PRIVACY
POLICY.
Effective July 6, 2026. This describes what Verinio actually collects and does, not a generic template.
1. Data we collect
Account info and request history. A hashed IP address only if you attempt to sign in.
- Account data: your email address, a bcrypt hash of your password (never the password itself), and a hash of your API key (only the first few and last 4 characters are ever shown back to you).
- Purchase data: your email, the Stripe checkout/payment session identifiers, credits purchased, amount, and currency. Verinio does not receive or store your card number, expiry, or CVC - Stripe handles and stores that directly.
- Request/usage history: for each API call tied to your account, we log the tool used, credits charged, status, and - for Fetch downloads - the source URL, requested format, and file size. This is retained as your usage and billing history, visible to you on the dashboard.
- Anonymous, no-account use: actions priced at 0 credits can be used without an account or any IP tracking. Actions priced above 0 credits require signing in, at which point they're tied to your account, not an IP address.
- Login attempts: your IP address is salted and hashed (not stored raw) solely to rate-limit repeated sign-in attempts and protect accounts from brute-force login attacks.
- Files and media content: uploaded files (for metadata processing) and downloaded media (for Fetch/Transcript) are processed in temporary storage and deleted immediately afterward. We do not keep a copy of the actual file or media content.
- Cookies: a session cookie identifies you as signed in after login; a separate cookie is used for the admin panel. These are strictly functional (not advertising or tracking cookies) and are required for the dashboard/admin to work.
- Analytics: we may use analytics to understand aggregate site usage (for example, which pages are visited), to improve the Service. This is separate from your account/request data described above.
2. Why we collect it (legal basis)
To run your account and the Service, and where relevant, because you asked us to. We process account, purchase, and usage data to perform our contract with you (providing the Service you're paying for), to maintain security and prevent abuse (rate-limiting, fraud prevention - legitimate interest), and to comply with legal obligations (for example, payment/tax records). Any analytics or optional communications are based on legitimate interest in improving the Service, or your consent where required by your local law.
3. Who we share data with
Stripe (payments) and Resend (transactional email) - that's it. We do not sell your data.
- Stripe processes payments and holds your payment method details directly.
- Resend delivers transactional emails on our behalf (for example, password reset emails), which requires sharing the recipient email address and message content with them.
We do not sell or rent your personal data to third parties, and we do not share your account or usage data with anyone else except as required by law.
4. How long we keep data
Files: deleted immediately. Account/usage history: kept while your account is active, deleted on request. Uploaded/downloaded file content is deleted right after each request completes. Account, purchase, and usage-history records are kept for as long as your account exists, so your dashboard and billing history stay accurate, and for a reasonable period afterward to comply with legal/tax obligations. You can request deletion of your account and associated data at any time (see Section 6).
5. Security
Passwords and API keys are hashed, not stored in plain text. We use industry-standard practices including password hashing (bcrypt), hashed API keys, hashed IP addresses for login rate-limiting, and standard web security headers. No method of transmission or storage is 100% secure, and we cannot guarantee absolute security.
6. Your rights
You can ask to see, correct, export, or delete your data, wherever you are.
- EU/EEA and UK (GDPR/UK GDPR): you have the right to access, rectify, erase, restrict or object to processing, and receive a copy of your data (data portability). You also have the right to lodge a complaint with your local data protection authority.
- California and other US states (CCPA/CPRA and similar): you have the right to know what personal information we hold, to request deletion, and to opt out of the sale or sharing of personal information. We do not sell or share personal information for cross-context behavioral advertising.
- Everywhere else: we'll honor reasonable requests to access, correct, or delete your personal data regardless of where you're located, to the extent practicable.
To exercise any of these rights, email [email protected]. We'll respond within a reasonable time, consistent with applicable law.
7. International data transfers
Verinio's infrastructure and processors (including Stripe and Resend) may process data in countries other than your own, including the United States. Where required, we rely on appropriate safeguards (such as standard contractual clauses) for such transfers.
8. Children's privacy
The Service is not directed at children, and we do not knowingly collect personal data from children under 16. If you believe a child has provided us with personal data, contact [email protected] and we will delete it.
9. Changes to this policy
We may update this Privacy Policy from time to time. The "Effective" date at the top reflects the latest revision. Material changes will be reflected on this page.
10. Contact
Questions about this Privacy Policy or your data: [email protected]. As noted in the Terms of Service, Verinio does not disclose a named operating legal entity or registered address in this document.