Trust & privacy

Privacy by architecture, not policy.

Strong privacy claims are the ones the architecture itself enforces. VERI-fy keeps detection on your machine, holds your account on a small layer that does only one job, and ships zero analytics SDKs.

Data flow

One arrow. No middlemen.

Every screenshot VERI-fy takes goes from your machine, over HTTPS, to generativelanguage.googleapis.com. The frames themselves are never routed through our account layer or held by us.

  1. Your screen

    Primary display, captured every 5 seconds. VERI-fy windows excluded from the capture during the cycle.

  2. VERI-fy on your machine

    Two frames ~50 ms apart, downscaled to 1280 px wide, JPEG q60. Held in RAM. Forgotten when the app closes.

  3. Google Gemini

    HTTPS to generativelanguage.googleapis.com using your own API key. Google's terms govern what Google does with the payload.

No VERI-fy analysis server. Frames go directly to Google. We never see them.

Guarantees

Four guarantees the architecture itself enforces.

  1. No VERI-fy analysis server

    Frames are not routed through us. Each scan goes from your machine straight to Google Gemini over HTTPS. The small account layer we run never sees the screenshots.

    01 / 04
  2. Session credentials in memory

    Your session token lives in process memory for the current session. Never written to disk. Logged out and forgotten when you close the app.

    02 / 04
  3. History in RAM only

    The most recent 50 detections live in RAM and are forgotten when you close the app. No audit log, no evidence chain.

    03 / 04
  4. No telemetry, no analytics

    VERI-fy ships without a single analytics, crash-reporting, or advertising SDK. The only network calls we make are signup, account, and the Gemini API.

    04 / 04

Google's side

Free vs paid Gemini key. Choose deliberately.

VERI-fy does not have an opinion on your data. Google does. The Gemini API tier you use determines what Google does with the screenshots VERI-fy sends. We strongly recommend a paid-tier key for sensitive screen content.

Training on your contentNot used by Google
Retention55-day abuse-monitoring only
CostPer Google's pricing

The right default for newsroom, research, or sensitive use. We are not selling you Google Cloud, go to Google AI Studio and create one.

Fair use protection

Free for everyone, fairly.

The Free tier is generous on purpose. To keep its monthly quotas open for the people who actually need them, we look for duplicate accounts that try to game the limits. Here is exactly what that means and what we will not do.

  1. Why we do this

    So 6 videos and 10 photos a month stay available to genuine users. One person opening a dozen accounts to get unlimited Free analyses is a small problem we choose to solve up front.

  2. What we look at

    A one-way SHA-256 hash of a small device-characteristic bundle and your public IP with the last octet masked (203.0.113.xxx form). Both signals only at signup and at sensitive actions.

  3. Legal basis

    Your explicit consent at signup plus our legitimate interest in fraud prevention. KVKK Art. 5/2(f) and GDPR Art. 6(1)(a) and 6(1)(f). You can object at any time.

  4. You stay in control

    12-month retention from your last activity, then automated deletion. Delete your account and the hashes are scrubbed within 90 days. Nothing about this is used for marketing.

Compliance

KVKK and GDPR, by design.

KVKK · Türkiye

Article 5/1: explicit consent of the data subject. VERI-fy shows a consent dialog on every launch that explains the data flow before detection can start.

Read the privacy policy

GDPR · EU

Article 6(1)(a): consent of the data subject. You can withdraw at any time by closing the app. The only persistent local file is consent.json, which records your acceptance.

Read the terms of service

Things we will not say

Five claims you will not see on this page.

  • End-to-end encrypted with respect to Google.Google must decrypt the screenshots to analyze them. TLS in transit, plaintext at the destination. We will say so.
  • Your data never leaves your machine.The frame pair leaves your machine and goes to Google. That is the whole point.
  • Court-admissible forensic evidence.VERI-fy is an experimental research prototype. Outputs are indicators, never evidence.
  • 99.9% accurate.We have no benchmark we trust enough to publish a number. Real cameras produce false positives.
  • Replaces human review.It does not. It is a second opinion. You are the first.