Verodian

Privacy Policy

Last updated: 11 May 2026

This Privacy Policy explains what data Verodian collects, why, and how we handle it. Verodian is operated as an independent project under the “Verodian” brand. For privacy questions, email support@verodian.com.

1. What we collect

We keep only what is needed to run the chat product:

  • Account data: your email address (required for magic-link sign-in), and optionally a display name and avatar URL.
  • Chat data: the messages you send, the marketplace queries we derive from them, the AI responses, and any images you attach.
  • Usage data: IP address, browser user-agent, request timestamps, and approximate AI token usage and cost per request.
  • Cookies: a single session cookie after you sign in. We do not use third-party advertising or analytics cookies.

We do not knowingly collect data from anyone under 16.

2. How we use it

  • Provide the service: authenticate you, return search results, persist your chat history, populate your sidebar.
  • Operate and improve: debug failures, monitor cost, prevent abuse, calibrate ranking and deal-scoring.
  • Communicate: send magic-link sign-in emails and service notifications. We do not send marketing email without your consent.

We do not sell your personal data. We do not share it with advertisers.

3. Third parties we route data through

To run the product, Verodian sends limited data to the following processors. Each acts on our instructions under their own privacy terms:

  • Neon — Postgres database; stores accounts, chats, listings.
  • Vercel — web hosting and Blob storage for uploaded chat images.
  • Fly.io — hosts the API and background workers.
  • Cloudinary — hosts profile avatar uploads.
  • Brevo — delivers transactional email (magic links and service notifications).
  • Upstash — message queue for background jobs.
  • Anthropic and OpenRouter— AI model providers. Your chat content is sent to a frontier model to generate the assistant’s response. We do not opt in to AI training on your data.
  • Marketplaces (eBay, Amazon, AliExpress, Walmart, Best Buy, and others as added) — we send only the search query string. Listings flow back; your identity does not flow forward.

4. Affiliate links

Some product cards in chat results link to marketplaces that may pay Verodian a commission when you buy. This does not affect ranking — we surface the best deal, not the best-paying deal. See our Terms for the full disclosure.

5. Data retention

  • Chat history: kept until you delete it or your account.
  • Magic-link tokens: expire 15 minutes after issuance and are deleted after use.
  • AI call logs: kept for 90 days for cost analysis, then aggregated.
  • Server logs: kept for 30 days.

6. Your rights

Under the Nigeria Data Protection Regulation (NDPR), you have the right to:

  • Access the personal data we hold about you.
  • Correct inaccurate data (you can edit your profile at /profile).
  • Delete your account and associated chat history.
  • Object to processing or withdraw consent.
  • Receive a copy of your data in a portable format.

Email support@verodian.com to exercise any of these. We respond within 30 days.

7. Security

All traffic is over HTTPS. Passwords do not exist — sign-in is magic-link only, with 15-minute token expiry. Session cookies are HttpOnly, Secure, and SameSite=Lax. No system is perfectly secure, but we take reasonable steps to protect your data.

8. International transfers

Some processors above (Anthropic, Vercel, Cloudinary) operate from the United States or European Union. Where data leaves Nigeria, we rely on the processors’ standard contractual clauses and equivalent safeguards.

9. Changes

We may update this policy as the product evolves. Material changes will be announced by email or in-product before they take effect. The “Last updated” date above always reflects the current version.

10. Contact