VERIFY data handling
VERIFY evaluates a public HTTP(S) service URL. It does not require prompts, completions, documents, wallet private keys, payment credentials or the business content handled by the target service.
What we collect
For authenticated checks, VERIFY receives the target resource URL, an API key, request timing and ordinary network metadata. Email is optional when a key is created. We derive limited operational metadata: a one-way key identifier, target hostname, risk result, recommendation, quota usage, response status and latency.
How it is used
The URL is used to resolve and probe the requested public service and produce the response. Operational metadata supports authentication, rate limiting, quota accounting, security, reliability and aggregate analytics. We do not sell customer data.
Storage and sharing
API keys are stored as one-way hashes. Optional email and quota records are kept in a permission-restricted seller-managed store. Limited event metadata is sent to PostHog for product analytics. Public target services and evidence sources receive the normal network requests needed to evaluate the URL.
Retention and deletion
Security-relevant audit events are retained for at least one year. API-key and optional email records are retained while the key is active and may be deleted after deactivation or a verified request, subject to security, fraud-prevention and legal retention needs. Email [email protected] to deactivate a key or request deletion.
Protection
Traffic uses HTTPS. Stored keys are hashed, sensitive files use restricted permissions, access is separated by API key, and caller-supplied URLs are screened against private, loopback, link-local and reserved destinations before fetch. Security events use a hash-chained audit record so modification is detectable.
Incidents and questions
Report a suspected incident or privacy question to [email protected].