Effective 31 August 2026
Terms of Service
These terms govern access to VeriHash and form a contract between Future Version Limited and the business or organisation using the service. They explain what each party may expect and the responsibilities that come with protecting and attributing sensitive web pages, images and documents.
01Agreement and eligibility
VeriHash is operated by Future Version Limited, company number 11739018, of The Station House, 15 Station Road, St. Ives, Cambs, PE27 5BH, United Kingdom (“VeriHash”, “we”, “us” or “our”). These Terms of Service (“Terms”) apply to the VeriHash website, customer workspace, JavaScript SDK, APIs, protected-session services, detector, evidence reports, support, and related services (together, the “Service”).
By creating an account, clicking to accept these Terms, accessing the Service, or allowing anyone to use it on your behalf, you agree to these Terms for the business or organisation identified during registration (the “Customer”, “you” or “your”). If you accept for an organisation, you confirm that you have authority to bind it. If you lack that authority, do not accept or use the Service.
The Service is offered for business and professional use, not personal or household use. Account holders must be at least 18 years old and legally able to enter this agreement. A written order form, enterprise agreement, or data-processing agreement signed by both parties may supplement these Terms; if it expressly conflicts with these Terms, the signed agreement controls for that conflict.
02Accounts and authority
You must provide accurate, current account and billing information and keep it updated. You are responsible for all activity under your account, including activity by owners, administrators, developers, analysts, viewers, employees, contractors, and integrations you authorise.
- Keep passwords, verification codes, API material, Web App keys, and administrative access secure.
- Assign the lowest appropriate role and Web App access to each user.
- Remove access promptly when a person no longer needs it.
- Notify support@verihash.co promptly if you suspect unauthorised access or credential compromise.
You may not share a named account between people, impersonate another person, register using misleading information, or attempt to obtain access to another customer’s workspace. We may rely on instructions given through an authenticated owner or administrator account.
03The Service and its limitations
VeriHash helps customers add session-specific visual signals to private Web Apps and create recipient-linked copies of images and PDFs. Submitted screenshots, images and documents can then be compared with eligible Web Sessions or VeriMark recipient records. Depending on configuration and evidence quality, the Service may return a likely viewer, recipient, session, page label, time range, confidence score, candidate comparison, supporting measurements, and evidence report.
VeriHash is a deterrence and attribution tool. It does not prevent screenshots, screen recordings, photography, copying, forwarding, disclosure, or other misuse. Results are probabilistic and can be affected by cropping, resizing, recompression, colour changes, rotation, physical display photography, file conversion, browser or display behaviour, implementation errors, an absent or obscured signal, incomplete session or recipient data, or the candidate set searched.
A result is an investigative lead, not an infallible statement of fact. False positives and false negatives are possible. You must apply meaningful human review, consider alternative explanations, and corroborate output before taking employment, disciplinary, legal, access, financial, or other consequential action.
Benchmarks and survivability information describe measured conditions, not a guarantee that the same result will occur for every capture, application, device, or future version. Unless a signed agreement says otherwise, the Service does not include a service-level agreement or guaranteed recovery threshold.
04Customer responsibilities
You decide where and why to deploy VeriHash, which viewers or recipients to identify, what identity information to supply, which users may access results, what evidence to submit, how long to retain it, and what action to take. You are responsible for your applications, recipient copies, viewers, notices, instructions, evidence, and decisions.
You must:
- use the Service lawfully, fairly, proportionately, and only for a specific legitimate purpose;
- identify and document an appropriate lawful basis for processing viewer and evidence information;
- give viewers clear, accessible information about monitoring and attribution unless a lawful, documented exception applies;
- complete a data-protection impact assessment and any workplace, employee, union, regulatory, or other consultation where required;
- obtain all permissions and rights needed to integrate the SDK, protect recipient copies, supply identity data, and upload or email evidence;
- avoid placing passwords, authentication tokens, special-category data, criminal-offence data, or unnecessary personal information in viewer IDs, page labels, URLs, filenames, notes, email subject lines, or evidence submissions;
- configure allowed origins, signed identity, access permissions, retention, and pseudonymisation appropriately for your risk; and
- maintain reasonable procedures for investigating, challenging, correcting, and documenting attribution decisions.
A protection mode described as “covert” concerns the visual presentation of the signal. It does not remove your legal duties of transparency, fairness, consultation, or accountability.
05Acceptable use
You must not use, enable, or assist use of the Service:
- for unlawful secret monitoring, stalking, harassment, discrimination, retaliation, intimidation, or surveillance;
- to monitor children or vulnerable people without a documented lawful basis and all required safeguards and permissions;
- as the sole basis for a decision that produces legal or similarly significant effects on a person;
- to upload material you do not have the right to process or that is unlawful, malicious, infringing, or designed to harm the Service;
- to probe, scan, overload, disrupt, reverse engineer, bypass, defeat, or gain unauthorised access to the Service, detector, watermarking methods, another account, or related systems, except to the limited extent a restriction is prohibited by law;
- to resell, sublicense, timeshare, or provide the Service to a third party unless your plan or a signed agreement permits it;
- to conceal your identity, evade plan limits, create abusive accounts, or use the Service to develop or benchmark a competing watermarking or attribution product; or
- in a way likely to expose VeriHash or another person to material security, privacy, legal, or reputational risk.
You may conduct proportionate security testing of your own implementation, but you must not test shared VeriHash infrastructure without our prior written permission. Contact us before reporting a suspected vulnerability publicly.
06Data protection and privacy
Our Privacy Policy explains how we process information as controller and, where relevant, as processor. For customer-controlled viewer identity, session, and evidence data, the Customer normally acts as controller and VeriHash normally acts as processor on the Customer’s documented instructions.
You are responsible for the lawfulness, accuracy, quality, and scope of personal information submitted to the Service, responding to individuals’ rights, and giving us instructions compatible with applicable law. We will process customer-controlled personal information to provide and secure the Service, meet your documented instructions, and comply with law. If the parties execute a separate data-processing agreement, it forms part of this agreement.
The SDK is not designed to capture page contents, screenshots, keystrokes, form fields, microphones, cameras, or unrelated browser activity. File content reaches VeriHash only when an authorised user deliberately uploads it to VeriMark or Evidence Lab, or sends it to a Web App evidence address. A VeriMark original is processed transiently to create the stored marked copy. You acknowledge that submitted files may contain confidential, sensitive, or personal information and must assess whether each submission is necessary. Resend receives inbound email before VeriHash checks whether the sender is authorised for that Web App.
07Customer materials and evidence
As between the parties, you retain ownership of data, images, evidence, notes, identifiers, configuration, and other material you submit to the Service (“Customer Materials”). You grant us a worldwide, non-exclusive, limited licence to host, copy, transmit, transform, analyse, display, and delete Customer Materials only as needed to provide, secure, support, and administer the Service, comply with your instructions, enforce this agreement, or comply with law.
You confirm that you have all rights and permissions required for Customer Materials and our processing of them under these Terms. You control evidence retention within the available settings and may delete cases through the Service. Deletion and termination are subject to reasonable processing time, backups, security records, legal obligations, and the retention details in the Privacy Policy.
You are responsible for maintaining any copy of Customer Materials and reports you need. VeriHash is not a general archive, legal hold, records-management system, or substitute for your own backup and evidence-preservation procedures.
08Plans, billing, renewal, and taxes
Plan features, limits, billing interval, and price are shown before Checkout or in a signed order form. Unless expressly stated otherwise, prices are in US dollars and exclude VAT, sales tax, withholding, and similar taxes. You are responsible for applicable taxes other than taxes based on our net income.
- Recurring plans. Stripe charges the payment method on file at the start of each billing period. The subscription renews automatically for successive periods of the same length until cancelled.
- One-time plans. A plan expressly described as one-time does not renew and provides only the access or entitlement described when purchased.
- Cancellation. An owner may cancel a recurring plan through the Stripe billing portal or by contacting support. Unless stated otherwise, cancellation takes effect at the end of the paid billing period.
- Refunds. Charges are non-refundable and unused time or capacity is not credited, except where required by law or expressly agreed in writing.
- Failed payment. We may retry a charge, ask you to update payment details, limit features, suspend access, or terminate the account if payment remains overdue.
You authorise us and Stripe to charge the payment method provided for fees, taxes, and renewals due under your plan. We may change future pricing or plan limits by giving reasonable advance notice; a recurring price change applies no earlier than the next renewal after that notice. Continuing the subscription after the effective date constitutes acceptance of the change. You may cancel before it takes effect.
09Intellectual property
VeriHash and its licensors retain all rights in the Service, software, SDK, APIs, detector, models, algorithms, reports’ design, documentation, branding, and improvements, excluding Customer Materials. Subject to payment and compliance with these Terms, we grant you a limited, non-exclusive, non-transferable, non-sublicensable, revocable right during your plan term to access the Service and integrate the SDK into applications you own or are authorised to operate.
You may use generated reports for your internal business, compliance, investigation, and professional-adviser purposes. You must not remove proprietary notices, imply that VeriHash has independently verified your conclusions, or present a report as guaranteeing guilt, liability, or identity.
If you provide feedback or suggestions, you grant us a perpetual, worldwide, royalty-free right to use them without obligation or attribution. This does not give us ownership of your Customer Materials.
10Confidentiality
Each party may receive non-public information that a reasonable person would understand to be confidential. The receiving party will use it only to perform or exercise rights under this agreement, protect it using reasonable care, and disclose it only to personnel, contractors, advisers, and providers who need it and are subject to confidentiality obligations.
Confidential information does not include information that the receiving party can show was lawfully known without restriction, becomes public without breach, is received lawfully from another source without duty, or is independently developed without use of the disclosing party’s information. A legally required disclosure is permitted where the recipient gives advance notice when lawful and reasonably cooperates with protective steps.
11Security
We use reasonable technical and organisational measures designed to protect the Service and customer-controlled information, including access controls, transport encryption, application-level authenticated encryption for stored evidence, marked copies and forensic secrets, and encrypted backups. These measures may evolve as the Service changes. No internet service, transmission, detector, or storage system is completely secure or error-free, and we do not guarantee absolute security.
You are responsible for securing your applications and devices, controlling user and Web App access, using supported browsers, restricting allowed origins, implementing signed identity where appropriate, protecting credentials and identity mappings, and installing updates or configuration changes we reasonably identify as security-related.
12Third-party services
The Service relies on or interoperates with third-party services such as Vercel, Supabase, Stripe, Resend, and Umami. Their availability and processing may be governed by their own terms. We remain responsible for our obligations under this agreement but are not responsible for a third-party product you independently choose, configure, or connect, or for failures outside our reasonable control.
Links to third-party sites do not imply endorsement. Stripe, not VeriHash, collects and controls payment-card or bank details submitted through Checkout or the billing portal.
13Availability, support, and changes
We aim to keep the Service available and useful, but maintenance, updates, incidents, provider failures, security work, legal requirements, and technical limits may cause interruption or degraded performance. Unless a signed agreement states otherwise, support is provided on a reasonable-efforts basis and no uptime, response, recovery, or detector-success level is guaranteed.
We may improve, replace, add, or remove Service features. We will give reasonable notice where a change materially reduces paid core functionality, unless urgent action is needed for security, law, provider availability, or abuse prevention. Preview, beta, test, benchmark, and experimental features may change or end at any time and may be less reliable.
14Suspension and termination
You may stop using the Service at any time and may cancel a recurring plan as described above. Closing an account does not automatically refund charges already paid or remove amounts already due.
We may limit or suspend access immediately where reasonably necessary to address a security risk, unlawful or prohibited use, material harm, unpaid fees, provider or legal requirement, or a material breach. Where practical, we will explain the reason and allow a reasonable opportunity to remedy it. We may terminate this agreement for a material breach that is not cured within 14 days after notice, or immediately where the breach cannot be cured, the Customer becomes insolvent, or continued provision would be unlawful or materially unsafe.
On termination, your right to use the Service ends. You should export reports and information you need before termination. We may delete Customer Materials according to your settings, our Privacy Policy, backup cycles, legal obligations, and any signed agreement. Provisions that by nature should survive—including payment, confidentiality, intellectual property, disclaimers, liability, indemnity, and general terms—will survive.
15Warranties and disclaimers
Each party warrants that it has authority to enter this agreement. We warrant that we will provide the paid Service with reasonable care and skill. If we breach that warranty, your remedy is for us to use reasonable efforts to correct the affected Service or, if correction is not commercially reasonable, allow termination and refund prepaid fees covering the unused period after termination.
Subject to the express warranty above and to the fullest extent permitted by law, the Service is provided “as is” and “as available”. We do not warrant that it will be uninterrupted, error-free, immune from attack, compatible with every application, or able to recover a watermark or correctly attribute every item of evidence. We disclaim implied warranties and conditions to the extent they may lawfully be excluded.
16Liability
Nothing in these Terms excludes or limits liability for death or personal injury caused by negligence, fraud or fraudulent misrepresentation, breach of obligations that cannot lawfully be limited, or any other liability that law does not permit a party to exclude.
Subject to that:
- neither party is liable for indirect or consequential loss, or for loss of profit, revenue, anticipated savings, business opportunity, goodwill, or reputation;
- VeriHash is not liable for decisions or action taken on detector output without appropriate human review and corroboration, your unlawful or improper deployment, disclosure by your users or viewers, or loss that could reasonably have been avoided through your access controls, backups, configuration, or compliance with these Terms; and
- each party’s total aggregate liability arising out of or relating to the Service in any 12-month period is limited to the greater of US$100 and the fees paid or payable by the Customer to VeriHash for that period.
The limitations apply in contract, tort (including negligence), breach of statutory duty, misrepresentation, restitution, and otherwise, to the extent permitted by law. The parties agree that the plan pricing reflects this allocation of risk.
17Customer indemnity
You will defend and indemnify VeriHash and its officers, employees, and contractors against third-party claims, regulatory action, damages, and reasonable costs to the extent arising from Customer Materials, your application, your breach of sections 4 or 5, or your unlawful use of viewer identity, monitoring, or evidence data.
We will notify you promptly of a covered claim, allow you reasonable control of the defence and settlement, and provide reasonable cooperation at your expense. You may not settle in a way that admits fault by, imposes an obligation on, or fails to release VeriHash without our written consent, not to be unreasonably withheld.
18General terms
Changes to these Terms
We may update these Terms to reflect changes to the Service, law, providers, risk, or business practices. We will post the revised version and change its effective date. For a material change affecting an active paid Customer, we will provide reasonable advance notice through the Service or account email. If you object, you must stop using and cancel the Service before the change takes effect. Continued use afterward constitutes acceptance.
Notices
We may send operational or legal notices to the owner email, display them in the Service, or post them on our website. Notices to VeriHash must be sent to support@verihash.co. Email notice is treated as received on the next business day unless the sender receives a delivery failure.
Assignment and subcontracting
You may not assign this agreement without our prior written consent. We may assign it as part of a merger, reorganisation, financing, sale of business or assets, or transfer to an affiliate. We may use subcontractors and remain responsible for our contractual obligations.
Force majeure
Neither party is liable for delay or failure caused by events beyond its reasonable control, except that this does not excuse payment obligations already due. The affected party will take reasonable steps to reduce the impact.
Entire agreement and interpretation
These Terms, the plan or order form, the Privacy Policy where incorporated, and any signed supplementary agreement are the entire agreement about the Service and replace earlier discussions or representations about it. Headings are for convenience. “Including” means “including without limitation”. A failure to enforce a term is not a waiver. If a provision is unenforceable, it will be modified to the minimum extent necessary and the remainder will continue.
No third-party rights
Unless these Terms expressly say otherwise, no person other than the parties has a right to enforce them under the Contracts (Rights of Third Parties) Act 1999.
Governing law
These Terms and any non-contractual dispute arising from them are governed by the laws of England and Wales. The courts of England and Wales have exclusive jurisdiction, although either party may seek urgent injunctive relief in any competent court.
19Contact us
15 Station Road
St. Ives, Cambs
PE27 5BH
United Kingdom