Legal and security
Updated on September 7, 2026
This page is where to go when something needs to be dealt with rather than read. What binds is in the terms and the code of conduct; this is the practical side.
Verno is run by the Verno Foundation, from the Netherlands. General contact: info@verno.foundation.
Reporting content
Anything that should not be standing here — work that breaks the rules, or material that infringes your rights — goes through the form at verno.foundation/report. You do not need an account.
You get a reference number by email, in the form VR-2026-9EVPE4. Keep it: it is the fastest way for us to find your report if you write again.
A person reads every report. Not a machine, and not a queue that empties itself — which is also why it is not instant. We come back to you at the address you gave, whether we act on it or not.
Reporting a security problem
If you find a way to reach data that is not yours, break something for other people, or get in without credentials: tell us at info@verno.foundation. Put "security" in the subject.
What we ask while you look:
- Do not access, change or keep other people's data. If you stumble into it, stop and tell us what you saw.
- Do not degrade the service for other people — no load testing, no mass automated requests.
- Give us a reasonable time to fix it before you publish anything about it.
- Stay out of anyone's account but your own.
What you get in return: we confirm we received it, we tell you what we found, and we tell you when it is fixed. If you followed the points above, we will not pursue you for having looked — and we would rather hear it from you than from someone else.
We do not run a paid bounty programme. We can offer credit where you want it, and honest thanks where you do not.
Something wrong with a payment
Write to us first: info@verno.foundation. We can see what was paid and what was credited, and most things are settled with that.
If you go to your bank or card issuer instead to have the amount reversed, it lands with Polar — they are the seller for that transaction — and it takes longer and costs us both money.
The credits belonging to that payment come off either way, even if you had already spent them. Your balance can go below zero as a result. You lose nothing you have made, but you cannot have anything new made until the balance is back above zero.
Requests from authorities
A request for user data is checked before anything is handed over: does it come from an authority that may make it, is it about a specific account, does it cover what it claims to. Anything broader than that is refused.
If we do have to hand something over, we tell the account holder — unless we are legally barred from doing so, in which case we tell them as soon as that bar lifts.
Your own data
What we keep and why is in the privacy policy. You can download everything we hold about you, and delete your account, from Settings → Account and privacy — no request needed, no waiting on us.
Age
Verno is not built for children. You need to be 16 or older to create an account, or the age of digital consent in your own country if that is higher.