VeriHash Back home

Last updated 31 August 2026

Privacy Policy

VeriHash is designed to preserve accountability without collecting the contents of protected pages. This policy explains what we process, why we process it, and the choices and rights available to customers, account users, protected viewers, and website visitors.

No page-content captureThe SDK does not take screenshots, record screens, read form fields, or transmit protected page contents to VeriHash.
Pseudonymous by defaultViewer identifiers are transformed by default, although optional names and email addresses remain identifying if supplied.
Files are deliberateImages and documents reach VeriHash only when an authorised user explicitly submits them for protection or analysis.
Customer controlledCustomers choose what viewer data to provide, who may access it, and how long submitted evidence is retained.
Contents
1. Scope and roles 2. Information we process 3. What the SDK does not collect 4. How we use information 5. Lawful bases 6. Customer responsibilities 7. Evidence analysis 8. Sharing and providers 9. International transfers 10. Retention and deletion 11. Security 12. Cookies and analytics 13. Your rights 14. Other important information 15. Contact us

01Scope and our data-protection roles

VeriHash is operated by Future Version Limited, company number 11739018, of The Station House, 15 Station Road, St. Ives, Cambs, PE27 5BH, United Kingdom (“VeriHash”, “we”, “us” or “our”). This policy applies to verihash.co, the interactive VeriHash demo, VeriHash customer accounts, the VeriHash JavaScript SDK, protected-session services, evidence analysis, reports, billing, support, and related administration.

Our role depends on the information and why it is processed:

  • VeriHash as controller. We determine why and how we process website analytics, prospective-customer enquiries, customer and staff account records, security logs, billing administration, service communications, and our own legal and operational records.
  • The customer as controller; VeriHash as processor. A customer normally determines why its Web Apps or recipient copies are protected, which viewers or recipients are identified, what identity fields are supplied, who may analyse evidence, and what action—if any—is taken following a result. For protected identity, session, recipient-copy, and customer-submitted evidence data, we normally process information on that customer’s documented instructions.
  • Limited independent processing. We may act as controller where we must protect VeriHash, investigate abuse of our service, comply with law, or establish, exercise, or defend legal claims.

If you encountered VeriHash through another organisation’s protected application, that organisation is normally the appropriate first contact for questions or rights requests about its use of the service. We will assist it where required.

02Information we process

The information processed depends on how you interact with VeriHash.

ContextInformation
Public websitePage and referring-page paths, hostname, visit timing, approximate location derived from network information, browser, operating system, device type, screen characteristics, and language. Our hosting and security providers may also process IP addresses and request metadata.
Interactive demoEmail address, email-verification state and timestamps, demo-entry time, screenshot-upload count, and first and latest upload times. For staff-created share links, we store the link label, creator, expiry, first-open time, and aggregate screenshot activity. A screenshot submitted in the demo is processed in memory to return the result and is not retained as an evidence case.
Performance monitoringAnonymous page route or URL, country, browser, operating system, device type, network speed, Web Vitals, relevant page-element attribution, SDK version, and event time. This is not tied to a user account, visitor identity, or browsing session.
Registration and accountsName, work email address, company name, password hash, role, account status, assigned Web Apps, sign-in times, and account creation and update records. Authentication challenges include hashed codes or links, expiry, attempt, and completion records. We do not store your plaintext password.
Company and Web App setupCompany name, domain, Web App names and keys, private evidence-email address, allowed origins, protection mode and strength, evidence-retention setting, pseudonymisation setting, access assignments, and configuration and audit history.
Protected SDK sessionsA customer-provided viewer ID or its pseudonymous replacement; any customer-provided display name and email; page path or label; session and Web App identifiers; watermark seed and policy; creation, heartbeat, and end times; application origin; browser user-agent; and a shortened keyed hash derived from the request IP address.
VeriMark file protectionThe uploaded image or PDF while it is being marked; original and output filenames; file type, dimensions or page count, size and cryptographic hash; intended recipient name and optional email; copy identifier and signal data; creator, download activity and timestamps. The output includes an opaque copy reference, issue time and authentication proof in file metadata, but no recipient name or email. The original upload is processed transiently and is not retained. The generated marked file is stored privately until an authorised user removes it or the company account is closed. Its recipient and signal record is retained after file removal so a copy surfacing later can still be attributed.
Evidence analysisThe submitted screenshot, image or PDF; original filename, file type, dimensions, cryptographic file hash, submission method, derived visual recovery image, detector scores, candidate ranking, likely viewer or recipient, session or copy metadata, notes, case status, report data, submitter, and timestamps.
BillingSelected plan, amount and currency, subscription or payment status, billing dates, and Stripe customer, price, subscription, Checkout, and event references. Payment-card and bank details are collected by Stripe and are not stored by VeriHash.
Transactional email and evidence intakeRecipient or sender email address, message and attachment metadata, delivery metadata, and the account, security, billing, support, or evidence event that caused the message. This covers verification codes, invitations, password messages, receipts, cancellation notices, and evidence deliberately sent to a Web App inbox. For evidence intake, we briefly record the sender, recipient, provider message reference, processing state, and attachment metadata needed to authorise, deduplicate, and process the request.
Sales, support and administrationMessages you send through our public sales or customer support forms, your name, work email address, company, enquiry topic, plan context, troubleshooting information you choose to provide, build and browser context, audit events, administrative actions, and records needed to respond, investigate availability, security, misuse, or disputes.

When pseudonymisation is enabled, VeriHash replaces the supplied viewer ID with a keyed pseudonymous reference before storing the session. This does not make the whole record anonymous: a display name, email address, page label, or other identifying field deliberately supplied by the customer remains readable to that customer’s authorised users.

We ask customers not to place passwords, authentication tokens, special-category information, criminal-offence information, or unnecessary personal data in viewer IDs, page labels, filenames, case notes, email subject lines, or evidence. A screenshot may inherently contain sensitive information; the customer must decide whether submitting it is necessary and lawful.

03What the SDK does not collect

The VeriHash SDK generates and renders a customer- and session-specific visual signal in the viewer’s browser. It is not a screen-capture, keylogging, or behavioural-replay product. The SDK is not designed to:

  • take or upload screenshots automatically;
  • record the screen, microphone, camera, keystrokes, pointer movements, clipboard, or form entries;
  • read or store the text, charts, files, or other contents of the protected page;
  • inspect unrelated browser tabs or applications; or
  • prevent a viewer from taking a screenshot.

The SDK does transmit limited session metadata described above. A page path or customer-supplied label can itself contain personal or confidential information, so customers should use stable, non-sensitive route labels and avoid placing secrets or individual names in URLs.

04How we use information

We use information to:

  • create, authenticate, administer, and secure customer and staff accounts;
  • provision companies, protected Web Apps, access roles, subscription entitlements, and service limits;
  • issue signed, short-lived SDK session material and maintain session health;
  • generate the visual protection selected by the customer, create recipient-linked VeriMark copies, and associate recovered signals with candidate sessions or marked copies;
  • authorise and analyse evidence deliberately uploaded or emailed by an authorised user, show confidence and supporting measurements, generate evidence reports, and return an emailed report where requested;
  • run customer-requested detector benchmarks and publish measured successes and misses;
  • verify access to the interactive demo, operate its protected test session and evidence analysis, and understand whether verified visitors use the screenshot workflow;
  • respond to prospective-customer and sales enquiries, provide support, diagnose faults, monitor availability, prevent abuse, and preserve service integrity;
  • process billing and reconcile Stripe events;
  • keep audit records and respond to complaints, disputes, lawful requests, and legal claims; and
  • understand aggregate public-site use and improve VeriHash.

We do not sell personal information. We do not use protected-viewer data or submitted evidence for advertising, data brokerage, unrelated profiling, or training general-purpose artificial-intelligence models.

05Our lawful bases

Where VeriHash acts as controller under UK data-protection law, our lawful basis depends on the purpose:

  • Contract. To create and operate customer accounts, provide requested service features and support, and administer subscriptions.
  • Legitimate interests. To secure and improve VeriHash, prevent fraud and misuse, keep proportionate audit and service records, understand aggregate public-site use, communicate essential operational information, and establish or defend legal claims. We consider the necessity and impact of this processing and provide ways to object where applicable.
  • Legal obligation. To meet accounting, tax, regulatory, law-enforcement, court-order, and other legal requirements.
  • Consent. Where we expressly request it for an optional purpose. Consent can be withdrawn without affecting earlier lawful processing.

Where we act as processor, the customer decides and must document the lawful basis for its monitoring, attribution, and evidence processing. Our contract with the customer, rather than this public policy alone, governs our processor instructions.

06Customer responsibilities

VeriHash can be used in contexts involving employees, contractors, subscribers, clients, investors, or other authorised viewers. Customers are responsible for using it lawfully and proportionately. In particular, a customer must:

  • provide protected viewers with clear privacy information, including the purpose of watermarking or attribution, unless a lawful and documented exception genuinely applies;
  • identify an appropriate lawful basis and comply with workplace-monitoring, employment, communications, surveillance, and sector-specific rules;
  • carry out a data-protection impact assessment where processing is likely to create a high risk, and consult workers, representatives, regulators, or other stakeholders where required;
  • limit supplied identity fields, Web App access, evidence submissions, retention, and internal disclosure to what is necessary;
  • keep the identity mapping needed to interpret pseudonymous viewer IDs secure and accurate;
  • ensure authorised users understand that detector output is evidence to review, not proof to accept without context; and
  • respond to protected viewers’ rights requests and notify us when processor assistance is required.

“Covert” describes the visual presentation of a protection mode; it does not remove a customer’s transparency or fairness obligations. Customers must not use VeriHash for unlawful secret monitoring, discrimination, retaliation, harassment, or decisions unsupported by appropriate investigation.

07Evidence analysis and automated output

When an authorised user uploads evidence—or emails one image to a Web App’s private evidence address—VeriHash checks eligible signed VeriMark metadata and exact issued-file hashes where present, then normalises the visual material and compares recovered spatial signals against eligible Web Session and/or VeriMark recipient-copy signals for the selected search scope. A retained opaque VeriMark filename may narrow this visual search but is never accepted as proof by itself. The service returns an attribution result, confidence and runner-up scores, supporting measurements, and report material. The detector normally searches a recent candidate window; older session metadata may still exist even when it is not included in that search.

For email intake, we first compare the sender address with an active Owner, Admin, or Analyst assigned to that Web App. An unauthorised attachment is not downloaded or analysed by VeriHash. The sender receives a generic rejection notice. For an authorised request, Resend supplies a temporary attachment-download address, the analysis is queued, the resulting case is added to Recent Evidence, and a generically named PDF report is returned to the account email. Customers can pause intake or rotate a Web App address.

Results can be affected by cropping, resizing, recompression, colour changes, rotation, display photography, limited candidate data, implementation choices, or an absent signal. False positives and false negatives are possible. VeriHash does not make employment, access, legal, disciplinary, credit, insurance, or similarly significant decisions about protected viewers. Customers must apply meaningful human review, corroborate results, consider competing explanations, and provide any process required by law before taking action.

08Who receives information

We disclose information only as needed for the purposes described above:

  • Authorised customer users. Owners, administrators, analysts, and other members receive information permitted by their role and Web App assignments.
  • Supabase. Database and private evidence-object storage infrastructure.
  • Vercel. Application hosting, delivery, request processing, operational infrastructure, and anonymous Speed Insights performance measurement.
  • Stripe. Checkout, payment, subscription, billing-portal, fraud-prevention, and financial compliance services. Stripe acts under its own privacy terms for information it controls.
  • Resend. Delivery of account, security, billing, sales, support, and evidence-report messages, and receipt of messages sent to Web App evidence addresses. Resend processes sender and recipient details, message and attachment content, and delivery metadata for these purposes. Resend receives an inbound message before VeriHash applies its account and Web App authorisation check; VeriHash does not download an unauthorised attachment.
  • Umami infrastructure. Privacy-focused analytics for public and authentication pages. Analytics is not loaded in platform administration or authenticated customer workspaces.
  • Professional advisers and authorities. Lawyers, accountants, insurers, auditors, courts, regulators, law enforcement, or other recipients where reasonably necessary and lawful.
  • Corporate transactions. A prospective or actual buyer, investor, group company, or successor, subject to appropriate confidentiality and data-protection safeguards.

Our service providers may use their own sub-processors. We assess providers according to the nature and risk of the processing and contractually restrict processor use where required. Customers may contact us for current processor and transfer information relevant to their service.

09International transfers

VeriHash is operated from the United Kingdom. Some providers, personnel, or infrastructure may process information in other countries, including the United States. Where UK data-transfer rules apply to a restricted transfer, we rely on a valid mechanism such as UK adequacy regulations, the UK International Data Transfer Agreement, the UK Addendum to approved standard contractual clauses, or another lawful safeguard, together with any required data-protection test or transfer risk assessment and supplementary measures.

Customers can contact us for further information about safeguards relevant to their data. Customers remain responsible for transfer information and safeguards for data they disclose to VeriHash as controller.

10Retention and deletion

  • Evidence files and cases. Evidence linked to a Web App follows its customer-selected retention period, set to 30 days by default. A setting of zero means it remains until manually deleted or the service relationship requires deletion. Evidence attributed only through VeriMark remains until an authorised user deletes it or the company account is closed. Expired evidence is removed during the next retention sweep; associated audit or minimal case records may be retained where needed for security, disputes, or law.
  • VeriMark copies. The original image or PDF is discarded after the protected output is generated. The downloadable marked file remains available until an authorised investigator removes it or the company account is closed. Removing that stored file hides it from the library, but its recipient, copy identifier and signal mapping remain until the company account is closed so future leaks can still be attributed.
  • Inbound evidence-email records. VeriHash’s processing-job metadata is deleted after 30 days once a job is completed or failed. Accepted emailed evidence follows the Web App’s evidence-retention setting. Inbound message and attachment copies held by Resend follow Resend’s contracted retention and deletion controls; rotating or pausing a VeriHash address does not itself erase a provider-held message.
  • Session metadata. Kept while needed to provide attribution, security, usage measurement, and account history. Stored sessions remain eligible detector candidates until the session record is deleted. We review retention against account status, customer instructions, disputes, legal limitation periods, and technical necessity.
  • Account and Web App records. Normally kept while the account or customer relationship is active and for a reasonable period afterward to handle reactivation, security, billing, support, and legal obligations.
  • Billing records. Subscription and transaction references are kept for accounting, tax, fraud-prevention, reconciliation, and legal periods. Stripe retains information under its own policy.
  • Authentication and transactional-email records. Verification and recovery challenges are retained only for their operational and short-term security purpose, then deleted or rendered unusable. Delivery providers may retain recipient, message, and delivery records under their contracted service and deletion terms.
  • Interactive-demo records. Email, verification, share-link, and aggregate upload-activity records are retained while reasonably needed to understand demo use, respond to prospective customers, prevent abuse, and maintain sales records. Share links stop granting access after seven days. Screenshots uploaded to the interactive demo are processed in memory and are not retained as evidence cases.
  • Audit, security, sales, and support records. Kept for as long as reasonably necessary to respond to enquiries, investigate events, demonstrate authorised activity, prevent repeat abuse, and establish or defend claims.
  • Public-site analytics. Retained according to our analytics configuration and operational needs, then aggregated or deleted.
  • Performance measurements. Anonymous Web Vitals and associated technical context are retained through Vercel Speed Insights according to our service configuration.

When deletion applies, we remove or anonymise information from active systems unless continued retention is required or permitted by law. Residual copies may remain temporarily in provider backups, logs, or disaster-recovery systems until overwritten under their normal cycles. Customers should export anything they must lawfully retain before account closure.

11Security and incident handling

We use technical and organisational measures appropriate to the service, including tenant and Web App access controls, role-based permissions, private evidence storage, password hashing, signed session material, origin controls, audit logging, secret separation, transport encryption, encrypted backups, and restricted administrative access. Evidence files, marked copies, forensic signal seeds, and Web App signing secrets are protected with application-level authenticated encryption before they are stored; infrastructure providers also apply their own storage encryption. Encryption keys are held separately from stored customer material. No online system is completely secure, and customers remain responsible for their own applications, endpoint security, credentials, identity mapping, integrations, and user access.

If we become aware of a personal-data breach affecting customer-controlled data, we will notify the relevant customer without undue delay where required and provide information reasonably available to help it meet its obligations. Please report suspected security issues to support@verihash.co. Do not send evidence to support or other ordinary mailboxes; use only the private Web App address shown in Evidence Lab when email intake is appropriate.

12Cookies, local storage, and public analytics

VeriHash uses strictly necessary first-party session cookies to keep authorised users signed in, protect account routes, maintain security state, and remember verified access to the interactive demo. Clearing these cookies signs you out or returns the demo to its email gate. The SDK may use in-memory or browser state necessary to maintain the current protected session; it is not used for advertising or cross-site tracking.

Public pages, registration, and sign-in pages use our Umami analytics service to understand aggregate traffic. This can include page and referrer paths, hostname, browser, operating system, device and screen characteristics, language, approximate location, and visit timing. The current tracker does not set analytics cookies, and we do not use Umami’s logged-in-user identification features. We do not intentionally send passwords, account email addresses, viewer IDs, uploaded evidence, or customer-workspace activity to Umami. Umami tracking is excluded from platform administration and authenticated customer areas.

All pages use Vercel Speed Insights to measure real-world loading, responsiveness, and visual-stability performance. Its data points are anonymous and are not associated with an individual visitor, IP address, account, or reconstructed browsing session.

We do not use third-party advertising cookies, sell audiences, or track protected viewers across unrelated websites. Browser “Do Not Track” signals are not interpreted as a universal legal instruction, but the service’s limited analytics and absence of behavioural advertising apply regardless.

13Your data-protection rights

Depending on your location and the circumstances, you may have rights to request access to, correction of, deletion of, restriction of, or portability of personal information; object to processing based on legitimate interests; withdraw consent; and complain to a regulator. Rights are not absolute and may be limited where information must be kept for security, legal obligations, the rights of others, or legal claims.

Customer account users and website visitors can send requests to support@verihash.co. We may request proportionate information to verify identity and authority. We normally respond within one month where UK GDPR applies; a lawful extension may apply to complex or numerous requests.

Protected viewers should normally contact the organisation whose application they viewed. Please identify that organisation and the approximate date of access. If a request reaches us, we may refer it to the relevant customer and assist them as processor rather than independently disclosing customer-controlled information.

You can raise a concern with the UK Information Commissioner’s Office at ico.org.uk/make-a-complaint. If you live elsewhere, you may also contact your local data-protection or privacy authority. We would appreciate the opportunity to address your concern first.

Where US state privacy law applies, you may also have rights to know, correct, delete, or obtain a copy of covered information and to appeal a refusal. VeriHash does not sell personal information or share it for cross-context behavioural advertising. We will not discriminate against you for exercising an applicable privacy right.

14Other important information

Children

VeriHash is a business service and is not directed to children. Customer account holders must be at least 18 or otherwise legally able to enter the relevant agreement. Customers must not use the service to monitor children or submit children’s information without a documented lawful basis, appropriate transparency, and any required parent, guardian, school, or authority involvement.

Third-party services

A customer’s protected application and any link from VeriHash may have separate privacy practices. This policy does not govern a customer’s application or an independent third party’s processing.

Changes to this policy

We may update this policy as VeriHash, our providers, or the law changes. We will change the date at the top and provide additional notice where a change is material and applicable law requires it. Earlier versions may be requested from us.

15Contact us

Privacy and supportsupport@verihash.co
Telephone+44 122 363 6806
Data controllerFuture Version LimitedCompany number 11739018
Registered office
The Station House
15 Station Road
St. Ives, Cambs
PE27 5BH
United Kingdom
© 2026 VeriHash
HomePrivacyTermsSign in