Veritiliz was built by a victim of fraud. The people who use this site are often in a vulnerable state. Privacy is not a legal formality here. It is a direct commitment to the people this site exists for.
This policy is written in plain language. If something is unclear, it is an error in writing, not a deliberate obscuring of intent.
What we do not collect
We do not run advertising. We do not use tracking pixels. We do not embed third-party social media scripts. We do not sell data. We do not share your information with any third party except as described in this policy.
We use Google Analytics 4 to count page visits and understand which parts of the site people find useful. It records the pages you open, roughly when, the type of device and browser, and the site that referred you. Your IP address is truncated before it is stored, and we have disabled Google Signals and ad personalisation, so your visits are not linked to a Google account or used to build an advertising profile.
Analytics never receives the content you submit. Nothing you type into the analysis box, no file you upload, no analysis result, and no email address is sent to Google Analytics. It sees the address of the page only.
Because the address of a page can itself be revealing — a page about romance-scam recovery says something about why you are here — you may prefer to block it. Any browser content blocker, or your browser’s “do not track” and cookie controls, will stop it, and the site works normally with analytics blocked. We do not use tracking pixels, advertising scripts, or third-party social media scripts.
We do not store the conversation text you type into the analyzer unless you choose to keep it. There are two separate, independent choices, and neither is ticked for you. If you make neither, nothing you type is stored anywhere — when you close the page, it is gone.
The first is saving to your history, described under “Saved analyses” below. This requires an account, keeps your message readable in your own account, and can be deleted by you at any time. The second is sharing anonymously for research, described under “Conversation text — anonymous sharing”. That one is scrubbed of identifying details, cannot be linked back to you, and for that same reason cannot be deleted.
We do not store copies of files you upload for analysis. Files are processed and then discarded. We do not log file contents. We do not keep a record of what you uploaded.
We do not store your raw IP address. If your IP address is processed for rate-limiting purposes, it is immediately converted to a one-way hash (SHA-256) before storage. The hash cannot be reversed to recover your IP address. See the section below on anonymous sessions for detail.
We do not handle payment card numbers, CVV codes, bank account details, UPI credentials, or any other payment credentials. When you make a payment, a payment window operated by Razorpay opens in your browser. Your financial details are entered there and never leave Razorpay’s infrastructure. They do not pass through our servers.
What we do collect
Anonymous session token
Your browser may receive a short token that identifies your session, stored under the key rc_anon_session in localStorage. It is used for the parts of the site that do not need an account — principally the “share your experience” forms on the recovery pages, where it limits how many reports can be sent per day. Running an analysis requires signing in, and quota for that is tracked against your account rather than this token.
The token contains no personal information. It is a random string signed with a server secret. It is not shared with any third party. You can clear it at any time by clearing your browser’s localStorage. Clearing it resets your quota counter for the current session.
IP address hash
To prevent abuse — specifically, people creating repeated accounts to reset the free allowance — we count analyses per network address. The address is passed through a one-way hash, SHA-256(IP + server secret), before it is used. The raw IP address is never written to our database, and neither is the hash: it is held only as a counter in temporary memory that expires after 24 hours.
Device and browser fingerprint
For the same reason, we compute a short identifier from properties of your browser and device. This includes your screen size, timezone, language, the number of processor cores your device reports, which fonts are installed, your graphics hardware’s name, and how your browser draws a small test image. Those properties differ enough between machines to distinguish one from another, and stay the same on your machine across visits.
We want to be plain about what this means: it identifies your browser, and it works even if you clear your site data or use a private window. That is the point of it — an identifier you can erase cannot tell us that five accounts came from one person, which is the abuse it exists to catch.
It is not used to track you across other websites, is not shared with anyone, and is not combined with advertising data. It is computed by our own code running in your browser; no third-party fingerprinting service is involved and no data leaves your browser to any other company for this purpose. The identifier is sent to our server, immediately re-hashed with a server secret, and only that result is stored. We keep no record of the underlying properties themselves.
What we store against it is limited to what the abuse check needs: which accounts share a browser, and how many analyses they have run today.
Saved analyses — your history
If you have an account, a checkbox appears offering to save the analysis to your history. It is unchecked by default. If you tick it, we store the message you submitted, the analysis result, the risk rating, the red flags, and the quoted excerpts — linked to your account.
The message is stored as you wrote it. It is not passed through the identifier scrubber described below, and we want to be plain about why: this record exists for you to read back, and the details a scrubber removes — the account name, the phone number, the wallet address the other party sent you — are frequently the evidence itself. Removing them would leave you with a record you cannot use.
What this means in practice: your saved messages are readable by your account, and by us as the operator of the database, in the same way as any account-based service. They are not shared, not sold, and not used to train any model. If you submit a file rather than typed text, the file's contents are not stored — only any message you type alongside it.
You can delete any saved analysis, or all of them, from the history page at any time. Deleting removes the stored message along with the result.
When you delete your account, everything you wrote is erased. That means every message you submitted for analysis, every file you uploaded, every analysis result, every follow-up conversation, and every saved record in your history. None of it is retained, archived, or recoverable, and none of it is used for any purpose afterwards.
The single exception is material you chose to make anonymous or public while your account was open: analyses you shared anonymously for research, and stories you submitted through the Share Story form. Both were separated from your identity at the moment you submitted them — that is what made them anonymous — so there is no link left by which to find and remove them. This is explained at the point you opt in, and it is why that choice is presented separately and is never ticked for you.
Follow-up conversations about a saved analysis are stored the same way, and have always been — each message you send in a follow-up is kept in full so the conversation can continue across sessions. These are deleted with the analysis they belong to.
Conversation text — anonymous sharing
After receiving your analysis result, a checkbox appears offering to share the result anonymously to help improve fraud detection for others. This is entirely optional and unchecked by default. If you check it and click “Save Anonymously,” the following happens:
The conversation text is passed through an automatic scrubber that removes email addresses, phone numbers, names, card numbers, cryptocurrency wallet addresses, dates of birth, and other common identifiers before anything is stored. The scrubbed text, the fraud type detected, the risk rating, and the analysis model used are stored in our database. No account, no IP address, no session token, and no identifying information is attached to this record. The record cannot be linked back to you.
You can only store once per analysis result. Storing is irreversible — we have no way to identify which record is yours in order to delete it, because we deliberately do not record that link.
Experience form submissions
Each of the six recovery pages contains an optional form where you can share your experience. Everything in this form is optional. You do not need to submit anything to use this site.
If you submit the form, it is sent directly to our backend server and stored in our database. What is stored: your selected fraud type, platform, amount lost, duration, and current status (all dropdown selections); the text you write in the experience field, if you write anything; and your email address, if you provide one.
The experience text is passed through the same PII scrubber described above before storage. Your email address, if provided, is stored in a separate database column and is never combined with your experience text, never included in any automated notification, and never shared. It is used only if the site owner needs to follow up with you directly and you have implicitly consented to that by providing it.
Form submissions are used for one purpose only: to understand new fraud patterns and improve the content on this site. They are not shared with third parties, law enforcement, government bodies, or any organisation.
Registered accounts
Creating an account is optional. The analyzer works without one. An account gives you a higher daily and monthly analysis limit and other features.
If you register, we store your email address. We do not store a password: sign-in is passwordless — we email you a single-use 6-digit code that expires after five minutes. Your email is used only to deliver that code and essential account notices. It is not used for marketing and is not shared.
Password reset emails are sent via Resend, a transactional email service. Resend receives your email address for the purpose of delivering the reset message. Their privacy policy applies: resend.com/legal/privacy-policy.
Subscription and payment records
If you purchase a plan or buy refill credits, we store a minimal record of the transaction. What is stored:
Your account email address (from your registered account). The plan tier purchased (Pro or Max), whether it is monthly or annual, and the period start and end date. A reference ID issued by Razorpay — an opaque string such as order_xyz789 or sub_xyz789. This is an internal tracking identifier, not your card number or any financial detail. For refill credit purchases: the number of credits added and the provider payment reference.
This record is used for one purpose: to determine what access level your account should have and when that access expires.
What the record never contains: card numbers, expiry dates, CVV codes, bank account details, UPI credentials, billing address, or any payment credential. We never see these because Razorpay handles them directly on its own infrastructure before confirming the transaction outcome to us.
Analysis requests
When you submit text or a file for analysis, the request is sent to our backend server (hosted on Render), which forwards it to Google’s Gemini API. Our server receives the analysis result and returns it to your browser. Your conversation text passes through our server in transit and is stored only if you saved the analysis to your history or shared it anonymously, both described above. Files are processed and then discarded.
Third parties
Netlify hosts the frontend of this site — the HTML, CSS, and JavaScript files. Netlify may log standard server access data (IP addresses, page requests, timestamps) as part of their infrastructure. Veritiliz does not control or access this log data. Netlify does not handle any form submissions or user data for this site. Netlify privacy policy: netlify.com/privacy.
Render hosts our backend server and PostgreSQL database. All API requests, account data, form submissions, anonymized analysis records, and subscription records are stored on Render’s infrastructure. Render privacy policy: render.com/privacy.
Google Gemini API processes the text and files you submit for analysis. Your conversation content passes through Google’s infrastructure. Google’s data handling for API requests is governed by their terms: ai.google.dev/gemini-api/terms. API data is not used to train Google’s models under their current API terms.
Resend delivers your sign-in codes and account emails. When you request a code, your email address is shared with Resend solely for delivery. Resend privacy policy: resend.com/legal/privacy-policy.
Razorpay processes every payment we take, in Indian Rupees and in US Dollars alike. It is our only payment processor. The Razorpay payment SDK opens a payment window in your browser; your card, UPI, net banking, or wallet credentials are entered in that window and transmitted directly to Razorpay — not to Veritiliz. We receive only an order and payment reference ID. We do not receive, store, or have access to your card number, expiry date, CVV, UPI PIN, or net banking credentials. Razorpay is a PCI-DSS certified payment processor. Razorpay privacy policy: razorpay.com/privacy.
Your rights
Under India’s Digital Personal Data Protection Act 2023 (DPDP Act), and under the UK and EU General Data Protection Regulation (GDPR) for visitors from those regions, you have the right to access, correct, and request deletion of any personal data held about you.
In practical terms, the personal data this site may hold about you is:
If you have an account: your email address. You can delete your account yourself at any time from the account page, which erases everything described under “Deleting your account” above immediately. If you would rather we did it, contact us via the contact page with the subject “Delete My Account” and we will action it within 30 days.
If you have made a payment: we hold a transaction record containing the plan purchased, the access period, and a payment provider reference. Records of completed transactions are retained for the period required by applicable tax and accounting law, as they are by any business that issues an invoice, and are used only for accounting, tax and the resolution of billing disputes. They contain no analysis content of any kind. Please note that removing a transaction record would not in any case constitute a refund; all payments are final and non-refundable.
If you submitted an experience form: your responses and, if provided, your email address. To have a submission deleted, contact us via the contact page with enough detail to identify it (approximate date, fraud type selected). We will remove it within 30 days.
Anonymized analysis records: if you opted in to anonymous storage, these records contain no identifying information and cannot be linked back to you. We therefore cannot delete a specific record on request because we have no way to identify which one is yours.
To exercise any of these rights or ask any question about this policy, use the recovery page forms with the subject “Privacy Request.” We will respond.
Minors
This site is intended for adults. If you are under 18, please speak to a trusted adult about what you are experiencing rather than using this site alone. Fraud affects people of all ages and there is no shame in asking for help from someone you know.
Changes to this policy
If this policy changes in any meaningful way, the date at the top of this page will be updated. We will not change this policy in ways that reduce your privacy rights without notice.
You came to this site because something felt wrong.
What you do here is yours.
We are not watching.