Skip to content
verss

DATA & PRIVACY

Your data,
explained plainly.

Here is how the current product handles the information you choose to upload.

Who is responsible for your data

Verss is operated by Ivan Prokopenko, at Praceta Chefe de Lanco 98, 2 FRT, 2955-040 Pinhal Novo, Portugal. Ivan Prokopenko is the controller responsible for the personal data described in this policy. For privacy questions or requests, contact info@verss.co.

No bank connection

Verss does not request your bank password or connect to your bank account. You export a statement yourself and upload it, then add your email to continue. Opening the public sample report does not upload any file.

What is stored

Your account includes your email address and a password digest. Original statements are stored as encrypted blobs so you can reopen them. Transaction descriptions and merchants are encrypted at rest. Card numbers are masked during normalization; counterparty account numbers are reduced to their last four digits and your own IBANs are hashed for transfer detection.

Before you add your email

Your upload is stored encrypted without being parsed. Unclaimed files expire after 24 hours and are deleted by an hourly cleanup. After you add your email (and confirm it for an existing account), all transactions are imported. Up to 100 are categorized for your one-time preview; the remaining transactions stay saved but hidden.

How categorization works

Saved rules categorize matching transactions. AI categorization uses selected fields: a normalized description, merchant, rounded amount, currency, direction, merchant category code when available, bank and your category list. The original statement file, your bank credentials and account identity are not sent as categorization inputs. Descriptions can still contain information from a transaction.

The configured AI provider is Anthropic’s Claude API. When AI is not configured, the app uses a local heuristic. Merchant research can use web search. This is server-side processing, not end-to-end encryption.

Deleting a statement

Use Delete on a statement to remove its stored file and imported transactions. This description covers the application’s stored records; it does not promise immediate erasure from infrastructure backups or third-party processing systems.

Site analytics and your choice

With your consent, Google Analytics records visits and neutral steps such as a successful upload, accepted email, viewed report and selected plan. It processes browser/device information, online identifiers and usage events. Analytics is blocked until you accept; advertising features are disabled. Custom events do not include statement contents, filenames, transaction amounts, merchants, email addresses or account identifiers.

Use Cookie Settings at the bottom of the page to reject analytics or withdraw consent. This does not affect the core service. Google Analytics cookies expire after 180 days under our configuration. Plausible, when configured during the transition, follows the same consent choice. See the Cookie Policy for storage details and how Google uses information from sites that use its services.

With the same analytics consent, Mixpanel measures product usage: imports, reports, transaction reviews, rules, AI research outcomes and confirmed purchases. We send a random browser identifier and, after sign-in, a pseudonymous user identifier to understand repeat usage across visits and devices. We do not send your email, uploaded files, bank account details, merchants, transaction amounts or search text. Published Verss plan prices may be included in purchase events. Events are delivered asynchronously from our server. Withdrawal cancels pending events once received by our server; it does not automatically erase events already delivered. See Mixpanel's privacy policy.

Questions or requests

Contact Verss at info@verss.co about your data or account. Please do not email bank statements or bank credentials.

Your next step

You can explore the entire public sample without an account. Before uploading, review the access conditions.

Explore the sample report →

With your analytics consent, LogRocket records masked session replays and usage events to help diagnose problems. Signed-in sessions use your internal user ID. Text, inputs and images are masked; network and console recording are disabled. LogRocket uses browser storage to connect sessions. Withdrawing consent reloads the page to stop recording; previously delivered recordings are not automatically deleted. See LogRocket’s privacy policy.

Necessary — always on
Required for sign-in, security and remembering your privacy choice.

Google Analytics measures visits and funnel steps. Mixpanel measures product usage, imports, reviews and purchases using a pseudonymous identifier. LogRocket records masked session replays and usage events to diagnose problems. Optional Plausible analytics follows the same choice. Advertising features remain off.

You can withdraw consent at any time. Your choice is remembered for six months.

Privacy Policy · Cookie Policy