Skip to content

Legal

Privacy Policy

Last updated October 3, 2026

This policy explains what personal information Reshapify, LLC (“we”) collects when you use Vermin, why, and what you can do about it. It covers vermin.dev, the API, the MCP server and the dashboard. Questions go to privacy@vermin.dev.

What we collect

  • Account information: your name, email address, password hash (we never see your password), and your GitHub profile if you sign in with GitHub. Organization names and team members you invite.
  • Billing information: plan, invoices and billing address. Card details go straight to Stripe; we never receive or store them.
  • API usage: for each request, the endpoint, the URL you asked for, status, credits used, latency, request ID, and the API key that made it. We store a hash of each API key, never the key itself.
  • Technical data: IP address and user agent in server logs, used for security and abuse prevention.
  • Website analytics: on our public marketing and documentation pages we use a cookieless analytics service. It records the page you viewed, the referring page, and coarse technical details such as browser, operating system, device type, language and country. We don't record analytics on the dashboard or any signed-in page, it sets no cookies, and it isn't linked to your account.
  • Chat and sales enquiries: what you type into the chat on our website and any contact details you choose to give it.
  • Error reports: when something breaks, a stack trace and the page or endpoint involved. We strip request bodies, headers, query strings and user identifiers before they leave our systems. If an error happens in the browser, we may record a replay of that session with all text and form inputs masked.

We don't use advertising or cross-site tracking cookies. The only cookies we set are the ones needed to keep you signed in; our website analytics are cookieless.

Content you retrieve

Pages you scrape or crawl are processed on your instructions. We act as a processor of that content on your behalf. If it contains personal data, you are responsible for having a lawful basis to collect it (see our Terms). We keep retrieved content only as long as needed to run the Service:

WhatKept for
Scrape cacheUp to 2 days by default (you control this with maxAge)
Crawl results7 days after the crawl ends
ScreenshotsUp to 3 days; links expire after 24 hours
Brand data (public company logos, colours and fonts)Up to 90 days, shared across customers
Request logs14 days (daily usage totals are kept with your account)
Webhook delivery logs30 days
Account, billing and credit ledgerWhile your account is open, then as required for tax and accounting (usually 7 years for invoices)

We don't sell personal information or use your data or results to train models.

Why we use it

  • To provide the Service: authenticate you, run requests, meter credits and bill you (contract).
  • To keep it secure, prevent abuse and fix bugs (legitimate interests).
  • To understand which of our public pages are useful, using aggregate, cookieless analytics (legitimate interests).
  • To send account, billing and usage-alert emails. We don't send marketing email without your consent.
  • To meet legal obligations such as tax records.

Who processes it

We use these service providers, each under a contract that limits how they can use your data:

ProviderPurposeLocation
Cloudflare, Inc.Hosting, API and website, caching, headless browsers, storageGlobal
Convex, Inc.Database for accounts, keys, credits and logsUnited States
Stripe, Inc.Payments, subscriptions and invoicesUnited States
Resend, Inc.Account and usage-alert emailsUnited States
Functional Software, Inc. (Sentry)Error monitoringUnited States
Social Hive (Umami)Cookieless website analytics on our public marketing and docs pagesUnited States
GitHub, Inc.Sign in with GitHub (only if you choose it)United States
PageClerk (Reshapify, LLC)The chat on our website: transcripts and contact details you give itUnited States

We may also disclose information if required by law, to protect our rights or users' safety, or as part of a merger or acquisition (we'd tell you first).

International transfers

We're based in the United States and so are most of our providers. If you're in the EU, UK or Switzerland, we rely on Standard Contractual Clauses or equivalent safeguards for transfers.

Your rights

Depending on where you live (for example under GDPR or the California CCPA/CPRA), you can ask to access, correct, delete or export your personal information, object to or restrict certain processing, and withdraw consent. You can delete workspaces in the dashboard; to delete your account or make any other request, email privacy@vermin.dev. We'll respond within 30 days and won't treat you differently for asking. You can also complain to your local data protection authority.

Security

Traffic is encrypted in transit. API keys and invite tokens are stored only as hashes. Access to production systems is limited to people who need it. No system is perfectly secure; if a breach affects your data, we'll tell you without undue delay.

Children

Vermin isn't for anyone under 18, and we don't knowingly collect their information.

Changes

We'll post changes here and, if they're material, email you before they take effect.

Contact

Reshapify, LLC
1111B S Governors Ave STE 23005

Dover, DE 19904

United States

privacy@vermin.dev