Verafy Privacy Policy
Effective date: 2026-08-11
App: Verafy+Anchor for Android and iOS (identifier com.dejify.verafy)
Controller: Verafy
Contact: privacy@verafy.me · support@verafy.me
This policy describes the personal information Verafy collects, why we collect it, how we share it, and the rights you have over it.
1. What Verafy is
Verafy is a Bluetooth-Low-Energy (BLE) proximity social-discovery app. Discovery, matching, and chat work primarily over BLE between phones in physical range. An internet connection is used only for account login, profile sync, support, and in-app purchases.
2. Information we collect
2.1 Information you provide
- Account identifiers: email address and/or phone number used to receive a one-time verification code (OTP).
- Profile information: display name, optional photo, age range, intent (e.g. "professional networking"), interests, energy level, and optional contextual focus tags.
- Optional contact information: email and/or phone number you explicitly choose to share with a matched user.
- Support content: messages you send through Support → Contact Us or the in-app myVera assistant.
2.2 Information collected automatically
- Device + diagnostic metadata: Android or iOS version, app version, build number, locale, and crash diagnostics (errors and warnings only — never the full console log).
- Bluetooth scanning telemetry: anonymous identifiers and signal strength used by the on-device matching engine.
- Approximate / precise location: required by Android as a precondition for BLE scanning on some OS versions. Verafy does not store, transmit, or log your GPS coordinates. On iOS the app requests no location permission at all — Apple’s CoreBluetooth does not require one to scan, so the permission is not declared in the iOS build.
2.3 Information from third-party services
- Resend delivers your OTP email. Resend processes only your email address.
- Twilio Verify delivers your OTP SMS. Twilio processes only your phone number.
3. How we use information
| Purpose | Data used | Legal basis |
|---|---|---|
| Create and secure your account | Email / phone, OTP | Contract |
| Run BLE discovery and matching | Profile, BLE identifiers | Contract |
| Provide chat between matched users | Profile, message content | Contract |
| Respond to support requests | Message content, account ID | Legitimate interest |
| Power the myVera AI support assistant | Your prompt text (anonymized) | Legitimate interest |
| Detect abuse / enforce safety | Reports, audit logs | Legitimate interest |
| Comply with law | Any of the above | Legal obligation |
4. How we share information
We do not sell or rent your personal information. We share information only with service providers acting on our written instructions:
- Resend — transactional email (OTP).
- Twilio — transactional SMS (OTP).
- OpenAI — myVera assistant. Prompts are sanitized and contain no account identifiers or contact details.
- Digital Ocean — hosting of the verafy.me API and database.
We may disclose information when required by law or to protect the rights, safety, or property of Verafy, its users, or the public.
5. BLE and on-device processing
Matching ("resonance") is computed entirely on your device. Profile data is never sent to a server during matching. Identifiers broadcast over Bluetooth are hashed/derived values — your name, email, and phone number are never advertised over the air.
5.1 Anchor (event mode)
Anchor lets an event organiser broadcast event information to attendees nearby. Attendees receive it over Bluetooth and can read it with no network connection; the event details and the organiser’s signature are verified on your device.
- Attendees: receiving an Anchor broadcast does not send anything about you to us. Nothing you receive over Bluetooth is reported back to our servers.
- Organisers: events and the advertisements shown inside them are stored on our servers so they can be managed and re-broadcast.
- Connections: when two people connect, we store a record of the pairing (the two account identifiers, its status, an affinity score and timestamps). We do not store where the connection happened.
6. Children
Verafy is for users 18 and older. We do not knowingly collect data from children. If you believe a child has used Verafy, contact privacy@verafy.me and we will delete the account.
7. Your rights
You can at any time:
- Access your profile from inside the app.
- Correct your profile from inside the app.
- Delete your account and all associated data — see
https://verafy.me/delete-account or Profile → Settings → Delete
Account.
- Withdraw consent to optional features by toggling them off in
Settings.
- Lodge a complaint with your local data-protection authority.
Requests covered by GDPR, UK GDPR, CCPA / CPRA, and similar regimes can be sent to privacy@verafy.me. We respond within 30 days.
8. Retention
| Data | Retention |
|---|---|
| Account profile | Until you delete your account |
| Chat messages | Until you delete the chat or your account |
| Support requests | 24 months after resolution |
| myVera interaction logs | 90 days (then aggregated) |
| Auth + audit logs | 12 months |
Deleting your account removes profile data, chats you originated, and Vera-token balance within 30 days from our primary systems and within 90 days from encrypted off-site backups.
9. Security
- All traffic between the app and verafy.me is HTTPS (TLS 1.2+).
- The Android Network Security Config denies cleartext traffic
app-wide. On iOS, App Transport Security is enforced
(
NSAllowsArbitraryLoadsis false), which blocks cleartext connections equivalently. - BLE bridge classes are listed in ProGuard
-keeprules; the rest of the app is R8-minified. - Passwords are never used — login is always OTP.
No system is perfectly secure. If you discover a vulnerability, please contact security@verafy.me.
10. International transfers
Verafy operates infrastructure in the United States. By using Verafy you acknowledge that your information may be processed there under appropriate safeguards.
11. Changes to this policy
Material changes will be announced in-app at least 30 days before they take effect. The "Effective date" at the top of this page always reflects the current version.
12. Contact
| Topic | Address |
|---|---|
| Privacy requests | privacy@verafy.me |
| Security disclosures | security@verafy.me |
| General support | support@verafy.me |
| Play Store reviewers | playreview@verafy.me |