Privacy Policy

Last updated: 11 June 2026

This translation is provided for convenience. The English version is the legally binding reference — please have it reviewed by a qualified professional for your jurisdiction.

This Privacy Policy explains what personal data VeruMail collects and how we use it when you use our email-authentication monitoring service.

1. Data we collect

Account data: your email address and authentication details. Service data: the domains you add and their public DNS records (SPF, DKIM, DMARC, MX) plus the analysis reports we generate. Usage data: basic logs needed to operate and secure the Service.

2. How we use your data

To provide and improve the Service, generate your reports and alerts, manage your subscription, and keep the Service secure. We do not sell your personal data.

3. Service providers

We share data with processors strictly to run the Service: Supabase (authentication and database), Vercel (hosting), Resend (transactional email delivery, e.g. confirmation and alert emails), Anthropic (AI analysis of the DNS and report data you submit), and Paddle (payments, as Merchant of Record). Each processes data under its own terms and security commitments.

4. Retention

We keep your data while your account is active and as needed to provide the Service or meet legal obligations. You can request deletion at any time.

5. Your rights

Under the UK GDPR, EU GDPR and similar laws, you have the right to: (a) access the personal data we hold about you; (b) request correction of inaccurate data; (c) request erasure ("right to be forgotten"); (d) restrict or object to certain processing, including direct marketing; (e) receive your data in a portable, machine-readable format; (f) withdraw consent at any time; and (g) lodge a complaint with the Information Commissioner's Office (ICO) or your local data protection authority. To exercise any of these rights, email support@verumail.com — we respond within 30 days.

6. Cookies

We use only strictly necessary cookies: session cookies for authentication, CSRF tokens for security, and minimal preference cookies for core functionality. We do not use analytics, advertising or tracking cookies and therefore do not require a consent banner under PECR or the ePrivacy Directive. You can block all cookies in your browser, but authentication will then fail. Third-party services we use (Supabase, Paddle) may set their own cookies on their own domains when you interact with them; their cookie policies apply.

7. Security & international transfers

We use industry-standard measures to protect your data. Some of our providers (including Resend, Supabase, Vercel, Anthropic and Paddle) process data in the United States. Where your data is transferred outside the EEA or UK, we rely on appropriate safeguards such as the EU-US Data Privacy Framework and/or the EU Standard Contractual Clauses.

8. Changes

We may update this policy and will note the date above.

Questions or requests: support@verumail.com

Full coverage of the email authentication stack
DMARCSPFDKIMBIMIMTA-STS
Payments secured byPaddle