Privacy Policy
VQC Checker is built to minimize the information kept on its servers. This policy explains the information used to provide the web service.
Inspection packet files
Uploaded document files are read in your browser and are not stored by VQC Checker. Deterministic extraction and comparison run on your device. When a field is uncertain, the service may send compact extracted text and up to two compressed page images from that document to a protected server endpoint for an AI second opinion. The full original file and the server API key are never sent to your browser.
Account and usage information
When you create an account, VQC Checker stores your email address, display name, a slow salted one-way password hash, a one-way recovery-code hash, a hashed session token, plan, subscription status, monthly packet count, and basic timestamps. VQC Checker does not store your readable password or recovery code.
Payments
Stripe processes checkout, payment methods, recurring charges, invoices, and billing management. VQC Checker stores Stripe customer and subscription identifiers but does not receive or store complete card or wallet credentials. The payment methods Stripe displays can depend on the buyer, browser, location, and provider availability.
Account support tickets
Only signed-in account holders can create or view support tickets. The ticket, account email, status, owner reply, and timestamps are stored so the customer and owner can communicate privately through their portals without email. Do not include controlled document content, payment credentials, passwords, or API keys in a ticket.
Website analytics
VQC Checker uses cookie-free, first-party analytics to understand page visits, approximate unique visitors, page journeys, landing pages, referring domains and their page paths, campaign tags, country, state or regional area, timezone, network owner and ASN, broad device type, browser family, signups, packet starts, checkout starts, and subscription starts. Referring-page query strings and fragments are discarded. Network ownership may indicate a business, internet provider, VPN, or cloud service and does not prove a visitor’s identity or employer. A monthly rotating one-way identifier is created from request information. After a successful sign-in, activity sharing the same rotating identifier may be associated with that account so the owner can understand the customer journey; the service does not guess an anonymous visitor’s real name or email. When the hosting edge does not provide ASN ownership, VQC Checker sends the request IP to the atlas.ipinfo.app lookup service and retains only the returned country, ASN, and organization; that provider states that request logs are normally retained for no more than 14 days. VQC Checker does not store raw IP addresses, exact city-level locations, precise coordinates, or complete browser identifiers in analytics records. Obvious automated traffic is filtered, Global Privacy Control is honored in both browser and server processing, access is limited to the owner account, and analytics events are retained for up to 400 days; cached network lookup results expire after seven days.
Security and service providers
VQC Checker uses slow salted password hashing, one-way recovery-code hashing, login throttling, hashed session tokens, secure HTTP-only cookies, same-origin checks, server-side authorization, usage limits, one-time AI run records, webhook signature verification, and security headers. Sign-in is handled directly by VQC Checker; OpenAI may process limited uncertain document evidence, Stripe processes billing, atlas.ipinfo.app provides fallback IP-to-ASN network ownership data, and the hosting provider runs the application and database. No internet service can promise absolute security.
Retention and deletion
Account, usage, billing, and support-ticket records are kept only as reasonably necessary to operate the service, prevent abuse, resolve disputes, and meet accounting or legal requirements. Aggregate analytics events are automatically removed after 400 days. A signed-in account holder can request account or ticket deletion through the private support portal.
Controlled or restricted information
Do not submit ITAR-controlled, export-controlled, classified, or other restricted information unless your organization has independently determined that the complete processing flow is authorized for that information.
Questions or requests
Registered customers can sign in to the VQC Checker Support portal to create a ticket and read the owner’s reply. VQC Checker does not provide a public contact form, support email, or physical support address.