Privacy Policy
Last updated: December 2025
VerdictFirst is local-first by design. Your validation data stays on your device. We use privacy-preserving analytics (cookieless, EU-hosted) to improve the product - but we never see your ideas, interviews, or evidence.
What stays on your device
All your validation data is stored locally in your browser using IndexedDB:
- Your ideas and hypotheses
- Interview notes and transcripts
- Evidence and commitment signals
- Walk-away criteria
- Verdicts (BUILD, EXTEND, PIVOT, PASS)
We cannot see your local data. It never leaves your browser unless you explicitly export it - or choose to use optional cloud features if we add them. Technical? Open DevTools → Network tab. Nothing uploads your content.
What we collect
If you join our waitlist, we collect only your email address. This is stored by our form provider (FormSubmit.co) and used solely to notify you when VerdictFirst is ready.
Analytics
We use privacy-preserving analytics to understand how people use VerdictFirst - which features help, what's confusing, where people get stuck. This makes the product better for everyone.
What we use
- PostHog (EU servers) - Product analytics configured for maximum privacy
- Cloudflare - CDN logging for security and performance
How we configured PostHog for privacy
- No cookies - We use cookieless mode. Zero cookies from PostHog.
- No localStorage/sessionStorage - Nothing persisted in your browser
- No cross-session tracking - Each visit is anonymous. We can't link your Monday visit to your Tuesday visit.
- No personal identifiers - We don't call identify(). You're a hash, not a person.
- EU data residency - PostHog Cloud EU (Frankfurt). Data never leaves the EU.
How the hash works: PostHog generates a daily hash from your IP + browser fingerprint, then immediately deletes the IP. The hash changes daily and is mathematically irreversible. Result: we can count "5 people visited today" but can't identify who or link visits across days.
What PostHog sees
- Page views (which pages, not who)
- User interactions (buttons, links - what's used, not content)
- Feature usage patterns (aggregate, anonymous)
- Errors (error type only - never the message which could contain your data)
What PostHog never sees
- Your validation data (ideas, interviews, evidence) - stays in IndexedDB
- Text content you enter - we block element text, input values, and titles
- Your identity - no login, no email, no name
- Cross-session history - each day you're a new anonymous hash
Technical guarantee: We use PostHog's sanitize_properties hook to explicitly block $el_text, elements, $input, $value, text, and title properties. All event properties are filtered through an allowlist of safe, code-defined values.
Your choice: Opt out anytime
Analytics is on by default to help us improve VerdictFirst. You can opt out at any time:
- In the app - Go to Settings → Privacy → Toggle off "Help improve VerdictFirst"
- Immediate effect - Toggling off stops all data collection instantly
- No penalty - All features work exactly the same either way
Verify yourself: Open DevTools → Network tab. Filter for "posthog". You'll see event data but no identifying information. No cookies set.
No tracking (the bad kind)
- No cookies - PostHog runs in cookieless mode
- No cross-site tracking - We don't know what other sites you visit
- No ad networks - Zero. We don't show ads or share data with advertisers.
- No selling data - We literally can't. We don't have identifying data to sell.
- No behavioral profiles - Anonymous aggregate stats only
Your rights
Since your data is stored locally, you're already in complete control:
- Export - Download everything anytime
- Delete - Clear browser data or use in-app delete
- Inspect - Open DevTools to see exactly what's stored
For waitlist removal, email [email protected].
Future cloud features
We may add optional cloud features like sync or team collaboration. If we do, they will be:
- Opt-in only - Local remains the default
- Transparent - Clear about what data syncs
- Your choice - Enable or disable anytime
We'll update this policy before launching any cloud features.
Contact
Questions about privacy? Email [email protected].
← Back to VerdictFirst