PRIVACY & SECURITY

Protection with a clear view of your data.

This notice explains what Sanctity Guard processes, what it keeps, and the choices available to you during our current Windows testing phase.

Updated September 30, 2026

We do not use your data to train our AI.

Sanctity Guard currently does not use customer browsing content, submitted images or videos, or support reports to train or fine-tune AI models. Reviewing content to make an allow/block decision is different from training a model. External AI providers have their own terms, explained below.

Information we handle

Data categories and why they are needed
InformationHow it is used
Account and subscriptionEmail address, password hash, account preferences, plan and subscription status, and payment-provider references support sign-in, billing, and access. Stripe handles payment details; our account service does not store full payment-card numbers.
Device and licensingAn installation identifier, device label, platform, browser and extension version, enrollment and license status, and last check-in time support activation and device limits. Organization accounts also associate devices with an organization.
Usage and operationsAggregate review counts, AI token/cost counters, security events, request references, timestamps, and response status help operate, secure, and troubleshoot the service. Hosting providers may process network metadata such as IP addresses in infrastructure logs.
Support reports you sendYour description, report reference, device and software details, and recent diagnostic request references are sent to support. A page address is included only when you choose to include it. Report content is delivered by email and may be retained in support mail; delivery and rate-limit metadata are stored separately.
Your own AI credentialsIf you connect a supported provider, its credential is handled to make authorized review requests and is encrypted when stored by our account service.

Content review is not browsing-history storage

The extension and local Windows companion examine relevant page addresses, text, images, and video information to apply your protection settings. Some checks take place on your device. When cloud review is used, relevant content can be sent through our service to the selected AI provider. Depending on the review, this can include page text, a page or video address, image data, or a video frame.

The account database does not store routine review payloads such as browsing addresses, page text, images, videos, prompts, or model responses as a browsing history. This does not mean content is never transmitted or processed, and it does not cover information you voluntarily include in a support report or an AI provider's own retention.

The local companion stores account/session state and a decision cache. Cached decisions and explanations can contain information derived from reviewed content; cache expiry is not a promise of immediate forensic erasure. Browser extension storage also holds settings and operational state.

What we do not collect automatically for support

Problem reports do not automatically attach screenshots, raw logs, browsing history, passwords, or access tokens. Please do not type sensitive credentials or unnecessary personal information into your report.

Services involved in delivering protection

Google Cloud hosts our account and review services. Stripe handles payments. Our email delivery service, Resend, delivers submitted problem reports to support. The configured AI provider processes the content needed for a cloud review.

Our no-training commitment describes Sanctity Guard's own use. An external provider's training and retention terms depend on the service, account, and configuration. Google states that Gemini Paid Services do not use prompts and responses to improve its products; other tiers and providers can have different terms. If you bring your own provider key, review your provider's terms and account settings. We do not promise that every third-party service has zero retention.

Google Gemini terms · Stripe privacy · Resend privacy

These services may process information in locations outside your state or country. We do not promise exclusive storage in a particular region in this testing release.

Security built into the service

Our safeguards include authenticated access, protected credential storage, encrypted cloud connections, checks on account and device authorization, and limits on what application diagnostics record. We use automated tests and dependency checks to catch regressions and known issues before releases.

Security improvements are released in stages. A cloud update does not automatically install a client update, and protections depend on the version installed on each device. We are testing further client hardening and signed software delivery before public release; these are not represented as already available on every test installation.

No product can guarantee that all inappropriate content is blocked or that all security risks are eliminated. We describe safeguards here without publishing credentials, internal access details, or operational configurations.

Your choices and requests

You can review available account and streaming preferences, choose whether to include a page address in a report, and stop submitting cloud reviews by discontinuing the service. In organization-managed deployments, your administrator controls some settings and device enrollment.

Account, billing, security, and support records have different purposes. We have not published a single retention period covering all of them. If you request deletion, some records may need to remain for legal, billing, fraud-prevention, or security purposes; third-party retention is governed separately. Uninstalling the software does not itself cancel a subscription or delete your cloud account.

For privacy questions or an access/deletion request, use the extension's support-report function and begin the description with “Privacy request.” We may need to verify account ownership before acting. Do not include passwords or payment-card details.

If we change how we use customer information, we will update this notice. A future training feature would require a separately explained policy and consent process; this notice does not authorize one.