Trust and privacy
Privacy Policy
Scope and who operates the service
This Policy describes how the independently operated Veritas Shield service handles personal information.
In this Policy, “Veritas Shield,” “we,” “us,” and “our” mean the operator of veritas-shield.org and the related web app, Chrome extension, account, analysis, subscription, and email services. You can reach the operator at support@veritas-shield.org.
This Policy does not control a publisher, website, Google service, payment network, or other third party that you choose to visit or use. Their own terms and privacy notices apply to their services.
Information we collect
The information depends on which Veritas features you use.
Account and identity information
- Your name, email address, account identifier, profile settings, authentication method, and verification state.
- If you use Google sign-in, Google provides the basic verified identity information needed to create or connect your Veritas account. Veritas does not receive your Google password.
- Email verification, login, and password-recovery challenges, including the email address, purpose, expiry, attempt and rate-limit state, and one-way code verification data. Veritas does not store a plaintext verification code in Supabase.
Article and analysis information
- The URL you submit and the article material needed for the requested report, which may include title, text, headings, links, pictures, captions, page metadata, and visible source or evidence passages.
- The resulting score, claims, evidence relationships, extraction status, review decisions, report metadata, comparison choices, and feedback associated with your request.
- Saved reports and share links. Reports remain private to your account unless you deliberately create a share link; anyone with that link may be able to view the shared report until it expires.
Extension information
The extension acts only after you request analysis. It may send the selected page's URL, cleaned article material, structure, links, pictures, and metadata to Veritas. It also keeps sign-in, feature preferences, compatibility state, and recent result state in Chrome storage. It does not continuously send your general browsing history to Veritas.
Payments, subscriptions, and communications
- Your selected plan, price, promotion code, subscription status, access dates, and the Zelle confirmation or transaction reference you submit for manual review. Do not put banking credentials or unrelated personal information in that reference field.
- Your optional article, announcement, and product-update preferences, unsubscribe state, and email delivery records.
- Messages you send to support and information needed to answer or secure your account.
Security and basic usage information
- Authentication and request information needed to operate and defend the service. Hosting and security providers may process ordinary network information such as IP address, browser or device signals, timestamps, and request metadata.
- At successful sign-in, the hosting layer may provide a two-letter country code derived from the network request. Veritas stores country-level sign-in history to detect a move between countries and send a security alert; it is not used for precise location tracking or advertising.
- Aggregate Blog view counts. A short first-party marker prevents repeated counting from the same browser during the same day without adding an identified reading-history record.
How we use information
We use information for the service you request, safety, communication, and responsible improvement.
- Provide article extraction, analysis, Reader, Evidence Atlas, comparison, History, and sharing features.
- Create and secure accounts, verify email ownership, maintain sessions, recover access, and detect unusual country changes.
- Administer prepaid subscriptions, verify payment requests, apply promotions, and provide the purchased access period.
- Send essential account, security, password, privacy, and terms messages, plus optional updates you have chosen to receive.
- Diagnose failures, protect availability, enforce usage limits, prevent abuse, and improve the clarity and reliability of the product.
- Comply with applicable law, respond to valid legal requests, and protect users, the service, and third-party rights.
Where data-protection law requires a legal basis, processing may rely on performance of the service contract, legitimate interests in operating and securing the service, your consent for optional communications, or compliance with legal obligations.
When information is shared
Veritas uses constrained service providers; it does not operate a data-broker or targeted-advertising business.
Information may be processed by providers that help deliver the service, including:
- Supabase for managed authentication, database, and storage services.
- Google when you choose Google authentication.
- Cloudflare for network protection and the private transactional-email and verification-code service.
- Resend, or a configured restricted broadcast provider, for optional articles, announcements, newsletters, and product updates.
- Infrastructure and technical providers that host, monitor, secure, or support the website and analysis service.
These providers receive only the information reasonably needed for their role and process it under their own contractual and legal obligations. When you ask Veritas to retrieve a public article, the publisher or hosting network may receive the ordinary network request information involved in that retrieval.
We may also disclose information when reasonably necessary to comply with law, respond to lawful process, investigate abuse or security incidents, protect rights and safety, or transfer the service as part of a reorganization or change of operator. We do not sell or rent personal information, and we do not share it for cross-context behavioral advertising.
How long information is kept
Retention follows the feature's purpose, security needs, and applicable obligations.
- Saved analysis reports and comparisons: available for 30 days from the original saved analysis and removable sooner from History. Associated evidence and share links expire with the report.
- Verification challenges: codes are one-time and normally expire after 10 minutes. Short supporting records may remain long enough to enforce cooldowns, request limits, and abuse prevention.
- Account and profile information: kept while the account is active and then deleted or de-identified when no longer reasonably required, subject to security, backup, dispute, and legal needs.
- Subscription, payment-review, security, legal-notice, and email-delivery records: kept as reasonably needed to administer access, document consent and delivery, prevent fraud, answer disputes, and meet legal obligations.
- Blog view marker: expires after approximately 26 hours. Blog posts retain only an aggregate count rather than an identified reader history.
Your privacy choices and rights
Product controls handle common choices; support handles requests that need identity verification or legal review.
- Review or update profile details and account-security methods from Profile.
- Delete saved reports and comparisons from History before their normal expiry.
- Change optional article, announcement, and product-update email choices from Profile. Essential security, account, and legal notices are separate.
- Connect or disconnect supported identity methods where the account controls allow it.
- Request access, correction, deletion, restriction, objection, withdrawal of consent, or a portable copy where applicable by emailing support.
We may need to verify your identity before completing a request. Some requests may be limited where retention is required for security, fraud prevention, dispute handling, another person's rights, or applicable law. You may also have a right to contact your local data-protection authority.
Security and international processing
Veritas uses layered safeguards, but no online service can promise absolute security.
Measures include encrypted network transport, hashed or provider-managed authentication credentials, short-lived verification proofs, one-time OTP consumption, server-only privileged keys, access controls, row-level database policies, bounded requests, rate limits, and restricted email-sender contracts.
Service providers may process information in the United States or other countries where they operate. Where required, transfers rely on contractual safeguards or other lawful transfer mechanisms. Laws in those locations may differ from the laws where you live.
If you believe your account or personal information is at risk, change your password and contact support@veritas-shield.org.
Children and policy changes
The service is not directed to children under 13, and material privacy changes will not be hidden.
Veritas Shield is not intended for children under 13, and we do not knowingly collect personal information from a child under 13. If you believe a child has provided information, contact support so the account and information can be reviewed and, where appropriate, removed.
We may update this Policy as the service or law changes. The page will show a new effective date. For a material change, we will provide reasonable notice through the service or by email when appropriate before the change takes effect.
Contact
Questions and privacy requests go to one monitored address.
Include the account email and the type of request, but do not send your password or a verification code.

