Veribix
← Back to home

Privacy Policy

Last updated: August 6, 2026

NextAI Forge, LLC, a Delaware limited liability company ("NextAI Forge," "we," "us," or "our"), operates veribix.com and provides Veribix, a measurement service for AI-driven traffic. This Privacy Policy explains how we collect, use, disclose, and protect personal information.

Our registered office in Delaware is 131 Continental Dr, Suite 305, Newark, Delaware 19713, New Castle County. Our registered agent at that address is Legalinc Corporate Services Inc.

This Policy is written for U.S. business-to-business services. If we materially change our data practices, we will update this Policy and the "Last updated" date. Where required by law, we will provide additional notice or obtain consent.

1. Personal information we collect

We collect the following categories of personal information, depending on how you interact with us:

  • Contact information: name, business email, company, and message content.
  • Account information: billing contact, plan, connected data sources,

configured prompt sets, notification preferences, and support requests.

  • Payment information: payment status, invoices, and transaction metadata.

Payment card details are processed by Stripe and are not stored by us.

  • Website and device information: IP address, browser type, pages viewed,

referring pages, timestamps, and similar security logs for veribix.com itself.

  • Customer analytics data: aggregated metrics we read from a customer's own

analytics and infrastructure accounts, described in section 2.

  • Measurement data: answers, citations, and model outputs collected when we

send prompts to AI assistants, together with the scoring derived from them.

Veribix is intended to measure companies and public business information, not private individuals. We do not profile a natural person as the measurement subject.

2. How we access a customer's analytics data

A customer connects Veribix to their own systems. In every case the access is read-only and granted by the customer, and we never receive the customer's passwords or Google account credentials.

  • Google Analytics and Google Search Console. The customer adds our Google

Cloud service account as a Viewer on their property. We read aggregated reports through the Analytics Data API and the Search Console API. We do not and cannot write to, modify, or delete anything in the customer's property, and access ends the moment the customer removes the service account.

  • File upload. A customer may instead upload a CSV or BigQuery export.
  • Cloudflare. The customer supplies a read-only API token scoped to

analytics.

  • Server logs. A customer may upload web server or CDN logs.

3. Log ingestion, redaction, and what we do not keep

Server logs can contain personal information inside URLs. We therefore redact at the point of ingestion rather than afterwards:

  • Query parameters are dropped unless they appear on an allowlist of parameters

known to be non-personal, such as campaign and source tags.

  • IP addresses are used only to distinguish automated crawlers from human

visitors and are not retained in the extracted data.

  • Raw uploaded logs are deleted after extraction. What we keep is the

aggregated result and a small number of redacted sample lines that let a customer verify a figure.

If a customer uploads a log file that we cannot redact reliably, we reject the file and say so rather than ingesting it.

4. The shared measurement corpus

To measure whether AI assistants name a company, Veribix sends prompts to those assistants and stores the answers as evidence.

Prompts fall into two kinds, and they are stored differently:

  • Category prompts contain no customer name. An answer to a category prompt

is a public model output that mentions whatever brands the model chose to mention. These answers are stored in a shared corpus and may inform the measurement of more than one customer. They contain no customer data.

  • Branded prompts contain a customer's own name or the names of competitors

that the customer entered. These are stored privately to that customer's account.

A customer never sees another customer's account, configuration, or results. A customer sees only the presence of brands they themselves track, derived from model answers that anyone running the same prompt would receive.

5. How we use personal information

We use personal information to provide and operate Veribix, authenticate accounts, run measurements, deliver alerts and reports, take payment, provide support, secure the service, meet legal obligations, and improve the service using aggregated or de-identified data.

We do not sell personal information and we do not share it for cross-context behavioral advertising.

6. How we disclose personal information

We disclose personal information to service providers who process it on our behalf under contract, listed on our Subprocessors page. We may also disclose information to comply with law, enforce our terms, protect rights and safety, or in connection with a merger or sale of assets, in which case we will state that this Policy applies to the transferred information.

7. Cookies and analytics on veribix.com

We do not run advertising trackers on veribix.com, and we do not sell or share visitor data.

Cookies that are strictly necessary to serve the site and to keep a signed-in session are set without asking, because the site cannot work without them.

We also use Google Analytics 4 to understand which pages people read and which AI assistants send them. It is not loaded until you accept it. If you decline, or if you ignore the banner, no analytics script is requested and no analytics cookie is set. You can change your mind at any time using the Cookie settings link in the footer of every page.

Because we honour that choice, our own visitor figures are incomplete. We would rather under-report our own numbers than measure you without asking.

8. Retention

We keep account and billing records for as long as the account exists and afterwards as required for tax, accounting, and legal purposes. Measurement evidence is retained according to the customer's plan and retention setting. Raw uploaded logs are deleted after extraction, as described in section 3.

A customer may export everything in their account, including the measurement evidence trail, and may delete their account. Deletion removes account data and tenant-private measurement records. Aggregated and de-identified statistics that cannot be linked back to a customer may be retained.

9. Security

We use encryption in transit, encryption at rest for credentials and tokens, least-privilege access, read-only scopes for every customer data source, and append-only storage with integrity verification for measurement evidence. No method of transmission or storage is completely secure, and we do not claim otherwise.

10. U.S. state privacy rights

Depending on your state, you may have the right to know, access, correct, delete, obtain a portable copy, and appeal a denial. We do not sell personal information or share it for cross-context behavioral advertising, and we do not use it for profiling that produces legal or similarly significant effects. To exercise a right, contact us at the address in section 13. We will verify the request and respond within the time the law allows.

11. International users

We operate in the United States and process information there. Where we act as a processor for a customer subject to the GDPR or UK GDPR, the Data Processing Addendum governs that processing and sets out the transfer mechanism.

12. Marketing email

We send service messages such as alerts, digests, and billing notices to account holders. Where we send marketing email, every message includes an unsubscribe link and our postal address, and unsubscribing is honored per notification type rather than all or nothing.

13. Contact

Questions about this Policy or a privacy request: privacy@veribix.com

NextAI Forge, LLC
131 Continental Dr, Suite 305
Newark, Delaware 19713
United States