ValideitySign in

Privacy policy

Last updated 26 September 2026. This describes what Valideity collects and why, in plain language.

Who is responsible for your data

Valideity decides what is collected and why for its own customers, waitlist and visitors, and is responsible for that data. Questions go to privacy@valideity.com.

Who this covers

A customer is someone with a Valideity account, running studies. A respondent is someone who opens a study link — they usually have no Valideity account and never will. A visitor is anyone using the public pages without an account: the waitlist, or the free AI first read of a web page. The sections below cover what is collected from each.

What is collected from a customer

  • Account details: email address, and a name if one is given.
  • Payment references from Paystack — never card details, which Valideity never sees or stores.
  • Study content: uploaded Figma files or connected prototypes, live URLs tested, the personas and questions a study is built from.
  • Usage: sessions run, plan and billing history, workspace membership.
  • Problem reports you send: your message, your email, the page you were on and your browser type.

What is collected from a visitor

  • The waitlist: your email address, a name if you give one, how you arrived (a referral link, or a first read), and when you were invited.
  • The AI first read: the address of the page you ask us to read, and the read itself. We open that public page, read its text and take screenshots of it, which are sent for AI processing to write the read and are not kept. The pages you read are listed in your history: with your account if you are signed in, otherwise on this browser, where they move to your account if you sign in on it.
  • Daily read limits: to count reads, we keep a random identifier for your browser and a scrambled form of your internet address, never the address itself. These counts are deleted after 7 days. If you share a read, the link records which browser shared it and which browsers opened it, so the sharer can be given more reads. Share links are deleted after 30 days.

What is collected from a respondent

A study link only asks for what its researcher turned on — most studies stay anonymous by default. When a study does ask, the fields are the ones its builder chose from: name, email, date of birth, gender, phone, country and city, occupation and work details, or, only for studies where the body is genuinely the subject (fitness, apparel, health), height and weight. Beyond that step, a respondent's interactions with the study — screens reached, clicks, navigation, and their answers to whatever questions the study asks — are recorded. This data belongs to the researcher who built the study, not to Valideity, and it is used only to produce that study's results. For this data, Valideity processes it on the researcher's behalf and follows their instructions.

When a study tests a website that has added the Valideity snippet, the snippet only reports what happens on that site while it is open inside a study, for that study. It does nothing for anyone visiting the site normally.

Simulated participants are not real people

A run's "Predicted" results come from simulated personas — fictional archetypes generated for the study, not real people. No real person's personal data is involved in producing them.

Why we use it

  • To provide the service you asked for: your account, your studies, your first read, your place on the waitlist.
  • To take payment and keep the records the law requires.
  • To keep the service working and fair: fixing problems, stopping abuse, and enforcing limits.
  • To email you about your account, your plan, your studies, and your waitlist invite.

Who at Valideity can see it

A small number of Valideity staff can see account, study, waitlist and first-read data through our internal tools, to give support, fix problems, check for abuse and run the service. They do not use it for anything else.

Who this is shared with

  • Paystack, to process payments.
  • Our database and authentication provider, to store accounts and studies securely.
  • An email delivery provider, to send account, billing, and study-related emails.
  • Cloud AI processing providers, to generate simulated participant behaviour and to analyse study content and results. Which specific provider or model is used for a given run is not disclosed as part of the product — see hello@valideity.com for that detail if it is needed for a security or procurement review.

None of the above use this data for their own marketing, and none of it is sold to anyone.

Some of these providers store or process data outside Nigeria, including in the European Union and the United States. We only use providers that protect data to a standard the law accepts for such transfers.

How long this is kept

Studies and other content are kept for 90 days after an account is closed, then deleted. Payment records are kept for as long as the law requires, separately from that.

  • Screen pictures from simulated sessions are deleted after 30 days; the results they produced stay.
  • First-read limit counts are deleted after 7 days, and share links after 30 days. A browser's list of reads is deleted 90 days after its last read.
  • Waitlist entries are kept until you ask us to remove them.

Cookies

Valideity uses only cookies it needs to work: one keeps you signed in, one remembers a first read you made so it is waiting for you after you sign up or join the waitlist, and one identifies this browser for your free first reads: the day's count and the list of pages you read. There is no third-party advertising or analytics tracking on this site.

Your rights

To see, correct, or delete the personal data held about you, or to ask a question about any of this, write to privacy@valideity.com. You can also ask us to stop using it, or to give you a copy to take elsewhere. A respondent asking about data collected through someone else's study should also contact that study's researcher directly, since they control what it was used for.

If you are not satisfied with our answer, you can complain to the Nigeria Data Protection Commission.

Children

Valideity is not directed at, and should not be used by, anyone under 18.

Security

Reasonable technical and organisational measures are used to protect this data. No online service can guarantee absolute security, and this is not a guarantee that none is ever possible.

Changes to this policy

Material changes to this policy will be announced by email to customers before they apply.