Legal

Privacy policy

LEGAL · PRIVACY

Effective date: September 3rd, 2026 · Last updated September 3rd, 2026

1. The short version

ValidThru tracks expiration dates and sends you reminders by email. To do that we hold the minimum data the job needs and encrypt the sensitive parts on our servers before they are written. Nothing you upload is stored: a scanned document is read in the moment and discarded immediately, and we keep the three fields you confirm — document type, issuer, expiration date — and nothing else. We run no ads, no analytics, and no trackers; we do not sell or rent personal data to anyone; and this website sets no cookies at all. Four companies handle data for us, and they are named in section 8. Sensitive data is encrypted on our servers, and like any provider we can be required to produce data under valid legal process. What a request can reach is deliberately small: no scan image at all, and no identifier you never gave us.

2. Who we are

ValidThru is operated by a small independent team based in Chicago, Illinois, and runs at validthru.app. In this policy, "we" means the operator of ValidThru and "you" means the person using it. Privacy questions go to privacy@validthru.app; section 18 has the full contact list.

3. What we collect

Everything we hold falls into one of two classes, and the class decides how it is stored.

  • Sensitive data — identifier numbers such as a passport number, free-text notes, an optional legal name, and authenticator-app seeds. Each of these is encrypted at the application layer, under a key unique to your account, before it is written anywhere. Sensitive fields are masked by default in the app and never appear in logs, error messages, URLs, or email.
  • Operational data — your email address, item labels, categories, issuers, dates, statuses, recurrence rules, plan tier, and timestamps. These are stored in readable form because the reminder scheduler has to query them to send your reminders on time. Every readable column exists for a stated reason, and adding one requires a written justification in our code.

In more detail, we collect:

  • Account. Your email address, used for sign-in and reminder delivery, and your sign-in credentials: a password verifier (a salted hash — never the password itself), passkey public keys and, if you enable an authenticator app, its seed stored encrypted.
  • Items. The labels, categories, issuers, dates, statuses, and recurrence rules you create. Labels appear in reminder emails, which is why the app coaches you to keep them non-sensitive — a holder can be a nickname, and nothing requires a legal name.
  • Sensitive fields you choose to add. Identifier numbers, notes, and an optional legal name. All are optional, off by default, and the product works fully without them.
  • Scan-and-discard images. A photograph of a document, held in memory for the length of the request and discarded when the response returns. It is never written to a database, an object store, a cache, or a log, and no preview or thumbnail is derived from it. What we collect during a scan is its document type, issuer, and expiration date, shown to you for confirmation; what we never keep is the image itself or anything else visible in it — a name, a photograph, an address, a document number — all of which is discarded in memory and never written anywhere.
  • Billing. Payments for the paid plan run through Stripe. Card numbers are entered on Stripe's hosted pages and never touch our servers; we hold your plan tier and subscription status. If you track your own card's expiry as an item, we hold at most the brand, last four digits, and expiry date you type.
  • Operational records. Your session list carries timestamps and a coarse device label such as "Safari on Mac" — no raw browser fingerprint and no IP address. The connecting IP address is used transiently to rate-limit sign-in and contact-form requests and is not stored with your account; scan limits are counted per account, not per address. Application logs carry opaque identifiers only; a build-failing test enforces that identifier numbers, notes, names, email addresses, scan images, and decrypted values never appear in any log.
  • Support email. If you write to us, we hold what you sent for as long as it takes to answer you. Do not put identifier numbers in email; the app is the place for those.

4. What we never collect

The strongest protection is not holding the data at all. The following are never collected, by design and by code review:

  • Full card numbers. Brand, last four, and expiry at most, and only if you type them.
  • Full Social Security numbers. Last four at most, and the app does not ask even for that.
  • Biometric data. No face recognition, no fingerprints, no derived biometric templates. Reading a scanned document extracts its type, issuer, and expiration date and nothing about the person pictured.
  • Medical details. You can track "annual physical due"; we never ask why.
  • Credentials for other services. We are not a password manager and will not hold your government-portal login.
  • Precise location. A scan image is never stored, so the GPS coordinates a phone photo carries are never stored either, and we never ask your device for its location.

5. How we use your data

We use what we hold for exactly these purposes: operating the service you signed up for; sending the reminders you configured; billing the paid plan; keeping accounts secure, including rate limiting and abuse prevention; answering you when you write to us; and complying with law. We do not build profiles, we do not use your data for advertising, and we do not use your data to train models beyond running the document-reading request you invoke.

6. How your data is protected

Sensitive data is encrypted with AES-256-GCM under a per-account key, and the key material lives in our hosting environment’s secret store — never in the database, the backups, or the code. Operational data is stored in readable form so the scheduler can do its job.

Encryption and decryption happen on our servers. That protects you against a long list of realistic failures — a leaked database, a lost backup, an injection bug — and no encryption protects data from someone who fully compromises the service running on it. What the security page covers, and what it does not, is written there plainly.

7. How long we keep things

Short retention is a security control: data that no longer exists cannot leak and cannot be compelled.

  • Items, dates, identifiers, and notes: kept until you delete them or your account. Deleting an item is immediate and permanent.
  • Scan-and-discard images: not kept at all. The image is held in memory for the length of the request and discarded when the response returns — it is never written to a database, an object store, a cache, or a log, and no preview or thumbnail is derived from it. Free accounts get five scans in total; paid accounts 60 a day, fair use.
  • Extracted fields awaiting confirmation: one hour, then deleted. Reading a document produces exactly three candidate values — document type, issuer, expiration date — which wait on a confirmation screen and are removed an hour later if you never confirm them. Nothing is saved to an item until you confirm.
  • Waitlist entries: kept until you ask to be removed. A removed address is marked unsubscribed rather than deleted so that a stranger cannot re-add it and have you mailed again; write to us if you want the row itself gone.
  • Account deletion: self-serve from settings, no email required, confirmed by typing a fixed phrase. Sessions are revoked the moment you confirm, and every database row belonging to the account is purged before the confirmation screen loads; if any step fails, an hourly job finishes the purge within 24 hours and the account can never be signed into again. Database restore history then expires within 30 days. What can persist in restore history during that window is encrypted data and metadata, and the account's wrapped key is destroyed with the rows, so any ciphertext that survives there is unreadable to us too.

8. Subprocessors

A subprocessor is another company that handles some of your data on our behalf. This is the complete list, and the trust center carries the same table:

  • Cloudflare — infrastructure. Hosts the application, the database, and the document-reading model, all inside Cloudflare's own network. Scan images are read on Workers AI within that infrastructure, are never sent to an external AI provider, and are never written to storage.
  • Resend — transactional email. Delivers reminders. Receives exactly the recipient address, the subject, and a body composed of item labels and dates — never identifiers, notes, or any link carrying a token. Resend also reports bounces and spam complaints back to us. If Resend is not configured, Cloudflare's email service carries the same messages under the same content rule; if neither is configured, nothing is sent and the messages wait.
  • Stripe — billing. Receives your email address, subscription status, and the payment details you enter on Stripe's hosted pages. Card numbers never touch our servers.
  • Proton Mail — the provider of our support, privacy, and security mailboxes. Receives whatever you choose to write to us at a validthru.app address, and nothing from the product itself.

There is no other third-party data egress of any kind: no analytics service, no error-reporting service, no font or script host. Additions to this list are announced 30 days before they take effect, on the trust center and by email.

9. No ads, no sale of data, no trackers

We do not sell, rent, or share personal data for advertising, and never have. There is no advertising, no advertising identifiers, and no analytics anywhere — no analytics service receives user content, and no scripts, fonts, or images load from third-party hosts on this site or in the app. Every request the page you are reading made went to us. This website sets no cookies. The app sets two: a session cookie and a refresh cookie whose only job is keeping you signed in; both are marked HttpOnly and Secure, and the session list in settings shows and can end every one of them.

10. Who at ValidThru can see what

The admin console has no view of your items, your identifiers, or your notes. Production infrastructure access is limited to the founders, is protected by hardware-key multi-factor authentication, and every session is logged.

11. Your rights

  • Export. From settings, on every tier, at any time, you can export everything your account holds — items, dates, identifiers, and notes — as JSON or CSV. Export is never a paid feature and never a retention lever.
  • Correction. Every field you can create, you can edit in the app.
  • Deletion. Account deletion is self-serve from settings — no email required, no retention counter-offer — on the timeline in section 7.
  • Access to activity. Your session list is visible in the app.
  • Waitlist removal. Write to privacy@validthru.app and we mark the address unsubscribed.

For anything you cannot complete in the app, write to privacy@validthru.app. We respond within 30 days and never charge for a request. If you live somewhere that grants additional rights — to object, to restrict processing, to complain to a supervisory authority — you have them, and the same address is where to start.

12. California and other state privacy rights

We do not sell personal information and do not share it for cross-context behavioral advertising, as California law defines those terms, so there is nothing to opt out of. The export, correction, and deletion mechanics above are available to everyone, not only to residents of states with privacy statutes, and we do not treat you differently for using them. The categories of personal information we collect are listed in section 3; the recipients are listed in section 8; the retention periods are in section 7.

13. Where your data lives

ValidThru is operated from the United States and hosted on Cloudflare's network, which stores our database in the United States and serves requests from data centers around the world. If you use ValidThru from outside the United States, your data is transferred to and processed in the United States under this policy. Our other subprocessors are named in section 8 with their locations.

14. Children

ValidThru is not directed at children under 13 and we do not knowingly collect personal information from them. If you believe a child under 13 has created an account, write to privacy@validthru.app and we will delete it.

Like any provider, we can be required to produce data under valid legal process, and we would comply. Our operating intent within that constraint: we require valid process before producing anything, we produce the minimum the process requires, and we notify you before complying unless the law prohibits it. Requests that arrive without valid process are refused. The most meaningful protection is what a request cannot reach: no scan image at all, no unconfirmed field older than an hour, and no identifier you never gave us.

16. If something goes wrong

If data from the sensitive class was plausibly exposed in decrypted form, we notify affected users directly and promptly, stating plainly what happened, what was reachable, and what we changed. Incidents and their post-mortems are published on the trust center. Where the law sets a shorter deadline or a specific form of notice, the law wins.

17. Changes to this policy

Material changes are announced by email 30 days before they take effect, and the change history is published beside this document. We will not weaken a retention promise for data you have already stored.

18. Contact

Privacy questions: privacy@validthru.app. Support: support@validthru.app. Security reports: security@validthru.app, as described in our security.txt.

End of policy