Legal and privacy
Privacy and cookie notice
This notice explains how VerifiedCode.dev handles personal data and source materials, and how this website uses cookies and browser storage.
Last updated: 27 July 2026
Who is responsible
VerifiedCode.dev is the data controller for the personal data described in this notice. Questions, rights requests, or deletion requests can be sent to [email protected].
Data we collect
- Account, contact, sign-in provider, and reviewer application details.
- Application context, repository packages, public repository URLs, and review materials supplied for the service.
- Reports, clarifications, disputes, feedback, assignments, QA decisions, and service history.
- Security and audit records such as source-access events, request metadata, and authentication activity.
- Optional analytics data such as sanitized route names, device type, approximate location, and navigation events after consent.
Do not submit source or account data that you are not authorized to share. Avoid including production credentials, private keys, or unnecessary personal data in a repository package.
Why we use data
- To create and secure accounts and provide requested review services.
- To inspect, assign, review, quality-check, deliver, and support review work.
- To prevent abuse, investigate incidents, and preserve an auditable service history.
- To meet legal obligations and establish, exercise, or defend legal claims.
- With consent, to understand website use and improve the service through Google Analytics.
Depending on the activity, processing is necessary to provide the service requested or take steps before entering a contract, supports legitimate interests in operating and securing the service, meets a legal obligation, or relies on consent. Analytics consent can be withdrawn at any time.
Who receives data
Data is available only where needed to operate the service, including authorized operators, assigned reviewers, and QA owners. Service providers may process limited data on our behalf, including Azure for hosting and repository storage, Resend for transactional email, and Google for optional Analytics. GitHub or Google processes data when their sign-in service is selected, and GitHub processes requests when a public repository import is used.
Some providers may process data outside the UK or EEA using their contractual transfer safeguards. Their own notices describe their processing. We do not sell personal data.
Retention
Account, review, security, audit, and service records are retained for as long as needed to provide and protect the service, resolve disputes, and satisfy legal requirements. Google Analytics event-level data is configured for 14-month retention; aggregate reporting may remain available after that period.
Automated source-retention and customer deletion controls are not yet complete. Repository packages may therefore remain in private storage after a review until an operator completes deletion. Request early deletion at [email protected]. Some records may need to be preserved separately for security, dispute, or legal purposes.
Google Analytics
Google Analytics 4, measurement ID G-CSZ54X4EV5, is optional. The Google tag is not requested and no Analytics event is sent unless analytics is accepted. Advertising storage, advertising user data, advertising personalization, and Google Signals are disabled by this website configuration.
Analytics covers public and authenticated routes, but page locations are reduced to route templates. Query strings, URL fragments, and review, submission, or user record identifiers are not sent in pageview locations. Never put personal or source data into URLs.
Read Google's privacy policy for more information.
Cookies and browser storage
| Name | Purpose | Duration | Category |
|---|---|---|---|
| verifiedcode_session | Keeps an authenticated account signed in and protects account-only features. | 24 hours | Necessary |
| verifiedcode_oauth_state | Protects GitHub or Google sign-in and account-linking flows against request forgery. | 10 minutes | Necessary |
| verifiedcode_theme | Remembers the light or dark colour theme selected by the visitor. | 1 year | Functional |
| currency | Remembers the displayed USD or GBP price preference. | 1 year | Functional |
| verifiedcode_cookie_consent | Remembers whether optional analytics was accepted or rejected. | 180 days | Necessary |
| _ga and _ga_* | Distinguishes visits and sessions for Google Analytics after consent. | Up to 2 years | Analytics |
The intake may also use one-time same-tab session storage to preserve non-source answers while a visitor signs in. It is removed after restoration and excludes repository packages, filenames, repository URLs, source classification, and source attestation.
Your rights
Depending on where you live, you may have rights to access, correct, erase, restrict, or receive your personal data, object to processing, and withdraw consent. Contact [email protected] to make a request. Identity verification may be required before disclosing or changing account data.
You may also complain to the UK Information Commissioner's Office or your local data-protection authority. Visit ico.org.uk/make-a-complaint.
Changes to this notice
This notice may be updated when the service, providers, legal entity, or retention controls change. Material changes will be identified by a new date and communicated where appropriate.
Return to VerifiedCode.dev