Legal

Privacy Policy

Last updated: June 2026

Veilora is built on a simple principle: your personal information should stay yours. This policy, from [Veilora - entity pending formation] (“Veilora,” “we,” “us”), explains what we collect, what we don’t, how we use it, and the rights you have.

The browser extension (prevention)

The Veilora extension runs entirely on your device. It never sends your browsing data, typed text, or any personal information to our servers or anywhere else.

  • • All detection and masking happens locally in your browser.
  • • We do not track which sites you visit or what you type.
  • • No analytics, no telemetry, no “phone home.”
  • • Your whitelists and sensitivity settings stay on your computer.

The removal service: what we collect

When you use our paid removal service, we collect what we need to act as your authorized agent:

  • Identifiers you give us to remove: name and past names, email addresses, phone numbers, current and past locations, age/birth year, and similar details you provide during intake.
  • Account data: your sign-in email and security/audit logs (sign-in events, key account actions).
  • Case records: the requests we send, broker responses, status history, and evidence such as screenshots of listings.
  • Payment data: handled by Stripe; we store your subscription status and plan, never full card details.

Sensitive identifiers you give us for removal are encrypted at rest on our systems.

How we use and share it

We use this information only to run your removal case and your account: submitting opt-out requests to data brokers, monitoring for re-listings, showing you progress, processing payments, and sending service emails.

Submitting a removal request necessarily means sharing your identifiers with the broker we’re contacting - that’s how opt-outs work. For some large aggregators we may send a request without first confirming they hold your data, so a broker that didn’t have your information may receive those identifiers as part of the opt-out. We follow a minimum-data principle: each broker gets only what it needs to process your request.

We do not sell your personal information, and we do not share it for cross-context behavioral advertising. We never have, and this policy commits us not to. We have no actual knowledge of selling or sharing data of consumers under 16.

Service providers

We use a small set of providers to run the service, each receiving only what their function requires: Stripe (payments), Resend (transactional email), Neon (database hosting), and our web host. They process data on our instructions and may not use it for their own purposes.

How long we keep information

  • Extension: nothing is stored by us - there’s no account and no server-side data.
  • Active removal cases: we keep your case file while your subscription is active, because monitoring and re-removal are ongoing.
  • After cancellation: we keep case records for a short wind-down period (typically 60–90 days) for follow-ups and disputes, then delete or fully anonymize them.
  • Account deletion: deleting your account from settings removes your personal data from our systems, except minimal records we must keep for legal, billing, or audit reasons.

Your privacy rights (CCPA and other state laws)

If you are a California resident, the CCPA/CPRA gives you specific rights. We extend these to all our customers regardless of state:

  • Right to know/access what personal information we have about you (your settings page includes one-click CSV/JSON export).
  • Right to delete - from settings or by emailing us.
  • Right to correct inaccurate information.
  • Right to opt out of sale or sharing - we don’t sell or share, so there’s nothing to opt out of.
  • Right to limit use of sensitive personal information - we already use it only to provide the service you asked for.
  • Right to non-discrimination for exercising any of these rights.

To exercise any right, email privacy@veilora.app or use your account settings. We verify requests via your account email and respond within 45 days. You may also use your own authorized agent to submit requests on your behalf - fitting, given that’s the service we provide.

Security

Sign-in is passwordless (email link + one-time code), sensitive identifiers are encrypted at rest, admin access to case data is restricted and audited, and we collect the minimum we need in the first place - the best protection for data is not holding it.

Children

The Services are for adults. We don’t knowingly collect information from anyone under 16, except identifiers a parent or legal guardian provides specifically so we can request removal of their child’s data.

Changes

If we make meaningful changes to this policy, we’ll post the new version here, note the date, and notify active customers by email. Continued use after changes take effect means you accept the updated policy.

Questions or privacy requests: privacy@veilora.app. We actually read and reply.