Verdict Labs, Inc. · Version 2.0
Privacy Policy
Effective 16 August 2026 for accounts created on or after that date. For an account created before it, this version takes effect thirty (30) days after Verdict gives notice of it, and until then the version in force when the account was created continues to apply. That version is at useverdict.io/legal/privacy/v1. Applies to the Verdict web application at useverdict.io and to related domains operated by Verdict Labs, Inc.
This Privacy Policy describes the personal data Verdict Labs, Inc. collects, the purposes for which it is processed, the third parties that receive it, how long it is retained, and the rights available to individuals. It should be read with the Terms of Service and the Data Processing Addendum, the latter of which governs personal data that Verdict processes on a customer’s behalf. Inquiries and rights requests may be sent to legal@useverdict.io.
Identity of the Controller
1.1 Controller. The controller responsible for the personal data described in this Policy is Verdict Labs, Inc., a Delaware corporation (“Verdict”). Verdict operates an artificial intelligence service that produces written investment analysis from documents its users submit. Capitalized terms used in this Policy and not defined here have the meanings given in the Terms of Service.
1.2 Where Verdict acts as a processor. Personal data contained in the documents a customer submits, such as information about company founders and their teams, is processed by Verdict on that customer’s behalf. In respect of that data the customer is the controller and Verdict is the processor, and the Data Processing Addendum governs the processing. This Policy describes the processing for which Verdict is itself the controller.
1.3 Contact. Privacy inquiries, rights requests under the GDPR, the United Kingdom GDPR, the CCPA as amended by the CPRA, or any other applicable law, and requests for the registered mailing address, may be directed to legal@useverdict.io. Verdict has not appointed a data protection officer, as it is not required to do so under Article 37 of the GDPR.
Categories of Personal Data Collected
2.1 Data provided directly.
- Account data. Email address, supplied through sign-up or through a third-party identity provider, display name, and the user type and role selected during onboarding.
- Profile data. For investor accounts: investment thesis, stage focus, sector focus, check-size range, geographic focus, stated dealbreakers, and portfolio companies. For founder accounts: company name, stage, sector, and fundraising context.
- Submitted documents. Pitch decks in PDF or PPTX format, business plans in PDF or DOCX format, written context entered on the upload form, and, where a user chooses to include one, a financial model in XLSX format. These documents commonly contain personal data about third parties, including names, roles, and biographies.
- Generated analysis and corrections. The written analysis Verdict produces, together with any correction a user submits through the in-product feedback control and any notes appended to a report.
- Correspondence. The content of messages sent to Verdict, retained so that Verdict can respond and refer back to the exchange.
- Survey responses. Where a user completes a survey or questionnaire Verdict makes available within the Service, the answers given. These commonly include the user’s role, the fund or company the user is associated with, the stage and sector focus of that work, how much material the user reviews and over what period, the tools the user currently uses, and the user’s assessment of the Service. Section 8.3 of the Terms of Service governs the intellectual property in this material.
2.2 Data generated through use of the Service.
- Product analytics. Page views, feature interactions, and session metadata including browser, operating system, screen dimensions, and approximate location derived from IP address. Two analytics providers are used and they behave differently: PostHog is configured to honor the Do Not Track browser header, which stops the browser library from capturing any event. A small number of account events recorded from Verdict’s own servers are not affected by that setting, and section 11.2 describes them. Google Analytics is loaded on every page and does not respond to that header. Section 11 describes the controls available.
- Processing telemetry. Computational cost, latency, token counts, and structural coverage measurements for each analysis, used for cost control and quality measurement.
- Error and performance data. Unhandled exceptions and performance traces captured by Sentry. Section 8.4 describes the limits of the redaction applied.
- Server logs. Timestamped request records including path, response status, latency, and IP address, retained by the hosting provider on its standard schedule.
2.3 Data obtained from other sources.
- Public web research. Where a user enables research on a company and its founders, Verdict issues searches against public web sources through the hosted search facility of its model provider, and surfaces publicly indexed professional information returned in those results. The search terms Verdict issues include company and individual names. Verdict does not extract data from LinkedIn directly and does not purchase founder data from a data broker. The feature can be declined for any individual submission. Verdict acts as a processor for this activity; see section 2.4.
- Investment professional research. Where a user enters the names of investment professionals for research, those names and any links supplied are sent to a web search provider. Submitted documents and profile data are not sent. Verdict acts as a processor for this activity; see section 2.4.
- Payment data. The payment processor holds the tokenized payment method, billing address, and transaction history. Verdict stores only the customer identifier issued by that processor and the resulting plan state. Full payment card numbers do not reach Verdict.
2.4 Data Verdict processes on a customer’s behalf. The two research activities described in section 2.3, and the personal data contained in the documents a customer submits, are processed by Verdict at that customer’s direction. For those activities the customer is the controller and Verdict is the processor, and the Data Processing Addendum governs the processing. Section 3 of that Addendum describes the categories concerned, and section 1.4 places responsibility for giving notice to the individuals concerned on the customer.
2.5 Whether provision is required. Providing an email address is necessary to create an account, and providing a document is necessary for the Service to generate a report. Without them the Service cannot be supplied. Every other category described above is optional, and declining to provide it limits only the corresponding feature.
Purposes and Legal Bases
3.1 To provide the Service. Submitted documents and profile data are processed to produce, store, and display the analysis a user requests, and to calibrate later analysis for the same account. Legal basis: performance of a contract.
3.2 To administer billing. Email address and payment processor identifier are processed to establish and maintain a plan. Legal basis: performance of a contract.
3.3 To operate and secure the Service. Error reports, server logs, and processing telemetry are processed to diagnose failures, control cost, and detect abuse. Legal basis: legitimate interests in maintaining a functioning and secure service, balanced against the rights of the individuals concerned.
3.4 To measure and improve the Service. Analytics data is processed to understand which features are used and where the product fails. This work uses aggregated views rather than the content of any individual’s documents. Legal basis: Verdict’s legitimate interests in measuring and improving a service it operates, balanced against the rights of the individuals concerned. Verdict does not currently operate a consent mechanism for the storage of or access to information on a device. Where the law of an individual’s country requires prior consent for non-essential cookies and similar technologies, Verdict does not at present obtain it, and the controls described in section 11 are the means available to that individual.
3.5 To communicate. Transactional messages, comprising account, billing, security, and completion notifications, are sent for the purposes of performing the contract. Product update messages are sent on the basis of legitimate interests and may be declined using the unsubscribe link in any such message.
3.6 To comply with law. Personal data may be processed where necessary to comply with a legal obligation, to establish or defend a legal claim, or to respond to a lawful request from a public authority.
3.7 Purposes expressly excluded. Verdict does not sell personal data. Verdict does not disclose personal data to a third party for that party’s own marketing. Verdict does not use submitted documents, generated analysis, or submitted corrections to train, fine-tune, or otherwise develop any generalized artificial-intelligence or machine-learning model. The training commitment is stated in full in the Data Processing Addendum.
Sub-processors and Recipients
This is the canonical list of third parties that receive personal data in the course of operating the Service. Each provider publishes its own privacy documentation, linked below. Verdict does not attest to any provider’s certification status.
- Clerk. Authentication and session management. Receives the account email address and any tokens issued by a third-party identity provider. Clerk privacy.
- Supabase. Database and object storage for submitted documents, generated analysis, and profile data. Encrypted at rest using AES-256 and in transit using TLS 1.2 or higher. Hosted on Amazon Web Services in
us-east-1. Supabase security. - Stripe. Payment and subscription processing. Receives payment details directly through tokenized checkout. Stripe privacy.
- Anthropic. Model inference. Receives the contents of submitted documents and the associated analysis prompts. Anthropic’s commercial terms prohibit training on customer data. Inputs and outputs may be retained by Anthropic for up to thirty (30) days for trust-and-safety review and are then deleted. Anthropic commercial terms.
- Voyage AI. Text embedding, used to retrieve relevant prior material when a later analysis runs for the same account. Receives text derived from submitted documents, including the extracted company description, sector, stage, and market information, and passages of the analysis Verdict has generated for the account. It does not receive the original document files. Voyage privacy.
- CloudConvert. Converts PPTX and DOCX uploads to PDF before Verdict reads them. Receives the uploaded file, converts it, and deletes it on its side under its own retention policy. Financial models in XLSX format are parsed by Verdict and are not sent to CloudConvert. CloudConvert privacy.
- Tavily. Web search used for research on investment professionals. Receives the names and links entered for that purpose. It does not receive submitted documents or profile data. Tavily.
- Resend. Email delivery, outbound and inbound. Receives the recipient address and the message body of transactional messages. Where a person subscribes to Verdict’s newsletter, the subscriber address is also added to an audience list that Resend stores in order to send that newsletter. Where an account enables the forwarding address offered in its settings, Resend also receives mail sent to that address before Verdict does, including the sender address, the subject, the message body, and any attached file, which for that feature is ordinarily a pitch deck. Resend privacy.
- Slack. Where a user connects a Slack workspace, Verdict delivers analysis content into that workspace at the user’s direction. Slack receives the material posted and the workspace credential issued during authorization, which Verdict stores in order to deliver into the workspace. This applies only to accounts that have connected a workspace. Slack privacy.
- PostHog. Product analytics. Receives page views and feature interactions. For a signed-in user it also receives that user’s account identifier, email address, and first name, so that activity can be attributed to an account. Configured to honor the Do Not Track browser header, to mask form inputs in session recordings, and to record profiles only for identified users. PostHog privacy.
- Google Analytics. Site measurement. Included by the application on every page of the Service, including authenticated pages. Where it executes it receives page views, device and browser metadata, and IP address. Verdict’s content security policy does not presently permit the script to load, so it is not at present receiving data. It does not honor the Do Not Track browser header. Section 11 describes the controls available. Google privacy.
- Cloudflare. Bot challenge presented on the sign-in and sign-up screens. Receives the visitor IP address and challenge telemetry. Cloudflare privacy.
- Sentry. Error monitoring. Receives stack traces and request metadata when a failure occurs. Section 8.4 states the limits of the redaction applied. Sentry privacy.
- Vercel. Application hosting and serverless execution. Retains standard request logs. Vercel privacy.
- Google (Calendar). For accounts holding an existing Google authorization, calendar event data is read to produce preparation summaries. Section 9 describes the current availability of this integration and the Limited Use commitments that govern it. Google privacy.
Verdict does not disclose personal data to any recipient other than those described in this Policy, except where disclosure is required by law, legal process, or an order of a court or governmental authority, or where necessary to establish or defend a legal claim. Where a new sub-processor is engaged, Verdict will update this section and notify each account by email at least thirty (30) days before the change takes effect.
Retention
5.1 Submitted documents. Ninety (90) days from creation by default, or twenty-four (24) hours from upload where the upload is marked “Sensitive” on the upload form. The twenty-four hour period runs from the upload itself and is not extended by re-running the analysis, by resuming it, or by opening the report, and it applies whether or not the analysis completed. Starting a new analysis by uploading a document again stores a separate copy with its own period; where the restart of a failed analysis reuses the copy already held, that copy is removed only once every report referring to it has reached the end of its own period, which can hold it longer than twenty-four hours. Both periods are applied by a scheduled job that runs every hour and that takes sensitive uploads more than twenty-three (23) hours old, so that removal falls inside the twenty-four hour period rather than at its edge. The job processes a bounded number of records per run, so the stated periods are minimums rather than guaranteed deletion dates. A financial model uploaded alongside a document is covered by the same two periods, and is reached on its own account, so it is removed on the period that applies to it whether or not the document it accompanied is still held. Deletion of a financial model before the end of that period may be requested under section 6.
5.2 Generated analysis and processing telemetry. Ninety (90) days from creation, then deleted together with the associated record.
5.3 Corrections and derived records. Corrections submitted through the in-product feedback control are retained beyond the ninety-day period, because they calibrate later analysis for the same account. The same applies to findings Verdict records at the end of an analysis and to passages of prose drawn from an account’s own reports, both of which are used to keep later reports consistent with earlier ones. Each is scoped to the account that produced it. The reference linking any of them to the originating report is severed when that report is deleted. Verdict’s policy ceiling for these records is the shorter of seven (7) years from creation or the closure of the account, and deletion may be requested at any time under section 6.
5.4 Account data. Retained until the account is closed.
5.5 Billing records. Retained by the payment processor on its own schedule and for the period required by applicable tax and accounting law. Verdict retains the processor’s customer identifier and the plan state for so long as the account is open.
5.6 Survey responses. Answers submitted through a survey or questionnaire in the Service are not subject to the ninety-day rule, because they record the respondent’s assessment of the Service rather than the analysis of a submitted document. No scheduled process deletes them. Verdict retains them and deletes them on request under section 6.
5.7 Backups. Infrastructure backups are maintained by Verdict’s hosting and database providers on their own schedules. A record that has been deleted may persist in a backup until that backup expires in the ordinary course, after which it is no longer recoverable.
Rights of Individuals
6.1 Rights available to everyone. Regardless of location, an individual may request access to the personal data Verdict holds about them, request its deletion, request correction of inaccurate data, and request a portable copy. Reports may be exported to PDF from the Service, and that is the only export function the Service provides. Any other copy is assembled by hand when an individual asks for one under section 6.2. Verdict does not presently commit to supplying it in a structured or machine-readable format, and an individual who requires one should say so in the request so that Verdict can confirm what it is able to provide.
6.1.1 Requests concerning data submitted by a customer. Where the personal data concerned is contained in material a customer has submitted, or was gathered at a customer’s direction, that customer is the controller of it and Verdict is the processor. In that case Verdict will acknowledge the request, will pass it to the customer responsible, and will act on that customer’s instruction, unless Verdict is legally required to respond directly. Verdict will tell the individual that it has done so.
6.2 How to exercise them. Requests should be sent to legal@useverdict.io from the email address associated with the account, or with sufficient information for Verdict to verify the requester’s identity. Verdict responds without undue delay and in any event within thirty (30) days, extendable by a further period where permitted by law and notified to the requester. Requests under the CCPA are answered within forty-five (45) days, extendable once by a further forty-five (45) days.
6.3 Account closure. An account may be closed by written request. Access to the account is revoked immediately, and the stored content is deleted within thirty (30) days. A share link or co-investor link generated before closure may remain readable, and should be revoked before the account is closed. The mechanics are set out in section 4 of the Data Processing Addendum.
6.4 Additional rights under the GDPR and the United Kingdom GDPR. Individuals in the European Economic Area, the United Kingdom, and Switzerland have the right to restrict processing, to object to processing carried out on the basis of legitimate interests, to withdraw consent at any time without affecting the lawfulness of processing carried out before withdrawal, and to lodge a complaint with a supervisory authority in their country of residence, place of work, or the place of the alleged infringement.
6.5 Additional rights under the CCPA as amended by the CPRA. California residents have the right to know the categories of personal information collected, the sources of that information, the purposes for collection, and the categories of third parties to which it is disclosed; the right to delete personal information; the right to correct inaccurate personal information; the right to limit the use of sensitive personal information; the right to opt out of the sale or sharing of personal information; and the right not to receive discriminatory treatment for exercising any of these rights. Verdict does not sell personal information and does not share personal information for cross-context behavioral advertising. Verdict operates no advertising campaigns, uses no advertising cookies, and does not collect sensitive personal information for the purpose of inferring characteristics.
6.6 Authorized agents. A request may be submitted by an authorized agent on presentation of written authorization from the individual concerned.
International Transfers
7.1 Processing location. Verdict infrastructure operates in the United States. Personal data submitted from another country is transferred to and processed in the United States, and may be processed in other countries in which a sub-processor listed in section 4 operates.
7.2 Transfer mechanism. Transfers of personal data protected by the GDPR or by United Kingdom data protection law to a country without an adequacy decision are made on the basis of the European Commission’s Standard Contractual Clauses, together with the United Kingdom International Data Transfer Addendum where applicable. Copies of the relevant transfer documentation are provided on written request to legal@useverdict.io.
Security
8.1 Encryption. Submitted documents are encrypted at rest using AES-256. Traffic to and from the Service is encrypted in transit using TLS 1.2 or higher. Payment card details are submitted directly to the payment processor through tokenized checkout and do not reach Verdict infrastructure.
8.2 Account isolation. Every request to a data endpoint resolves the authenticated user on the server before any record is read or written, and each query is scoped to that user. Row-level security is enabled on every table holding customer data, and no policy admits an unauthenticated request: each requires either a service-role credential or an authenticated session, so an anonymous query returns no rows. Some policies grant scoped access to the signed-in database role. The application ships no browser-side database client, so in practice a browser does not query the database directly. Server-side access uses a credential that is not subject to row-level security, so isolation between accounts is enforced by server-side scoping of every query, with row-level security operating as an additional layer behind it. Verdict personnel holding an administrative account can open any account’s reports through the application, and can download the deck file uploaded with a report while that file is still held, which is how support and debugging requests are answered. Two people hold that access: Verdict’s founder, and one further person Verdict has authorized to assist in operating the Service. They hold several such accounts between them, because the founder signs in under more than one address. The access is not conditioned on a per-incident authorization, and opening a report leaves no record at all, so Verdict cannot report whether or when an account’s reports were opened by Verdict personnel. Verdict does not represent that row-level security would contain an application-layer scoping defect.
8.3 Public availability of reports. Reports are private to the account that created them, and Verdict does not make a report readable outside that account on its own initiative. A report becomes readable by a person who holds no account where the customer makes it so, including where the customer generates a share link, generates a co-investor link, connects a Slack workspace, in which case Verdict delivers report content into the channel the customer selects and it is readable by that channel’s members, or exports a report and distributes the exported file. A share link or a co-investor link may be revoked at any time, and a workspace may be disconnected. Verdict separately publishes a gallery of analyses that Verdict itself prepares, of companies Verdict selects for demonstration and that are not Verdict customers; Verdict does not publish a customer’s submitted documents, or any report generated from them, to that gallery or to any other public surface without the customer’s prior written consent.
8.4 Error reporting and its limits. Server-side error reports are filtered before transmission to remove authentication tokens, session cookies, known secret values, and email addresses, and long payloads are truncated. Two qualifications apply. First, this filtering is applied to server-side reports; reports originating in the browser and at the network edge are transmitted without it. Second, error sessions may include a session recording captured with the provider’s default masking, which is designed to obscure text and media but is not a guarantee that no content is captured. Verdict does not currently offer a control that excludes an individual from error-session recording, and the recording is delivered through Verdict’s own domain, so a browser extension that blocks third-party trackers does not prevent it. An individual who does not wish to be recorded should write to legal@useverdict.io.
8.5 Incident notification. On becoming aware of a security incident affecting personal data, Verdict notifies the email address associated with each affected account within seventy-two (72) hours, stating what occurred, which categories of data were affected so far as then known, what is being done in response, and any recommended action.
8.6 Controls Verdict does not have. Verdict holds no SOC 2, ISO 27001, or equivalent third-party attestation, has engaged no auditor, and has commissioned no external penetration test. A full statement is maintained at useverdict.io/security.
Google User Data and Limited Use
Verdict’s use and transfer to any other app of information received from Google APIs will adhere to Google API Services User Data Policy, including the Limited Use requirements.
9.1 Current availability. The Google Calendar integration is not currently available to new users. The control that begins authorization is disabled in the Service, and the relevant Google authorization scope has been withdrawn from Verdict’s consent screen pending Google verification. Accounts that completed authorization while the scope was offered continue to have calendar data read as described below, and may withdraw that authorization at any time under section 9.4.
9.2 What is accessed. Where an authorization is in place, Verdict reads events from the Google Calendar of the authorizing user in order to produce a preparation summary before a scheduled meeting and to identify engagement for reminder purposes. Access is read-only. Verdict does not create, alter, or delete calendar entries. Verdict requests only the scopes required for the feature the user has enabled, and those scopes are displayed on Google’s consent screen before any access is granted.
9.3 Restrictions on use. Verdict does not use Google user data to serve, target, or measure advertising. Verdict does not use Google user data to train, fine-tune, or improve any generalized artificial intelligence or machine learning model. Verdict does not sell, rent, or transfer Google user data to any third party except as necessary to provide the feature the user has enabled, to comply with applicable law, or to investigate abuse. Verdict personnel do not read a user’s Google data except with that user’s express consent while investigating a support request that the user has raised, where required by law, or to investigate a security incident.
9.4 Withdrawing authorization. Authorization is withdrawn from Google Account permissions at myaccount.google.com/permissions, which takes effect immediately. Verdict does not currently provide a withdrawal control inside the Service. To have calendar data already stored by Verdict deleted, write to legal@useverdict.io, and Verdict will delete it within thirty (30) days of the request.
9.5 Storage. Calendar data retrieved under an authorization is stored under the same encryption and access controls as the rest of the account’s data, and is subject to the retention periods in section 5.
9.6 Google Analytics is separate. The Google Analytics measurement described in sections 4 and 11 is a distinct processing activity. It does not rely on any Google user authorization, applies to every visitor rather than to authorizing users only, and is not governed by this section.
Children
The Service is intended for use by adults. Verdict does not knowingly collect personal data from any person under eighteen (18) years of age. Where Verdict becomes aware that it holds such data, it deletes the data and closes the associated account. Reports may be made to legal@useverdict.io.
Cookies and Similar Technologies
11.1 Categories in use.
- Strictly necessary. Session cookies set by the authentication provider to keep a user signed in, and cookies set by the payment processor during checkout to support fraud prevention. The Service cannot function without these.
- Analytics. Cookies and equivalent local storage set by PostHog, and, where that script executes, the
_gaand_ga_*cookies set by Google Analytics. These record page views and feature usage for measurement purposes.
11.2 Controls. Enabling the Do Not Track setting in a browser stops the PostHog browser library from capturing any event. A small number of account events recorded from Verdict servers are not affected by that setting. Google Analytics does not respond to that setting; it can be prevented from collecting data by installing Google’s browser opt-out add-on, by using a browser or extension that blocks the Google Analytics script, or by blocking cookies for this site. Blocking analytics cookies does not affect the operation of the Service.
11.3 Advertising. Verdict does not use advertising cookies, does not operate advertising campaigns using data collected through the Service, and does not participate in cross-context behavioral advertising.
Changes to this Policy
Verdict may amend this Policy. Where an amendment is material, including the engagement of a new sub-processor, the collection of a new category of personal data, a new purpose of processing, or a change to a retention period, Verdict will notify each account by email at least thirty (30) days before the amendment takes effect and will update the version designation and effective date on this page. Continued use of the Service after the effective date constitutes acceptance of the amended Policy.
Contact
Privacy inquiries, rights requests, requests for transfer documentation, and requests for the registered mailing address may be sent to legal@useverdict.io.