Last updated: October 2, 2026
VeriPrompt ("we", "us", "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, store, and protect your personal data when you use our AI Gateway & Agentic Platform ("Service").
The data controller responsible for your personal data is VeriPrompt, operated by Axel Weber. Contact details are available on our Impressum page.
Data Protection Officer: Axel Weber has been appointed as Data Protection Officer, contactable at data.protection@veriprompt.tech.
We collect the following categories of personal data:
We use your personal data to:
You can play our public mini-games without creating an account. Pacman currently has no voucher claim. When a Slots voucher campaign is open, our app records a short-lived game session, the spin sequence and outcome, and whether a voucher was issued. To enforce play and claim limits, it stores a keyed, one-way value derived from your network IP address rather than the address itself in the mini-game tables. The game host and our servers still receive ordinary connection data, such as IP address and browser information, when you visit them. The games do not set advertising or analytics cookies. A local browser preference may remember that you dismissed a help tip. Slot quiz choices are sent to the app to unlock the next set of plays, but are not stored in a player profile or used to decide whether you may continue. Pacman quizzes run in the browser without sending answers.
If you claim a win, we collect the name and email address you enter, your language choice, claim time, voucher reference, and delivery status. We use these details to check eligibility, issue a one-use voucher, prevent duplicate claims, and email the code through our email delivery provider, Brevo. We do not add you to a marketing list merely because you played or claimed a voucher. Claim data is collected before account registration; accepting account terms later does not replace this notice.
The claim form asks for your consent to use your name and email to verify the claim, send the voucher, and prevent duplicate claims (GDPR Article 6(1)(a)). You may withdraw that consent by contacting us, although we may then be unable to deliver or re-send the code. We use the minimum game and network data needed to operate the campaign and prevent abuse on the basis of our legitimate interests (Article 6(1)(f)). Registering and redeeming a code are covered by the account-related processing described elsewhere in this policy.
Game sessions expire after 20 minutes and are normally deleted about a day later. Mini-game claim rate counters are deleted after a day; play-limit records are deleted after 24 hours without activity. Aggregate daily win counts are deleted after 90 days. We normally delete voucher claim records after 90 days; the configured period may range from 8 to 365 days. A code already redeemed may remain in account and promotion records under the general retention rules below.
The current participation rules are in our Terms of Service. You can ask about your game data or withdraw claim consent using the contact details below.
VeriPrompt includes a built-in PII sanitization module that can detect and tokenize personally identifiable information before sending prompts to AI providers. Within that module, some email lookup values use one-way hashing and some personal names are encrypted at rest. This does not describe account contact details or the name and email entered for a voucher claim, which must be available for delivery and verification. Companies can configure data protection policies per project, team, or user.
We share data with third parties only as necessary to provide the Service:
The complete, current list of sub-processors — including purpose, location and DPA status for each — is published at /legal/subprocessors. We notify you before a new one takes effect.
We do not sell your personal data to third parties.
We retain your personal data for as long as your account is active or as needed to provide the Service. Usage logs are retained for analytics purposes and are automatically purged after the retention period configured by your company administrator. You may request deletion of your account and associated data at any time.
Under the General Data Protection Regulation (GDPR), you have the following rights:
To exercise these rights, contact us through the information on our Impressum page.
We use essential cookies for authentication and session management. We do not use third-party tracking cookies or advertising cookies. Analytics data is collected server-side without client-side tracking scripts.
We implement industry-standard security measures including encrypted data transmission (TLS/SSL), encrypted data at rest (AES-256), role-based access controls, and regular security audits. However, no method of transmission over the Internet is 100% secure.
We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy on this page and updating the "Last updated" date.
For questions about this Privacy Policy or to exercise your data protection rights, please contact us through the information provided on our Impressum page.