Most products in this category make a vague privacy claim and leave it there. Below is the specific version — what is encrypted, what is not, and the one moment we can see your photograph.
STATUS — AUGUST 2026Verso is pre-release. This page describes the architecture we have committed to and are building against, published now so it can be judged before there is anything to lose. It becomes a description of running software on the day it runs.
Full end-to-end encryption and server-side vision are architecturally incompatible: a model cannot read an image it cannot see. Rather than blur that, we draw the line and publish where it falls.
You photograph the work, the label, the receipt, or the certificate. That image is sent to Google's Gemini, which reads it and drafts the record; a smaller subset — where the read is uncertain or fields disagree — also goes to Anthropic's Claude as a second opinion. To do that, each model has to see the picture.
You confirm the drafted fields. The record and its images are encrypted on your device, with the key we cannot unwrap.
The record and the master file we archive, sync, and back up are ciphertext. Searching and reporting happen against data only your devices can read. The one image you keep seeing afterwards is the exception: Cloudflare Images, our image-hosting infrastructure, has to read the picture to generate the thumbnails and crops you scroll through, so that single served copy stays on our systems, behind the same short-lived signed links as everything else.
So the honest sentence is this: the record and the master file we archive are unreadable to us at rest, and at the instant of capture, two named providers briefly can see the photograph. Google holds what it sees for up to 55 days, Anthropic for up to 30 days — both solely to watch for abuse of their own service, both in writing that they don't train on it — and we've asked both for zero retention instead; we'll update this the moment either one grants it. Capture images are never used to identify you or what you own to anyone else. One more thing named plainly: the copy you actually browse afterwards is held in the clear on Cloudflare Images, our image-hosting infrastructure, because generating the view you're looking at requires reading the picture — it never reaches Google or Anthropic, and it is never served except behind a short-lived signed link.
The three phases above as one drawing: the photograph leaving the device in the clear to two named providers, the key derived and the record sealed on the device, and everything after that crossing the wire as ciphertext. One line marks the boundary, and the two retention windows are labelled on the near side of it. Engraved, in the site's rules and mono — not a stock cloud-and-padlock.
Records and documents are encrypted with AES-256-CBC and authenticated with HMAC-SHA256 — encrypt-then-MAC — before they leave the device. What reaches our database is ciphertext.
Your password derives a key through PBKDF2-SHA256, which wraps the key that actually encrypts your data. We store the wrapped form. We cannot unwrap it, which is the point.
The way back in if you forget the password. It is generated once, shown once, and meant for a safe — because if you lose the password and the recovery key both, your records are genuinely unrecoverable. We would rather say that than quietly keep a spare.
Originals live in private object storage and are delivered only through signed URLs that expire in about an hour. There is no public-by-default path to any image or document in Verso.
Who opened what, and when — including anyone you gave a share link to. Every link is scoped, expiring, and revocable from one screen.
Actor, timestamp, action, and a before-and-after of every change to every record. It is what makes your documentation defensible in a claim, and it is also how you audit us.
Your account and sign-in details, your billing record with our payment processor, and the encrypted contents of your collection. Operational metadata — object counts, timestamps, error traces — is kept in the clear because the system cannot run otherwise, and we keep as little of it as will do the job.
A short, published list of infrastructure providers: the platform serving this site, the database, object storage, and the vision and OCR models that read a photograph at capture. No advertising networks, no analytics broker with a resale business, no data enrichment.
No advertising. No sale or sharing of collection data. No training a model on your collection. No monetising the record in any form, at any tier, ever. For this audience that is not a policy — it is the product.
Export everything — CSV, images, documents — any time. Delete the account and we offer the export first, then hard-delete: database rows and stored files both, not a flag that hides them.
A PLAIN-LANGUAGE SUMMARY. THE FORMAL PRIVACY POLICY IS PUBLISHED BEFORE GENERAL RELEASE.
A record-keeping tool. You own your records and your images; we hold them on your behalf and make them available to you. Nothing you catalogue becomes ours.
Not an appraisal, not an authentication, not investment advice, and not a marketplace. Figures Verso derives are estimates, labelled as estimates, with their source attached — they are not a substitute for a credentialled appraiser.
That you have the right to the images and documents you upload, and that you do not use Verso to store material you are not entitled to hold.
We will not promise perfect uptime, and we will not hide behind that either: your data is exportable at any moment, which is the only guarantee that survives us having a bad day.
A PLAIN-LANGUAGE SUMMARY, NOT A CONTRACT. THE FORMAL TERMS ARE PUBLISHED BEFORE GENERAL RELEASE.
You, and no one else — unless you create a sharing link, which you scope and expire yourself. We never look at, surface, or analyse your collection for anyone.
The photograph is briefly processed by named vision providers so Verso can draft the record; neither trains on it. The archived master and record are then encrypted on your device. Our Security page publishes the providers, retention windows, and the separate image-hosting exception in full.
No, and we will not let that blur. Acquisition prices, insured values, and market comparables are recorded as what they are; anything Verso derives is labelled an estimate with its source attached, every time it appears. A formal appraisal comes from a credentialled appraiser, and Verso stores it rather than replacing it.
No. Verso is a private registrar, not a marketplace. We have no stake in what you buy, sell, or keep, and we will never build a feed telling you what to buy next.
Export everything — CSV, images, documents — with one click, anytime. Your records leave with you, intact and in formats that work elsewhere. No feature will ever make a collection un-exportable.
Your records are encrypted with a key derived from your password and wrapped so that we never hold it. The printed recovery key is the way back in if you forget the password — which means if you lose both, we genuinely cannot recover the data. That is the cost of the guarantee, and we would rather state it than quietly hold a spare key.
We offer the full export first, then hard-delete: records, images, and documents, from the database and from object storage both.