Back to home
This is a draft for orientation only. Please have a qualified lawyer review and adapt these texts before you go live.

Privacy Policy

How the trust check works

To produce the trust signal, a short voice sample is analysed once at the moment of verification. The analysis fails closed, meaning that if it cannot complete confidently no badge is issued, and the voice sample is not retained long-term.

Data we process

We process your account email, your profile avatar (stored via Vercel Blob), and the results of your trust check (stored on Neon and Vercel infrastructure). We keep only what is needed to issue and display your badge.

Payments

Payments are processed by Stripe acting as a sub-processor. We do not see or store your card data; Stripe handles it under its own security standards.

Fraud and bot prevention

To tell real humans from bots, we assess how the connection behaves — not who you are. Your IP address is used transiently to derive a coarse country and a connection classification (e.g. residential vs. datacenter/VPN); we store only a one-way hash of the IP, the country, and a hashed device fingerprint, never the raw IP. If enabled, an IP-intelligence provider (IPinfo) may receive the IP solely to return this classification. We do not infer demographics such as gender or age from this data.

Your rights

Under the GDPR you have the right to access, correct, and delete your personal data. To exercise these rights, contact us using the details in the imprint.