VERIDIC — Privacy PolicyIn plain words
Privacy Policy
Last updated: 25 September 2026
VERIDIC is a Chrome extension that explains dense legal, academic, financial and form text in plain English. It does not analyse medical or clinical documents. This policy describes exactly what data the extension handles, where it goes, and how to stop it.
1. What VERIDIC collects
Text you explicitly submit. When you highlight a passage and click the decoder, or paste text into the popup, that text is analysed. Nothing is analysed unless you actively ask for it — the extension does not read pages in the background.
Page content during a full-page audit. When you ask VERIDIC to read a whole page, the readable text blocks of the current page are extracted for analysis.
Account data. If you create an account, it is held by Supabase Auth. Your password is transmitted over TLS to Supabase and is never stored, hashed, or otherwise retained by this extension. We hold your email address, your display name, your subscription tier, and lifetime counts of analyses and scans run — the counts exist to enforce the free daily quota. Using VERIDIC without an account is fully supported; the free tier requires no sign-up.
Diagnostic telemetry. See section 3.
VERIDIC does not collect browsing history, keystrokes outside its own input fields, passwords or form values from the pages you visit, or any data from pages where you have not invoked it. It does not store the text you submit for analysis — see section 2.
2. Where your text goes
Some analyses never leave your computer. Where Chrome provides a built-in AI model (Chrome 138 and later, on supported hardware), VERIDIC uses it for the free tier and for anyone who selects "Always on this device" in settings. In that mode the passage is read by a model running inside your browser: nothing is transmitted, no request is made, and it works with no network at all. The result tells you which engine answered, every time.
Otherwise, analysis runs on VERIDIC's own service. You do not need an API key and VERIDIC never asks you for one. When you run an analysis, the passage you selected is sent to our analysis endpoint, hosted on Supabase Edge Functions in eu-west-2, which forwards it to a large language model via OpenRouter and returns the explanation.
What we do with the passage. It is held in memory for the length of the request and used for nothing else. We do not write it to a database, we do not log it, and it is not retained after the response is returned. We do not use it to train anything.
What the model provider does with it is governed by our OpenRouter account settings and by the policy of the model that serves the request. We configure our account to restrict retention, but the processing happens on their infrastructure, not ours.
What is stored. A per-day count of how many analyses you have run, so the free allowance can be enforced. It is keyed either to your account id, if you are signed in, or to a random identifier generated on this installation if you are not. No document text is stored against either.
If the service is unreachable, or you have used up the day's free analyses, VERIDIC falls back to a heuristics engine that runs entirely inside your browser. Nothing leaves your device on that path, and the extension tells you when it happens.
3. Diagnostic telemetry
VERIDIC sends limited usage events to a database operated by the developer (hosted on Supabase) to monitor reliability and feature usage. Events may include: the event type (analysis, scan, sign-up, quota reached, payment), your account email if you are signed in, the document type detected, text length, and — for whole-page reads — the title and URL of the page.
The text of your documents is never included in telemetry.
This is off by default and requires your consent. You can turn telemetry on or off at any time in Settings. Turning it off stops all transmission immediately.
4. Payments
Payments are processed by Paystack — never by VERIDIC directly. Card details are entered on Paystack's own hosted checkout page and are never seen by, transmitted through, or stored by VERIDIC. We receive the transaction reference, the amount and currency, and the outcome. See the Paystack privacy policy.
Every Paystack purchase is a time-boxed pass with no stored card and nothing to cancel. Section 6c below has the full detail.
VERIDIC previously used ExtensionPay with Stripe; that integration and its access to extensionpay.com have been removed.
5. Data storage and retention
Settings and your analysis history are stored locally in your browser via the Chrome storage API and never leave your device. Your account record lives in Supabase. Telemetry and subscription records are retained for up to 24 months, then deleted.
Uninstalling the extension removes all locally stored data, including your history, your installation identifier and your signed-in session. It does not delete your account — use the contact address below to request that.
6. Your rights
You may request a copy of, correction of, or deletion of any data associated with your email address by writing to the contact address below. Requests are answered within 30 days. You can delete your local data at any time by clearing the extension's history and signing out, or by uninstalling.
If you are in the EEA or UK, the legal basis for processing is your consent (telemetry) and performance of a contract (subscription management).
6b. Documents, watched documents, and take-aways
Uploaded documents are read on your machine. When you open a PDF or Word file in VERIDIC's reader, the file is parsed inside the browser. The file itself is never uploaded anywhere. If you then ask for an audit, the extracted text is sent to the analysis service under the same terms as section 2 — or to the on-device model, in which case it goes nowhere.
Watched documents stay on this device. The list of pages you watch, the text VERIDIC compares against, and the differences it finds are all held in local browser storage. VERIDIC does not fetch watched pages in the background and does not hold your list on any server.
Tracked deadlines stay on this device. When you press "Track these dates", or add a renewal yourself, the deadline, the document's title and address, and the quoted wording it came from are saved in local browser storage. The list is not synced and not sent to any server.
The weekly digest is built on this device. VERIDIC summarises your tracked deadlines and changed watched documents from local storage and keeps that summary locally. No server builds or sends it. "Email it to me" opens your own mail program with the text filled in; nothing is sent until you send it.
Comparing two versions happens in your browser. The two texts you paste or load are compared inside the page and are not uploaded or kept.
Reports and calendar files are built in the browser and held in session storage only until you close the tab that shows them. VERIDIC does not draft messages for you to send, and never sends anything on your behalf.
The local clause tally. When a clause is compared against VERIDIC's reference set, a counter for that clause type is incremented in local storage. It is counts only — no clause text, no URLs — and never leaves the device.
6c. Payments
VERIDIC never sees your card. VERIDIC processes payment through Paystack. Payment is taken on Paystack's own hosted checkout page. The extension holds no payment credential, renders no card field, and no card number, expiry or CVV ever passes through it or through our servers.
What we store about a payment. A ledger row per transaction: Paystack's own reference for it, your account id and email, which pass you bought, the amount and currency, the outcome, and the payment channel. This is the record that proves what you bought if you need a refund or dispute it. It is readable only by our server; no client key can reach it.
Why paying requires an account. Access is attached to your VERIDIC account, not to your browser, so it follows you to any computer you sign in on and survives reinstalling the extension.
A one-time, fixed-term pass. Every Paystack tier is a single payment for a fixed period that simply ends. There is no stored card, no recurring charge, and nothing to cancel.
Previous provider. VERIDIC previously used ExtensionPay with Stripe. That integration has been removed entirely, along with its permission to access extensionpay.com.
7. Permissions, and why each is needed
storage — Save your settings, quota counter, history, watched documents, tracked deadlines, the weekly digest and account locally. There is no API key: the extension holds no model credential.
alarms — Re-check your pass status about twice a day, so a pass that ends is reflected without you reopening the popup; and build the weekly digest on the day you chose.
notifications (optional) — Only requested if you turn on digest notifications, and only at that moment. Shows one Chrome notification a week when your digest is ready. Never requested at install.
contextMenus — Add the right-click "Read in plain words with VERIDIC" entry for selected text.
activeTab / scripting — Read the text of the page only when you invoke the decoder or auditor on it.
Host access to the VERIDIC analysis service — Send the passage you selected for analysis, and receive the explanation.
Host access to the Supabase project — Sign in, load your profile, run analyses, start a payment, and send diagnostics if you enabled them.
Typefaces — Bundled with the extension. The popup and the in-page panel load them from the extension itself, so the extension makes no request to Google Fonts or any other font service.
Content script on all sites — Show the highlight-to-decode trigger, and check a page against your watch list if you have added it. The trigger activates on text selection only and transmits nothing until you click it.
8. Children
VERIDIC is not directed at children under 13 and we do not knowingly collect their data.
9. Changes
Material changes will be announced in the extension's changelog and reflected in the "last updated" date above.