Privacy & Data Handling

How Veil protects your data

Last updated: 11 March 2026

The short version: We built Veil to protect your privacy, not compromise it. Your personal data is encrypted at rest, never sold, never shared with advertisers, and never used to train AI models. We collect the minimum data needed to protect you, and nothing more.

What data we collect and why

Information you provide

Information we gather on your behalf

Encryption and storage

All sensitive personal data is encrypted at rest using AES-256-GCM with unique encryption keys derived per household. This means:

How we use external services

To protect you, we interact with several external services. Here is exactly what data reaches each one:

Breach monitoring (HaveIBeenPwned, Dehashed)

Your email addresses are sent over encrypted connections (HTTPS) to check against known breach databases. No other personal data is shared. These services do not retain your query.

Social media monitoring (Apify)

We send your public name or social media handle as a search query. This is information that is already publicly visible. We never send your email, phone number, household details, or any private identifiers to social monitoring services.

AI-powered classification (Anthropic Claude)

When we find a public mention, we send only the short text snippet (up to 280 characters of publicly visible content) and the display name of the person being monitored to our AI classifier. This allows us to determine whether a mention is concerning (threats, impersonation, bullying) or routine (neutral press coverage). We do not send your email, phone number, or any encrypted personal data to the AI service. Your data is not used to train AI models.

Email notifications (Mailgun)

Your email address is used to send you security alerts and daily digest reports. We do not share your email with any other party.

What we never do

Access control

Every query to our system is scoped to your household. It is architecturally impossible for one household to access another household's data. This is enforced at the database query level, not just at the application level.

Data retention

Your monitoring data is retained for as long as your account is active. Alert history is preserved so you can review past incidents and track resolution. If you close your account, all associated data — including encrypted identities, alerts, and household information — is permanently deleted.

Your rights

You can at any time:

Infrastructure

Veil runs on Cloudflare's global network, which provides:

Changes to this policy

We will update this page if our data handling practices change. Significant changes will be communicated to active users via email. The "Last updated" date at the top of this page reflects the most recent revision.

Questions?

If you have questions about how we handle your data, contact us at privacy@veilprivacy.app.