Legal · Privacy policy

Privacy Policy

This policy explains how Seedrus LLP, Vora's legal operator and controller where applicable, handles information across Vora's website, app, and AI workflows, including how it is used, shared, protected, and the choices available to you.

Last updated August 2, 2026

Our Data Processing Addendum explains the additional terms that apply when Seedrus LLP processes personal data on a controller's behalf.

Jump to a section
  1. 01Introduction
  2. 02Information We Collect
  3. 03How We Use Information
  4. 04AI Processing and Uploaded Documents
  5. 05Data Protection Roles; Processors and Subprocessors
  6. 06Data Retention
  7. 07Cookies and Tracking Technologies
  8. 08Sharing of Information and Service Providers
  9. 09International Transfers
  10. 10Security
  11. 11User Rights and Choices
  12. 12Children’s Privacy
  13. 13Third-Party Services and Links
  14. 14Changes to this Privacy Policy
  15. 15Contact Us
01

Introduction

This Privacy Policy explains how Seedrus LLP ("we", "our", or "us"), the owner and legal operator of the Vora brand and product ("Vora"), collects, uses, stores, shares, and otherwise processes information when you access or use our website, web application, legal workflow tools, AI-powered features, communications, and related services (collectively, the "Services"). Where applicable, Seedrus LLP is the controller of personal data processed under this Privacy Policy.

We designed Vora as an on-the-go, pocket legal AI assistant for individuals, teams, businesses, founders, in-house counsel, and legal professionals. We aim to be transparent about our data practices so users can make informed decisions about how Vora fits into their operational, compliance, and security requirements.

This Privacy Policy applies to information processed through the Services, including when you browse our website, create an account, upload documents, request AI-generated outputs, purchase credits, contact us, or otherwise interact with Vora.

02

Information We Collect

A. Account Information

When you register for Vora or use account-based features, we may collect information such as your name, email address, phone number if provided, company or organization name if provided, account preferences, and authentication-related information supplied through our login or identity providers, including Google or Microsoft where those sign-in methods are available.

B. Billing and Subscription Information

If you purchase credits or otherwise engage in a billing relationship with us, we may collect credit-pack details, billing address, invoice details, limited transaction metadata, payment status, and records relevant to payment administration. We do not store full payment card numbers where payments are handled by third-party payment processors.

C. User Content

We may process content that you submit to the Services, including prompts, questions, instructions, contracts, uploaded files, documents, clauses, matter details, notes, annotations, generated outputs, and other materials you provide as part of your legal or commercial workflows.

D. Usage and Technical Data

We may collect technical and usage data such as IP address, browser type, device information, approximate location derived from IP, session activity, pages viewed, referring URLs, timestamps, feature usage, diagnostic data, performance analytics, and error or crash logs.

E. Communications

If you communicate with us, we may collect support requests, emails, feedback, survey responses, waitlist submissions, demo requests, partnership inquiries, and other information you choose to share with us.

03

How We Use Information

We use information we collect for legitimate business and operational purposes, including to:

  • Provide, operate, maintain, and improve the Services
  • Process uploads, prompts, and instructions in order to generate requested outputs and workflow results
  • Create and manage user accounts, logins, and workspace access
  • Authenticate users, prevent fraud, detect abuse, and maintain platform security
  • Administer credit packs, billing, invoices, and payment-related workflows
  • Respond to support requests, onboarding inquiries, and other customer communications
  • Send service-related notices, updates, confirmations, and administrative communications
  • Send product news, educational content, and marketing communications where permitted, subject to available opt-out choices
  • Analyze usage trends, performance, reliability, and feature adoption
  • Support enterprise account administration, workspace management, and internal reporting
  • Comply with legal obligations, enforce our terms and policies, and protect our rights, users, and business
04

AI Processing and Uploaded Documents

Vora includes AI-assisted features that may analyze uploaded text, clauses, contract structures, drafting instructions, summaries, risks, and other document characteristics in order to provide the outputs or workflow assistance you request. This includes Contract Review, Chronology Builder, Issues List, and any other document-upload or document-analysis workflow made available through the Services.

When you upload documents or submit prompts to Vora, that content may be processed through our systems and through third-party providers that support the requested functionality, including AI model or API, hosting, cloud infrastructure, storage, database, security, monitoring, and related technical providers. We use this processing as reasonably necessary to deliver the workflow you request, generate outputs, maintain service reliability and security, prevent abuse, troubleshoot problems, and comply with law.

  • You are responsible for ensuring that you have the rights, authority, notices, permissions, and consents needed to upload, share, and instruct the processing of documents or data through the Services, including when acting for an organization, client, counterparty, employee, or other person.
  • AI-generated outputs may contain inaccuracies, omissions, or incomplete reasoning and should be reviewed by a qualified human before use.
  • Vora is software and does not replace professional legal judgment or independent review.
  • Sensitive, confidential, regulated, or privileged information should be uploaded only after you or your organization determine that doing so is appropriate under your internal policies and legal obligations.

We encourage users to apply appropriate internal approval, access control, and review processes when using Vora for important legal, commercial, or operational matters.

05

Data Protection Roles; Processors and Subprocessors

Our data protection role depends on the type of information, the context in which it is submitted, the purposes of the processing, any separate written agreement, and applicable law. References to controller, processor, service provider, and subprocessor in this Privacy Policy are intended to describe those roles where the relevant legal framework uses them.

For documents, prompts, matter information, and other content submitted by or for a user, business, professional practice, or organization ("Customer Content"), the submitting customer generally determines the purposes and means of processing and acts as the controller. Seedrus LLP generally processes Customer Content as a processor or service provider on the customer's instructions to provide, secure, support, and troubleshoot the requested Services. To the extent the customer is a controller and Seedrus LLP acts as its processor, our Data Processing Addendum applies automatically. These roles may differ where the customer does not determine the relevant processing or where applicable law assigns a different role.

Seedrus LLP generally acts as the controller for personal data processed for our own account and service operations, including account registration and administration, authentication oversight, billing and payment administration, security and fraud prevention, support and service communications, legal compliance, and service analytics used to understand and operate Vora.

We use external providers for functions such as AI models and APIs, hosting and cloud infrastructure, storage and databases, authentication and identity, payments, email and service communications, analytics, monitoring and security, customer support, and related technical services. When we act as a processor and a provider processes Customer Content on our behalf, that provider generally acts as our subprocessor. When we act as a controller, providers handling personal data on our behalf generally act as processors or service providers. In limited circumstances, a provider may act independently for processing it determines under applicable law or its own service terms.

Provider categories and specific providers may change as the Services evolve. Where appropriate, we seek contractual, technical, organizational, and legal safeguards suited to the provider, data, and processing involved. Where applicable law or a separate written agreement requires notice of a material provider change, we will provide notice through this Privacy Policy, the Services, or another reasonable channel.

06

Data Retention

We retain information for as long as reasonably necessary to provide the Services, maintain accounts, support business operations, resolve disputes, enforce agreements, comply with legal obligations, preserve security, and maintain backups or logs. Retention periods may vary depending on the type of data, the nature of the Service, technical requirements, legal obligations, and your credit-pack or enterprise arrangement.

If you delete content or close your account, some information may remain in backups, logs, archives, billing records, or security systems for a limited period where reasonably necessary for legal, compliance, fraud prevention, operational continuity, or disaster recovery purposes.

Where we process Customer Content as a processor or service provider, retention and deletion depend on the relevant workflow, the customer’s instructions, any separate written agreement, technical requirements, and applicable law. Where a workflow states that source documents or outputs are not saved as durable Vora workflow records, the content may still be transmitted and processed transiently by our systems and subprocessors to complete the request, maintain security, prevent abuse, troubleshoot failures, or meet legal obligations.

07

Cookies and Tracking Technologies

We may use cookies and similar technologies to operate and improve the Services. These may include essential cookies, authentication or session cookies, security-related cookies, preference cookies, and analytics technologies that help us understand performance and usage patterns.

  • Essential cookies help core functionality work properly.
  • Authentication and session cookies help keep users signed in and maintain session continuity.
  • Security-related technologies help detect abuse, protect accounts, and support platform integrity.
  • Preference cookies may remember settings such as interface choices or experience preferences.
  • Analytics tools, if used, help us understand feature usage, reliability, and product performance.

You can usually control cookies through your browser or device settings. Disabling certain cookies may affect the availability or functionality of some parts of the Services.

08

Sharing of Information and Service Providers

We do not sell personal information in the ordinary course of our business. We may share information only on a limited basis where reasonably necessary to operate the Services, support our business, comply with law, or protect rights and security.

Depending on the circumstances, we may share information with:

  • Infrastructure, cloud hosting, storage, and database providers
  • Authentication and identity providers
  • Payment processors and billing service providers
  • Email, notification, and service communications providers
  • Analytics, logging, and performance-monitoring providers
  • Security, fraud-prevention, and incident-response providers
  • AI model providers, model APIs, and related technical service providers
  • Customer support, communications, and CRM tools
  • Professional advisers such as lawyers, auditors, insurers, or consultants
  • Affiliates or related entities involved in operating or supporting Vora
  • Courts, regulators, law enforcement, or other authorities where required by law or legal process
  • Actual or prospective counterparties in connection with a merger, acquisition, financing, restructuring, asset sale, or similar business transaction

Where appropriate, we seek to use contractual, legal, technical, and organizational safeguards to protect information shared with service providers and business partners. Service providers may act as processors, service providers, or subprocessors as described above; their role depends on the information and processing context.

09

International Transfers

We and our service providers may process information in multiple jurisdictions depending on where our infrastructure, support operations, vendors, or technical systems are located. As a result, information may be transferred to or processed in countries that may have different data protection laws from the country where you are located.

Where required, we use reasonable safeguards intended to support lawful cross-border processing, taking into account the nature of the information, the applicable legal framework, and the providers involved.

Where we process Customer Content as a processor or service provider, international processing may occur to deliver the requested Services using our subprocessors and infrastructure. The allocation of controller and processor responsibilities, any customer instructions, and any additional transfer terms in a separate written agreement continue to apply, subject to applicable law.

10

Security

We use reasonable technical and organizational measures designed to protect information against unauthorized access, misuse, loss, alteration, or disclosure. These measures may include access controls, role-based permissions, encryption where appropriate, monitoring, logging, vendor review, and ongoing operational improvements.

No system, platform, vendor environment, or method of transmission over the internet can be guaranteed to be completely secure. You are also responsible for using appropriate security practices on your side, including strong credentials, device security, user access management, and internal review of what information is appropriate to upload to the Services.

When engaging providers that process personal data on our behalf, we seek safeguards appropriate to the provider’s role, the nature of the data, and the processing risk. These measures reduce risk but do not guarantee that every incident, loss, or unauthorized access can be prevented.

11

User Rights and Choices

Depending on your location and the laws that apply to you, you may have rights regarding your personal information. These may include the right to request access, correction, deletion, restriction, objection, portability, or withdrawal of consent where processing is based on consent.

  • You may request access to certain personal information we hold about you.
  • You may ask us to correct inaccurate or incomplete information.
  • You may request deletion of certain information, subject to legal or operational exceptions.
  • You may opt out of marketing communications using the unsubscribe methods provided in those communications.
  • You may close your account or request account-related assistance through our support channels.
  • You may submit privacy-related requests to hello@seedrus.in.

We may need to verify your identity or authority before acting on a request, and some rights may be limited by law, security needs, technical constraints, or our need to retain certain information for legitimate business or legal purposes.

12

Children’s Privacy

The Services are not intended for children, and we do not knowingly collect personal information from children under the age at which such collection requires parental consent under applicable law. If you believe a child has provided personal information through the Services, please contact us so we can review and address the issue.

13

Third-Party Services and Links

The Services may contain links to third-party websites, tools, integrations, or services, and may depend on third-party infrastructure or providers. Those third parties may have their own privacy notices, terms, and security practices. This Privacy Policy does not apply to third-party services except to the extent we directly control the relevant processing.

We encourage you to review the privacy policies of third-party services you access or connect through Vora before relying on them.

14

Changes to this Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our Services, providers, business operations, legal obligations, or privacy practices. When we do, we will update the "Last Updated" date on this page, and where appropriate we may provide additional notice through the Services or by other reasonable means.

Your continued use of the Services after an updated Privacy Policy becomes effective means that the updated version will apply to your continued use, to the extent permitted by law.

15

Contact Us

If you have questions, concerns, or requests about this Privacy Policy or our data practices, you can contact Seedrus LLP, Vora's legal operator and the controller of personal data where applicable, at:

  • hello@seedrus.in
  • hello@seedrus.com

© 2026 Seedrus LLP. Vora is a brand and product owned and operated by Seedrus LLP.