verisualBack to Verisual

PRIVACY POLICY

Collect less. Protect what remains.

What crosses the boundary, what stays in your CI, and how long evidence is retained.

EffectivePublic version 1.0

01

Scope and roles

This Privacy Policy explains how Verisual processes personal data when you visit our website, sign in, connect GitHub, run visual reviews, or contact support.

Verisual is responsible for the account, product, and support data described here. Paddle independently processes checkout and payment data as merchant of record under Paddle's privacy notice. An organization using Verisual may also be responsible for data it chooses to include in repositories, journeys, or screenshots.

02

Data we collect

Account and organization data

GitHub user ID, username, display name, verified email, avatar, organization membership, invitations, roles, session records, and authentication and security events.

Repository and CI metadata

Repository identity, installation ID, workflow identity, branch, pull-request number, commit SHA, run and job identifiers, journey and checkpoint names, browser-environment metadata, comparison status, image hashes, timing, and approval history.

Visual artifacts

Screenshots and diffs for visual results that need review. Matching screenshots are represented by hashes and metadata and are not uploaded.

Usage, device, and support data

Quota counters, feature settings, request and security logs, IP address, browser and device information, support correspondence, and diagnostic details you choose to provide.

Billing references

Paddle customer, subscription, transaction, and price identifiers, subscription status, billing period, and payment-failure state. Verisual does not receive or store full payment-card details.

03

What stays in your environment

In the GitHub/CLI workflow, your application, Playwright execution, authentication storage state, and environment variables remain in your CI environment. Paid hosted URL projects instead run constrained journeys in Verisual's isolated browser worker and do not accept arbitrary Playwright code. Owners and admins may explicitly upload an encrypted browser-state profile for optional Pro agent reviews; use a dedicated test account.

Pixel comparison happens before upload. When a comparison matches, Verisual receives the result, hashes, and timing—not the redundant screenshots. The Free plan never sends screenshot content to an AI provider.

04

How and why we use data

  • provide accounts, visual review, baseline history, billing, and support;
  • authenticate users and CI jobs, enforce workspace isolation, and prevent fraud or abuse;
  • measure quotas, operate retention, reconcile subscriptions, and improve reliability;
  • communicate service, security, billing, and material policy changes;
  • comply with law, enforce agreements, and protect users and the Service;
  • provide optional AI features when an eligible workspace enables them.

Depending on your location and the context, these uses rely on performance of a contract, our legitimate interests in operating a secure service, compliance with legal obligations, or consent where required.

05

Service providers and sharing

We share data only as needed with:

  • GitHub for authentication and repository integrations;
  • Paddle for checkout, tax, invoices, subscriptions, and buyer support;
  • hosting, database, object-storage, queue, observability, and email providers that operate Verisual;
  • Vercel AI Gateway and the selected downstream model providers for optional paid-plan authoring, changed-result analysis, or Pro agentic test reviews;
  • professional advisers, authorities, or transaction counterparties where legally necessary.

We do not sell personal data or share it for cross-context behavioral advertising.

06

AI processing

AI processing is disabled on Free and can be controlled at the workspace level on eligible paid plans. Local CLI authoring sends the prompt and relevant structured context. Browser-backed journey generation and repair send transient screenshots and visible structured page context from an approved target while exploring and replaying a journey. Changed-result analysis sends only the visual evidence and context needed for that failed test. Optional Pro browser agent tests—including security, product, support, and business reviews—send screenshots and visible structured page context from an approved test target, but not authentication secrets. Code Auditor runs send repository structure, language and framework metadata, manifests, and selected source excerpts from an immutable GitHub snapshot. Its current-practice research may use web search and retains the cited source URLs. Requests use Vercel AI Gateway with storage disabled, prompt training disallowed, and zero data retention requested on every eligible provider route.

Do not include secrets, special-category personal data, or unnecessary personal information in prompts, journeys, screenshots, repositories, or source comments submitted to Code Auditor.

Pro owners and admins may separately opt in to failure-based product improvement. Verisual reduces a failed journey or agent run to generalized action types, locator strategies, failure categories, execution surface, prompt/tool versions, and counts. It does not include customer identifiers, URLs, page text, code, screenshots, prompts, authentication data, secrets, or raw errors. A platform-funded process may use this generalized signal to open a draft product change for human review. It does not consume customer credits or plan allowances, and proposed guidance remains inactive until a maintainer explicitly approves it through the evaluated product-development process. The preference is off by default and can be disabled in Workspace Settings.

For paid browser-backed journey tasks, named secrets are encrypted and the model receives their names but never their values. The hosted runner receives configured values only after it claims the job, keeps them in memory, resolves secret fills there, masks secret-filled controls, and exact-redacts secret and authentication values from model observations and errors. For an authenticated agent review, the isolated worker receives the selected project's encrypted-at-rest browser state only after claiming the job and injects it before model observation. Cookie and local-storage values are not sent to the model. Journey generation and repair retain no browser screenshots, videos, or traces. Code Auditor source is streamed through an authenticated, lease-bound route without exposing GitHub credentials to the worker, is never executed, and is deleted after the audit attempt.

07

Retention and deletion

Default artifact retention is 7 days on Free, 30 days on Starter, and 90 days on Pro. Workspace settings may shorten retention but cannot exceed the plan maximum. Full browser-agent videos and traces, code audit reports, evidence excerpts, and research citations use the Pro retention period. Downloaded repository archives and extracted source workspaces are not retained after the attempt.

Account, audit, usage, billing-reference, and security records are kept only as long as reasonably necessary for the Service, dispute resolution, fraud prevention, financial reporting, and legal obligations. Deletion from active systems may be followed by a limited backup-retention period.

To request workspace export or deletion, contact privacy@verisual.com. We may need to verify your identity and workspace authority first.

08

Cookies and similar storage

Verisual uses essential cookies for sign-in, OAuth state, browser sessions, security, and request integrity. These cookies are required for the Service to work. We do not currently use advertising cookies.

Paddle Checkout and linked third-party services may use their own cookies under their published notices. Your browser settings can remove cookies, but doing so may sign you out or interrupt checkout.

09

International transfers

Verisual and its providers may process data in countries other than yours. Where required, we use contractual and organizational safeguards designed to protect personal data during international transfers.

10

Your privacy rights

Depending on your location, you may have rights to access, correct, delete, restrict, object to processing, or receive a portable copy of personal data, and to complain to a data-protection authority.

Send a request to privacy@verisual.com. We do not discriminate against people for exercising privacy rights. If Verisual processes data solely for your organization, we may direct the request to that organization.

11

Security and children

We use access controls, tenant scoping, encrypted transport, secret redaction, signed webhooks, short-lived tokens, and monitoring designed to protect the Service. No system is completely secure, so please report concerns to security@verisual.com.

Verisual is a professional software-development service and is not directed to children under 16. Contact us if you believe a child has provided personal data.

12

Updates and contact

We may update this Policy to reflect product, provider, or legal changes. The effective date and version at the top identify the current policy. We will provide additional notice when required.

Privacy questions and requests may be sent to privacy@verisual.com. Product-support requests should use Support.