How Verifyd handles your information under POPIA.
#
Privacy Policy
How Verifyd handles your information under POPIA.
Effective date 27 June 2026
Version 1.0
Last updated 27 June 2026
Verifyd is built around minimal data collection.
We do not require you to create an account. We do not store the raw
text of messages you submit. We strip personal details before sending
content to our AI classifier. Camera frames for QR codes are
processed entirely on your device and never reach our servers.
Who We Are
This Privacy Policy explains how Verifyd Technologies (Pty) Ltd,
a private company incorporated in the Republic of South Africa which
trades as and operates the "Verifyd" service
("Verifyd", "the Company", "we",
"us", "our"), collects, uses, and protects
personal information when you use the Verifyd service at
www.verifyd.co.za (the "Service").
Verifyd Technologies (Pty) Ltd is the responsible party for the
processing of personal information through the Service under the
Protection of Personal Information Act 4 of 2013
("POPIA"). References to "Verifyd" in this
Policy refer interchangeably to the Service and to Verifyd
Technologies (Pty) Ltd as the responsible party.
Information Officer contact: info-officer@verifyd.co.za
Our Privacy Principles
Verifyd is designed to handle as little personal information as possible:
What Information We Process
When you use the Service, you may voluntarily submit:
Submitted Content may incidentally contain personal information about
you or about third parties (such as the sender of the message).
When you visit the Service, we automatically receive:
Because the MVP does not use accounts, we do not collect:
How We Use Information
We process information to:
We process personal information on the following lawful bases under POPIA:
Processing activity Lawful basis (POPIA)
Running validation checks on Submitted Content Performance of a service requested by you (s 11(1)(b)) and your consent inferred from voluntary submission (s 11(1)(a)).
Storing hashed records of submissions Legitimate interests in service operation, abuse prevention, and trend analysis (s 11(1)(f)).
Technical logs and rate-limiting Legitimate interests in security and availability (s 11(1)(f)).
Responding to support enquiries Performance of a service / your consent (s 11(1)(a)–(b)).
Compliance with law Legal obligation (s 11(1)(c)).
How Submitted Content is Handled
The raw text of any message you submit for a check is processed in
memory only, for the duration of your validation request. We do not
store the raw message body.
After a check, the system stores:
Where the Service uses an AI classifier (Anthropic's Claude API,
Haiku model) to assess content, automated redaction removes the
following before content is sent to the AI service, and before the
structured check record is stored:
URLs are deliberately not redacted, because a phishing link is itself
the primary evidence of a scam. Redaction is automated and
best-effort. We cannot guarantee that every piece of personal
information will be removed. You should not submit content containing
personal information about others where you do not have a lawful basis
to do so.
QR code decoding takes place entirely on your device, using your
device's camera. Camera frames and images are never uploaded.
Only the decoded URL is sent to our servers for further checking.
Reporting a scam is a deliberate, opt-in action that is separate from
running a check. When you submit a report, you are choosing to share
the message with us. In that case the full readable message text is
stored, together with:
Reported messages are kept for human review, moderation, and to
improve our detection. This is the only path on which we store a
readable copy of a message you submit. Reports do not influence any
verdict automatically; they only affect detection after a human
reviewer has assessed them.
Who We Share Information With
We share limited information with the following categories of
operators (third parties acting on our instructions). Each operator
is bound by contractual obligations to process information only for
the purposes we specify and to keep it secure.
Recipient Purpose and information shared
Anthropic (Claude API) Content classification. Receives PII-redacted message content and sender details. Under Anthropic's Commercial Terms, API inputs and outputs are not used to train Anthropic's models, and API logs are retained for 30 days.
Google Safe Browsing URL threat lookups. Receives only URLs extracted from messages. No message body is sent.
WHOIS providers Domain age checks. Receives the domain portion of URLs only.
Fly.io Application hosting (Johannesburg region). Runs the backend and processes request and response payloads in transit.
Supabase Database and infrastructure hosting (London region). Stores hashed validation records, reference data, and scam reports.
If we later introduce message-forwarding channels (for example, by
email or SMS), the relevant providers will be added to this list
before those channels go live.
We may also disclose information:
International Transfers
Some of our operators (including Anthropic, Google, and Supabase)
process information outside South Africa. POPIA permits transfers
outside South Africa where the recipient is subject to laws or
binding agreements that uphold principles substantially similar to
POPIA.
Where we transfer personal information internationally, we rely on
the recipient's contractual undertakings, recognised
certifications, or applicable adequacy frameworks.
How Long We Keep Information
Type of information Retention
Raw message body, raw sender details (when you run a check) Not stored (in-memory only during processing).
Validation records (message hash, verdict, and check signals including URLs) Anonymised after 24 months. The check-detail content is stripped in place and only a hashed, non-personal skeleton (hash, verdict, timestamps) is retained for trend analysis. We anonymise rather than delete: records are not hard-deleted.
Reported scams (full message, sender, and reporter identifiers, when you report a scam) Anonymised after 24 months. The stored message, sender, and reporter identifiers are overwritten in place; an anonymised record (category, status, and curator review outcome, with no personal content) is retained for audit.
Operational and technical logs (request metadata, hashed identifiers; no raw IP) Up to 7 days (our hosting platform's default log-retention window), unless needed for an active investigation.
Support correspondence 24 months from last contact.
Aggregated, anonymised statistics Indefinitely (no longer personal information).
Security
We use reasonable technical and organisational measures to safeguard
personal information, including:
Full details are in our Security Statement,
available at www.verifyd.co.za/security.
No system is perfectly secure. If we become aware of a security
compromise that affects your personal information, we will notify
the Information Regulator and affected data subjects in accordance
with section 22 of POPIA.
Your Rights Under POPIA
Subject to POPIA, you have the right to:
accounts, we generally cannot identify which validation logs (if
any) relate to you. To exercise your rights, you may need to
provide additional information that helps us identify the
relevant records.
To exercise any right, contact our Information Officer at info-officer@verifyd.co.za.
Information Regulator (South Africa): inforegulator.org.za | complaints.IR@inforegulator.org.za
Children
The Service is not directed at children under the age of 18. We do
not knowingly process the personal information of children. If you
believe a child's information has been submitted to the
Service, please contact us so we can take appropriate action.
Cookies and Local Storage
We use only essential cookies and local storage entries necessary
to operate the Service (for example, to remember your channel
selection and to apply rate limits). We do not use third-party
advertising or marketing tracking cookies.
Changes to this Policy
We may update this Privacy Policy from time to time. The current
version will always be available at www.verifyd.co.za/privacy.
Material changes will be flagged on the Service.
Contact
Privacy questions and requests can be sent to:
Information Officer: Marcel Norman
Email: info-officer@verifyd.co.za
End of Privacy Policy · Version 1.0 · Effective 27 June 2026