1. What we collect
- Account information, through our authentication provider: email address, authentication identifiers, sign-in events, and the record of which version of the Terms you accepted and when.
- Billing information: your credit balance and transactions, and payment records processed by our payment processor, Stripe. We do not store card numbers.
- Usage records: per-request metadata in our ledger (the tool called, credits charged, request identifiers, timestamps) and rate-limit events. Our code stores no IP addresses; our hosting provider keeps its standard request log (method, path, status) for its own short retention, as described in the Data Handling Statement.
- Verification records: the structured results of your requests (citations found, verification labels, evidence excerpts, audit entries), retained for you as described in the Data Handling Statement.
- Customer Content in transit: documents and text you submit are processed to produce results and are not stored as documents.
- Website visits to the public pages, as described in section 2. The signed-in console loads no analytics.
We do not collect information from consumers who are clients of our customers. If Customer Content contains third-party personal information, our customer is responsible for having the right to process it.
3. How we use information
To provide, secure, meter and bill the Service; to prevent abuse and fraud; to comply with law; to communicate service notices; to understand which public pages are useful; and to produce aggregate, de-identified service metrics. We do not train machine-learning models on Customer Content, and we do not sell personal information or share it for cross-context behavioral advertising.
5. Retention
Account records, including your Terms-acceptance record: for the life of the account. Billing and usage rows: retained as financial records, for at least seven years. Verification records: 90 days in the live database, then moved to encrypted object storage operated by our hosting provider, from which they remain retrievable through the verification-log API for as long as you hold access; on request to support@verdict.io we delete their content, keeping the billing row our retention obligations require. Hosting-provider request logs: held by the provider for its standard short retention and not exported by us.
6. Security
Encryption in transit; access tokens bound to our service; per-tenant isolation enforced at the query layer; secrets in a managed secret store; a billing and audit ledger whose rows are never deleted. No method is entirely secure; we will notify affected customers of a breach as required by law. Security reports go to security@verdict.io, per our security.txt.
7. Your rights and choices
You may access, correct, export or delete your account information and verification records by writing to support@verdict.io from your account’s email address. Depending on where you live, you may have statutory rights to access, deletion, correction and portability; we honor verified requests regardless of jurisdiction and do not discriminate for exercising them. Analytics choices are described in section 2: Global Privacy Control is honored everywhere, and Cookie preferences in the footer lets you withdraw or give consent at any time.
California residents. Verdict does not currently meet the thresholds that make a company a “business” under the California Consumer Privacy Act: annual gross revenue above the adjusted statutory threshold, personal information of 100,000 or more California consumers or households a year, or half of revenue from selling or sharing personal information. We do not sell or share personal information, and we honor the browser Global Privacy Control signal. If we become subject to the Act we will update this policy and provide the notices it requires; until then, the rights in this section are offered to everyone regardless.
8. Visitors in the EEA, UK and Switzerland
If you visit from the European Economic Area, the United Kingdom or Switzerland, analytics cookies are not set unless you accept them through the banner; declining is one click, and the site works identically either way. The strictly necessary cookies in section 2 are set without consent because the console cannot function without them.
The Service is offered to legal professionals in the United States and is not directed at the EEA, the United Kingdom or Switzerland; data is processed in the United States. If the GDPR or the UK GDPR nonetheless applies to you, our legal bases are the performance of our contract with you (your account, billing and verification records), our legitimate interests in securing and improving the Service, and your consent for analytics cookies. You have the rights of access, rectification, erasure, restriction, portability and objection, exercisable by writing to support@verdict.io, and the right to complain to your supervisory authority. We have not appointed a representative in the Union or the United Kingdom because our processing of data from those places is occasional and low-risk.
9. Children
The Service is for professionals aged 18 and over. We do not knowingly collect children’s information.
10. Changes and contact
Material changes will be announced through the Service or by email at least 14 days in advance. Contact: support@verdict.io. VERDICT, LLC, 1207 Delaware Ave 4588, Wilmington, DE 19806.