Verno

Privacy policy

Updated on September 7, 2026

Verno is built on a simple rule: ask for as little as possible, and be able to explain every field. This page tells you what we hold, why, who else touches it, and how to get it back or get rid of it.

You can read Verno without an account. Do that, and we hold nothing about you at all — see the cookie statement for the one thing your own browser remembers.

What we hold

To have an account at all. Your email address, and a username you choose. If you sign in with Google we receive your email address and nothing else — no contacts, no profile, no photo.

Because you filled it in. A display name, your language, whether your profile is public or private, and which image quality you prefer. A display name is optional; leave it out and people see your username.

What you make. Timelines, moments, images, video, styles, stories, recordings, links between timelines, and which of these you marked as favourites. This is the point of the site, and it is the bulk of what we hold.

Your credits. Every grant and every deduction, with what it was for. That ledger is how you can check where your credits went, so it is kept as long as your account is.

For a purchase it also records which payment service it went through and the order number that belongs to it, so an amount can always be traced back.

Old usernames. If you rename yourself, we keep the previous name so that links people already shared keep working. Nothing else is attached to it.

If something goes wrong. If an account is blocked, we record why, by whom, and until when. Without that, a block cannot be explained or lifted.

We do not ask for your real name, your address, your date of birth, or your phone number, and there is nowhere to enter them.

Why, and on what basis

To give you the account and the service you asked for, we need the email address, the username and what you make with it. That is the contract between us.

To keep Verno usable for everyone we need to be able to act on abuse. That is our legitimate interest, and it is why the moderation fields exist.

To know that the site works we measure page speed and visits, without cookies and without following you anywhere. That is also legitimate interest, and it is the lightest form of it we could find.

Where the law asks for your consent, we ask for it and you can take it back. Right now there is nothing on Verno that needs it.

Who else touches it

Verno is a small site and runs on other people's infrastructure. These are all the parties involved, and each of them only sees what it needs.

Supabase — the database, the sign-in system and the file storage. Everything you make passes through here.

Vercel — the servers that build and deliver the pages, and the visit and speed measurements.

Anthropic — when you have text generated: suggestions for moments, a description, a story. What is sent is the material for that request.

Replicate — when you have an image, a video or a recording made. The models run there; for speech, Google's voices run through Replicate rather than through us.

Polar — when you buy credits. They receive your email address and a reference to your Verno account, so the credits reach the right person. What you give them in order to pay — your name, your address, your card details — stays with them. We never see it and store none of it. What comes back is the order number and how many credits it was.

Polar is based in the United States. That differs from the rest of this list, which runs inside the EU, and it was a deliberate trade-off: they take over accounting for VAT in dozens of countries, which a foundation this size cannot do itself. The consequence is that your email address and your purchase are processed outside the EU.

Google — only if you choose to sign in with Google.

We do not sell your data, and we do not hand it to advertisers. There is nobody else.

Your work is only as public as you set it

Every timeline is private, shared or public, and you choose. Private means private: the files behind it are not reachable by a direct link either, because our storage is closed and every image is served through a link that expires.

Your profile is private by default. Set it to public and your username, display name and public timelines become visible to anyone; your email address never does.

How long

As long as your account exists. Delete it and it goes, in the same moment — no waiting period, no copy that lingers on our side.

One exception, and it is deliberate: timelines are not deleted with you. They are transferred to a Verno management account, so that the work stays available to the people who were reading it and to anyone you linked to. That is why the moments and the images survive; your name comes off them. If you would rather they disappear, delete the timelines yourself before you delete your account.

What you can do, without asking us

See everything. Settings → Account & privacy has a download of all your data — a readable PDF summary, and a JSON file with everything.

Correct it. Your username, display name, language and visibility are all editable at any time.

Delete it. The same page has a delete button. It removes your account and everything attached to it, with the exception described above.

Object, or take back consent. Tell us and we will act on it.

If you think we are handling your data wrongly, tell us first — we would rather fix it than hear about it from someone else. You also have the right to complain to a data protection authority; in the Netherlands that is the Autoriteit Persoonsgegevens.

Getting in touch

Write to info@verno.foundation. One person reads that address, and that person is also the one who built this.

When this page changes

If something material changes, this page changes with it and the date at the top moves. Verno is being built, and this text describes what it does today, not what it did last month.

This costs credits