Last updated: March 2026 · Compliant with EU GDPR · California CCPA · UK GDPR
This policy explains how VeriflyAI Lda ("VeriflyAI", "we", "our") collects, uses, stores and protects your personal data when you use our Service.
Data Controller: VeriflyAI Lda
Registered: Portugal, European Union
DPO Contact: support@veriflyai.com
Account data: Email address, encrypted password, registration date, plan/subscription status.
Profile data: Usage counters (analyses used, documents generated), preferred language and country, subscription history.
Document content: Text you submit for analysis, answers you provide when generating documents. This content is processed by our AI models and may be temporarily cached for performance. We do not use your document content to train AI models.
Usage data: Pages visited, features used, AI task types, response times, error logs. Collected anonymously for service improvement.
Payment data: Subscription status, billing history. Payment card details are processed exclusively by Stripe — we never see or store your card number.
Technical data: IP address, browser type, device type, operating system, cookies. See our Cookie Policy.
Contract performance (Art. 6(1)(b))
Processing your account data, usage data and document content to provide the Service you signed up for.
Legitimate interests (Art. 6(1)(f))
Fraud prevention, security, service improvement, anonymised analytics.
Legal obligation (Art. 6(1)(c))
Retaining billing records as required by Portuguese/EU tax law.
Consent (Art. 6(1)(a))
Marketing communications (opt-in only). You may withdraw consent at any time.
We never sell your personal data to third parties.
Supabase (Supabase Inc., USA)
Database and authentication provider. Your account data and document history are stored in Supabase. Data stored in EU region (eu-west-1). DPA in place. Privacy Policy
Anthropic, PBC (USA)
AI model provider (Claude). Your document text is sent to Anthropic's API for processing. Anthropic does not use API inputs to train models. Privacy Policy
Stripe, Inc. (USA)
Payment processing. Stripe is PCI-DSS certified and handles all payment data. We never receive your full card details. Privacy Policy
Vercel, Inc. (USA)
Hosting and CDN. Processes request logs containing IP addresses. EU data transfer covered by Standard Contractual Clauses.
Some processors (Anthropic, Stripe, Vercel) are based in the USA. We ensure adequate protection through:
Account data: Retained for the duration of your account plus 12 months after deletion, except where legal obligations require longer retention.
Document content: Retained for the duration of your account. You may delete individual documents at any time from History.
Billing records: Retained for 10 years as required by Portuguese tax law (IRS/IVA).
AI processing logs: Anonymised and retained for 90 days for debugging.
When you delete your account, your personal data is erased within 30 days from our systems, subject to legal retention obligations.
As a data subject under EU GDPR, you have the right to:
Access (Art. 15)
Request a copy of all data we hold about you
Rectification (Art. 16)
Correct inaccurate or incomplete data
Erasure (Art. 17)
Request deletion ("right to be forgotten")
Portability (Art. 20)
Export your data in machine-readable format
Restriction (Art. 18)
Limit how we process your data
Objection (Art. 21)
Object to processing based on legitimate interests
Withdraw consent
At any time, for consent-based processing
Lodge a complaint
With the CNPD (Portuguese DPA) or your local authority
To exercise your rights, email support@veriflyai.com. We respond within 30 days. You may also exercise most rights directly in your account settings.
California residents have additional rights under the California Consumer Privacy Act (CCPA) / CPRA:
To exercise CCPA rights, contact support@veriflyai.com with subject "CCPA Request".
We implement appropriate technical and organisational measures to protect your data:
In the event of a data breach affecting your rights, we will notify you and the relevant supervisory authority within 72 hours as required by GDPR Article 33.
We use essential cookies for authentication and session management. See our Cookie Policy for full details.
VeriflyAI is not directed at children under 16. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, contact us at support@veriflyai.com and we will delete it promptly.
We may update this Privacy Policy from time to time. We will notify you of material changes by email and/or in-app notice at least 30 days in advance. Continued use after changes take effect constitutes acceptance.
Data Protection Officer: support@veriflyai.com
CNPD (Portugal): www.cnpd.pt