Vercatus

Legal

Privacy policy

Version 1 · 16 September 2026 · Vercatus, hello@vercatus.com

What we collect, and why

From visitors to this site: nothing beyond standard server logs held by our hosting provider (Cloudflare) for security, and the contents of any email you send us. This site sets no tracking cookies and runs no analytics scripts.

From workspace users: your name, work email and role, so you can sign in and so we can attribute actions inside a workspace; session cookies strictly required to keep you signed in; and the data your workspace produces — the sites you analyse, the pages fetched from them, the findings and reports. API keys are stored as one-way hashes.

From the websites we analyse: publicly available pages of domains a customer has verified they control, fetched by a crawler that identifies itself. We do not analyse domains without that verification, and we do not use any content from customer sites to train models.

Who processes it

Hosting and networking (Cloudflare; the application host), the database host, and the model provider for analysis (Anthropic, under a no-training agreement). Enterprise workspaces may route analysis through their own model-provider account instead. We do not sell or share personal data with anyone else.

How long

Fetched page bodies: 30 days, then deleted. Derived data (findings, reports, graphs): for the life of the workspace, then deleted within 30 days of closure. Account data: until you delete your account. Server logs: per the hosting provider's retention, at most 30 days.

Your rights

You can ask for a copy of the personal data we hold about you, ask us to correct or delete it, or object to its processing, by writing to hello@vercatus.com. If you are in the EU/EEA or the UK, you also have the right to complain to your supervisory authority.

Changes

We will post changes here with a new version number and date, and tell workspace owners by email when the change affects their data.