Last updated 2026-09-04

Privacy Policy

Verissimum makes short narrated, animated story videos. This policy says what the service stores about you, why it stores it, who else can see it, and how you delete it. It covers the Verissimum app on iOS and Android and the Verissimum website.

Who we are

Verissimum is operated by EZ-WEB, Lda., Portugal, which is the controller of the personal data described here. Write to privacy@ez-web.pt about anything in this policy.

The service runs on servers rented from Hetzner Online GmbH in Germany. The database, the rendered video files and the API all run there.

Who Verissimum is for

You must be 18 or older to open a Verissimum account. Verissimum is not directed at children, and this version has no children’s mode.

An account holder creates viewers. A viewer carries a maturity band, which sets the style and the content boundaries of the stories written for it. This version ships two bands: Teen and Adult. The Kids band is not available in it.

What we store about you

The service stores this, and nothing else about you:

  • Your email address. It identifies the account, and it is where a sign-in link goes.
  • Your name, if you give one. It is optional, and it does not have to be your real name.
  • How you sign in: which method, and, for Google and Apple, the account identifier that provider gave us. We match on that identifier and we never display it. We also keep the address the provider gave at the time, so support can tell two linked accounts apart.
  • If you set a password, an Argon2id hash of it. The password itself is never stored and never written to a log.
  • If you set a parental PIN, an Argon2id hash of it. We cannot read the PIN.
  • One record per signed-in device: a SHA-256 hash of the session token and the date it expires. The device holds the token itself, in the Android Keystore or the iOS keychain. A stolen copy of our database hands out no live sessions.
  • For a sign-in link: a SHA-256 hash of the token inside the link, the address it was sent to, when it expires, and when it was used. The record outlives the link on purpose, so a second click on the same link fails.
  • Each viewer: the name you type, the maturity band, an optional age, an optional picture address, the themes you prefer and the themes you exclude, an optional story length and an optional time zone.
  • Each story you ask for: the theme, the maturity band, and any note you type with the request.
  • Where a viewer got to in a story: the position in seconds, the length of what played, and whether the viewer finished it. One record per viewer per story.
  • Your plan and your usage: the plan on the account, which is the free plan in this version, and how many stories the account has generated in the current 30-day period.
  • A push token, if you turn notifications on. The token identifies one installation of the app on one device, not you, and it is stored with the platform it belongs to.

A story generated from your request stays inside your account. Any viewer on your account whose band allows that story can watch it, which is how one household shares a shelf. No other account ever sees it. Some stories on the shelf were requested by nobody: those are house content and every account sees them.

What we never collect

  • No advertising identifier. The Android app never asks for the com.google.android.gms.permission.AD_ID permission, and it removes that permission if a library adds it.
  • No location, no contacts, no calendar, no photo library, no files, no camera and no microphone.
  • No payment data. Nothing is for sale inside Verissimum in this version.
  • No third-party advertising network, no third-party analytics service and no crash-reporting service is built into the app.
  • No tracking of you across other companies’ apps or websites, and no advertising viewer of you or of anyone in your household.

Why we store it

  • To sign you in, and to keep you signed in on the devices you chose.
  • To write a story that suits the viewer it is for, and to keep that story inside the boundaries of the viewer’s band.
  • To start a story again where the viewer stopped it, on any device.
  • To tell a device that a new story is ready, when the account asked us to.
  • To count the stories an account generates in a period, so the free allowance of 30 stories per 30 days is applied fairly.
  • To keep the service safe. We count sign-in link requests per address and per network address, so nobody can flood an inbox or walk a list of addresses.

If you are in the European Union or the United Kingdom, the lawful basis is the contract between us for the account, the viewers, the stories and the playback positions; your consent for push notifications, which you withdraw by turning them off; and our legitimate interest in a service that is not abused, for the rate limits and the other security measures.

Who else sees it

We do not sell your personal data, we do not share it for advertising, and no advertising network receives anything at all.

These providers process data for us, and only to run the service:

  • Hetzner Online GmbH, which hosts the servers, the database and the video files in Germany.
  • An email provider, which delivers the sign-in link when you ask for one.
  • Google and Apple, if you choose to sign in with them. We verify the identity token they issued to you. We send them nothing about what you do in Verissimum.
  • The Apple and Google push services, if you turn notifications on. They carry the notification to your device.

We give data to an authority only where the law obliges us to.

How long we keep it

  • The account, the viewers, the story requests and the playback positions: while the account exists.
  • A session record: until it expires, or until you sign out on that device, which deletes it.
  • A sign-in link record: it stops working within minutes, and we keep the used record only long enough to make a replay fail.
  • A push token: until the app removes it, or until the viewer it belongs to is deleted.
  • A download on your phone: on your phone only. Removing the download, or the app, deletes it. We are never told which stories you downloaded.

Deleting your account

You can delete your account yourself, from the account settings in the app and on the website. There is no form to fill in and nothing to ask us for.

One deletion removes the account and everything that hangs off it: your sign-in identities, every session on every device, every viewer, and each viewer’s push tokens, story requests and playback positions. The stories generated from your requests go with the requests.

One thing is not deleted, on purpose. A story that nobody requested is house content on the shared shelf, and it was never your data.

The deletion happens immediately in the live database. We take a database backup every night and keep 14 days of them, so a copy of a deleted account can survive in a backup for up to 14 days before it rotates out. Backups are only ever used to restore the service after a failure.

Your rights

Write to privacy@ez-web.pt and you can ask for a copy of the data on your account, ask us to correct it, ask us to delete it, object to a use of it, or ask us to restrict a use of it. We answer within 30 days.

You can withdraw your consent for push notifications at any time, by turning them off.

If you think we have handled your data badly, tell us first. You can also complain to a data protection authority: ours is the Comissão Nacional de Proteção de Dados (CNPD), and you may instead complain to the authority in the country you live in.

How we protect it

  • Everything between your device and our servers travels over HTTPS.
  • Passwords and parental PINs are stored as Argon2id hashes. Session tokens and sign-in link tokens are stored as SHA-256 hashes. None of the four can be read back out of the database.
  • The app keeps its session token in the Android Keystore or the iOS keychain, never in a plain file.
  • The internal tools we use to review stories run on a separate address behind their own password, and they are not reachable from the app.

Children

Verissimum is not directed at children. This version has no children’s mode, no Kids band and nothing in it is designed for a child under 13. Accounts are for adults.

We do not knowingly collect personal data from a child. If you believe a child has opened an account, write to privacy@ez-web.pt and we will delete it.

A children’s mode is planned. We will rewrite this policy, and get the consent the law requires, before any part of Verissimum is offered to a child.

Changes to this policy

We change this policy when the product changes. The date at the top says when we last did. We tell you inside the app before a change that matters to you takes effect.

Contact

EZ-WEB, Lda., Portugal. Privacy: privacy@ez-web.pt. Anything else: support@ez-web.pt.