The short version
You are uploading photographs of your face. That is the most sensitive thing we hold, and this page describes exactly how it is handled — including the parts that are less flattering than a marketing page would put them.
We have never sold or licensed a photo, and we never will. We do not use your photos or your facial geometry to train models. Aggregated research use requires your separate, explicit opt-in, which you can withdraw at any time.
Where your data lives
In the United States. Our database and photo storage run on Supabase in AWS
us-east-2, and our image-processing services run on Google Cloud Run in
us-east1. We say this plainly because data location is a real question for people
outside the US, and a vague answer is worse than an inconvenient one.
If you are in the EU, EEA or UK, your data is transferred to the United States to provide the service, and you have the rights set out in our privacy policy.
How photos are protected
- Private storage, keyed to your account. Photos and generated images live in private buckets under a path derived from your account id. There is no public URL for any of them.
- Short-lived signed links. When the portal shows you an image, the server mints a time-limited signed URL for that one object. Links expire; they are not permanent addresses.
- Encrypted in transit and at rest. All traffic is over TLS, and storage is encrypted at rest by the provider.
- Row-level security on every table. Access rules are enforced by the database itself rather than only by application code, so a bug in a query cannot return another person's row. Owner-read policies are declared per table and reviewed in migrations.
- Uploads are validated server-side. We identify file types by inspecting the actual bytes rather than trusting the declared content type, cap file sizes, and check each photo for a detectable face and usable framing before it is stored.
- Consent before the first photo. We explain what we collect, why, who processes it and how long we keep it, and record your written consent, before any photograph is accepted. The service is for adults only — 18 or older.
Who else sees them
Producing your analysis requires sending your photos to three providers. We name them because a claim that your photos never leave us would not be true:
- Anthropic — the written analysis.
- OpenAI — the generated images in your galleries and your Blueprint.
- Google Cloud — image processing and facial measurement.
Each is contractually bound to use your photos only to provide that service, and not to train on them or use them for any other purpose. Storage, authentication and our database are provided by Supabase; hosting by Vercel; payments by Stripe, which handles your card details directly — we never receive or store your card number. The full list is in our privacy policy.
Members of our team can access your photos where it is necessary to operate the service or to answer a support request that requires it. We do not pretend otherwise.
Account security
- Authentication uses signed tokens verified against a rotating public key set; we never see or store your password in readable form.
- Passwords must be at least 12 characters and include a letter and a number, and are checked against a database of passwords exposed in known third-party breaches. A breached password is refused at sign-up and when you change it.
- Privileged database routines are executable only by our server, not by browser-facing roles.
Retention and deletion
We never keep your photos more than one year after you stop. While your subscription is active we keep them, because your history and progress comparisons depend on them. When it ends — whether you cancel or it simply lapses — we keep them for one more year so you can still open your results, then delete them and everything generated from them. If you never had a subscription, that year runs from the last time you used VERASOMA.
You can have everything erased sooner at any time by emailing support@verasoma.com; we complete it within 30 days. The full schedule is in Data retention.
Encrypted provider backups are retained on a rolling window and age out on their own schedule, so a deleted photo can persist in a backup for a short period after deletion. We would rather say that than imply a deletion is instantaneous everywhere.
Monitoring and incidents
We use Sentry for application error monitoring and keep server-side request logs. To be precise about what that is and is not: it is error and exception tracking, not continuous anomaly detection on access patterns. We are a small team and we would rather describe our posture accurately than imply a security operations centre.
No system is perfectly secure. If we identify a breach affecting your information, we will notify you promptly and as required by law.
Reporting a vulnerability
We support the work of security researchers. If you believe you have found a security issue, email security@verasoma.com with enough detail to reproduce it. We aim to acknowledge every report within 24 hours.
Bug bounty. We pay bounties for meaningful findings. Award amounts are at our discretion and scale with the severity of the issue and the quality of the report. In scope: our marketing site, the customer portal, and our public API endpoints. Out of scope: findings produced solely by automated scanners with no demonstrated impact, denial-of-service, social engineering of our staff or users, and issues in third-party services we do not operate.
Please do not access, modify, or retain data belonging to other people while investigating — use your own account. If you do encounter someone else's data, stop, tell us, and delete anything you obtained; we will treat a good-faith report handled that way as a finding, not a violation. A PGP key is available on request.