The short version of what Veridex collects, stores, and does with the data you hand us — written in plain language, not legal jargon.
The short version
1 · What we collect
We split this into two buckets because the answer is genuinely different.
Just standard HTTP access logs the hosting platform writes for every web property. Nothing about you is added on our side.
The signup form asks for: name, email, and password (stored hashed, never in plain text). An optional avatar image can be attached. Email is flagged as verified the first time you confirm it.
When you sign in, the platform also stores a session cookie plus the IP address and browser user-agent that the session was created from. That row expires automatically when you log out, and we use it only to recognise you across pages and to keep your account secure.
2 · How scan data is processed
When you run a check the input you pasted is scored against a server-side set of weighted rules — DNS lookups, certificate state, sender authentication records, an offline brand-impersonation list, and a lexicon of pressure language. The rules do the work; there is no human reviewer looking at your messages and no large language model summarising them. We do not connect to your mailbox, do not crawl links from your browser history, and do not require any browser extension.
The brief scoring step finishes in the time it takes to load a page; the verdict and the matched signals are then written to a private row in your account, visible only to you on your /history page.
3 · What we store from a scan
Every successful scan saves a single row to your account. That row is private — only the signed-in account that ran the check can view or delete it. Results surface on your /history page. There are no public share links. You can delete any result at any time from the history page.
id — the short permalink identifier.kind & target — what kind of check it was (URL, email, text, QR, screenshot) and the input you pasted.score, verdict, trustLabel — the 0–100 Trust Score, the recommendation band, and the human-readable label.topFlags — the red flags that most moved the score, in plain language.createdAt — when the check ran.userId — only set when you are signed in. Blank by default.4 · Data retention
Scan rows persist until you delete them from your Scan history page. Each row has a delete button — deletion is immediate and permanent. We do not quietly remove results you chose to keep, and we never sell or share inputs.
Sign-in sessions expire automatically after a period of inactivity. We do not invent an arbitrary day-count here — the session timer is set by the authentication library we use and applies the same way to every account. You end a session at any time by logging out from your account page.
Account rows are kept while your account is active. If you close your account your name, email, hashed password, and any rows owned by you are deleted together. If you never created an account, there is nothing to close.
5 · Security practices
We don’t promise certifications we don’t hold. The list above is what we actually do today — there is no claim of a third-party audit, penetration test, or compliance framework that hasn’t run.
6 · Your choices
Use the trash icon on your Scan history page to permanently delete individual results. Deletion is immediate. To delete your entire account, email us at veridex-7@polsia.app.
Logging out clears the session cookie from your browser. Re-login starts a new session record; older session rows are kept until they expire.
Scan results are saved privately to your account and are never publicly accessible. Signing in is required to run checks and view your history. To share a Family plan across accounts, sign in with the account that holds the subscription.
7 · Contact
Direct line
veridex-7@polsia.appRelated reading
Effective 2026-07-26 — last updated 2026-07-26