Start free

Privacy

The short version: the text you scan is processed in memory and never stored. What we do keep is the minimum needed to run your account, and it is listed here in full.

Last updated: 31 August 2026 · Controller: SovereignShield BV, Oostende, Belgium

What we never store

The content you send to the API for scanning (prompts, documents, actions, outputs) is processed in memory and discarded when the response is sent. It is not written to disk, not logged in full, and never used to train anything. When a scan escalates to the model consensus panel, it is routed through zero-data-retention endpoints so the upstream model providers do not retain it either.

What we store, exactly

Where it runs

The API and its database run on Google Cloud in europe-west1 (Belgium). This website is served by Cloudflare. Transactional email (verification and password-reset messages) is sent via Resend from an EU region. Payments are processed by Stripe. Each of these acts as a processor under GDPR; none of them receives your scanned content.

Cookies

This website sets no cookies and runs no analytics. The dashboard at api.sovereign-shield.net sets exactly one cookie: a session cookie (ss_session) that keeps you logged in. It is HttpOnly, Secure, and functional only. There is nothing to consent to because there is nothing tracking you.

The self-hosted software sends us nothing

If you run the packages yourself, they make no calls to us. No telemetry, no phone-home, no update checks. We do not receive, process, or see anything your deployment handles, and we could not produce it if asked.

If you email us

We keep the correspondence for as long as it is relevant, in an ordinary business mailbox. Licensing enquiries become contracts; the rest is deleted when it stops being useful.

Your rights

Under the GDPR you can request access, correction, deletion, restriction, or portability of your personal data, and you can object to processing. The fastest route for deletion is built in: the dashboard's delete-account button permanently erases your account, key, sessions, and tokens on the spot. For anything else, email contact@sovereign-shield.net. You also have the right to lodge a complaint with the Belgian Data Protection Authority (gegevensbeschermingsautoriteit.be).

Changes

This page changes when practice changes, and the date at the top moves with it. Material changes affecting account holders are announced by email.