VeristreamSign in

Privacy policy

Last updated 30 July 2026

Veristream verifies creator clip performance for advertising campaigns. This policy describes what it collects, why, how long it keeps it, and how to have it removed. Simon Stawski is the data controller; questions go to hi@simonstawski.com.

What is collected

Three kinds of data, from three sources.

  • What you enter. Your name, handle, sign-in email and payout email. A password, if you create one, is stored only as a hash by the authentication provider and is never visible to us.
  • What a connected platform account returns. Only your own content: your account ID and public username or channel name, the list of posts on that account, and the performance metrics of posts you submit. Details per platform are below.
  • What a submission contains. The clip URL, its caption, and — if you upload one — the video file, from which an audio transcript and still frames are produced for the advertising-compliance check.

What each platform connection reads

  • YouTube (Google).Read-only access to your channel identity, your uploads list, and the view, like and comment counts on videos you submit. Your Google email address is read once, at sign-up, to create your account. Veristream’s use of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.
  • TikTok.Your open ID and display name, your video list, and each video’s view, like, comment and share counts. TikTok does not disclose an email address to applications, so a TikTok-only sign-up has no email until you add one.
  • Instagram.Your professional account’s ID and username, your media list, and the views and reach of posts you submit. This connection does not disclose an email address.

Access is read-only in every case. Veristream cannot post, comment, send messages, follow, or modify anything on a connected account, and reads no other person’s content.

Why it is collected

To run the service you signed up for: confirming that a submitted clip belongs to you, recording its performance from the platform rather than from a screenshot, checking the clip against the advertising rules the campaign is subject to, and calculating what you are owed. Metrics are read on a recurring schedule because a payout is calculated from a series of readings over time, not a single figure.

Who it is shared with

Your submissions, their verified metrics, and their compliance results are visible to the operator of the campaign you submitted to. Beyond that, data is shared only with the service providers that run the product:

  • Supabase — database, authentication and file storage.
  • Cloudflare — application hosting.
  • Groq — transcribes the audio of an uploaded video for the compliance check. Anthropic — analyses that transcript, the caption, and extracted frames against the rule set. Both receive submitted clip content only, never your account credentials or tokens.

Nothing is sold, and nothing is used for advertising or profiling.

How it is protected

Platform access tokens are encrypted with AES-256-GCM before they are written to the database, so the database never holds a usable token. Application access to your records runs server-side only. Transport is HTTPS throughout.

How long it is kept

  • Platform access tokens — until you disconnect the account, at which point the stored token is erased. Disconnecting stops all further reading immediately.
  • Detected posts you never submitted — deleted on request, and deleted automatically when you disconnect the account they came from.
  • Submissions, verified metric readings, compliance decisions and payment records — retained after an account closes. These are the records that substantiate a payment made to you and a regulated advertising decision, and the compliance record is deliberately append-only: it cannot be edited or deleted, by us or by anyone. If you want your data erased, read the next section, which explains what can and cannot be removed and why.

Your choices, and deleting your data

You can see and change your profile, and disconnect any platform account, on your profile page at any time. To request erasure, or a copy of what is held about you, follow deleting your data or write to hi@simonstawski.com.

One limit, stated plainly: records of payments made to you and compliance decisions about published advertising are kept even after erasure, because they are the evidence that those payments and decisions were sound. Everything else — your profile, your stored authorizations, and posts that were never submitted — is removed.

If you are in the UK or EU, you can complain to your data protection authority; in the UK that is the Information Commissioner’s Office.

Children

The service is for creators old enough to hold an account on the platform they connect and to be paid for advertising work. It is not directed at children.

Changes

Material changes are published on this page with a new date at the top. Continued use after a change means the updated policy applies.