Legal
Privacy Policy
Last updated: June 12, 2026
This Privacy Policy describes how Verdict Inc. ("Verdict", "we", "us") collects, uses, and protects personal information when you use verdict-app.net and the related APIs, CLI, MCP server, and SDKs (the "Service").
1. Information we collect
- Account information. When you sign in with Google or email, we receive your name, email address, and profile image from the identity provider. We do not store passwords.
- Testing session data. The URLs you submit for testing, test configuration, agent activity logs, generated test plans and bug reports, and screenshots captured during testing. Screenshots may incidentally contain content of the tested website.
- Authentication material you provide for testing. If you supply credentials (e.g. cookies or test-account logins) so the agent can test authenticated areas, they are used only to run your session.
- Usage and billing records. Credit balances, transactions, API key metadata, and service logs (IP address, user agent, timestamps) needed to operate and secure the Service.
2. Payment information
Payments are processed by Paddle.com Market Ltd, our merchant of record. Paddle collects and processes your payment details (card number, billing address) under its own privacy policy (paddle.com/legal/privacy). We never receive or store full payment card numbers.
3. How we use information
- To provide the Service: run testing sessions, generate reports, meter usage, and bill.
- To secure the Service: authentication, abuse and fraud prevention, rate limiting.
- To communicate with you about your account, sessions, and material changes to the Service.
- To improve the Service using aggregated, de-identified usage statistics.
We do not sell personal information, and we do not use your data for third-party advertising.
4. Where data is processed and stored
The Service is hosted on Google Cloud Platform in the United States (Cloud Run, Firestore, Cloud Storage). AI analysis during testing sessions is performed using third-party large language model APIs (e.g. Google Gemini); session content needed for analysis is sent to those providers under their API data-use terms and is not used to train their models.
5. Retention
- Screenshots captured during sessions are automatically deleted after 90 days.
- Session records, reports, and billing/transaction history are retained while your account is active and as required for accounting and legal obligations.
- You may request deletion of your account and associated personal data at any time (Section 7).
6. Cookies
We use only essential cookies: session cookies for authentication (NextAuth) and security. We do not use advertising or cross-site tracking cookies.
7. Your rights
Subject to applicable law (including the Korean Personal Information Protection Act and, where applicable, the GDPR), you may request access to, correction of, or deletion of your personal data, restriction of or objection to processing, and data portability. Contact us at support@verdict-app.net and we will respond within the legally required period. You may also lodge a complaint with your local supervisory authority.
8. Security
Data is encrypted in transit (TLS) and at rest. Secrets are stored in a dedicated secret manager, access to production systems is restricted, and API keys are stored hashed. No method of transmission or storage is completely secure; we will notify you of any breach affecting your personal data as required by law.
9. Children
The Service is not directed to children under 14, and we do not knowingly collect their personal information.
10. Changes to this policy
We may update this Privacy Policy from time to time. Material changes will be announced on the website or by email before they take effect.
11. Contact
Verdict Inc. — privacy inquiries: support@verdict-app.net