it at any time in your email preferences or by email. Withdrawing does not affect what we did before.
  • Complain: tell us first (see below). You may also complain to your local data protection authority.

We may ask you to confirm it is you before we act on a request. We aim to reply within one month.

9. India: DPDP Act

If you are in India, the Digital Personal Data Protection Act gives you the rights above, and also the right to nominate another person to exercise your rights if you die or cannot act for yourself. To nominate someone, write to privacy@vyrelio.com.

You can also manage your consent through a Consent Manager registered under the Act, once such services are available.

10. California: CCPA and CPRA

We do not sell your personal information, and we do not share it for cross-context behavioural advertising. We use sensitive personal information only to run the service you asked for. California residents can ask to know, correct or delete their information by writing to privacy@vyrelio.com. We will not treat you worse for using these rights.

11. Children and age

Vyrelio is for people aged 18 and over. We do not knowingly collect data from anyone younger. If you think someone under 18 has joined, tell us and we will remove the account.

12. Security

Passwords are hashed. Connections to the service use HTTPS. You can turn on two-factor authentication. No system is perfectly secure, so please use a strong, unique password.

13. Changes to this policy

We may update this policy. The date at the top of the page shows when it last changed. When a change is material, we will tell members by email or in the app before it applies.

14. Contact and complaints

Privacy questions: privacy@vyrelio.com. Complaints go to our Grievance Officer, see grievance.

Who we are

Company
Soner Private Limited
Email
privacy@vyrelio.com
TermsPrivacyCookiesCommunity guidelinesData deletionGrievance

Product

  • How it works
  • Founders
  • Builders
  • Ventures
  • Trust
  • Download

Company

  • About
  • FAQ
  • Contact

Legal

  • Terms
  • Privacy
  • Cookies
  • Community guidelines
  • Data deletion
  • Grievance

© 2026 Soner Private Limited. All rights reserved.

Vyrelio is a product of Soner Private Limited, India.