Legal
Privacy Policy
FeeGuard reads your Stripe account through a key you create and restrict, or through event data you paste yourself for the free audit. Here is the rest of it.
Last updated 24 August 2026
Who we are
FeeGuard is a product of Veristria, a Norwegian aksjeselskap (AS) under incorporation (24 August 2026), based in Norway. Veristria is the controller of the personal data described here, and its organization number goes on this page the day registration completes.
One address handles everything on this page — access, correction, deletion, or an argument about a sentence you do not believe: info@useveristria.com.
What FeeGuard reads from your Stripe account
Monitoring uses a Stripe API key you create yourself. We ask for a restricted key with five read permissions — charges, transfers, application fees, balance and events — which is everything detection needs and nothing more. Two write permissions exist and are optional: reversing a transfer and refunding an application fee, both used only if you turn on automatic recovery for a rule. A full secret key also works, and the interface tells you that is more access than the job needs.
Checking which permissions a key has never mutates your account. The two write scopes are probed with a request that is invalid by construction — reversing a transfer that does not exist, for zero amount — so Stripe’s answer tells us whether the scope is present without anything being created, changed or reversed.
The key is encrypted before it is written, is never returned to your browser, and stops working the instant you roll or revoke it in Stripe.
What the free audit does
The free audit does not accept a Stripe key. You paste charge.refunded events or charge objects, or run the built-in sample. Nothing you paste is stored: the detectors run against it and the result is returned to your browser. No signup, no credentials.
What we store once you connect an account
Not your Stripe events verbatim, and never a card number — Stripe holds those and remains their controller. What we keep is the reconciliation record: the Stripe object identifiers for the charge, transfer, application fee or dispute involved, the amounts, and the discrepancy our detectors computed between them.
What else we collect
Your account. Sign-in is email and password, or a magic link, through Supabase Auth, rate-limited against guessing. We hold your email address, an account identifier and which organization you belong to. Passwords are handled by Supabase Auth; we do not see or store them in the clear.
Support conversations. Where the support assistant is available, the conversation is processed by a third-party model provider to produce a reply and logged on our side so a person can follow up. If you give a name and an email so we can send you the transcript, those are stored with the conversation. The assistant is labeled as an AI.
Billing. Your FeeGuard subscription is billed through Stripe. Stripe collects and holds the card details; what reaches us is a customer identifier, a subscription identifier, the plan, and whether the invoice was paid.
The launch list. If you give us your email for product updates we store three things: the lowercased address, the site that captured it, and the timestamp. No IP, no name, no referrer. The address is never written to a log, on success or on failure.
Why we are allowed to hold it
Contract — your account, your reconciliation records and your billing history exist because you asked for the service.
Consent — the launch list, which you can withdraw from at any time.
Legitimate interests — keeping the service available and abuse under control, which is what rate-limit counters and server logs are for.
Legal obligation — invoices and the accounting records behind them, which Norwegian law requires us to keep.
Who else touches it
These companies process data on our behalf. We sell nothing, and we have no advertising partners.
- Vercel — hosting and delivery for this site.
- Supabase — the Postgres database and sign-in service behind FeeGuard itself.
- Stripe — both the processor of your FeeGuard subscription, and the platform whose account data we read through the restricted key you create. Stripe is the controller of the card data it collects.
- OpenRouter — model inference for the support assistant. It receives the conversation text only, never account or reconciliation records.
Cookies
Strictly necessary only: the session cookie that keeps you signed in, and the cookies Stripe sets during checkout. No advertising cookies, no analytics cookies, no cross-site tracking.
That is why there is no consent banner in front of this page. Strictly necessary cookies do not require consent and we have nothing else to ask about. If we ever ship anything that is not strictly necessary, a banner appears first and it defaults to off.
How long we keep it
Account data and reconciliation records: for as long as the account exists. Disconnecting your Stripe key clears the stored key material immediately.
Launch-list addresses: until you unsubscribe or ask us to delete them. Invoices: for the period Norwegian bookkeeping law requires, which we cannot shorten on request. Rate-limit counters: minutes.
Your rights
Under the GDPR you can ask for a copy of what we hold about you, ask us to correct it, ask us to delete it, ask for it in a portable form, object to processing based on legitimate interests, and ask us to restrict processing while something is disputed. Where we rely on consent you can withdraw it at any time.
Email info@useveristria.com and we answer within a month. No form, no fee. We will ask you to confirm you control the address in question, because handing an account’s data to whoever asks first would be its own privacy failure.
Where the data lives
We are based in Norway and operate for the EEA. Some of the processors above are established in the United States and may process data there, covered by the transfer mechanisms those providers publish — standard contractual clauses and, where applicable, the EU–US Data Privacy Framework.
Complaints
Tell us first if you can. If we do not resolve it, you can complain to the Norwegian Data Protection Authority, Datatilsynet, at datatilsynet.no, or to the supervisory authority where you live.
Changes to this policy
When the code changes, this page changes, and the date at the top moves with it. If a change materially affects what we do with data you have already given us, we tell you by email rather than quietly editing the page.
Questions about any of this
Including “prove it”. If a sentence here does not match what FeeGuard does, that is a bug and we want to know.