Privacy Policy

This Privacy Policy explains what information UI Verify (“we”, “us”) collects, how we use and protect it, who we share it with, and the choices you have. It applies to our website and the UI Verify service.

1. Information we collect

  • Account information: your name, email, and organization, provided through our authentication provider when you sign up.
  • Customer Content: the screenshots, story metadata, and source references you upload so we can render, diff, and review your UI.
  • Usage & log data: build activity, feature usage, IP address, and device/browser information, used to operate and secure the Service.
  • Billing information: processed by our payment provider; we store plan and usage records, not full card numbers.
  • Cookies: used for authentication sessions and privacy- respecting product analytics.

2. How we use information

We use the information we collect to:

  • provide, maintain, and improve the Service;
  • render and compare your screenshots and generate review results;
  • process payments and manage subscriptions;
  • communicate with you about your account and service updates;
  • detect, prevent, and address abuse, security incidents, and technical issues.

3. Automated visual review

To classify a change as intended, a regression, or flaky, screenshots may be processed by an AI provider on our behalf. This content is used only to produce your review result. It is not used to train third-party or foundation models, and is retained by the provider only for a limited period under its standard API terms before deletion.

4. Sub-processors

We rely on a small set of trusted providers to run the Service. Each processes data only as needed to perform its function, under contractual data-protection obligations. The current list is on our Sub-processors page.

5. Data retention

We retain Customer Content for as long as your account is active so baselines and history remain usable; retention windows for baselines are configurable on paid plans. After you close your account, we delete Customer Content within 30 days, except where we must retain limited records to comply with legal obligations. Operational logs are retained for a limited period and then removed.

6. How we share information

We do not sell your personal information. We share information only with the sub-processors described above, when required by law or valid legal process, or in connection with a merger or acquisition (with notice).

7. Security

We encrypt data in transit and at rest, isolate each team’s data, and restrict internal access on a least-privilege basis. Read more on our Security page.

8. International transfers

Our providers are primarily located in the United States. Where we transfer personal data outside the UK or EEA, we rely on appropriate safeguards such as the UK International Data Transfer Agreement or the Standard Contractual Clauses.

9. Your rights

Depending on your location, you may have the right to access, correct, export, or delete your personal information, and to object to or restrict certain processing (for example under the UK GDPR, EU GDPR, or CCPA). To exercise these rights, contact us at the address below; we will respond within the time required by applicable law.

10. Children

The Service is not directed to individuals under 16, and we do not knowingly collect their personal information.

11. Changes to this policy

We may update this policy from time to time. For material changes we will provide notice through the Service or by email.

12. Contact

For privacy questions or requests, email privacy@uiverify.ai.