Last updated · 2026-09-02
Privacy Policy
This Privacy Policy describes how the VeriBag iOS application and public verification service (together, the “Service”) handle information. We collect the minimum required to provide the Service and we don’t sell user data.
1. What we collect
- Subscription identifier. RevenueCat processes an anonymous App User ID and purchase status so the App can provide paid access. We do not receive your payment card or full Apple ID.
- Scan photographs. Sent over TLS through our Cloudflare Worker to OpenAI for visual analysis. We do not write scan photographs to Supabase or another report database. OpenAI processes them under its applicable API data terms.
- Text observations and structured report. Textual observations produced during visual analysis are sent to DeepSeek for report reasoning. Unless Private Scan is enabled, the final 22-checkpoint output, market comparables, a tamper-evident hash, and the anonymous RevenueCat App User ID are stored in Supabase so the public verification link can work.
- Network information. Cloudflare and our service providers necessarily receive network metadata such as IP address. An IP-derived key may be stored temporarily for rate limiting and abuse prevention. The App does not include a third-party analytics or advertising SDK.
2. Private Scan Mode
Private Scan still sends photographs through the Cloudflare Worker to OpenAI and sends resulting text observations to DeepSeek so the requested analysis can be produced. When Private Scan is enabled, the App does not save the report to local history, the Worker does not save the structured report or RevenueCat App User ID to Supabase, and no public verification URL is created.
3. Public verification page
When you share a case link (veribag-verify.pages.dev/v/<id>), the public page shows only the structured report — brand/model, generation timestamp, checkpoint table, market comparables, and tamper-evident hash. It never exposes your photographs, your account identifier, your device, or your location.
4. Payment information
Subscriptions are processed by Apple. We never receive your payment card or full Apple ID.
5. Data retention
- Scan photographs: not written to our report database; AI processors handle them according to their applicable API retention terms.
- Structured reports: retained while the case link is intended to remain live. You can request deletion from support.
- Subscription data: RevenueCat retains purchase and entitlement records as needed to operate and restore purchases. For public reports, the anonymous App User ID remains with the report until the report is deleted. Private Scan does not store it in Supabase.
6. Children
The Service is not directed at children under 13 and we do not knowingly collect data from them.
7. Your rights
You can request access, correction, or deletion of data tied to your subscription identifier at loveykovl@gmail.com.
8. Contact
loveykovl@gmail.com