Skip to content
Veristria
See the evidence

Legal

Privacy Policy

The short version: we collect an email address if you give us one, and each product collects what it needs to do the job you asked it to do. Our sites use Google Analytics to count visits. Nothing is sold and nothing is shared with advertisers.

Last updated 16 September 2026


Who we are

The controller of the personal data described here is Veristria, a Norwegian aksjeselskap (AS) under incorporation (filed 24 August 2026), at Sofie Steinnes'veg 9A, 4352 Kleppe, Norway. The organisation number will be published on this page the day registration completes.

The legal desk handles anything on this page — access requests, deletion requests, corrections, a DPA, or a question about a sentence you do not believe: legal@teamveristria.com. Anything else reaches support@teamveristria.com; phone +47 988 36 369 (Europe/Oslo). We only send email from @teamveristria.com, @useveristria.com, @meetveristria.com, @veristriagroup.com, @veristriahq.com, @veristriaworks.com and @withveristria.com.


Scope

What this page covers

Four sites, one company, four different answers to “what do you actually collect?”

This page covers veristria.com and gives the accurate summary for each product. Each product site — keydrift.dev, rowshield.dev and feeguard.dev — publishes its own privacy page with the full detail for that service, and that page is the authoritative one if you are a customer of it.


What veristria.com collects

This site has no accounts, no login and no payments. It runs Google Analytics in production, and there is exactly one form on it: the launch list.

When you submit that form we store three things — the email address you typed, lowercased; a tag saying which of our sites captured it; and the time of the insert. No IP address, no browser fingerprint, no referrer, no name. The address is never written to a log, on success or on failure. We use it once: to tell you when the products go live, and to send the newsletter if you asked for it. Every message we send carries an unsubscribe link.

The rest of this site is static pages. Apart from Google Analytics on the production site, it sets no cookies of its own and loads no third-party scripts.


Per product

What the products collect

These differ more than you might expect. One of the three never asks for a credential at all.

KeyDrift — reads what your site already serves in public

You give KeyDrift a URL. It fetches that page and the JavaScript files the page links to, exactly as a browser would, and reads them for exposed keys. It never asks for a credential, never signs in to anything, and issues only GET and HEAD requests — the fetch layer refuses anything else.

It stores the URL you submitted, the URL it ended up at after redirects, which files it read, and the findings. A finding never contains a live secret: the value is masked to a short prefix and suffix, and stored alongside a salted hash. Scan reports created from a URL are public and can be opened by anyone with the link. If you paste source code instead of a URL, the pasted text is not stored at all and the report is not indexed.

Full policy on keydrift.dev

RowShield — reads your database's structure, not its contents

The free audit takes a URL and, optionally, the publishable key your app already ships to browsers. It checks which tables that key can reach. To do that it asks each table for a single row, then immediately reduces the answer to the column names and the row count. Row values are never stored, never returned to you, and never leave the request.

Continuous monitoring uses a Postgres connection string you create and can revoke. It is encrypted before storage and decrypted only inside the scanner. The scanner runs a fixed set of catalog queries — tables, columns, policies, indexes, storage bucket settings, server version — and issues no writes of any kind. What we keep is a snapshot of that structure plus the findings derived from it.

Full policy on rowshield.dev

FeeGuard — reads your Stripe account through a key you restrict

The free audit deliberately does not accept a Stripe key. You paste event data, or run the built-in sample, and nothing you paste is stored — the findings are returned to your browser and the export is built there.

Monitoring uses a Stripe API key you create yourself. FeeGuard asks for a restricted key with five read permissions; two write permissions are optional and only enable automatic recovery. The key is encrypted with a per-tenant key before it is written, is never returned to your browser, and stops working the moment you revoke it in Stripe. What we store from your account is the reconciliation record: Stripe object identifiers, amounts, and the discrepancies found between them.

Full policy on feeguard.dev


Accounts, support and payments

Accounts. The product sites sign you in with a magic link or an email and password handled by our authentication provider. We hold your email address, an account identifier, and which organisation you belong to. We do not store passwords ourselves.

Support conversations. Where a site offers the support assistant, the conversation is processed by a third-party model provider and logged on our side so a human can pick up what the assistant could not answer. If you give a name and an email so we can send you the transcript, that is stored with the conversation. The assistant is labelled as an AI and will say so if you ask.

Payments. Subscriptions are billed through Stripe. Stripe collects and holds the card details; we never see or store a card number. What reaches us is the customer and subscription identifier, the plan, and whether the invoice was paid.


Legal bases

Why we are allowed to hold it

Contract
Account data, scan and audit records, and billing data are processed because you asked for the service and we cannot deliver it otherwise.
Consent
The launch list and the newsletter. You gave us the address for that purpose, and you can withdraw it from any message we send, or by emailing us.
Legitimate interests
Keeping the services up and abuse under control — rate-limit counters, server logs, and the audit trail of who changed what inside an account. We keep these narrow and short-lived.
Legal obligation
Invoices and the accounting records behind them, which Norwegian law requires us to retain.

Processors

Who else touches it

These are the companies that process data on our behalf. We do not sell data and we have no advertising partners.
Vercel
Hosting and delivery for all four sites. Sees requests as they arrive.
Supabase
The Postgres database and the authentication service behind the products and the launch list.
Stripe
Payments, subscriptions and the billing portal. Stripe is the controller of the card data it collects.
OpenRouter
Model inference for the support assistant. It receives the conversation text only — no account records, no scan data.

Individual products use a small number of additional processors for things like queues and transactional email. Each product’s own privacy page lists them.


Cookies

On the product sites the strictly necessary cookies are the session cookie that keeps you signed in and the cookies Stripe sets during checkout. On every site, including this one, the production deployment loads Google Analytics, which sets its own cookies to count visits and see which pages get read. There are no advertising cookies.

Analytics is the one thing here that is not strictly necessary. It is not gated behind a consent prompt: the cookie notice tells you it is there, and any browser-level tracking protection or content blocker stops the tag.


How long we keep it

Launch-list and newsletter addresses: until you unsubscribe or ask us to delete them.

Account and product data: for as long as the account exists. Close the account, or email us, and we delete it.

Scan and audit records: kept with the account that created them. Records created without an account — a free scan you ran while logged out — are currently kept until you ask us to remove them. We would rather tell you that plainly than publish a retention period we do not yet enforce in code.

Invoices and accounting records: for the period Norwegian bookkeeping law requires, which is longer than any of the above and is not something we can shorten on request.

Rate-limit counters: minutes to a day, then gone.


Your rights

Under the GDPR you can ask us for a copy of what we hold about you, ask us to correct it, ask us to delete it, ask for it in a portable form, object to processing based on legitimate interests, and ask us to restrict processing while a dispute is open. Where processing rests on consent, you can withdraw it at any time.

Email legal@teamveristria.com and we will answer within a month. There is no form and no fee. We will ask you to confirm you control the address in question, because handing an account’s data to whoever asks first would be its own privacy failure.


Where the data lives

We are based in Norway and the services are operated for the EEA. Some of our processors are established in the United States and may process data there. Where that happens it is covered by the transfer mechanisms those providers publish — standard contractual clauses and, where applicable, the EU–US Data Privacy Framework. Their current terms are linked in the processor list above.


Complaints

Tell us first if you can — most things are a misunderstanding we can fix the same day. If we do not resolve it, you have the right to complain to the Norwegian Data Protection Authority, Datatilsynet, at datatilsynet.no, or to the supervisory authority where you live.


Changes to this policy

When the code changes, this page changes, and the date at the top moves. If a change materially affects what we do with data you have already given us, we will say so by email rather than quietly editing the page.

Ask us anything on this page

Including “prove it”. If a sentence here does not match what a product does, that is a bug and we want to know.