Security & data
Straight answers in one place: where the data is, who processes it, how we use AI, what you can export and what we don't have yet. We only describe what works today.
Last reviewed: 28 September 2026
Where the data is
- The database (Google Cloud Firestore) runs in the eur3 multi-region in the European Union.
- Files are stored in Google Cloud Storage, in the EU multi-region.
- Server functions run in the europe-west1 region in Belgium.
- The database is backed up once a week, on Sunday. Each backup is kept for 60 days, also in eur3.
How we protect data
- Connections are encrypted (HTTPS). Google Cloud also encrypts data at rest in the database, in files and in backups.
- Permissions are checked by the database's security rules on the server, not just by the app's screens. The same rules keep different organizations' data apart.
- You sign in with a password, a Google account or a one-time code sent by email.
- You can encrypt selected attendance list fields with your own password. We don't store it and can't recover it, so losing it means losing access to those fields.
- We don't collect or store payment card details: payments are handled by Stripe.
Who else processes data
- Google Cloud and Firebase: sign-in, database, files, server functions and hosting.
- Google Workspace: email sent from Verbalu.
- AI model providers: Google (Gemini), OpenAI and Anthropic. Details in the next section.
- Stripe: payments and invoices on paid plans.
- Google Analytics, Hotjar and Google Ads: their cookies are set only after you consent in the cookie banner.
- We don't sell personal data or share it with anyone for their own marketing.
- Some providers belong to US groups and may process data outside the EEA. Such transfers rely on the EU-U.S. Data Privacy Framework or on standard contractual clauses approved by the European Commission.
Artificial intelligence
- Content reaches an AI model only when someone uses an AI feature, for example to generate a quiz from a file. Features that run on their own, such as automatic review of a written assignment, are switched on by the organizer.
- Text is generated by one provider that we choose for the whole service: Google Gemini, OpenAI or Anthropic.
- A few features always use the same provider: images and AI search run on Google Gemini, and transcription of a recording in “Session Recap” runs on OpenAI.
- We don't train AI models on your content, and the providers don't use it to train theirs.
- “Session Recap” recordings never go into the service's file storage: the audio passes through a server function, and from then on we work with the text only.
Participants
- They join with a code, a link or a QR code, without creating an account.
- In a quiz, survey or game, a name or nickname is enough. We store it with their answers and score.
- An email address appears only where it's needed, for example on a training sign-up page. In a course it can be given, but it's optional.
- Only the attendance list collects a handwritten signature and the location at the moment of signing, and only when the organizer turns these options on.
- Session data and participant results stay until the organizer deletes them.
Who is responsible for the data
- Verbalu is run by Octigo sp. z o.o. of Wrocław, Poland (KRS 0000360836). Octigo is the controller of trainer and organizer account data.
- The session organizer is the controller of participant data. Verbalu processes it on their instructions, as a processor (Article 28 GDPR).
- Organization owners can download the data processing agreement (DPA) template in the app: open “Organization”, then the “Compliance pack” tab. Anyone else can get it on request.
- The same place has a FERPA addendum, the HECVAT Lite questionnaire, an accessibility report and a description of integrations, in three languages, as PDF downloads.
- We pass participants' requests about their data on to the organizer and help them handle those requests.
Export and leaving
- You can export results on every plan, including the free one: quiz reports to Excel, attendance lists to Excel and PDF, and survey and course results to CSV.
- You can download the whole knowledge base as a ZIP of Markdown files, and a single article as PDF, DOCX or Markdown.
- “Design Studio” designs save as PNG, PDF, PPTX or DOCX (pages as images), whiteboards as PDF and PNG, and whiteboard notes as CSV.
- There is no separate export of quiz questions today (the session report shows them only as statistics), and no export of a whole account at once.
- If you cancel a paid plan, the account goes back to the free plan and nothing is deleted. Free plan limits apply only to new actions, such as inviting a person, uploading a file or a participant joining a session.
- The monthly AI credit allowance ends with the plan; credit packs you bought stay.
- You can ask us to delete your account and data at any time at hello@verbalu.com. There is no button in the app that does it automatically today.
Accessibility
- We aim to meet WCAG 2.1 at level AA.
- Organization owners find the accessibility report (an ACR in the VPAT 2.5 format) in the app, in the “Compliance pack” tab. It is our own assessment, not an external audit, and it lists the known gaps too.
What we don't have yet
- Single sign-on (SAML, OIDC) or enforced two-factor authentication (2FA). When you sign in with a Google account, that account's protections apply, including 2-Step Verification if it's turned on.
- An ISO 27001 certificate, a SOC 2 report or an external penetration test. The Google Cloud infrastructure we run on has its own certificates and reports.
- Backups more often than once a week, or a choice of the region where data is stored.
Report a security issue
Spotted a vulnerability, or is something worrying you? Write to us:
The same address handles personal data matters. We have not appointed a data protection officer.
