Last updated: May 12, 2026
Verndr is built on zero-knowledge architecture. This means your files, health data, and personal information are encrypted on your device before they ever reach our servers. We hold only ciphertext — encrypted data that is mathematically useless without your personal encryption key, which we never possess.
When you create an account, we collect your email address and payment information (processed by our PCI-compliant payment provider). This is the minimum required to operate your account.
We never collect, access, or process the contents of your vault, health records, or files. All data is encrypted client-side before transmission. We store only encrypted blobs that we cannot decrypt.
We do not collect analytics, telemetry, usage patterns, or behavioral data. We do not use cookies for tracking. We do not employ third-party analytics services.
Account information is used solely for:
Your encrypted data remains on our servers as long as your account is active. Upon account deletion, all encrypted data is permanently purged within 30 days. Account metadata (email, payment records) is retained as required by applicable law.
You have the right to access, export, and delete your data at any time through the Verndr app or Klixr CLI. Under GDPR, CCPA, and similar regulations, you also have the right to data portability, rectification, and to lodge a complaint with a supervisory authority.
Verndr operates servers in multiple jurisdictions. Because all data is encrypted before leaving your device, the physical location of our servers does not affect the confidentiality of your data — we hold only ciphertext regardless of jurisdiction.
We will notify all registered users via email before any material changes to this policy take effect. The current version is always available at this URL.
For privacy-related questions: legal@verndr.com