Privacy Policy
Last updated: August 16, 2026
1. Overview
This Privacy Policy explains how NexiphorVerifier ("we") handles personal data when you use our email verification service (the "Service"), including our website, API, dashboard, and browser extension. We act as a data controller for account, billing, support, and security data about you, and as a data processor for email addresses and related columns you upload to be verified, which we process on your instructions under our Data Processing Agreement.
2. Information We Collect
- Account data: name, email address, hashed password, optional avatar, authentication provider (email or Google), 2FA/passkey metadata, sessions, and login history.
- Signup and security data: IP address, approximate geolocation (city/region/country via MaxMind), user agent, referral identifiers, and bot-challenge tokens.
- Billing data: processed by Stripe. We store customer, subscription, and transaction references, never full card numbers.
- Verification and Finder data: email addresses and associated columns you submit, SMTP probe results, Email Finder names/domains/candidates, leads you save, and job metadata.
- Integrations: OAuth tokens or API credentials you connect for CRMs/ESPs, webhook endpoints, and delivery-feedback events you send us.
- Communications: support transcripts, notification preferences, transactional email logs, and (only if you opt in) marketing/product-update mail.
- Team and agency data: memberships, invites, audit events, and workspace impersonation for agency clients you manage.
3. How We Use Information
- To provide email verification, Email Finder, integrations, and return your results;
- To manage your account, credits, teams, and billing;
- To secure the Service, prevent abuse, and comply with legal obligations;
- To send service-related communications;
- To send product updates or marketing emails only when you have opted in.
We do not sell your data. We do not use the email addresses you submit for verification for any purpose other than performing the verification you requested (and related security, metering, and support).
4. Legal Basis
Where the GDPR applies, we rely on: performance of a contract (to provide the Service), legitimate interests (to secure and operate the Service), consent (for optional marketing and for Google Sign-In / non-essential third-party scripts), and legal obligations. When you upload email lists, you are the controller of that data; we act as your processor under the DPA.
5. Subprocessors
We use these subprocessors to run the Service:
- Stripe (Ireland/US) — payment processing;
- OVHcloud — hosting and infrastructure (EU region, Frankfurt, Germany), including PostgreSQL and Redis on our VPS;
- MaxMind — IP geolocation for fraud prevention;
- Cloudflare — Turnstile bot protection on public forms;
- Google — Sign-In (GIS) when you choose Google authentication;
- Transactional email — sent over SMTP from our OVHcloud VPS. Resend is not active in production;
- OpenAI — optional admin email-copy assist (disabled unless we enable it; subject/body of campaign drafts may be sent to OpenAI in the US).
Transfers outside the EEA, if any, use appropriate safeguards such as Standard Contractual Clauses.
6. Artificial intelligence
The verification engine itself is not a generative AI chatbot. Optional OpenAI copy assist is used only by platform administrators to draft marketing/operational email copy. We do not use customer verification lists to train public AI models. AI or human support output is not a binding contract, legal advice, or billing commitment.
7. Data Retention
We retain account and billing records for as long as your account is active and as required by tax and accounting law (billing ledger rows are a legal hold). Verification lists and results are retained so you can access them from your dashboard until you delete a job or your account. Deleting a job removes its associated email data. Deleting your account purges verification and Finder lists you own, integration credentials, webhook endpoints, in-app notifications, support threads, login history, and passkeys, then anonymizes the user row. Residual legal-hold fields include credit-ledger amounts, billing transaction metadata, revoked API-key records, removed team memberships, and redacted mail-delivery logs — not your uploaded list emails.
8. Data Security
We use encryption in transit, hashed credentials, access controls, and rate limiting. No method of transmission or storage is completely secure. We will notify you of material breaches as required by law.
9. Your Rights
Depending on your location, you may have rights to access, correct, delete, export, or restrict processing of your personal data, and to object to certain processing or withdraw consent. Signed-in customers can download a copy of their account data or request account deletion from Dashboard → Settings → Privacy. You can also contact privacy@nexiphorverifier.com.
10. Children
The Service is for people 18 years or older. We do not knowingly collect personal data from children. If we learn that an account belongs to someone under 18, we will delete it.
11. Browser Extension
If you install the Nexiphor Verifier browser extension, your API key is stored in the browser's extension-local storage (chrome.storage.local). It is not synced across devices. The key is used only to call https://api.nexiphorverifier.com and is never placed in a URL. The in-page content script never receives the key and never calls the API.
12. Cookies and similar technologies
We use strictly necessary cookies to keep you signed in and to secure the Service. Cloudflare Turnstile runs on public forms as security. Google Sign-In scripts load only after you choose Google authentication (on register, after you accept these terms). We do not use advertising pixels. Optional error monitoring (Sentry) is loaded only if configured.
13. Changes
We may update this policy from time to time. Material changes will be communicated by email or in-app notice.
14. Contact
Questions or data requests: privacy@nexiphorverifier.com. Operator identity: Impressum.