Processing and privacy

Real-time text and temporarily retained log sources have different lifecycles.

Real-time scans

Real-time scan text remains memory-only. Input, context, and structured-field values are not saved as activity content. Stored activity contains decisions, check codes, original character offsets, usage, version identifiers, and a keyed request fingerprint for retries.

Redacted output is not stored. A retry must resubmit matching input; a metadata lookup cannot recover its text. If no redact action applies, an explicitly requested redacted response can contain the original text.

Anonymous trials

Submitted text, customer-message context, pasted CSV/JSONL and displayed results stay in request memory. Relevant checks may run installed local models; input is not sent to paid model providers. There are no uploaded trial sources, saved visitor results or customer credit debits. Signing in does not transfer pasted content.

A signed anonymous cookie lasts up to 24 hours. Keyed session and network counters enforce limits and expire one hour after their last admitted submission; retry records expire after one hour. Expired abuse metadata is removed on the next admission or maintenance cleanup. Raw network addresses are not stored in these counters.

Content-free scan, request-fingerprint and credit metadata remains in isolated operational accounting. Your cookie cannot retrieve it; a retry must resubmit the original input.

Authenticated log audits

Uploaded log sources are temporarily retained outside the database. The default is 24 hours; delete-on-completion and seven days are explicit options. Mapped source text can be inspected only while the source is available and the user is authorized.

Result metadata, review events, and credit records follow their own lifecycle. Expiring source text does not erase those records. Text exports require an explicit choice and an unexpired source; generated exports are private and short-lived.

Processing and other systems

Policies use local processing unless an organization owner publishes a version with the remote-processing disclosure. That version can send raw target and context to Modal for selected encoder checks and privacy detection. Modal Web Function inputs and outputs may be retained for up to seven days. It can send sanitized target and context, plus required semantic-policy text, to Mistral. Sanitization may miss sensitive data. Mistral Free is not zero-data-retention, and this installation requires its training opt-out before activation. Guardful AI does not silently fall back between local and remote processing.

The policy version records the disclosure, selected processing bundle, authorizing owner and time. Playground and anonymous execution require a separate acknowledgement before that request can run. Third-party workflow tools can retain their own inputs and outputs; configure their history and retention separately.

Redaction masks only identified spans. It is not a guarantee of anonymization or detection of every sensitive value.

Journey measurement

Completion events contain only a fixed event name, an example or integration choice, the UTC day, and whether the operation was a preview. They contain no visitor or workspace identifiers, source text, filenames, credentials, or URLs. Signup continuation retains only the selected workflow in the existing session. Operators can count first completed scans and full audits from existing operational metadata without exporting workspace identities.

These events use the installation’s log output. Operators control any capture and retention; this application adds no analytics service, tracking cookie or event database.

This installation’s limits

This application does not encrypt local development data at rest and provides no backup or recovery guarantee. Lost or reset sources must be recreated or uploaded again. Use synthetic examples here.

These notes describe implemented product behavior and planned hybrid-provider boundaries. Remote activation, deployed processing locations and commercial claims require separate reviewed acceptance and publication.

Security controls · Privacy contact