Gevnius legal

Last updated: July 15, 2026

Privacy Policy

This policy explains what Gevnius collects and uses to provide source checks, account access, credits, payments, security, and support.

Who we are

Gevnius is operated by GEVNIUS LLC. GEVNIUS LLC is the controller for account, source-check, credit, security, and support information handled by Gevnius. For privacy questions, requests, or regional contact details, email support@gevnius.com

Paddle acts as merchant of record for checkout and may separately control payment, tax, invoice, refund, and buyer-support information under Paddle's own terms and privacy notices.

Information we collect

  • Email address for sign-in, account access, support, and subscription matching.
  • Google sign-in information if you choose that option, including the verified email address Google returns for account access.
  • One-time verification records, including hashed codes, attempt counts, expiry time, and hashed IP or user-agent signals for rate limiting and security.
  • Temporary Google OAuth security records, such as state and nonce cookies, used to complete Google sign-in safely.
  • Session security records, including the session version used to sign out across devices.
  • Plan, credit, subscription, and billing status needed to provide Free and Golden access.
  • Source-check inputs, including what you want to check and the source name or link you provide.
  • Temporary source-check job and result data used to recover an interrupted check and deliver its result.
  • Temporary browser storage used for a pre-login source-check draft, active-check recovery data, and checkout flow state.
  • Support messages and related account context when you contact us.

How we use information

We use information to run source checks, manage email sign-in, show credits and plan status, process subscriptions, prevent abuse, protect accounts, fix technical issues, and respond to support.

Notice at collection

This section summarizes the main categories of personal information, where they come from, why they are used, who receives them, and how long they are generally kept.

  • Account and sign-in information comes from you, Google if you use Google sign-in, and our authentication systems. It is used for account access, support, subscription matching, and security. It may be processed by Vercel, Supabase, Resend, Google, and Paddle where needed. It is kept while your account exists and longer where needed for legal, security, payment, or dispute records.
  • One-time code, session, device, IP, browser, and rate-limit signals come from your browser, device, and our security systems. They are used for login, session management, abuse prevention, fraud prevention, and service reliability. They may be processed by Vercel, Supabase, Resend, and security or infrastructure providers. OTP records are short-lived; security records are kept only as long as reasonably needed for protection, investigation, legal, or reliability purposes.
  • Source-check inputs and results come from you and from the source-check process. They are used to generate, deliver, recover, and secure source-check results and may be processed by Vercel, Supabase, and OpenAI. Before sign-in, the two source-check fields may be stored only in the current browser tab for up to 10 minutes, restored once after sign-in, and then deleted. Active-check recovery data expires after about 15 minutes and is removed from browser storage the next time Gevnius accesses that stored recovery data. Completed result content expires 10 minutes after completion and is then deleted, normally within about 5 additional minutes, though limited operational, security, or error records may remain where needed.
  • Plan, credit, checkout, billing, transaction, tax, refund, and subscription status information comes from you, Paddle, and our billing systems. It is used to provide paid access, update credits, handle cancellations, support payments, prevent fraud, and keep required business records. It may be processed by Paddle, Supabase, Vercel, and related accounting, tax, or support systems. It is kept as long as needed for the subscription, accounting, tax, legal, dispute, fraud-prevention, and audit purposes.
  • Support messages come from you and may include account context. They are used to respond to you, solve problems, protect the service, and maintain business records. They may be processed by email, hosting, database, and support providers. They are kept as long as needed for support, legal, security, dispute, and business-record purposes.

Legal bases

Where privacy law requires a legal basis, we process information to perform our contract with you, including account access, source checks, credits, subscriptions, and support. We also process information for legitimate interests such as security, abuse prevention, fraud prevention, service reliability, and product improvement.

We process some billing, tax, accounting, dispute, and legal records to meet legal obligations. Where we rely on consent, such as optional account or privacy choices, you may withdraw that consent where the law allows.

Source checks and AI processing

Source-check inputs are sent to OpenAI to generate the recommendation. Gevnius may send a hashed safety identifier for abuse prevention. Source-check jobs and completed results are stored temporarily by Gevnius so an interrupted check can be recovered and its result delivered. Completed result content expires 10 minutes after completion and is then deleted, normally within about 5 additional minutes. The app may temporarily store active-check recovery data in local or session storage, but it does not intentionally write the completed result content to either storage area.

OpenAI states that API inputs and outputs are not used to train OpenAI models by default unless the API customer opts in. OpenAI may retain API inputs and outputs for abuse monitoring, security, service operation, or legal reasons as described in OpenAI's policies.

Gevnius does not use source-check results to make automated decisions with legal or similarly significant effects about you.

Do not submit passwords, payment card numbers, government ID numbers, private keys, or other sensitive information that is not needed for a source check.

Payments

Gevnius does not store card numbers. Paddle acts as merchant of record and processes checkout, subscription billing, tax calculation, invoices, refunds, and payment-related buyer support. Gevnius receives billing identifiers and subscription events from Paddle so your plan and credits can be updated.

No sale, ads, or financial incentive

Gevnius does not sell personal information, does not share personal information for cross-context behavioral advertising, does not use advertising cookies, and does not offer a financial incentive program in exchange for personal information.

Gevnius does not intentionally collect sensitive personal information such as government ID numbers, payment card numbers, precise geolocation, health information, biometric data, or private account credentials. If you submit sensitive information anyway, we use it only as needed to operate the service, protect the service, respond to your request, delete it where appropriate, or comply with law.

Cookies and browser storage

Gevnius uses essential cookies for sign-in sessions and pending login or account-deletion verification, plus a short-lived source-check recovery cookie containing the check ID and plan. If you use Google sign-in, temporary OAuth cookies help verify the sign-in response. The app also uses browser storage for a pre-login source-check draft, short-lived active-check recovery data, and checkout flow state.

These technologies are used to make Gevnius work. Gevnius does not use advertising cookies.

Service providers

We use Vercel, Supabase, Resend, OpenAI, Paddle, and Google for hosting, database, email delivery, AI processing, checkout, subscriptions, tax, payment support, and optional Google sign-in.

We share information with these providers only as needed to operate Gevnius, protect the service, process payments, handle support, or comply with legal obligations. Gevnius does not sell personal information for advertising.

These recipients are categories of infrastructure, database, email, artificial intelligence, payment, authentication, security, operational, tax, accounting, and support providers. We do not publish your source-check inputs or results as public content.

International processing

Gevnius and its service providers may process information in countries other than where you live. Those countries may have different data protection rules. We use service providers and transfer mechanisms, such as contractual safeguards or equivalent provider safeguards, intended to protect information as required by applicable law.

Security and retention

We use essential session cookies, hashed one-time code records, server-side rate limiting, session-version sign-out, and limited-access service providers to protect accounts and reduce abuse.

We keep account, credit, billing, and security records as needed to operate Gevnius, meet legal obligations, prevent abuse, and resolve support issues. No online service can guarantee perfect security, so keep control of the email address you use to sign in.

Source-check data follows the short retention periods described above. OTP records are short-lived. Account, billing, subscription, security, and support records may be kept longer where needed to operate the service, meet legal obligations, prevent abuse, handle disputes, or maintain accurate business records.

Your choices

You can sign out from all sessions in settings, cancel Golden in settings, manage your Google account through Google if you use Google sign-in, and request account deletion when eligible.

Account deletion is available when no current Golden subscription or checkout is still in progress and is scheduled with a 7-day grace period. Signing in again before the deletion date cancels the request. Some records may be retained when needed for payment records, legal obligations, security, dispute handling, or abuse prevention.

For privacy questions, email support@gevnius.com

Privacy rights

Depending on where you live, you may have rights to request access to, correction of, deletion of, or a copy of personal information, and to object to or restrict certain processing. You may also have rights to data portability, to withdraw consent where processing is based on consent, to appeal a privacy decision, and to complain to a local privacy authority.

California residents may have rights to know, delete, correct, opt out of sale or sharing, limit use of sensitive personal information, and receive non-discriminatory treatment for exercising privacy rights. Gevnius does not sell personal information and does not share personal information for cross-context behavioral advertising.

To exercise privacy rights, email support@gevnius.com from the email connected to your Gevnius account whenever possible. We may need to verify your request before acting on it, and we will respond within the time required by applicable law.

You may use an authorized agent where applicable law allows it. We may ask for proof that the agent is authorized and may still need to verify your identity directly where the law permits or requires.

Policy changes

We may update this policy as the service, providers, laws, or data practices change. The posted Last updated date shows when this page was last changed. If a change materially affects how we handle personal information or requires notice by law, we will provide notice in a way reasonably suited to the change.

Children

Gevnius is a general-audience service for users aged 13 or older. It is not directed to children under 13, and we do not knowingly collect personal information from them. Where local law requires parental authorization for an older minor to use an online service or for the related personal-data processing, that minor may use Gevnius only with the required authorization. If you believe a child under 13 provided personal information to Gevnius, contact support@gevnius.com so we can review and delete it where appropriate.