This policy explains what Verth collects and why. Verth is run by Umesh, Datarpur, District Hoshiarpur, Punjab, India. We follow India’s Digital Personal Data Protection Act, 2023.
What we collect
- Account: your name, email address, mobile number, gender, date of birth, country, when you agreed to these terms, and whether your email is confirmed (handled by Google Firebase Authentication). Your gender and date of birth are never shown to anyone. Your mobile number is kept private: only the admins of a circle you ask to join can see it, so they can recognise you before approving. Other members never see it, and it isn’t shared or used for marketing.
- Private chat: messages, files and payment notes between two circle members are end-to-end encrypted on their devices. Verth stores only the encrypted text, who sent it to whom, and when; nobody else, including circle admins and Verth, can read it. Senders can delete their messages for both people.
- Scam database: when a check finds a scam, Verth automatically stores only a scrambled fingerprint (a one-way code) of the message, link, number or picture text, plus a count. The content itself is never stored, and nobody can see whose check flagged it. People can’t mark a number or link as a scam by hand, so honest numbers can’t be falsely labelled.
- Payment receipts: Pay safely records and the paid / received confirmations are end-to-end encrypted like chat messages; only the two people can read them.
- UPI ID (optional): if you add a UPI ID for “Pay safely”, the people in that circle can see it and when you last changed it. Verth never sees or processes your payments.
- Organisation staff lists (optional): an organisation’s admins can add the names and work emails of people they expect to join, and can limit joining to their company’s email domain. Only that circle’s admins can see the list, and they can remove entries at any time.
- Fingerprint / face login (optional): your phone or computer checks your fingerprint, face or screen lock itself. Verth never receives any biometric data; it only stores a public security key and the device name you turned it on from, so it can recognise your device. You can remove it any time in your profile.
- Circles and checks: the circles you create or join, your role, the verification requests you send or answer (who, what was asked in your words, the channel, the answer and time).
- Device keys: public keys that tie your answers to your own device, plus a simple device label like “Chrome on Android”. Private keys never leave your device.
- Scam check: the text you paste, and any screenshot or photo you choose, is checked on your device and is not uploaded or stored. We keep only a count of checks (daily for text, in total for photos). If Verth finds something to be a scam, it stores a one-way scrambled fingerprint of it, never the text.
- Payments: your subscription ID, plan, status and renewal date. Card, UPI and bank details are collected and processed by Razorpay, not by Verth.
- Verth Helper: common questions are answered on your device from the built-in guide. Questions the guide can’t answer are sent, with the last few messages of that chat, through our server to Google Gemini to write a reply. We don’t store the chat, and anything that looks like an OTP, PIN, password or card number is never sent. Please don’t type personal details into the helper.
- Phone safety check-up: your ticks and score stay on your device. “Verth checked this device” only reads what your browser shares with every website (for example your Android or iOS version, browser version, and whether a screen lock exists); it isn’t stored. App X-ray reads the screenshot you choose on your device; the picture and the app names are not uploaded. Questions to the AI Phone Doctor are handled like Verth Helper questions (sent through our server to Google Gemini, not stored by us). If you choose “Share my score”, your circle can see only your daily score (for example 8/10), your streak and the date; you can stop sharing at any time, which deletes it.
- Email login codes: to log in with a code, your email address is sent to our email provider (Brevo) to deliver the code. We keep only a scrambled fingerprint of your email and code for a short time to check it and to stop abuse.
- “I’m not a robot” check: when you ask for an email code, Cloudflare Turnstile checks that a real person is using the page. Cloudflare looks at technical signals from your browser (not your identity) and gives us only a yes or no.
- Bank name for a UPI ID: when you type a UPI ID, or open “Pay safely”, the ID is sent through our server to Razorpay to look up the name the bank account is registered to, so you can see who you are really paying. We don’t store these lookups, and each person can make only a limited number a day.
- Kept only on your device: your scam check history, your daily safety check-up ticks, app lock setting, video language and similar settings stay in your browser on this device. They are never sent to us, and clearing your browser data removes them.
- Mobile number check (when switched on): to verify your mobile number, it is sent to our SMS provider (2Factor) to deliver a one-time code. We keep a scrambled fingerprint of the number so one number can verify only one Verth account, and remove it when you delete your account.
What we don’t do
Verth never reads your SMS, WhatsApp, calls, contacts, photos or email unless you choose to paste or pick them, and even then they are checked on your phone. We don’t sell your data, show ads, or use your data for marketing by others.
Cookies and tracking
Verth uses no advertising or tracking cookies and no analytics that follow you around the web. We use your browser’s storage only to keep you signed in, remember your settings, and make the app work offline. The how-to videos are served from our own website and don’t track you.
Who processes data for us
Google Firebase (accounts and database), Razorpay (payments and UPI ID name checks), Cloudflare (our server for payments, login codes and AI help, and the “I’m not a robot” check), Brevo (sends login codes by email), 2Factor (sends mobile verification codes by SMS), GitHub Pages (website hosting), and Google Gemini (AI answers in Verth Helper). Each processes data only to provide their service.
Keeping and deleting data
We keep your data while your account is active. The verification log of a circle is kept for the circle’s records. You can delete your account yourself in your profile; this removes your account, profile and sign-in keys. Some of these services may store data outside India, under their own security and privacy commitments.
Your rights
Under India’s Digital Personal Data Protection Act, 2023 you can ask to see the personal data we hold about you, correct or update it, delete it, withdraw your consent, and name someone to act for you if you can’t. Email umeshdk22@gmail.com; we reply within 7 days and complete deletion within 30 days, except records we must keep by law (such as payment records). You can also complain to the Data Protection Board of India.
Security
We protect your data with several layers:
- Every connection uses HTTPS. Private chats, files and payment receipts are end-to-end encrypted on your phone.
- Your answers to checks are signed with a key that never leaves your device, so a stolen password alone can’t fake them. Fingerprint / face login uses passkeys, which can’t be phished.
- Strict database rules decide exactly who can read or change each record, and are tested automatically before every update.
- Login codes, AI help and lookups are rate-limited, and an “I’m not a robot” check blocks automated sign-up attempts.
- The website refuses to load scripts from unknown places and can’t be shown inside other websites (to stop look-alike tricks).
- Our code is scanned automatically for security weaknesses, leaked keys and libraries with known security holes.
No system is perfectly secure. If a breach affects you, we’ll tell you and the authorities as the law requires. Found a security problem? Please email umeshdk22@gmail.com privately (see our security policy).
Children
People under 18 should use Verth with a parent or guardian, for example as part of a family circle.
Grievance officer
Umesh, umeshdk22@gmail.com. Questions or complaints about your data are answered within 7 days.