Privacy Policy

How VerifiedDR collects, uses, and protects your account data. Effective August 11, 2026.

In Short

We use your data to run your account and the features you choose. You can export or delete your data in settings. Contact us for any privacy request.

Who We Are

VerifiedDR (verifieddr.com) is the controller of the personal data described in this policy. For any privacy request or question, contact contact@verifieddr.com.

Information We Collect

Account data: your name, email address, optional profile details, password hash or the identity provided by a sign-in provider, and session metadata (IP address, browser user agent).

Product data: the websites you claim or submit, generated reports, keyword targets, growth runs, link exchange messages you send, and the notification preferences you set. Website metrics themselves (DR, TrueDR, backlinks, traffic) describe websites, not people.

Billing data: orders and subscription state. Card details go directly to Stripe; we never see or store them.

Usage data: product events (pages viewed, features used), an analytics identifier stored in your browser, and rate-limiting counters keyed by IP address to prevent abuse.

Integrations you connect: if you connect Google Search Console or Google Analytics, we store the Google account email and access tokens. These tokens let us read data for the properties you choose. We store a Slack or Discord webhook URL when you use it for alerts.

How We Use Information And Legal Bases

To provide the service (contract, GDPR Art. 6(1)(b)): accounts, authentication, site verification, reports, alerts, link exchanges, billing, and support.

To secure and improve the service (legitimate interest, Art. 6(1)(f)): abuse prevention, rate limiting, error monitoring, and product analytics.

To send product emails (legitimate interest with opt-out, Art. 6(1)(f)): product news, tips, and digests for account holders. Every such email carries a one-click unsubscribe link, and you can opt out any time in settings. Transactional email (verification, receipts, security) is sent as part of the contract.

To publish aggregate research (legitimate interest, Art. 6(1)(f)): we combine results from AI visibility scans across all accounts into statistics about the public web, such as which kinds of pages AI engines cite. These are counts over thousands of third-party pages. They never name a customer, a customer's website, or a customer's tracked questions, and no individual account can be identified from them. You can object to this use by emailing contact@verifieddr.com.

To meet legal obligations (Art. 6(1)(c)): tax and accounting records for payments.

Google User Data And Limited Use

You choose whether to connect Google. VerifiedDR requests these read scopes:

https://www.googleapis.com/auth/webmasters.readonly: reads Search Console performance data (clicks, impressions, positions, queries and pages) for the properties you connect, so your dashboard can show how your websites perform in Google Search.

https://www.googleapis.com/auth/analytics.readonly: lists your Google Analytics properties and their web data streams so the right property can be matched to your website, and reads that property's aggregated reports (sessions, users, engagement, and the top channels, pages, countries and devices), so your dashboard can show your measured traffic.

https://www.googleapis.com/auth/userinfo.email: reads the email address of the Google account you connect, so we can show you which account an integration is using.

We use Search Console and Analytics data in your private dashboard and reports. Your data stays out of public pages, sales, ads, AI training, and other user accounts.

VerifiedDR's use and transfer of information received from Google APIs to any other app adheres to the Google API Services User Data Policy, including the Limited Use requirements.

You can disconnect an integration from your dashboard. This deletes the stored tokens. Google gives one grant per Google account. We revoke it when none of your other integrations use it. Saved metrics stay in your dashboard for your history. Delete your account to erase them, or ask us at contact@verifieddr.com. You can also revoke access directly at myaccount.google.com/permissions.

How We Protect Your Data

Security procedures are in place to protect the confidentiality of your data, and we treat the Google data described above, along with the OAuth tokens that reach it, as our most sensitive category.

Encryption: all traffic between your browser and VerifiedDR is encrypted with HTTPS (TLS), as is every request we make to Google's APIs. Every service connection uses HTTPS.

Access control: Google access tokens stay on our servers. The browser, API and data export cannot read them. Database rules limit access to our servers. We keep admin keys and Google secrets in encrypted deployment storage. They are absent from the source code.

Least privilege: we request read scopes. The tokens grant view access and block changes to your Google account. Every request for your Google data re-checks that you still own the website it belongs to before returning anything, so one account can never read another's metrics.

Abuse prevention: the endpoints that begin an integration or trigger a sync are rate limited, and the link that carries you back from Google's consent screen is cryptographically signed and expires, so it cannot be replayed or pointed at another account.

Revocation and deletion: disconnecting an integration deletes the tokens we stored for it, and revokes the underlying Google grant once nothing else you connected is still using it. Deleting your account revokes every Google grant you gave us, for both Search Console and Analytics, and deletes those records along with the rest of your personal data. Access to production data is limited to the people who operate the service.

No system is perfectly secure, and we do not claim otherwise. If you believe you have found a vulnerability, report it to contact@verifieddr.com and we will respond.

Cookies

We set first-party cookies that are necessary to run the service (the authentication session cookie and a currency preference cookie) and first-party analytics cookies and local storage from PostHog, our EU-hosted analytics. Each brand sends this data to its own PostHog project. These tools recognize your browser across visits so we can measure how the product is used. We do not share PostHog analytics data with ad networks.

The X pixel uses a tracking cookie to connect an X ad visit with a free scan, account, trial, or purchase. It measures our own ads. You can block or clear this cookie in your browser at any time without losing access to the service.

When you are signed in, product events are tied to your account so we can understand and improve how the product is used. You can block or clear cookies in your browser at any time; the service keeps working, you just may need to sign in again.

Service Providers

We share data with services needed to run VerifiedDR. Cloudflare hosts the app and sends email. Convex stores data. Stripe handles payments. PostHog handles EU-hosted analytics. X measures ads when you allow it. Upstash limits abuse. Resend sends email. Google and GitHub handle sign-in and connected Google tools. Ask for the current list, regions and safeguards at contact@verifieddr.com. We do not sell personal information.

International Transfers

Some processors are located in the United States. Where personal data leaves the EEA, transfers rely on the EU-U.S. Data Privacy Framework or the European Commission's Standard Contractual Clauses.

Data Retention

We keep account and product data while your account exists. We delete it when you delete your account. The system removes expired sessions. We keep email send logs to honor unsubscribe choices and audit delivery. Payment records are retained by Stripe for as long as tax law requires. The system expires rate-limit counters within days. Backups roll over on a fixed schedule, so deleted data also leaves backups within weeks.

Your Rights

Under the GDPR you can access, correct, delete, export, restrict, or object to the processing of your personal data. Two of these are self-service in settings: "Export your data" downloads everything we store about you as JSON, and "Delete account" permanently erases your account and personal data, cancels active subscriptions, and revokes any connected Google access.

For anything else, email contact@verifieddr.com and we respond within 30 days. You also have the right to lodge a complaint with your local supervisory authority.

Business Customers

Using VerifiedDR on behalf of an agency or company? Our Data Processing Addendum covers processing we do on your behalf.

Contact

For privacy requests, contact contact@verifieddr.com.

Ready to increase your Domain Rating?

Help more people find your website in Google and AI answers. Build stronger links and track your growth.

Start my DR growth planTrack DR and TrueDR each week for free. No credit card required.Already have an account? Sign in