Legal · Privacy

Privacy Policy

Veridraw exists to make giveaway draws provable. That only works if we’re equally plain about the data behind them — so this page lists what we store, why, and how to get rid of it. No dark patterns, no third-party ad tracking, no analytics scripts.

Last updated 25 July 2026

1. Who we are

Veridraw (veridraw.io) is a giveaway-draw service operated by MB „Pakalnės“, established in Lithuania (European Union). For the personal data described below we are the data controller, except where this page says otherwise.

You can reach us about anything on this page at hello@veridraw.io.

2. What we store

Only what the product needs to run a draw and prove it later. There is no advertising profile, no behavioural tracking, and no analytics service embedded in the site.

Your account
Your email address and sign-in identity, held by our authentication provider (Clerk). If you sign in with Google we receive your email address and basic profile from Google — never your password. We also store your plan and, if you claim one, your public creator handle and display name.
Your giveaways
The post link and title you enter, the rule settings you choose, and the raw text you paste in.
Draw records
For each draw: the frozen list of entries, the seeds and hashes that make it verifiable, the public randomness round it was bound to, the chosen theme and stage look, the winners, and any disqualification you record afterwards.
Usage counters
A count of draws you have run this month, so plan limits can be enforced.
Technical logs
Standard server logs from our host (IP address, user agent, requested URL, timestamps), used for security and debugging and retained on a short rolling basis by that provider.
Payments
Paid plans are not live yet. When they are, checkout and billing run through Stripe: Stripe handles card details directly and we store only the subscription state (plan, status, period end) and the customer reference needed to manage it. We never receive or store card numbers.

3. The comments you paste

When you paste a comment thread, that text usually contains other people’s usernames and words. We process it strictly to build the entry pool, apply your rules, and freeze the snapshot the certificate proves. We do not use it to build profiles, do not sell it, and do not use it to train AI models.

Roles, plainly

For your own account data we are the controller. For the comment content you bring in, you are the controller and we act as your processor — you decide which thread to import and what rules apply; we only do what the app is built to do with it. That also means you are responsible for having a lawful basis to run the giveaway and to publish the winner’s username.

We never fetch, scrape or auto-collect comments from any platform, and we cannot see follows, subscriptions or likes — Instagram and YouTube do not expose that data, so nothing we publish ever claims to have verified it. Everything we work from is text you supplied.

The optional caption assist is the only AI step in the product: if you press it, the caption text you pasted is sent to Anthropic’s API, which returns suggested filter settings that you review and confirm before they apply. No entry list, no comment pool and no personal account data is sent, and the AI never decides who wins or who is excluded.

4. What becomes public

Verifiability is the point of the product, so some data is public by design. Nothing else is.

  • Certificates at /verify/<id> are public web pages: the giveaway title, the creator handle, the entrant usernames in the frozen pool, the winners and backups, the seeds and hashes, the beacon round, the applied rules, and any disqualification reason you record. Anyone with the link can read and recheck them, and search engines may index them.
  • Creator profiles at /@handle are public if you claim a handle: your handle, display name, number of verified draws and links to those certificates. Your email address is never shown.
  • The audience overlay at /obs/<id> shows the qualified usernames and, after the reveal, the winners. It is not indexed.

Comment text itself is never published on a certificate — only usernames and the counts. Certificate pages carry no advertising, ever.

5. Why we may use your data

  • To perform our contract with you (GDPR Art. 6(1)(b)) — creating your account, running and storing draws, publishing certificates you generate, enforcing plan limits, and billing once paid plans are live.
  • Our legitimate interests (Art. 6(1)(f)) — keeping the service secure and abuse-free, debugging, and keeping published certificates intact so a draw stays checkable.
  • Legal obligations (Art. 6(1)(c)) — accounting and tax records once payments are live.

We do not run advertising or profiling, and we do not make automated decisions with legal effect about you.

6. Who else processes it

A short list, kept short on purpose. Each of these acts on our instructions under a data-processing agreement.

Clerk
Account sign-in and session management. Data: Email address, sign-in identity (including Google sign-in), session cookies. Location: United States (EU–US Data Privacy Framework / standard contractual clauses).
Supabase
Database hosting for accounts, giveaways, draws and entries. Data: Everything stored in the app database. Location: European Union (AWS eu-central-1, Frankfurt).
Vercel
Application hosting and delivery. Data: HTTP request data and server logs (IP address, user agent, requested URL). Location: Global edge network; server processing and logs may take place outside the EU under standard contractual clauses.
Anthropic
Optional caption assist — turns your pasted giveaway caption into suggested filter rules. Data: Only the caption text you paste into that field, only when you press the button. Location: United States (standard contractual clauses).
Stripe (not yet active)
Payment processing for paid plans. Data: Billing details, handled by Stripe directly — we never see or store card numbers. Location: Ireland / United States.

Where a processor is outside the EU/EEA, transfers rely on the European Commission’s standard contractual clauses or an equivalent adequacy mechanism.

One outbound call carries no data of yours: to bind a draw to public randomness we fetch a round from the drand beacon. We send nothing but the round number we want, and anyone can fetch the same value to recheck a draw.

7. How long we keep it

Draw records and their frozen entry snapshots are kept for as long as the certificate is public, because deleting them would destroy the proof. Everything else is deleted with the account.

  • Account data — for as long as your account exists, then deleted.
  • Giveaways and pasted text — until you ask us to delete the giveaway or close the account.
  • Draw records and certificates — for as long as the certificate stays public. If you ask us to delete a draw, its certificate goes with it: the link stops working and the proof cannot be restored. That is the trade-off of a public, tamper-evident record.
  • Server logs — kept on our host’s short rolling retention.
  • Billing records — once payments are live, kept as long as accounting law requires.

8. Cookies

We use strictly necessary cookies only: the session cookies our authentication provider sets so you stay signed in, and standard security cookies. There are no analytics, advertising or third-party tracking cookies on this site, which is why you are not asked to consent to any. Public pages — certificates, creator profiles, this page — work without signing in and without cookies.

9. Your GDPR rights

If you are in the EU/EEA you can ask us to give you a copy of your data, correct it, delete it, restrict or object to its processing, or port it elsewhere. Write to hello@veridraw.io and we will answer within one month.

Deletion is handled by request today rather than by a button in the app: email us and we will delete a single draw, a giveaway, or the whole account. Because a certificate is a public proof, deleting the draw behind it takes the proof down with it — we cannot keep a verifiable certificate and erase its underlying record at the same time.

If you appear as an entrant or winner in someone else’s draw, the creator is the controller of that content — ask them first. You can also contact us and we will pass the request on, and remove content where we are legally required to.

You may also lodge a complaint with the Lithuanian State Data Protection Inspectorate (Valstybinė duomenų apsaugos inspekcija) or your local supervisory authority.

10. Children

Veridraw is a tool for creators and is not directed at children. You need to be at least 16 to hold an account. If you believe a child has created an account, tell us and we will remove it.

11. Changes to this policy

If we change how we handle data we will update this page and its date. Material changes affecting account holders will be sent by email. The date in the masthead is always the current version.

12. Contact

Questions, requests, or something on this page that doesn’t match what you see in the product: hello@veridraw.io. Our Terms of Service cover the rest of the relationship, and the FAQ explains how the fairness proof works.