Privacy policy

We are direct about what data we collect, why, and how long we keep it. No fine print.

Data Controller

The controller of your personal data is Vericto S.A.S. (hereinafter, "Vericto"), domiciled in Bogotá D.C., Colombia. For any query relating to the processing of your data, or to exercise your habeas data rights under Law 1581 of 2012, you can contact us at privacy@vericto.com.

Data collected

Vericto collects three categories of data:

1. Account data

  • Email: for authentication, transactional notifications and service communications.
  • Nombre del workspace: identificador del proyecto o entorno.
  • Billing information: processed directly by the payment processor (Paddle, or Stripe for earlier subscriptions). Vericto never receives or stores card numbers; it keeps only the customer and subscription identifiers the processor returns, plus invoice metadata (amount, currency, date, status).
  • IP address and user agent: recorded on each session for security and rate limiting.

2. Product usage data

  • Database connection strings: stored encrypted with AES-256-GCM. Used only to establish the proxy connection.
  • Text of intercepted SQL queries: stored encrypted in the audit trail. Retained according to your plan (7-90 days). Accessible only to workspace members.
  • Query metadata: timestamp, dialect, decision (BLOCKED/ALLOWED), triggered rule, latency, AST node. Not encrypted; used for dashboard metrics.
  • Rule configuration: active standard rules and custom rules defined by the user.

3. Telemetry data

  • Dashboard usage events: pages visited, features used, session duration. Collected via Google Analytics 4 (with anonymised IP).
  • Errors and exceptions: anonymised stack traces sent to Sentry for debugging. No user data in error reports.

Vericto never stores the results of your queries (the data returned by your database). Only the text of the submitted query and the metadata of the block decision.

Data usage

We use your data exclusively for:

  • Service delivery: intercepting and analysing SQL queries, maintaining the audit trail, sending block notifications.
  • Seguridad: detectar accesos no autorizados, prevenir abuso, rate limiting.
  • Product improvement: aggregated, anonymised analysis of usage patterns to prioritise features. Never individualised analysis without consent.
  • Transactional communications: verification emails, password recovery, quota alerts, invoices. We do not send marketing emails without explicit consent.
  • Technical support: when you contact support, we may access your workspace metadata (not the content of your queries) to diagnose the issue.

We never sell your data to third parties. We never use the content of your queries to train AI models.

Data retention

Data type Free Plan Builder Plan Team Plan Enterprise
Query text and metadata (audit trail) 7 days 30 days 90 days Configurable
Account data Until cancellation + 30 days
Access logs (IP, user agent) 90 days
Billing data 7 years (legal obligation)

Upon cancelling your account, all your data is permanently deleted within a maximum of 30 days, except billing data which we must retain due to legal obligations.

Third parties and subprocessors

Vericto uses the following subprocessors to provide the service:

  • Supabase (PostgreSQL): storage of account data, audit trail and configuration. Data in the EU region (Frankfurt) by default.
  • Fly.io: TCP proxy hosting. Region selection configurable.
  • Paddle.com Market Ltd (United Kingdom): payment processing as merchant of record. Receives your email, name, country and payment details to issue the invoice and calculate taxes. Acting as the authorised reseller, Paddle processes that data as an independent controller, subject to its own privacy policy. Transfers outside the EEA are covered by the UK standard contractual clauses.
  • Stripe, Inc. (United States): payment processing for subscriptions started before the migration to Paddle, until they renew. Subject to Stripe's privacy policy and its standard contractual clauses.
  • Resend: transactional email delivery. Receives only the destination address and the email content.
  • Cloudflare: CDN and DDoS protection. May process source IPs.
  • Google Analytics 4: dashboard usage telemetry. Anonymised IP. You can opt out with browser extensions.
  • Sentry: error reporting. Anonymised stack traces with no user data.

All subprocessors are subject to data processing agreements (DPA) and comply with GDPR.

Your rights under GDPR

If you are a resident of the European Economic Area, you have the following rights:

  • Access: you can request a copy of all the personal data we hold about you.
  • Rectification: you can correct inaccurate data directly in your account settings or by requesting it via email.
  • Erasure ("right to be forgotten"): you can request deletion of your data. Billing data is retained as a legal obligation for 5 years.
  • Portability: you can export your data in JSON format from the dashboard (audit trail, rule configuration).
  • Objection: you can object to the processing of your data for usage analytics. This does not affect how the service works.
  • Restriction: you can request restriction of processing while a dispute about data accuracy is resolved.

To exercise any of these rights, write to privacy@vericto.com. We will respond within a maximum of 30 days.

If you believe that the processing of your data does not comply with the GDPR, you may file a complaint with the Spanish Data Protection Agency (AEPD) at www.aepd.es.

Your rights under CCPA (California residents)

If you are a California resident, you have additional rights under the California Consumer Privacy Act:

  • Right to know: you can request information about the categories of personal data we collect and who we share it with.
  • Right to delete: you can request deletion of your personal data, subject to applicable legal exceptions.
  • Right to non-discrimination: we do not discriminate against users who exercise their CCPA rights.
  • Right to opt out of sale: Vericto does not sell personal data. The sale opt-out mechanism does not apply.

Cookies

Vericto uses the following cookies:

  • Session cookies (essential): authentication JWT in an httpOnly cookie. Required for the service to work. Cannot be disabled.
  • Preference cookies: interface theme (dark/light), language preferences. Stored in localStorage, not in cookies.
  • Analytics cookies (Google Analytics 4): _ga, _ga_*. Used for aggregated usage analysis. You can disable them with browser extensions or by rejecting analytics cookies in the consent banner.

We do not use advertising or cross-site tracking cookies.

Contact the DPO

For any privacy inquiry, exercise of rights, or security incidents related to personal data, contact our Data Protection Officer:

  • Email: privacy@vericto.com
  • Response time: maximum 30 business days
  • Idiomas: español, inglés

For security incidents that may affect personal data, write to security@vericto.com. We respond in less than 48 hours.