Data Processing Agreement
Last updated 13 August 2026
Why this exists
If you use Verdict on behalf of an organisation — and especially if you scan builds belonging to your own clients — you need a written agreement governing how we handle personal data on your instructions. Article 28 of the UK and EU GDPR requires one.
This page is that agreement. It applies automatically to every customer, forms part of the Terms of Service, and needs no signature to take effect. If your organisation requires a countersigned copy, write to support@appverdict.net.
Which of us is responsible for what
The split matters, and a single label for the whole relationship would be wrong.
For your own account — the email you sign in with, your billing details, the record of your subscription — we are the controller, and our privacy policy governs.
For the material you put into the service — the builds you upload, the listing text and screenshots you submit, and any store credentials you connect — you are the controller and we are your processor. If you are an agency acting for a client, you are likely their processor and we are your sub-processor; this agreement works the same way in that arrangement.
What we process, and for how long
Subject matter and duration: providing Verdict to you, for as long as your account is open.
Nature and purpose: static analysis of the builds and metadata you submit, in order to produce and store the reports you ask for, and to run the optional features you choose to start.
Categories of data subject: your personnel and account holders; your clients, where you scan on their behalf; and any individual whose personal data happens to appear inside material you submit.
Types of personal data: account and contact identifiers; whatever personal data is contained in a build, listing text or screenshot you choose to upload; and connected App Store Connect or Google Play credentials. We do not ask for and have no use for special category data, and you should not submit it.
Our obligations
We will:
- process personal data only on your documented instructions, which your use of the service constitutes, and tell you if we believe an instruction breaches data protection law;
- ensure anyone authorised to process it is bound by confidentiality;
- keep the technical and organisational measures set out below;
- assist you, so far as we reasonably can, in responding to requests from data subjects and in meeting your own obligations on security, breach notification and impact assessments;
- notify you without undue delay after becoming aware of a personal data breach affecting your data, with the detail you need to meet your own reporting deadlines;
- make available the information reasonably necessary to demonstrate compliance with this agreement, and cooperate with an audit request at reasonable frequency and notice.
Security measures
Traffic is encrypted in transit. Uploaded builds are deleted within the same request that analyses them, in a finally block, so deletion runs whether the analysis succeeded or failed. Connected store credentials are encrypted with AES-256-GCM before they are written and are never displayed again. API keys are stored as hashes rather than in any form we could read back. Database access runs entirely through our server, with direct client access denied outright. Access to production is limited to Ramzi Zeineddine.
We are a small operation and say so plainly: there is no security team, and these are specific measures rather than a certification. Judge them on what they are.
Sub-processors
You give general authorisation for the sub-processors below, each engaged under written terms no less protective than this agreement.
- Vercel Inc. — United States
Hosting, content delivery, and the temporary storage a build occupies while it is being analysed. - Google LLC (Firebase) — United States
Account authentication and the database holding your reports, apps, and subscription status. - Stripe, Inc. — United States
Payment processing and subscription billing. Card details are given to Stripe directly and never reach our servers. - Resend — United States
Transactional email: your receipt, team invitations, and anything you send us through the contact form. - OpenAI, L.L.C. — United States
The optional AI features. Runs the report assistant, tailored fixes, AI review, and screenshot reading. Only ever receives what one of those features needs, and only when you start it. Content sent through the API is not used to train their models.
We will give you at least 30 days’ notice by email before adding or replacing a sub-processor. If you reasonably object on data protection grounds within that period, you may terminate your subscription and receive a refund of the unused portion.
International transfers
Every sub-processor listed above is in the United States, so using Verdictinvolves transferring personal data outside the UK and EEA. Each transfer relies on the European Commission’s Standard Contractual Clauses, the UK International Data Transfer Addendum, or an adequacy decision where one applies.
Return and deletion
You can delete a report, an app, or your whole account from the product at any time. On termination, or on your written request, we delete the personal data we process for you within 30 days including backups, except where law requires us to keep something — billing records being the usual case.
Precedence
This agreement forms part of the Terms of Service. Where it conflicts with them on the processing of personal data, this agreement prevails.