Verdict

Privacy Policy

Last updated 13 August 2026

Who is responsible

Verdict is operated by Ramzi Zeineddine, an individual, from Massachusetts, United States. For the purposes of the UK and EU General Data Protection Regulation, Ramzi Zeineddine is the data controller for the information described here. Questions, requests, and complaints all go to support@appverdict.net.

Builds you upload

A build exists on our infrastructure only for as long as the analysis takes, and is deleted immediately afterwards — in afinallyblock, so deletion runs whether the analysis succeeded, failed, or timed out. It is read as bytes and never executed: there is no simulator, device, or sandbox anywhere in this service where your code runs.

What outlives the upload is the report — the score, the findings, and the identifiers we read out of the binary, such as the app name, bundle identifier, version, and minimum OS. Those are kept so you can open the report again and compare it with your next build.

Account information

If you create an account we store your email address, display name, and the authentication identifiers Firebase issues. If you subscribe we also store your Stripe customer identifier, plan, and subscription status, because the product has to know what you have access to.

On a Team plan, scans and apps belong to the shared workspace rather than to the member who ran them. Anyone in that workspace can see them. That is the feature working as intended, and it is worth knowing before you upload a client’s build into a workspace somebody else administers.

The AI features, and what they receive

Detection and scoring are deterministic. They are rules run over your binary, they produce the same answer every time, and no model is involved in reaching a score.

Four optional features do use a model, each only when you start it: the report assistant, tailored fixes, AI review, and reading store screenshots you upload. These send the relevant material — your question, the findings already produced, the app metadata, or the screenshot itself — to OpenAI, who process it to return an answer. Material sent through their API is not used to train their models. We do not send your binary. If you never use these features, nothing about your account reaches a model.

Connected store credentials

A Pro user may connect their own App Store Connect API key or Google Play service account so that scans can be cross-checked against what the store already knows. This is the most sensitive thing this service holds, and it is treated accordingly.

The credential is encrypted with AES-256-GCM before it is written, using a key held only in our server environment, and it is never displayed again after you save it. It is read only by our own server, is never sent to any AI provider, and you can disconnect it at any time, which deletes it.

Cookies and local storage

We set two cookies and neither is used for advertising. One links anonymous scans to your browser, so a report you ran before signing in can be attached to your account afterwards. The other records only that somebody is signed in on this browser, so the server can send a returning reader to their workspace without first painting a page they have no use for. It carries no identity and grants no access.

Some things stay in your browser and never reach us at all: your conversations with the report assistant, the checklist items you tick off, and interface preferences. Clearing your browser data removes them.

We run no advertising, no cross-site tracking, and no third-party analytics that profile you.

Who else processes your data

These are every processor we use, what each one does, and where.

  • Vercel Inc. — United States
    Hosting, content delivery, and the temporary storage a build occupies while it is being analysed.
  • Google LLC (Firebase) — United States
    Account authentication and the database holding your reports, apps, and subscription status.
  • Stripe, Inc. — United States
    Payment processing and subscription billing. Card details are given to Stripe directly and never reach our servers.
  • Resend — United States
    Transactional email: your receipt, team invitations, and anything you send us through the contact form.
  • OpenAI, L.L.C. — United States
    The optional AI features. Runs the report assistant, tailored fixes, AI review, and screenshot reading. Only ever receives what one of those features needs, and only when you start it. Content sent through the API is not used to train their models.

All of them are located in the United States, so using Verdict involves transferring your information there. Each is engaged under terms that include the European Commission’s Standard Contractual Clauses or an equivalent safeguard.

Why we are allowed to hold it

Where the UK or EU GDPR applies, we rely on the performance of our contract with you for anything needed to run your account, deliver a report, or take payment; on our legitimate interests in keeping the service secure and working, for rate limiting and abuse prevention; and on your consent for the optional AI features, which you give by choosing to use one and withdraw by not using it.

How long it is kept

Uploaded builds are deleted within the same request. Reports, apps and account records are kept until you delete them or close your account. Billing records are kept as long as tax and accounting obligations require. Rate-limiting counters expire automatically within hours.

Your rights

You can ask for a copy of your data, correct it, delete it, restrict or object to how it is used, or receive it in a portable form. If you are in California, you may request disclosure or deletion, and we do not sell or share personal information as those terms are defined by the CCPA — so there is nothing to opt out of.

Write to support@appverdict.net from your account address. Deletion removes your account and every report linked to it, and completes within 30 days including backups. Exercising any of these rights costs nothing and we will not degrade your service for it. If you believe we have mishandled your data you may complain to your local supervisory authority.

Security

Traffic is encrypted in transit. Store credentials are encrypted at rest. Database access runs entirely through our server with client access denied outright, and API keys are stored hashed rather than in a form we could read back to you. No service can promise it will never be breached; what we can say is which specific measures are in place, and those are they.

Children

Verdict is a developer tool and is not directed at children. Do not use it if you are under 16. We do not knowingly collect information from anyone younger, and will delete it if we learn we have.

Changes

If this policy changes materially we will update the date above and, where the change affects how your existing data is used, email account holders before it takes effect.