PRIVACY NOTICE / EFFECTIVE JULY 22, 2026 / VERSION 2026-07-22-US-NC-B2B-v1
Minimal records, accurately described.
This Notice describes Verahelm Holdings LLC's business website, passwordless access, API, and manual-intake processing for eligible United States business and professional users.
Information Verahelm processes
Depending on the service, Verahelm may process a random internal customer reference; protected email lookup and encrypted transactional email; entitlement and plan state; accepted document versions, purpose, and time; protected API-key references, scopes, expiration, and revocation state; aggregate quota and usage metadata; minimal security events; hosted-billing references and state when billing is enabled; and an exact non-confidential manual summary a verified Customer explicitly approves.
Information Verahelm does not require
Verahelm does not require passwords, usernames, conventional profiles, avatars, social login, team directories, telephone numbers, demographics, contacts, precise location, device fingerprints, advertising identifiers, browsing histories, uploads, repositories, saved prompts, saved API runs, or saved evidence. Verahelm does not collect card or bank credentials. Do not submit personal, confidential, regulated, restricted, privileged, credential, source-code, production-export, or third-party trade-secret material.
API and local-tool content
API input and full output are held only during the active synchronous request and are not persistently retained, cached, queued, or made searchable by default. Rejected bodies are discarded. Free-tool entries and drafts remain local in the browser unless the user separately reviews and explicitly submits an approved non-confidential summary. Verahelm does not train models on Customer content.
Purposes
Limited records are used to provide passwordless access, transactional notices, entitlements, quota, billing state, legal acceptance, Customer-requested handoff, privacy rights, abuse prevention, security, accounting, dispute handling, and legal compliance. Verahelm does not sell Customer content, broker personal data, use targeted advertising, or operate cross-site tracking, fingerprinting, heatmaps, or session replay.
Human verification. Interactive access, testing-key, and checkout actions use Cloudflare Turnstile, operated by Cloudflare, Inc., to distinguish human users from automated traffic. Turnstile processes transient browser and network signals (such as request headers, TLS/client characteristics, and interaction behavior) on Cloudflare systems for challenge purposes, under Cloudflare's own privacy commitments; Verahelm receives only a pass/fail token validation result and does not create, receive, or retain a device fingerprint from this processing. This third-party anti-bot processing is distinct from — and does not create — any persistent advertising or identity fingerprint.
Disclosure
Verahelm discloses minimum necessary information to essential contracted providers for infrastructure and security, transactional email, and hosted billing when enabled; to professional advisers bound by duties of confidentiality; in a corporate transaction subject to appropriate protection; or when required by valid legal process. Provider-specific disclosures required by an applicable signed agreement are available through privacy@verahelm.com.
Retention and deletion
The Data Processing and Retention Notice describes category schedules. Required billing, tax, contract, dispute, fraud, incident, legal-hold, or legal records may remain for the applicable period. API payloads cannot be produced or restored because they are not retained. Scheduled cleanup removes expired authentication and session records.
Access, correction, deletion, and closure
After email-code reverification, a Customer may request a summary of stored records, correction of the service email, deletion, key revocation, or entitlement closure through the passwordless privacy flow. Verahelm does not reveal whether an email has a record before verification. Deletion revokes active access and pseudonymizes or deletes records not subject to a required retention exception. Requests may also be sent to privacy@verahelm.com without including secrets or prohibited data.
Security and transfers
Verahelm uses minimization, encryption, keyed lookup values, access controls, isolation, bounded contracts, redaction, and revocation. No organization can promise absolute security. Internet and service-provider processing may occur in the United States or another location used to deliver the contracted service, subject to applicable contractual and legal safeguards.
Children and consumer use
The service is not directed to children, consumers, or personal, family, or household use. Verahelm does not knowingly provide this service to anyone under 18. Contact privacy@verahelm.com if you believe prohibited personal information was submitted.
Changes and contact
Material changes will use a new version and effective date and, where required, renewed acceptance. Verahelm Holdings LLC is the business responsible for this Notice. Privacy: privacy@verahelm.com. Legal: legal@verahelm.com. Security: security@verahelm.com.