VERDICT MEMORY
Privacy Policy
Who we are
Verdict Memory is operated by Shpigel Nadav Shimon, Israel, who acts as the data controller for the personal data described in this policy. Contact for any privacy matter:support@finalverdict.ai. For payments, Paddle acts as Merchant of Record and is an independent controller of checkout and billing data.
What we store
- Account data: your email address and your Google account identifier.
- Your memories: everything you and your connected assistants store, together with who wrote it, when, its review status, and its version history. This is the product; it is stored until you delete it.
- Governance records: the audit trail of what was quarantined, approved, rejected, or superseded, and by which connected assistant. This record is what makes the service trustworthy, and it is retained alongside your memories.
- Usage metrics: the counters needed to enforce your plan (connected assistants, stored memories, timestamps).
Where your memories live
Each active account gets its own isolated instance: its own database file, on its own storage volume, reachable only through your own authenticated endpoint. Your data is not stored in a shared table with other customers' data. Instances run in Frankfurt, Germany by default.
Who can read your memories
Your connected assistants, and no one else in ordinary operation. The dashboard shows governance information (which assistants are connected, what is quarantined, what was approved) but never the content of your memories; there is no route from the dashboard to your stored text.
One disclosure you should understand: when you ask a connected assistant to read your memory, that content is sent to that assistant's provider (Anthropic, OpenAI, or whoever you connected) under your agreement with them, not ours. That is the point of the service, and it is your choice which assistants to connect and what to let them read.
What we send where
To operate the service, the text you store is sent to our embedding provider so that it can be searched by meaning. Nothing else leaves your instance. We do not send your memories to any AI model for training, analysis, or any other purpose.
Legal bases for processing
- Performance of a contract: creating and maintaining your account and instance, storing and retrieving your memories, providing support and refunds.
- Legitimate interests: securing the service, preventing fraud and abuse, and improving reliability using aggregate usage metrics that identify no individual.
- Consent: optional product-update emails, which you can withdraw at any time.
- Legal obligation: retaining transaction records required for tax and accounting, handled principally by Paddle as Merchant of Record.
Processors
- Fly.io: hosting and storage of your instance.
- Cloudflare, Inc.: network and proxy layer in front of the service; traffic passes through it.
- DeepInfra: embedding generation, which receives the text of stored memories and search queries.
- Google: sign-in only; we receive your account identifier and email address.
- Paddle: payment processing. Paddle is the seller of record for all purchases and processes payment data as an independent controller under its own privacy policy. We never receive or store your card details.
We publish any change to this list before it takes effect.
What we don't do
- We do not sell your data.
- We do not run advertising.
- We do not train models on your content, and our providers' terms exclude training on the data we send them.
- We do not read your memories. Support cannot see your stored content.
How we protect your data
All traffic is encrypted in transit (TLS/HTTPS). Each instance's storage volume is encrypted at rest. Isolation is physical, not a setting: separate database, separate volume, separate authenticated endpoint per account. Every write records which assistant made it; assistants you have not marked trusted cannot enter your trusted memory without review. Credentials live in a managed secrets vault and never appear in client code or logs. Payment card data never touches our servers; checkout is handled end-to-end by Paddle, a PCI-DSS-compliant Merchant of Record. No method of transmission or storage is 100% secure, but the architecture is built so failures stay contained to one account.
Your rights
Deletion is self-serve. Delete any memory, or your entire account, from your account page; content is removed from live systems the moment you confirm. Residual copies in encrypted infrastructure backups expire within 30 days. You can export everything you have stored, including the governance record, at any time from your account page. For access requests or anything else, email support@finalverdict.ai.
Cookies
Session cookies only, used to keep you signed in.
Questions about privacy? Email support@finalverdict.ai.
Last updated: 2026-08-07.