Legal

Privacy

The editor works without an account and keeps your work in your browser. If you sign in and save, we store what you saved. We don’t sell your data, run ads or use trackers.

Last updated

Who runs verve

verve is an independent product, run from Pennsylvania, United States. We’re the data controller for everything described on this page, which means we decide what gets stored and why, and we’re who you hold to it.

hello@verveapp.dev reaches us, and it’s the right address for a privacy request or a complaint.

Using the editor without an account

The editor runs in your browser. Pasting a component, animating it and exporting code all happen on your device, and none of it is sent to us. Close the tab and it’s gone.

One optional feature does talk to a server, and only when you use it: AI assist. What it sends is under “Other services” below.

What we store when you sign in

  • Your account. Your email address. If you sign in with Google or GitHub, also the account ID and the name that provider shares. There’s no password to store: you sign in with an emailed link or code, or with the provider.
  • Animations you save. The document: elements, keyframes, springs, its name, and the component code you pasted. If you paste code you’d rather not store, don’t save that animation.
  • Springs you save by name, so they follow you between devices.
  • Share links you create. A copy of the animation as it looked when you shared it. Anyone with the link can see it until you turn the link off.
  • Reports you send about a share link: the reason, anything you wrote, and your account if you were signed in.

Everything except share links is private to your account. The database itself enforces that, so a bug in the app can’t show your work to someone else.

Images you drop into the editor are never uploaded. They stay in your browser, and saved animations and share links don’t include them.

Other services

We use a few companies to run verve. Each gets only what its job needs.

  • Supabase hosts the database and handles sign-in.
  • Vercel hosts the site and keeps standard request logs, which include IP addresses. It also counts page views for us, without cookies and without identifying anyone: the page, a rough country, and the kind of browser. Visitors are a hash that resets every day, so it can’t tell whether you’ve been here before, and neither can we.
  • Resend delivers sign-in emails, so it sees your email address.
  • Anthropic receives the text you type into AI assist, and nothing else, to generate a starting animation.
  • Cloudflare forwards email you send to hello@verveapp.dev on to our inbox.
  • Stripe handles payments for Pro. Your card details go to Stripe, never to us. We keep your plan, and Stripe’s customer ID for you.
  • Sentry receives error reports when something breaks: what went wrong, the page it happened on, and your browser. Not your email, not your account, and not the code you pasted. There is no session recording.

These services run on servers in the United States. When your data leaves the EU or the UK, it’s covered by the standard contractual clauses in each company’s data processing terms.

Cookies and browser storage

verve sets three kinds of cookie, all its own:

  • sb-…-auth-token: Supabase’s sign-in cookies, which keep you signed in. They last up to 400 days and go when you sign out.
  • verve-signed-in: says only that you’re signed in, so the page shows the right buttons before it loads. It holds no account details and lasts a week.
  • verve-editor-used: remembers that you’ve pasted a component, opened a template or saved, so the editor opens on a blank stage instead of the demo. It lasts a year.

Browser storage holds your theme, editor view settings, whether you’ve seen the tour, springs you saved while signed out, images you dropped in, and whether you chose to open the editor on a small screen this visit. It also keeps a copy of an animation with unsaved changes, so a reload or signing in doesn’t lose it. That copy stays in your browser, and goes when you save or discard it.

Each of these does a job for you here. There are no analytics, advertising or tracking cookies, so there’s nothing to consent to and no cookie banner.

What we don’t do

  • No selling or sharing your data for marketing.
  • No training AI models on your animations or your code.
  • Nothing in exported code reports back to us. It’s plain Motion, GSAP or CSS.
  • Pasted code runs in a sandboxed frame with no network access and no access to the rest of the page.

Keeping things running

To stop abuse, we count requests over short time windows. For signed-in actions the count is tied to your account. For signed-out ones, like requesting a sign-in email, it’s tied to your IP address. Old counts are cleared automatically, so they don’t build up.

Legal basis

Data protection law (the GDPR, and the UK’s version of it) asks for a reason behind each use of your data. Ours are:

  • Providing verve. Your account, what you save and share, sign-in emails and AI assist are the service you asked for, so they rest on our contract with you.
  • Keeping it safe and working. Request logs, the counts that stop abuse, reports about share links and error reports rest on our legitimate interest in running a secure service. They hold only what that needs, and you can object to them.
  • Meeting legal duties. Payment records are kept because tax law requires it.

We don’t make automated decisions about you with legal or similarly significant effects.

How long we keep it

  • Your account and what you save: until you delete them, or your account.
  • Share links: a link you turn off stops working at once, but its copy stays with the animation until you delete the animation or your account.
  • Reports about share links: kept as a record of what was reported and what we did about it.
  • The counts that stop abuse: cleared automatically within a day.
  • Vercel’s request logs: up to 30 days.
  • Sign-in emails at Resend: 30 days.
  • What you type into AI assist: Anthropic deletes it within 30 days, unless it breaks their usage policy.
  • Error reports in Sentry: up to 90 days.
  • Email you send us: as long as we need it to answer you.

Your data, your call

Delete any saved animation from your library. In settings you can change your email, download everything saved under your account as a JSON file, and delete your account.

Deleting your account removes your animations, saved springs, share links and profile in the same step. Reports you sent about other people’s links stay, with your account removed from them.

You can also ask for a copy of anything else we hold about you, or ask us to correct it, delete it or limit what we do with it. Email hello@verveapp.dev from the address on your account and we’ll reply within a month.

If you’re in the EU or the UK and unhappy with how we’ve handled your data, you can complain to your local data protection authority. In the UK, that’s the ICO.

Children

verve is not for children under 13, or under the minimum age in your country if that’s higher. We don’t knowingly keep accounts for them.

Changes and contact

When this page changes, the date at the top changes too. If a change affects what we store or who sees it, we’ll say so on the site first.

Questions, or a request about your data: hello@verveapp.dev.