Legal
Privacy Policy
The short version: we collect an email address if you give us one, and each product collects what it needs to do the job you asked it to do. Nothing is sold, nothing is shared with advertisers, and there is no tracking across sites.
Last updated 24 August 2026
Who we are
The controller of the personal data described here is Veristria, a Norwegian aksjeselskap (AS) under incorporation (24 August 2026), based in Norway. The organization number will be published on this page the day registration completes.
One address reaches us for anything on this page — access requests, deletion requests, corrections, or a question about a sentence you do not believe: info@useveristria.com.
Scope
What this page covers
This page covers veristria.com and gives the accurate summary for each product. Each product site — keydrift.dev, rowshield.dev and feeguard.dev — publishes its own privacy page with the full detail for that service, and that page is the authoritative one if you are a customer of it.
What veristria.com collects
This site has no accounts, no login, no payments and no analytics. There is exactly one form on it: the launch list.
When you submit that form we store three things — the email address you typed, lowercased; a tag saying which of our sites captured it; and the time of the insert. No IP address, no browser fingerprint, no referrer, no name. The address is never written to a log, on success or on failure. We use it once: to tell you when the products go live, and to send the newsletter if you asked for it. Every message we send carries an unsubscribe link.
The rest of this site is static pages. It sets no cookies of its own and loads no third-party scripts.
Per product
What the products collect
KeyDrift — reads what your site already serves in public
You give KeyDrift a URL. It fetches that page and the JavaScript files the page links to, exactly as a browser would, and reads them for exposed keys. It never asks for a credential, never signs in to anything, and issues only GET and HEAD requests — the fetch layer refuses anything else.
It stores the URL you submitted, the URL it ended up at after redirects, which files it read, and the findings. A finding never contains a live secret: the value is masked to a short prefix and suffix, and stored alongside a salted hash. Scan reports created from a URL are public and can be opened by anyone with the link. If you paste source code instead of a URL, the pasted text is not stored at all and the report is not indexed.
RowShield — reads your database's structure, not its contents
The free audit takes a URL and, optionally, the publishable key your app already ships to browsers. It checks which tables that key can reach. To do that it asks each table for a single row, then immediately reduces the answer to the column names and the row count. Row values are never stored, never returned to you, and never leave the request.
Continuous monitoring uses a Postgres connection string you create and can revoke. It is encrypted before storage and decrypted only inside the scanner. The scanner runs a fixed set of catalog queries — tables, columns, policies, indexes, storage bucket settings, server version — and issues no writes of any kind. What we keep is a snapshot of that structure plus the findings derived from it.
FeeGuard — reads your Stripe account through a key you restrict
The free audit deliberately does not accept a Stripe key. You paste event data, or run the built-in sample, and nothing you paste is stored — the findings are returned to your browser and the export is built there.
Monitoring uses a Stripe API key you create yourself. FeeGuard asks for a restricted key with five read permissions; two write permissions are optional and only enable automatic recovery. The key is encrypted with a per-tenant key before it is written, is never returned to your browser, and stops working the moment you revoke it in Stripe. What we store from your account is the reconciliation record: Stripe object identifiers, amounts, and the discrepancies found between them.
Accounts, support and payments
Accounts. The product sites sign you in with a magic link or an email and password handled by our authentication provider. We hold your email address, an account identifier, and which organization you belong to. We do not store passwords ourselves.
Support conversations. Where a site offers the support assistant, the conversation is processed by a third-party model provider and logged on our side so a human can pick up what the assistant could not answer. If you give a name and an email so we can send you the transcript, that is stored with the conversation. The assistant is labeled as an AI and will say so if you ask.
Payments. Subscriptions are billed through Stripe. Stripe collects and holds the card details; we never see or store a card number. What reaches us is the customer and subscription identifier, the plan, and whether the invoice was paid.
Legal bases
Why we are allowed to hold it
- Contract
- Account data, scan and audit records, and billing data are processed because you asked for the service and we cannot deliver it otherwise.
- Consent
- The launch list and the newsletter. You gave us the address for that purpose, and you can withdraw it from any message we send, or by emailing us.
- Legitimate interests
- Keeping the services up and abuse under control — rate-limit counters, server logs, and the audit trail of who changed what inside an account. We keep these narrow and short-lived.
- Legal obligation
- Invoices and the accounting records behind them, which Norwegian law requires us to retain.
Processors
Who else touches it
- Vercel
- Hosting and delivery for all four sites. Sees requests as they arrive.
- Supabase
- The Postgres database and the authentication service behind the products and the launch list.
- Stripe
- Payments, subscriptions and the billing portal. Stripe is the controller of the card data it collects.
- OpenRouter
- Model inference for the support assistant. It receives the conversation text only — no account records, no scan data.
Individual products use a small number of additional processors for things like queues and transactional email. Each product’s own privacy page lists them.
Cookies
We set strictly necessary cookies only. On the product sites that means the session cookie that keeps you signed in, and the cookies Stripe sets during checkout. There are no advertising cookies, no analytics cookies and nothing that follows you to another site. veristria.com sets none at all.
That is why you are not reading this through a consent banner. Strictly necessary cookies do not require consent, and we have nothing else to ask you about. If that ever changes — if we ship anything that is not strictly necessary — a consent banner appears first, and it will default to off.
How long we keep it
Launch-list and newsletter addresses: until you unsubscribe or ask us to delete them.
Account and product data: for as long as the account exists. Close the account, or email us, and we delete it.
Scan and audit records: kept with the account that created them. Records created without an account — a free scan you ran while logged out — are currently kept until you ask us to remove them. We would rather tell you that plainly than publish a retention period we do not yet enforce in code.
Invoices and accounting records: for the period Norwegian bookkeeping law requires, which is longer than any of the above and is not something we can shorten on request.
Rate-limit counters: minutes to a day, then gone.
Your rights
Under the GDPR you can ask us for a copy of what we hold about you, ask us to correct it, ask us to delete it, ask for it in a portable form, object to processing based on legitimate interests, and ask us to restrict processing while a dispute is open. Where processing rests on consent, you can withdraw it at any time.
Email info@useveristria.com and we will answer within a month. There is no form and no fee. We will ask you to confirm you control the address in question, because handing an account’s data to whoever asks first would be its own privacy failure.
Where the data lives
We are based in Norway and the services are operated for the EEA. Some of our processors are established in the United States and may process data there. Where that happens it is covered by the transfer mechanisms those providers publish — standard contractual clauses and, where applicable, the EU–US Data Privacy Framework. Their current terms are linked in the processor list above.
Complaints
Tell us first if you can — most things are a misunderstanding we can fix the same day. If we do not resolve it, you have the right to complain to the Norwegian Data Protection Authority, Datatilsynet, at datatilsynet.no, or to the supervisory authority where you live.
Changes to this policy
When the code changes, this page changes, and the date at the top moves. If a change materially affects what we do with data you have already given us, we will say so by email rather than quietly editing the page.
Ask us anything on this page
Including “prove it”. If a sentence here does not match what a product does, that is a bug and we want to know.