Privacy Policy

Privacy Policy

The short version of what Veridex collects, stores, and does with the data you hand us — written in plain language, not legal jargon.

The short version

Three sentences, in plain English.

  1. Scan results are saved privately to your account. Only the signed-in account that ran the check can view or delete its results — there are no public share links. Your results are visible on your /history page.
  2. If you create an account we hold what the signup form asks for: your name, your email, and a hashed password. We never sell or share inputs, and we never read your browsing history.
  3. To delete a result, use the trash icon on your Scan history page — deletion is immediate and permanent.

1 · What we collect

Different things are collected depending on whether you sign in.

We split this into two buckets because the answer is genuinely different.

Anonymous visitors

Just standard HTTP access logs the hosting platform writes for every web property. Nothing about you is added on our side.

Signed-up users

The signup form asks for: name, email, and password (stored hashed, never in plain text). An optional avatar image can be attached. Email is flagged as verified the first time you confirm it.

When you sign in, the platform also stores a session cookie plus the IP address and browser user-agent that the session was created from. That row expires automatically when you log out, and we use it only to recognise you across pages and to keep your account secure.

2 · How scan data is processed

Deterministic rules. No inbox tap. No browsing history.

When you run a check the input you pasted is scored against a server-side set of weighted rules — DNS lookups, certificate state, sender authentication records, an offline brand-impersonation list, and a lexicon of pressure language. The rules do the work; there is no human reviewer looking at your messages and no large language model summarising them. We do not connect to your mailbox, do not crawl links from your browser history, and do not require any browser extension.

The brief scoring step finishes in the time it takes to load a page; the verdict and the matched signals are then written to a private row in your account, visible only to you on your /history page.

3 · What we store from a scan

A small private result row — visible only to the account that ran the check.

Every successful scan saves a single row to your account. That row is private — only the signed-in account that ran the check can view or delete it. Results surface on your /history page. There are no public share links. You can delete any result at any time from the history page.

What the row actually contains

  • id — the short permalink identifier.
  • kind & target — what kind of check it was (URL, email, text, QR, screenshot) and the input you pasted.
  • score, verdict, trustLabel — the 0–100 Trust Score, the recommendation band, and the human-readable label.
  • topFlags — the red flags that most moved the score, in plain language.
  • createdAt — when the check ran.
  • userId — only set when you are signed in. Blank by default.

4 · Data retention

Scan rows persist until you delete them. Sessions expire automatically.

Scan rows persist until you delete them from your Scan history page. Each row has a delete button — deletion is immediate and permanent. We do not quietly remove results you chose to keep, and we never sell or share inputs.

Sign-in sessions expire automatically after a period of inactivity. We do not invent an arbitrary day-count here — the session timer is set by the authentication library we use and applies the same way to every account. You end a session at any time by logging out from your account page.

Account rows are kept while your account is active. If you close your account your name, email, hashed password, and any rows owned by you are deleted together. If you never created an account, there is nothing to close.

5 · Security practices

What we actually do — no fluff, no fake certifications.

  • Hashed passwords. Your password is hashed by the authentication library we use and never stored in plain text. We do not store passwords we can read.
  • HTTPS in transit. Traffic to and from the platform is served over HTTPS so your inputs and session cookies cannot be read off the wire.
  • Environment-managed secrets. The signing key for sessions and the database connection string are stored as platform-managed environment variables and never appear in the application source.
  • Owner-admin only. The only people with operator access to the database are the founding operators of Veridex, scoped to a single administrative role. Administrative actions are recorded.

We don’t promise certifications we don’t hold. The list above is what we actually do today — there is no claim of a third-party audit, penetration test, or compliance framework that hasn’t run.

6 · Your choices

What you can do about your data, and how to do it.

Delete results

Use the trash icon on your Scan history page to permanently delete individual results. Deletion is immediate. To delete your entire account, email us at veridex-7@polsia.app.

Log out

Logging out clears the session cookie from your browser. Re-login starts a new session record; older session rows are kept until they expire.

Results are private by default

Scan results are saved privately to your account and are never publicly accessible. Signing in is required to run checks and view your history. To share a Family plan across accounts, sign in with the account that holds the subscription.

7 · Contact

Write to us.

Related reading

Cross-references

Effective 2026-07-26 — last updated 2026-07-26