Privacy policy
What VerLake collects when you visit verlake.com or use the app at app.verlake.com, why we collect it, who we share it with, and how to ask us to change or delete it.
VerLake is in beta. Some of the features and privacy and compliance measures described in this policy are still being built and will be added in the coming weeks. We will update this page as they go live. If you have a question about how something works today, email info@mindslake.com.
Who we are
VerLake is a synthetic monitoring service operated by Mindslake ("we", "us"). This policy covers the website verlake.com, the app at app.verlake.com, public status pages hosted by VerLake, and the VerLake MCP connector. Questions go to info@mindslake.com.
What we collect
When you create an account
- Sign-in details. Your name, email address and profile picture from Google or GitHub when you sign in with them, or your email and a hashed password if you use one.
- Organization details. Your organization's name, time zone, plan and the people you invite to it, with their roles.
When you use the app
- What you configure. Projects, monitors, Playwright scripts, schedules, alert settings, status pages and connected Git repositories.
- Environment variables and keys. Values you store for your monitors (for example test-account passwords), your organization's AI API key, and personal access tokens. We use them only to run your monitors and features you turn on.
- Run results. For each run: status, timings, the steps, console output, errors, and screenshots or video from test runs in the editor. These can contain whatever your monitored pages show, so point monitors at test accounts and test data.
- Usage and billing. Execution-seconds used, plan and payment status. Card details are entered on Stripe's checkout page and never reach our servers.
Status page subscribers
If you subscribe to a status page hosted on VerLake, we store your email address so the page owner's incident updates can reach you. The organization that runs the status page decides what it publishes there.
When you visit the website or app
- Analytics. We use Google Analytics to count visits and see which pages and features people use. It records pages viewed, buttons clicked (for example "Start free"), the site you came from, approximate location, device and browser. Inside the app we attach your internal user and organization IDs, never your name or email.
- Advertising measurement. We use the Google Ads tag to learn which of our ads lead to sign-ups and purchases, and to show our ads again to people who visited our site.
- Server logs. Our servers record IP addresses, request times and errors, to keep the service secure and working.
Cookies
The app keeps you signed in with a token stored in your browser. Google Analytics and the Google Ads tag set cookies (for example _ga and _gcl_au) on verlake.com and app.verlake.com. In the European Economic Area, the United Kingdom and Switzerland these cookies stay off unless you agree to them. You can also block them in your browser settings, or use Google's Analytics opt-out add-on and My Ad Center.
How we use it
- To provide the service: run your monitors, send alerts, show results, publish your status pages and bill for usage.
- To keep accounts secure and stop abuse.
- To understand how people find and use VerLake, and to improve it.
- To measure our own advertising.
- To contact you about your account, billing and changes to the service.
We do not sell your personal data, and we do not use your monitor scripts, run results or stored values to train AI models.
Who we share it with
We share data only with the providers that run parts of the service for us, and only what each one needs:
| Provider | What for |
|---|---|
| Amazon Web Services | Hosting, databases and the machines that run your monitors (Mumbai region) |
| Sign in with Google, Google Analytics, the Google Ads tag | |
| GitHub, Bitbucket | Sign in with GitHub, and the repositories you connect |
| Stripe | Payments and invoices |
| Anthropic | The AI assistant and AI failure summaries, using your organization's own API key. Only the content you send to the assistant, or the failed run being summarized, is sent. |
| Our email provider | Alert, invitation and status page emails |
We may also disclose data when the law requires it, or to protect the security of the service and its users.
Where we keep it, and for how long
Data is stored on Amazon Web Services in the Mumbai (ap-south-1) region. Some of the providers above process data in other countries, including the United States. We keep account data while your account is active. Run history is available for your plan's history period.
Security
Traffic is encrypted in transit, passwords are stored hashed, and access to production systems is limited to the people who run the service. No system is perfectly secure. If we learn of a breach that affects your data, we will tell you and the relevant authorities as the law requires.
Your choices and rights
You can see and change most of your data in the app. You can ask us to give you a copy of your personal data, correct it, delete it, or stop using it for analytics or advertising. Depending on where you live (for example under India's Digital Personal Data Protection Act or the EU and UK GDPR), you may have further rights, including the right to complain to your data protection authority. Email info@mindslake.com and we will reply within 30 days.
If you use VerLake on behalf of an organization, that organization controls the data in its account, and some requests have to come from its owner or admins.
Children
VerLake is a tool for businesses and is not meant for anyone under 18.
Changes to this policy
When we change this policy we update the date at the top. If a change materially affects how we use your data, we will tell account owners by email before it takes effect.
Contact
Mindslake, India. Email info@mindslake.com for privacy questions, requests and grievances.