Privacy

Privacy Policy

Last updated September 3, 2026

Veridenti is built so we can't see your data — not "won't," can't. This page explains exactly what is stored, where it lives, and what never leaves your device.

The short version

The short version: Veridenti is built so we can't see your data. Your vault is encrypted on your device with a key only you hold. We don't sell data, we don't show ads, and we don't contact any server unless you turn on a feature that needs one. Our only revenue is subscriptions — you're the customer, not the product.

Data we collect, how we use it, where it's stored, and who it's shared with

The table below lists every category of personal or sensitive data Veridenti handles, and — for each — why we use it, where it is stored, and whether it is shared. Fuller detail follows in the numbered sections.

Data we collect How we use it (handling) How & where it's stored Sharing
Login credentials — usernames, passwords, TOTP/2FA secretsTo autofill and protect your sign-ins on sites you useEncrypted on your device (AES-256-GCM, key derived from your master password). If you enable sync, also uploaded as an unreadable encrypted blob to our server, which never holds the key.Not shared.
Identity details (personal info) — name, email, phone, postal address, date of birthTo fill sign-up, checkout, and contact forms for youSame encrypted vault (on device; optional encrypted-blob sync)Not shared.
Financial & estate information — the Legacy Vault (accounts, policies, and related details you choose to enter)To keep your estate/continuity information in one encrypted placeSame encrypted vault (on device; optional encrypted-blob sync)Not shared.
Notes, bookmarks, private custom values (e.g. rewards/membership numbers), per-site preferences, and learned form-fill dataTo fill and organize your logins and formsSame encrypted vault (on device; optional encrypted-blob sync)Not shared.
Masked-email provider API tokenTo create masked email aliases through the provider you chooseEncrypted in your vaultSent only to the email provider you select, directly from your browser — never through Veridenti's servers.
Account email address (only if you enable sync)To authenticate you and associate your encrypted vault with your account; not used for marketingOn our server, alongside a one-way authentication hash and a saltNot shared.
Anonymous usage aggregates (opt-in only, off by default)To understand feature reliability (see §4)Aggregated on our server; contains no identifiers, no IP, and no vault contentsNot shared.

We do not sell or rent your data, show ads, or use any third-party trackers or advertising/analytics SDKs. Retention and deletion are described in section 7.

1. What Veridenti stores, and where

2. Optional cloud sync

If you enable sync, your vault is uploaded as an encrypted blob to our backend (a Cloudflare Worker with KV storage). The server stores only the encrypted blob, a one-way authentication hash, and a salt. The server cannot decrypt your vault — it never has the key. This is zero-knowledge / end-to-end encryption. If you never enable sync, nothing leaves your device.

3. Masked email

Masked email is generated through a provider you choose (Fastmail, addy.io, SimpleLogin, DuckDuckGo, Firefox Relay, or Forward Email) using your own account/API token, stored encrypted in your vault. The request goes directly from your browser to that provider — it never passes through Veridenti's servers. Veridenti does not operate an email service and does not receive your messages.

4. Anonymous usage stats — off by default, opt-in only

Veridenti contacts no analytics server unless you explicitly turn on "Share anonymous usage stats." If you opt in, what we collect is anonymous and aggregate: an active-device count via a token that rotates weekly (not a persistent identifier); coarse country (never city, never a stored IP); and form-fill success rate and which form types get fixed. If you opt in, Veridenti may also report an aggregate count of how many items your vault holds — a single number, never the contents, names, or any value of those items.

What we never collect, even when opted in: your logins, passwords, or vault contents; any value you type; the specific sites you visit or full URLs; your identity; your IP or precise location. There are no third-party trackers, no advertising SDKs, and no analytics cookies anywhere in Veridenti.

4a. Breach monitoring & Leak Radar — matched on your device

Veridenti can warn you when a company you have an account with has been breached, and (with masked email) flag when one of your per-site aliases starts receiving unexpected mail ("Leak Radar"). Both work on your device: we download a public list of recently-breached domains — an ordinary request for public data that contains nothing about you — and compare it against your saved sites locally; the comparison, and your list of accounts, never leave your device. Leak Radar reads only your masked-email activity metadata (such as when an alias last received mail) from your own provider, directly — never the content of any message, and never through Veridenti's servers.

5. Phishing / "Protect" features are 100% local

Veridenti's anti-phishing protection (look-alike-site warnings, password-reuse warnings, form-skimmer detection) runs entirely on your device, comparing pages only against your own saved logins. Your browsing is never sent anywhere for these checks.

6. Permissions

Veridenti requests broad host access (http://*/*, https://*/*) for one reason: a password manager must be able to fill and protect logins on any site you use, and it can't know in advance which sites those are. It does not read or transmit page contents; it looks at form fields locally to fill them and to detect threats.

6a. On mobile (iOS & Android apps)

The Veridenti iOS and Android apps use the same zero-knowledge, on-device model as the extension. A few platform specifics:

7. Data sharing, retention, deletion

8. Your rights (GDPR / CCPA)

Because we hold only an unreadable encrypted blob and (if opted in) anonymized aggregates, we hold no personal data we can identify you by. You can still request deletion of any synced blob. We do not sell personal information as defined by CCPA.

9. Children

Veridenti is not directed to children under 13 and does not knowingly collect their data.

10. Who we are & contact

Veridenti is operated by Veridenti, LLC, a Michigan limited liability company. We'll post changes to this policy here with a new "last updated" date. Questions: privacy@veridenti.com.

Back to veridenti.com