VeriBridge Privacy Policy
Effective date: August 16, 2026 · Last updated: August 16, 2026
This Privacy Policy explains what information VeriBridge collects, why we collect it, how it is used, stored, and shared, and the controls you have. It covers the VeriBridge platform at veribridgeai.com, the VeriBridge API, and the VeriBridge Website Proof Recorder Chrome extension (see the extension section below and the extension-specific policy at veribridgeai.com/extension/privacy).
What VeriBridge is
VeriBridge is a platform where students build a verified Work Passport: a profile backed by real evidence of their skills. Students create proofs — uploaded documents, recorded project demonstrations, linked GitHub repositories, and screen-recorded website demos — which VeriBridge analyzes into verified skill reports. Students choose what to publish; recruiters can view published passports and reports and connect with candidates.
Information we collect
Account and authentication information
- Your email address and basic account identity.
- If you sign in with Google, the identity information Google shares for sign-in (name, email, avatar). If you sign in with email, we send one-time sign-in codes/links to your address. VeriBridge does not store passwords.
- Session tokens used to keep you signed in and to authorize your requests.
Profile and passport content you provide
- Profile details you add to your Work Passport, such as your name, photo, education, headline, and the skills and projects you describe.
Evidence you create (proofs)
- Documents you upload as proof (for example certificates or reports).
- Video recordings you make when defending or demonstrating a project, and transcripts generated from them (you can correct transcripts; corrections are stored too).
- GitHub repository data for repositories you choose to link, such as commit history, file contents, and contribution metadata, used to generate skill evidence.
- Website Proof recordings captured with the Website Proof Recorder extension — see the extension section below.
- Analysis results derived from your evidence (skill assessments, report content) become part of your account data.
Recruiter account information
- Recruiters provide their email and profile details (such as name and company), and VeriBridge stores the candidates they save and the passports they connect with.
Visitor and view information on published pages
- When someone opens a published Work Passport, public report, passport card, or share link, we record a view event. Depending on the surface, this can include the visitor's IP address, browser user-agent, referring page, and how the link was reached (for example a QR-code scan). We use this to show passport owners how their published pages are being viewed and to prevent abuse.
Support communications
- If you email support@veribridgeai.com, we receive your message and email address so we can respond.
The Website Proof Recorder Chrome extension
The Website Proof Recorder is a Chrome extension with a single purpose: it records a demonstration session that you start from your signed-in VeriBridge account and attaches the resulting evidence to the VeriBridge project you selected. It collects nothing while you are not recording a proof session. The full extension-specific policy is at veribridgeai.com/extension/privacy and is incorporated into this policy.
What the extension collects — only during a proof session you start
- Screen recording videoof the tab, window, or screen you explicitly choose in Chrome's screen-share picker (no audio, no microphone, no camera). Recording stops when you stop it and is capped at 5 minutes.
- On-page evidence from the website you demonstrate: visible page text, page titles, page URLs, clicks, and form interactions, so your evidence shows the real workflow.
- Screenshots (still frames) of the demo tab at key moments.
- File-upload metadata when your demo includes uploading a file: only the file type, extension, and a non-reversible hash of the name — never the file itself.
- Basic browser metadata (user-agent, language, platform) recorded with the proof for authenticity.
- Your VeriBridge session identity: a short-lived access token handed to the extension by the VeriBridge page you are signed in to, used solely to upload your evidence to your own proof session.
What the extension never collects
- Nothing at all while you are not recording a proof session.
- No cookies, no localStorage or sessionStorage contents, no browsing history.
- No passwords or sensitive fields: password inputs and fields that look like tokens, API keys, card numbers, bank details, or one-time codes are replaced with a redaction marker beforeanything leaves your browser, and URLs with sensitive query parameters are redacted the same way. VeriBridge's servers run a second, independent privacy scan on everything received.
- No audio or camera capture of any kind.
Extension permissions and why they are required
storage— keeps the active proof-session configuration and an in-progress recording's recovery state on your computer so a crash or browser restart cannot lose your recording before upload. This local state is removed once the upload is confirmed, and uninstalling the extension removes everything it stores.- Host access (
https://*/*and localhost) — you demonstrate your own project website, whose address is different for every student and unknown at install time, so the content script must be able to run on the site you choose. It captures nothing unless a proof session you started is actively recording. - The extension requests no other permissions, runs no remote code, and uploads evidence only to VeriBridge's own API — it refuses to send data anywhere else.
Why we process this information
- To provide the service: build your proofs, analyze your evidence into skill reports, assemble your Work Passport, and let you share it.
- To verify authenticity: evidence is bound to the account and session that created it so it can never be attached to someone else, and uploads are checked server-side for ownership.
- To show owners engagement: view events let passport owners see how their published pages are viewed.
- To keep the service secure: authentication, abuse prevention, and debugging.
- To communicate with you: sign-in emails and replies to your support requests.
How information is transmitted and stored
- All data moves over HTTPS. Evidence uploads go only to VeriBridge's own API.
- Account data, evidence, and analysis results are stored in VeriBridge's database and file storage, hosted by our infrastructure providers listed below.
- An in-progress extension recording is also held temporarily in the extension's local storage on your computer so a crash cannot lose it; it is removed once the upload is confirmed.
Service providers we use
VeriBridge does not sell your data and does not share it with advertisers. We use no third-party advertising or analytics trackers on our pages. The following service providers process data on our behalf to run the product:
- Supabase — authentication, database, and file storage (where your account data and evidence live).
- Vercel — hosts the VeriBridge web application.
- Render — hosts the VeriBridge API and evidence processing.
- Google — optional Google sign-in; our pages also load fonts from Google Fonts, which means your browser requests those files from Google when a page loads.
- Resend — delivers transactional emails such as sign-in codes and confirmations.
- ImprovMX — forwards email sent to our support address to our team's mailbox.
- AI processing providers (Anthropic, OpenAI) — where these capabilities are enabled, evidence you submit (such as recordings, transcripts, repository contents, and documents) may be processed by these providers on our behalf to generate transcripts and skill analyses. They act as processors for VeriBridge; we do not permit them to use your data for advertising.
Beyond these providers, we disclose information only when you choose to share it (publishing a passport, sharing a report link) or if required by law.
Your controls and sharing choices
- Your proofs and passport are private to your account by default. They become visible to others only through the sharing and disclosure choices you make (publishing your Work Passport, sharing a report link or card, or granting access).
- A master visibility switch lets you take your entire public passport offline at any time, and granular disclosure settings control which sections and evidence appear publicly.
- Share links can be revoked, after which they stop resolving.
- Extension recording starts only from your explicit action plus Chrome's own screen-share consent dialog, and you can stop it at any time. Your proof is not finalized until you send it.
Retention and deletion
- Your account data, proofs, and evidence are retained while your account exists, so your Work Passport keeps working.
- To delete a proof and its evidence, or to request deletion of your account and all data associated with it, contact support@veribridgeai.com.
- Uninstalling the extension removes everything it stores locally on your computer.
Security
All traffic is encrypted in transit with HTTPS. Evidence uploads are bound to the signed-in account and session that created them and are verified server-side. Sensitive-looking fields are redacted in your browser before upload, and our servers run an independent second privacy scan on received evidence. Access tokens handed to the extension are short-lived and are accepted only from VeriBridge's own website.
Children
VeriBridge is built for university students and recruiters and is not directed to children under 13. We do not knowingly collect information from children under 13.
Data sale and advertising
VeriBridge does not sell your personal information, does not use it for third-party advertising, and does not use or transfer it for purposes unrelated to the product's single purpose of building and sharing verified skill evidence you control.
Changes to this policy
If this policy changes, the effective date above is updated and material changes are announced in the product before they take effect.
Contact
VeriBridge — support@veribridgeai.com
Extension support page: veribridgeai.com/extension/support
Extension-specific policy: veribridgeai.com/extension/privacy