Privacy Policy

Last updated: 12 September 2026

This policy explains what personal data Veris Labs collects, why, and what rights you have. We keep it short and plain on purpose.

1. Who is responsible for your data

The data controller is Veris Labs, the operator of verislabs.io, the Veris Labs dashboard, and the Veris Labs API. Veris Labs is operated by a natural person conducting unregistered business activity (działalność nierejestrowana) under Polish law; the controller's full identification details are provided on request.

For anything privacy-related, contact [email protected].

2. What data we collect and why

Account data. When you sign up, we store your email address and a bcrypt hash of your password (never the password itself). If your account was created via Discord, we also store your Discord user ID. We use this to run your account, log you in, and confirm your email address. Legal basis: performance of the contract.

API keys and usage telemetry. We store your API keys and per-request telemetry tied to your API key and product (for example request counts and feedback data). We use this to bill you correctly, operate and improve the service, and detect abuse. Legal basis: performance of the contract and our legitimate interest in running a reliable, abuse-free service.

Server and security logs. Our servers automatically record technical data such as your IP address, browser and device type, and access times. We use this to secure the service, prevent abuse, and diagnose problems. Legal basis: our legitimate interest in keeping the service secure and reliable.

Billing data. When you buy credits or a package, we create an invoice with the amount and a payment URL. The payment itself is processed by Zenobank - we never see or store card data, wallet keys, or other payment credentials. We keep invoices because tax law requires it. Legal basis: legal obligation and performance of the contract.

Support communications. If you contact us on Discord, Discord processes that conversation and we see your Discord username and message history. Legal basis: our legitimate interest in providing support.

Analytics. The marketing site (verislabs.io) and the documentation site (docs.verislabs.io) use Umami, a privacy-focused analytics tool that we host ourselves. It does not set any cookies and does not collect personal data - we only see aggregate statistics such as pages visited and approximate device/browser information.

3. Who processes data for us

We use the following processors (sub-processors):

  • Zenobank - cryptocurrency payment processing.
  • Resend - transactional email (signup confirmations and similar).
  • vShield - hosting of our servers and databases.
  • Discord - customer support channel.

Some of these processors are located outside the European Economic Area (in particular in the United States). Where data is transferred outside the EEA, we rely on appropriate safeguards, such as the EU–US Data Privacy Framework or standard contractual clauses.

4. How long we keep data

  • Account data - kept while your account is active, and deleted when you delete your account.
  • Invoices and billing records - kept for the period required by tax law (typically 5 years).
  • Usage telemetry - kept for about 12 months.
  • Server logs - kept for up to 12 months.
  • Support conversations - kept for as long as needed to handle your request.

5. Your rights

Under the GDPR you have the right to:

  • access the personal data we hold about you,
  • have inaccurate data corrected,
  • have your data erased ("right to be forgotten"),
  • receive your data in a portable format,
  • object to or restrict certain processing,
  • withdraw consent where processing is based on consent.

To exercise any of these rights, email [email protected] from the address linked to your account.

You also have the right to lodge a complaint with the Polish data protection authority, Prezes Urzędu Ochrony Danych Osobowych (Prezes UODO), ul. Stawki 2, 00-193 Warsaw, Poland.

6. Cookies

  • Dashboard (dashboard.verislabs.io) - uses only strictly necessary cookies for login sessions. These are required for the service to work and do not require consent.
  • Marketing site and documentation site - our self-hosted Umami analytics does not use cookies at all.

You can block or delete cookies in your browser settings; the dashboard will not work without its session cookie.

7. Security

We protect your data with industry-standard measures, including encrypted connections (HTTPS), bcrypt-hashed passwords, and access to production systems restricted to those who need it. No method of storage or transmission is 100% secure, but we work to keep your data safe.

8. No sale, no profiling

We do not sell your personal data to anyone. We do not use your data for automated decision-making or profiling that produces legal or similarly significant effects.

9. Changes to this policy

We may update this policy from time to time. The current version is always at verislabs.io/privacy, with the date it was last updated. If we make a significant change, we will notify you by email or on Discord.

10. Contact