• Trust
  • Privacy Policy
  • Who we share with
  • Security
  • Parents’ rights
  • Accessibility
  • Terms of Service

We don’t need your data. So we don’t take it.

Veristack helps students find real opportunities and helps schools see whether that is working. None of that requires building a profile of a young person, so we don’t. This page explains exactly what we hold, who ever sees it, where we fall short, and how to check that we mean it.

What we promise, and how it’s enforced

Anyone can promise these things. Each one below is followed by the mechanism that makes it true, because a promise with no mechanism behind it is just marketing.

  • We do not advertise to students, and we never will.

    There is no advertising network, no marketing pixel and no tracking script anywhere in this site. Not disabled — absent. You can confirm it in your browser’s network tab.

  • We do not sell, rent or trade anyone’s data. There is no version of this we would do.

    Our schools pay us. That is the entire business. Selling data would be a different company.

  • Organizations that post opportunities never receive student data.

    Organizations see their own listings and their own account — nothing about who viewed, saved or attended. That is enforced in code by an explicit list of the only fields an organization may be shown; anything outside the list stops the request rather than quietly passing through.

  • Reports never expose small groups.

    When a statistic would describe too few students to stay anonymous, it is withheld rather than rounded. An automated check runs on every code change and fails the build if a new report skips that rule.

  • When data is deleted, it is gone — with one exception we will name.

    Deletion removes the record rather than hiding it, and we specifically test that a later roster import cannot resurrect a deleted student — the usual way “deleted” turns out to mean “hidden”. The exception: if you report an organization as unsafe and later delete your account, your name and your words are removed but the fact that a report was made is kept. Three reports about one organization protect other children, and one person leaving should not erase that.

  • Software reads what a student writes. It may sort it into a subject; it may never attach a name to it.

    When a student asks for something anonymously, no adult at the school can read what they wrote — but the school still has to be able to tell "somewhere to fix bikes" from "a beginner art workshop", or nothing anonymous ever gets acted on. So the software reads the words and records ONE value from a fixed list of subjects we publish: creative arts, athletics, community service, and twenty-four more. It records nothing else. It never writes a note about the student, never adds the request to anything that decides what that student is shown next, and never lets a person see the words. Grouping requests and doing something about them stays a person’s decision, and a group is only ever shown to anyone once enough separate students have asked for the same thing.

  • The assistant is scoped, masked and logged.

    Identifying details are stripped before any question reaches the language model, every request is logged, usage is capped per school, and nothing is used to train anyone’s model.

  • Your school decides. We only hold the data.

    Schools own their records and we act on their instructions. Every query for a student record passes through one scoping layer that adds the school boundary automatically — a query that forgets to filter is refused rather than answered — so forgetting is not sufficient to cause a leak. Database-level enforcement underneath that is written and tested but not yet switched on, and we say so on the security page rather than describing it as though it were.

Where we fall short

Everything above is true. These are the things that are not yet, written down before you have to find them. Each was measured or read out of our own code in August 2026, and each moves off this list only when it is actually fixed.

  • Most data has no automatic expiry.

    We have written down how long every table in the product should live — all 124 of them — and a scheduled job enforces that on 54. The rest are deleted when somebody asks, not when a clock says so, which means a graduate’s record stays until a school directs otherwise rather than ageing out on its own. A build check counts the unenforced ones and refuses to let that number rise. We would rather tell you the number than describe the register as though it ran.

  • Nothing here has been tested with a screen reader.

    Our checks are automated analysis, manual review, and — since August 2026 — real measurement in a browser across every page and role. None of that can tell you how something is announced to a blind user. We would rather say so than let the absence of a known bug read as evidence there is none.

  • Some staff and operator screens fail our own contrast standard.

    A browser pass in August 2026 measured colour as it actually renders rather than as the design tokens promise, and found text as faint as 1.09:1 against its background where 4.5:1 is required. Every instance is on a staff or administrator screen, not a student one. They are named individually in our conformance report, which we will send on request.

  • Database-level tenant isolation is written but not switched on.

    Separation between schools is enforced today by a scoping layer every query passes through. The second layer beneath it — the database refusing cross-school reads on its own — exists and is tested but is not yet enabled in production. Both facts are on the security page in the same words.

  • Our email domain is monitored for impersonation, not protected from it.

    Mail we send is cryptographically signed. But our published policy tells receiving mail servers only to report a forged message, not to reject one — so someone impersonating our domain to a parent would probably still be delivered. Moving to enforcement is a configuration change we have not yet made, and until we do this is worth knowing.

  • No independent security certification.

    We hold no SOC 2 report, no ISO certificate, and have commissioned no third-party penetration test. Everything on these pages is our own account of our own system, backed by code you can ask us about. If your district requires an independent attestation, we do not have one, and we would rather you learn that here than three months into a procurement.

What you can do right now

These are working controls, not a form that emails us. You do not need our permission and you do not need to explain why.

  • Download everything we hold about you

    A complete copy of your own record, built on request. Available to students, parents, counsellors and administrators.

  • Delete your account

    Students, parents and administrators can request erasure here. Your school reviews the request, and then it is carried out for real rather than hidden.

  • Correct anything that is wrong

    You can edit your own details. Nobody needs to approve a correction.

  • Students: stop us counting what you look at

    Opening an opportunity listing counts towards a per-listing total your school sees. It is the only thing here we observe rather than being told, and one switch turns it off.

  • Parents: control what is shared

    Withdraw directory consent or any other permission you have given. Withdrawal takes effect immediately.

The details

Six documents, and this is all of them. They carry one shared review date rather than six divergent ones, because in practice they are reviewed together or not at all.

  • Privacy Policy — What we collect, why, who sees it, and how long we keep it.
  • Who we share with — Every outside company that receives anything. There are five.
  • Security — How the data is protected, described specifically enough to be checked.
  • Parents’ rights — What a parent can ask for, and how to ask.
  • Accessibility — Where we conform, where we do not yet, and what was measured.
  • Terms of Service — The agreement itself.

Ask us anything about your data

A real person answers. If you are a parent, a student, or reviewing us for a district and something here is unclear or looks wrong, we would rather hear it.

privacy@veristack.dev

  • Trust
  • Privacy Policy
  • Who we share with
  • Security
  • Parents’ rights
  • Accessibility
  • Terms of Service

No advertising or tracking. Cookies only keep you signed in.

© 2026 Veristack, Inc.