Privacy Policy
Veracrat is a US-based company. This policy explains what we collect, why, where it goes, and how to get it deleted, with protections for US state privacy laws and global frameworks including GDPR.
1. What we collect
- Account data — email address, authentication identifiers, and the organization (tenant) you belong to.
- Inventory data you upload — asset tags, serial numbers, models, manufacturers, and rack positions.
- Scan images — photographs you capture or upload of racks and equipment.
- AI output — the structured findings the model returns, and (for a limited period) the raw model response.
- Pilot enquiries — name, work email, company, role, facility count, and any message you submit.
- Operational metadata — timestamps, the user who ran a scan, and rate-limiting records keyed to a truncated IP address.
We do not collect precise geolocation. We do not use cookies for advertising, and we do not run third-party analytics or ad trackers.
Usage analytics. We do not operate a third-party product-analytics or advertising SDK. The only usage data we hold is generated by the application itself: server logs and error reports (request path, status, timestamp, and a user or tenant identifier), scan provenance (which user ran which scan, against which rack, with which model version), and rate-limiting counters. Cookies and browser storage are used only to keep you signed in.
Billing data. Paid plans hold the plan name, billing interval, renewal date, cancellation state, and the address used for renewal reminders. If and when card payments are enabled, card details are handled by the payment processor and never stored by Veracrat.
1a. Third parties that receive or process your data
We use a small number of processors, each bound by a data processing agreement and permitted to use the data only to provide their service to us:
- Hosting, database, authentication, and object storage — Lovable Cloud, running on Supabase (Postgres, Auth, Storage) and Cloudflare edge compute. Receives all account data, inventory records, scan images, and findings.
- AI inference — Lovable AI Gateway, which routes to Google (Gemini) as the underlying model provider. Receives the scan image and the expected-inventory summary for that rack.
- Transactional email — the provider that delivers account, renewal-reminder, and support email. Receives your email address and the message content.
- Payment processing — a PCI-DSS-compliant processor, engaged only when card payments are enabled. Would receive billing contact and card data directly; Veracrat receives only the payment status.
- DCIM / ITSM integrations — only the systems you explicitly connect. Data flows in the direction you configure; we do not connect anything on your behalf.
We do not sell data, do not disclose it to advertisers or data brokers, and do not use customer content to build features for other customers. We may disclose data where legally compelled, and will tell you unless prohibited. The current named list is on the sub-processor page, which we update before adding a processor that touches scan images or inventory data.
2. Legal basis and US / global privacy rights
US state privacy laws. For residents of California, Virginia, Colorado, Connecticut, Utah, and other US states with comprehensive privacy statutes, Veracrat acts as a business or service provider. We process personal information for the following purposes:
- Providing and maintaining the audit service — performing our contract with you.
- Security and abuse prevention — protecting accounts, infrastructure, and data.
- Customer support — responding to enquiries and troubleshooting issues.
- Product improvement — internally analyzing usage and error data to improve the service; we do not sell or share personal information for cross-context behavioral advertising.
We do not sell personal information. We do not share personal information for cross-context behavioral advertising. We do not process sensitive personal information except as needed to provide the service or with your consent where required by law.
Your US state rights. Depending on your state, you may have the right to know what personal information we collect, access it, correct inaccuracies, delete it, opt out of certain processing, and request portability. We will not discriminate against you for exercising these rights. To make a request, email privacy@veracrat.com. We verify requests before acting and respond within the timeframe required by applicable law. If we decline a request, you may appeal where state law provides an appeal process.
Global / GDPR and UK GDPR. Where UK or EU law applies, we rely on: performance of a contract, legitimate interests (security, abuse prevention, responding to enquiries), and consent where you tick a box or otherwise opt in. Where your organization is the controller and Veracrat is the processor, our data processing terms govern and we act only on your documented instructions.
3. People captured in photographs
Scan photographs are intended to show equipment, not people. You must not deliberately photograph identifiable individuals, badges, or screens containing personal data. Where a person is incidentally captured, that image is personal data and you are responsible for having a lawful basis and appropriate notice for your staff and contractors.
Veracrat does not run facial recognition, does not attempt to identify individuals, and does not create biometric templates from any image.
4. AI processing and international transfer
To produce findings, the scan image and the expected-inventory summary for that rack are transmitted to the Lovable AI Gateway and onward to the underlying model provider. This processing may take place outside your country of residence, including in the United States.
Exactly what is sent. The photograph you capture, the rack label, and the list of asset tags, serials, models, and rack positions expected in that rack. Your email address, account identifiers, and other facilities' data are not sent.
Training. Your images, inventory, and prompts are not used to train or fine-tune Veracrat models or the model provider's models. We send inference requests under enterprise/API terms that exclude training on submitted content.
Retention at the provider. Inference is stateless from our side: we do not ask the provider to persist conversations. Providers may hold a request transiently for abuse monitoring under their own terms (typically up to 30 days). Inside Veracrat, the raw model response is redacted 30 days after the scan and only the structured findings and model provenance remain.
Human review. Every AI finding is labelled as AI-generated and requires a human decision before it counts as audit evidence. No automated decision with legal effect is made about any individual.
For UK and EU users, transfers rely on the UK IDTA / EU Standard Contractual Clauses with our sub-processors. See the sub-processor list for the current chain, and the AI transparency notice for how AI output is labelled.
5. Retention and deletion
- Scan images and findings: retained for the retention window configured for your tenant (default 365 days), then purged.
- Raw model responses: redacted 30 days after the scan; the structured findings are kept.
- Pilot enquiries: retained for up to 24 months, or until you ask us to delete them.
- Rate-limiting records: pruned automatically within the limiting window.
You can delete an individual scan and its underlying image at any time from the scan detail page in the console. Deletion removes the stored object, not any copy you have already exported.
Deletion is real deletion. Deleting a scan removes the photograph from object storage as well as the database record — it is not hidden from the interface while remaining on disk. Closing your account from Console → Settings erases, immediately and irreversibly, every scan image, AI finding, sign-off record, asset, rack, site, subscription record, and the login itself for any organisation you solely own. The console reports how many stored images were removed and confirms the storage prefix is empty. Encrypted infrastructure backups may retain data for up to 30 days before rolling off; we do not restore deleted customer data from them for any other purpose.
Scan images live in a private bucket. There is no public bucket and no public object URL: access is only ever through a short-lived signed URL issued to a signed-in member of the owning organisation.
5a. Billing, renewal, and cancellation
Paid plans renew automatically — every 30 days on monthly billing, or every 12 months on annual billing — at the list price, until cancelled. We email a renewal reminder 7 days before each charge to the address on the account. Cancellation is one click in Console → Settings and never requires an email, a phone call, or a retention conversation. Cancelling stops the next charge and access continues to the end of the period you have already paid for.
6. Your rights and how to contact us
You may request access, correction, deletion, restriction, portability, or object to processing where applicable law gives you those rights. To exercise any right, or to ask about this policy, email privacy@veracrat.com. We respond within the timeframe required by the law that applies to you. EU and UK residents may also complain to their local supervisory authority.
7. Security
Data is isolated per tenant at the database level, scan images are stored in a private bucket accessible only through short-lived signed URLs, and all write endpoints are rate limited. No system is perfectly secure; report a suspected vulnerability to security@veracrat.com.
This page is maintained by Veracrat. It describes our current practices and is not an independent certification or legal advice. Questions: privacy@veracrat.com.