Privacy Policy

How Veridge handles personal information.

This policy describes the public website and private beta messaging service on the web and iOS. It is specific about cloud translation and the limits of current controls.

Effective: September 9, 2026

1. Scope and operator

Veridge is operated by Alex Brooks in an individual capacity. This Privacy Policy explains how Veridge ("Veridge," "we," "us," or "our") handles personal information through the public website and private messaging service on the web and iOS. Questions and rights requests may be sent to support@veridge.io. Any required postal contact details must be confirmed before public launch.

2. Information we collect

Information you provide

  • Email address and identifiers created for authentication.
  • Profile information, including display name, language preferences, interface locale, voice preference, and an optional profile photo.
  • Private conversation content, including text, voice recordings, photos, videos, and message metadata.
  • Support, privacy, deletion, safety, and feedback communications you choose to send.
  • Versioned records of machine-processing permission and Terms and Privacy acknowledgement.

Information created while providing the service

  • Transcripts, translations, synthesized speech, processing status, timestamps, and links between originals and derived artifacts.
  • Opaque account, conversation, message, session, request, and idempotency identifiers.
  • Content-free operational information such as processing stage, provider and model identifier, latency, retry count, error class, and billable units.
  • Limited network and device information necessarily processed by hosting and security providers when you connect.

Information not requested by the current service

Veridge does not request an address book, phone number, precise location, advertising identifier, payment information, or social-media account. The public site contains no advertising or analytics trackers.

3. How we use information

  • Authenticate approved users and maintain secure sessions.
  • Create private one-to-one conversations and deliver messages to authorized participants.
  • Transcribe voice, translate text, and synthesize translated speech.
  • Keep originals available and present machine-generated variants with their status.
  • Prevent duplicate processing, enforce limits, recover failures, and protect the service.
  • Respond to support, privacy, deletion, and safety requests.
  • Comply with law and enforce the Terms of Use.

Veridge does not sell private message content or use it for targeted advertising. Veridge does not use live private messages as reusable model-training or quality-test data unless the sender separately and explicitly chooses that separate use.

4. Cloud processing and providers

The current translation path is cloud-based, not on-device and not end-to-end encrypted. ElevenLabs receives voice content for transcription and translated text for speech synthesis. Direct OpenAI GPT-5.6 models receive transcript or text content for cleanup and translation. These services must process the required content in plaintext to complete the requested task.

Amazon Web Services provides identity, hosting, database, private object storage, queues and workflows, email delivery, and content-free operational monitoring through services including Amazon Cognito, API Gateway, Lambda, DynamoDB, S3, SQS, Step Functions, Amazon SES, CloudFront, AWS WAF, and CloudWatch.

Veridge limits provider requests to the content and technical metadata needed for the relevant stage and does not intentionally add names, email addresses, conversation titles, or unrelated history. Provider terms and configurations differ. This policy does not promise that every provider never retains or uses content beyond processing unless that protection has been verified for the applicable account and service.

We may also disclose information when reasonably necessary to comply with law, protect rights and safety, investigate abuse, obtain professional advice, or complete an organizational transaction. A successor remains subject to this Policy for information collected under it.

5. Retention and deletion

  • Original message content, original media, transcripts, translations, synthesized audio, and other derived conversation artifacts expire after 30 days. Read paths reject expired records while asynchronous physical cleanup completes.
  • Veridge creates no separate long-recording transcription staging copy; provider requests remain task-limited.
  • Content-free application, gateway, and staging-access logs are configured for 30 days. Failed queue jobs may remain up to 14 days.
  • The current browser session is configured for eight hours. Other authentication records have their own security lifetimes.
  • Consent records have a two-year expiry while the account remains active and are included in account deletion.
  • Pending deletion jobs and their recovery receipts remain until cleanup succeeds. A minimal deletion marker and status-only receipt remain for 31 days after completion. Unlinkable abuse-prevention counters expire within their existing lifetimes, up to 24 hours plus one minute; native sign-in request deduplication records expire after ten minutes. These records cannot restore account access.
  • Account and profile information remains while an account is active and for a limited period needed to fulfill deletion, security, fraud-prevention, dispute, or legal obligations.

You may delete individual messages or initiate account deletion in Settings. Account deletion permanently removes all your shared conversations for both participants, including the other person’s messages, photos, videos and audio. It cannot be cancelled after confirmation. Access stops when the request is accepted; cleanup may remain pending. The status screen confirms completion only after active application data and identity cleanup. See account-deletion instructions. Provider records and backups have separate retention limits; we do not promise immediate erasure from those systems. We will explain any applicable legal exception.

6. Logs, analytics, and support

Application logs and operational alerts are designed to contain identifiers, status, timing, counts, and classified errors rather than message content. Veridge does not intentionally place private message text, transcripts, translations, audio, signed media URLs, access tokens, or one-time codes in logs, metrics, notifications, analytics, dashboards, or crash reports.

Do not send private conversation content in an ordinary support email. If a future support process asks for content, it must explain exactly what will be shared and collect only what is necessary.

7. Security

Current controls include TLS transport, encryption at rest, private object storage, server-side conversation authorization, short-lived scoped media operations, authenticated sessions, CSRF protection for mutations, rate limits, and stage-specific cloud permissions. No system is perfectly secure. See the Security page for implemented controls and open limits.

8. International processing

The primary application workload is configured in Amazon Web Services US East (Ohio), us-east-2. ElevenLabs also processes content for its assigned stages, and provider operations or support may involve other countries. Veridge does not make a broader data-residency guarantee.

9. Your choices and rights

Depending on where you live, you may have rights to know, access, correct, delete, or obtain a copy of personal information and to appeal or opt out of certain processing. You may change profile preferences, reveal original content, delete messages, stop using the service, or submit a request to support@veridge.io. We may verify identity before completing a request.

California law provides rights to qualifying residents when coverage conditions are met. Veridge will not discriminate against a person for exercising an applicable privacy right.

10. Adults-only beta

The initial Veridge beta is for adults aged 18 or older. We do not knowingly permit people under 18 to participate. If you believe someone under 18 has provided personal information, contact us so we can investigate and address the account and data.

11. Changes

We may update this Policy when the service, providers, or law changes. We will update the effective date and provide additional notice when required. Public and in-product disclosures must remain consistent with the released service.

12. Contact

Privacy questions and rights requests: support@veridge.io
Product and safety support: support@veridge.io

Safety and device information

In iOS, open the conversation’s Safety menu to report or block a user; touch and hold a received message to report it. On the web, use conversation or message details. Manage blocked users and contact support in Settings. While blocked, neither person can contact the other or view the conversation. Unblocking restores access to unexpired history. Previously downloaded content and media links already issued for up to five minutes cannot be recalled. Reports contain account, conversation and optional message identifiers, a selected reason, timestamps and review status, not copies of message text or recordings. Reports and safety request records expire after 30 days; account deletion also removes linked reports and blocks. Blocks remain until removed or account deletion. The operator reviews reports and may restrict an abusive account. Contact support@veridge.io for support, safety follow-up or an appeal, without sending private content or sign-in codes. This is not an emergency service; contact local emergency services for immediate danger. Native authentication uses an installation identifier, device-bound sessions and app version. Optional notifications use an APNs device token and language preference; Apple delivers a generic notification. These identifiers support authentication, delivery and security, not advertising or tracking. Veridge has no advertising or tracking SDKs. The iOS app has an invite-only TestFlight release path; this is not a public App Store release.