Legal

Terms of Service

Last Updated: 2026-06-12

By accessing or using the Veramask API (the "Service"), you agree to be bound by these Terms. If you are using the Service on behalf of an organization, you represent that you have the authority to bind that organization to these Terms.

1. The Service

Veramask provides stateless middleware for detecting and anonymizing Personally Identifiable Information (PII). You acknowledge that the Service is a tool to assist with data privacy and that you remain solely responsible for ensuring your data processing complies with applicable laws (such as GDPR and CCPA).

2. Usage & Payload Limits

  • Payload Size: To ensure service stability, limits apply per request. Please refer to your subscription plan for specific details. Requests exceeding your plan's limit will be rejected.
  • No Retention: The Service is stateless. We do not store the content of your data payloads.
  • Accuracy: Detection is based on probabilistic models. Veramask does not guarantee 100% detection of all sensitive entities. You are responsible for configuring settings appropriate for your security requirements.
  • Deterministic Output: If you utilize features for repeatable output, you are responsible for the secure management of the associated cryptographic secrets.

3. Prohibited Conduct

You may not:

  • Attempt to re-identify individuals from anonymized data produced by the Service.
  • Reverse-engineer the detection logic or bypass security controls.
  • Submit data for which you do not have the necessary legal rights or user consent.
  • Submit Protected Health Information (PHI) or other health data subject to HIPAA or similar laws, unless you have a separate written agreement with us (see Section 6 below).
  • Use the website's support form, account system, or newsletter to submit data subject to special-category protections under GDPR Article 9 (e.g. health, biometric, genetic data).

4. Health Information and HIPAA

The Veramask website (this portal, including the support form, account system, and billing) is not a HIPAA-compliant service and is not intended to receive, store, or process Protected Health Information (PHI) as defined by the U.S. Health Insurance Portability and Accountability Act (HIPAA) or analogous health privacy laws.

You agree not to submit PHI through the website. The Veramask API itself may, in a separate, customer-specific deployment, be used to process health data under a business-associate agreement (BAA); that use case is governed by the BAA and the API terms, not by these Terms.

5. Disclaimers & Liability

The Service is provided "as is." Veramask disclaims all warranties, express or implied. We are not liable for any damages resulting from undetected PII, data breaches occurring on your systems, or your failure to meet regulatory obligations.

6. Termination

We reserve the right to suspend or terminate access if these Terms are violated or if your usage threatens the stability of the Service.

7. Changes to These Terms

We may update these Terms from time to time. The "Last Updated" date above reflects the most recent revision. For material changes, we will notify you by email (if you have an account) or by a prominent notice on the website. Continued use of the Service after changes are posted constitutes acceptance of the updated Terms.


By using Veramask, you acknowledge you have read and agreed to these Terms.