Legal

Privacy Policy

What we collect, where it lives, who else touches it, how long we keep it, and how to reach us.

Effective 6 September 2026.

1. Who we are

dVeracity (226 Skylark Pt, Jupiter, FL 33458, USA) operates dveracity.com, the dVeracity API at api.dveracity.com, the dVeracity MCP server, and the verification platform behind them. For the personal data described here, dVeracity is the data controller. You can reach us at contact@dveracity.com.

2. What we collect

When you create an account

  • Your email address, your organisation name, and a password. The password is stored only as a one-way hash; we cannot read it.
  • Your account role, subscription tier and status, whether your email is verified, and the time of your last login.
  • If you reset your password, a single-use reset token and its expiry.

When you use the API or the MCP server

  • API keys. We store a one-way hash of each key, its first characters (so you can recognise it), the name you gave it, its scopes, and when it was last used. We cannot recover a key from what we store.
  • OAuth. When an AI client connects through OAuth, we store the client's registration details (name, redirect URLs, any contact or policy URLs it declares), and one-way hashes of the tokens we issue, with their scopes, expiry and revocation time.
  • Usage records. For every metered call we record which endpoint was called, when, the response status and timing, and which API key or account it was billed to. This is how credits are metered and how we investigate faults.
  • Request telemetry. Our services record the user agent of each request and, for MCP connections, the name and version the connecting client declares about itself. We do not build profiles from this.
  • Verified-agent identity (optional). If an agent authenticates with a vLEI credential, we record the agent identifier (AID), the legal entity identifier (LEI) it presents, and the scopes granted for that session.

When you submit data for verification

  • Emissions data, product footprints, supporting documents and the results of validating them. This is business data you choose to submit. It may contain personal data if you include it (for example, a contact name inside a document); please avoid submitting personal data that the verification does not need.
  • Uploaded files are stored in a cloud storage bucket assigned to your tenant.

When you pay

  • Payments are handled by Stripe. We send Stripe your email address and account name and keep Stripe's customer and subscription identifiers so we can recognise your subscription. We never see or store card numbers.

What we do not collect

The website runs no analytics or advertising scripts and sets no tracking cookies. We do not buy data about you from third parties.

3. Why we use it

  • To operate your account and authenticate you, your API keys, and the AI clients you authorise.
  • To meter and bill usage, and to show you your own usage and balance.
  • To run verifications you request and return their results to you.
  • To keep the service reliable and secure: diagnosing faults, detecting abuse, attributing traffic to the account responsible for it.
  • To send you transactional email — password resets and, where you have opted in, service notices. We do not send marketing email from this system.

Where the GDPR applies, we rely on performance of our contract with you (account, API and billing), our legitimate interest in running a secure, reliable service (telemetry and usage records), and your consent where we ask for it.

4. Where it is stored — residency and sovereignty

dVeracity is designed so that where your data resides and whose law governs it are decided separately, per customer, rather than fixed by where we happen to run. Each customer organisation is provisioned as its own tenant with its own database and file storage, and the platform records for that tenant the data region it is provisioned in, its data classification, and its retention period. Data belonging to one tenant is never stored alongside another's.

Residency — the region in which a tenant's database and files are held — is set when the tenant is provisioned and can be chosen to satisfy the customer's own regulatory obligations. Sovereignty — which jurisdiction's law applies, who the controller is for the customer's own data, and what must be retained for how long — follows the customer's jurisdiction, not the hosting region. Where a customer has not specified a region, tenants are currently provisioned on Google Cloud in the United States (us-east1); the public website is served from the Netherlands (europe-west4). Ask us before onboarding if you need a specific region, and we will provision your tenant there.

5. Who we share it with

We do not sell personal data. We share it only with the providers we need to run the service:

  • Google Cloud — hosting, database, file storage, logging and telemetry, and email delivery (Google Workspace SMTP relay for transactional mail).
  • Google Vertex AI — documents and data you submit for verification may be processed by Vertex AI models to extract and structure their contents. Google does not use Vertex AI customer inputs to train its models.
  • Stripe — payment processing, as described above.
  • The AI client you connect. When you authorise an AI assistant (Claude, ChatGPT or another MCP client) to use dVeracity, the results of the tools it calls are returned to that client. What that client does with them is governed by its operator's privacy policy, not ours.
  • Authorities, where the law requires it.

6. How long we keep it

  • Account data — for as long as your account exists, and after that only for as long as the regulation of your jurisdiction requires us to keep it. You can ask us to delete your account at any time; we delete what the law does not oblige us to retain, and tell you what remains and why.
  • API keys — until you revoke them or they expire.
  • OAuth tokens — access tokens expire after one hour, refresh tokens after thirty days, authorisation codes after ten minutes. Revoked tokens are marked rather than deleted, as an audit record.
  • Usage records — for the period the regulation of your jurisdiction requires for billing and audit records, and no longer. They are needed for billing disputes and abuse investigation.
  • Service logs and telemetry — per Google Cloud Logging's retention, thirty days by default.
  • Verification data and documents — for the retention period recorded for your tenant, which we set to match the regulation and reporting standards of your jurisdiction, since a verification result must remain reproducible for as long as anyone may rely on it. Tell us the period you are bound to and we will set it.
  • Password-reset tokens — single use; expire shortly after issue.

7. AI agents and connectors

dVeracity is built to be used by AI agents. Three things are worth knowing:

  • An agent can connect only with a credential a human created — an API key from a subscribed account, or an OAuth grant approved on our consent screen. We do not issue anonymous access.
  • Every tool the MCP server exposes is read-only against your data: none of them creates, changes or deletes anything you own. Metered tools spend credits; that is a billing event, not a change to your data.
  • We record which client connected (its declared name and version) and which account it acted for, so that usage is attributable. We do not record the content of your conversation with the agent — only the requests that reach us.

8. Cookies

When you sign in on dveracity.com we set one cookie holding your session token. It is marked HttpOnly, Secure and SameSite=Strict, and lasts thirty days or until you sign out. It is strictly necessary for the service and is the only cookie we set. We use no analytics, advertising or third-party cookies.

9. Your rights

Depending on where you live, you may have the right to access the personal data we hold about you, to correct it, to have it deleted, to restrict or object to how we use it, and to receive it in a portable form. Deletion is subject only to what the regulation of your jurisdiction obliges us to retain. You can see and revoke your API keys and connected clients in your dashboard. For anything else, email us at contact@dveracity.com; we respond within thirty days. If you are in the EU or UK you may also complain to your supervisory authority.

10. Security

Passwords, API keys and OAuth tokens are stored only as one-way hashes. All traffic is encrypted in transit. Each customer's data is isolated by tenant, and access to production is limited to the people who operate it. If we learn of a breach affecting your data, we will tell you without undue delay.

11. Changes

When we change this policy we update the effective date at the top. Where a change materially affects how we use your data, we will notify account holders by email before it takes effect.

12. Contact

dVeracity, 226 Skylark Pt, Jupiter, FL 33458, USA. contact@dveracity.com

See also Pricing and the Semantic API.