Privacy Policy
What this portal collects about you and your account, what it deliberately does not collect, and who else touches it.
Veblen Appraisals LLC operates the portal and answers for every record named here. Effective July 30, 2026
The short version. This portal knows who your practice is, what you are licensed for, and whether your deployments are healthy. It does not know who your clients are, what you appraised, or what any report says.
Two different systems. This policy covers veblen.dev. Your Veblen deployment is a separate system holding your appraisal work, and your own privacy policy governs what you do with your clients' information there.
1. What we collect
| Category | Fields | Why |
|---|---|---|
| Account | Company name, billing email, pricing model, support tier, and default asset classes | To identify the account, issue licenses, and bill it |
| Sign-in | Your email, a salted password hash, and session identifiers | To authenticate you. We never store your password itself |
| Deployments | Deployment name, license key, entitled asset classes, and for hosted tenants the subdomain and brand details you enter | To issue and verify licenses, and to provision hosted stacks |
| Telemetry | Software version, schema tip, active user count, and a ledger health flag | To show you your fleet health and to warn you before a deployment goes stale |
| Billing | Stripe customer and subscription identifiers, invoices, and the volume figures your deployment reports | To charge the correct amount. Card numbers go to Stripe and never reach us |
| Support | Tickets and the messages in them | To answer you and keep the history of what was asked |
| Audit | Account actions with the actor and a timestamp | To let you and us reconstruct who changed what |
We do not buy personal data, we do not sell it, and we do not run advertising or cross-site tracking.
2. What we never receive
A self-hosted deployment sends the portal six fields in total, its license key, its deployment identifier, its version, its schema tip, its active user count, and a ledger health flag. It does not send, and we have no way to read, any of the following.
- Your client list, their contact details, or their addresses
- Documents your clients upload, including titles, receipts, and certificates
- Appraisal files, valuations, photographs, or finished reports
- Your invoices to your clients, or your ledger
- The API keys in your environment, including your payment and market data credentials
This is a property of the design rather than a promise about our conduct. The verify and heartbeat endpoints accept a fixed set of fields and there is no channel through which the rest could arrive.
3. Fully hosted deployments
A different relationship. If we operate your deployment for you, then your client data sits on infrastructure we administer, and we act as a processor of it on your instructions. You remain the controller.
What that means in practice. We access a hosted tenant to provision it, keep it running, restore it, and act on a support request you make. We do not browse tenant data, we do not use it to train models, and we do not disclose it except where the law compels us and we may lawfully tell you first.
Isolation. Each hosted tenant is a single-tenant stack with its own database. Your practice is never in a shared table with another practice.
Getting out. Request an export at any time and move to your own server. After a hosted deployment is terminated we keep its data for 30 days so you can retrieve it, then delete it.
4. Who else processes it
| Processor | What they do | What they see |
|---|---|---|
| Cloudflare | Hosts this portal and stores its database and uploaded brand assets. Also provides the bot check on our forms and our site analytics | Everything in the table above, plus request metadata |
| Stripe | Processes payments and holds the payment methods on file | Billing email, company name, and payment details you enter with Stripe directly |
Our email and our container registry run on our own infrastructure, so no third party handles your notification mail or your image pulls. Hosted tenants run on servers we operate.
5. Cookies and analytics
Session cookie. Signing in sets one cookie that identifies your session. It is http-only, same-site, and secure in production. Nothing about it tracks you off this site.
Bot check. Our public forms run Cloudflare Turnstile, which is designed to verify a human without the behavioral profiling a traditional captcha performs.
Analytics. We use Cloudflare Web Analytics, which is cookieless and does not fingerprint visitors. It tells us which pages get read. There is no advertising pixel on this site.
6. How long we keep it
Account records. For as long as the account exists, and after closure for as long as tax and accounting law requires us to keep the financial record.
Telemetry. Heartbeats age out on a rolling window and are only useful while current.
Sessions and reset links. Sessions expire, and password reset links are single-use and expire in 45 minutes.
Hosted tenant data. Deleted 30 days after the deployment is terminated.
7. Your rights
You may ask us for a copy of what we hold about you, ask us to correct it, ask us to delete it, or object to a particular use. Write to privacy@veblen.dev and we will answer within 30 days.
Depending on where you live you may also have the right to complain to a data protection authority, and we would rather you told us first so we can fix the problem.
Deleting your account data ends your licenses, since the license key is the record. We will say so plainly before acting on a deletion request.
8. Security
Passwords are stored as salted hashes and never in a readable form. Traffic runs over TLS. Registry tokens and host agent tokens are stored as hashes, so the plaintext exists only at the moment we show it to you. License grants are signed, so a modified grant fails verification.
No system is perfectly secure. If we learn of a breach affecting your data we will tell you without undue delay and describe what happened and what we did.
9. International transfers and children
Transfers. Our processors operate globally distributed infrastructure, so data may be processed outside your country. Where transfer safeguards are required we rely on the mechanisms our processors publish.
Children. This is a product for professional practices. It is not directed to anyone under 16 and we do not knowingly collect their information.
10. Changes and contact
If we change this policy in a way that materially affects you we will notify the billing address on your account. The effective date at the top always reflects the current version.
Questions go to privacy@veblen.dev, or open a support ticket. The Terms of Service cover the commercial side of this relationship.