PRIVACY & SECURITY
Protection with a clear view of your data.
This notice explains what Sanctity Guard processes, what it keeps, and the choices available to you during our current Windows testing phase.
Updated September 30, 2026
We do not use your data to train our AI.
Sanctity Guard currently does not use customer browsing content, submitted images or videos, or support reports to train or fine-tune AI models. Reviewing content to make an allow/block decision is different from training a model. External AI providers have their own terms, explained below.
Information we handle
| Information | How it is used |
|---|---|
| Account and subscription | Email address, password hash, account preferences, plan and subscription status, and payment-provider references support sign-in, billing, and access. Stripe handles payment details; our account service does not store full payment-card numbers. |
| Device and licensing | An installation identifier, device label, platform, browser and extension version, enrollment and license status, and last check-in time support activation and device limits. Organization accounts also associate devices with an organization. |
| Usage and operations | Aggregate review counts, AI token/cost counters, security events, request references, timestamps, and response status help operate, secure, and troubleshoot the service. Hosting providers may process network metadata such as IP addresses in infrastructure logs. |
| Support reports you send | Your description, report reference, device and software details, and recent diagnostic request references are sent to support. A page address is included only when you choose to include it. Report content is delivered by email and may be retained in support mail; delivery and rate-limit metadata are stored separately. |
| Your own AI credentials | If you connect a supported provider, its credential is handled to make authorized review requests and is encrypted when stored by our account service. |
Content review is not browsing-history storage
The extension and local Windows companion examine relevant page addresses, text, images, and video information to apply your protection settings. Some checks take place on your device. When cloud review is used, relevant content can be sent through our service to the selected AI provider. Depending on the review, this can include page text, a page or video address, image data, or a video frame.
The account database does not store routine review payloads such as browsing addresses, page text, images, videos, prompts, or model responses as a browsing history. This does not mean content is never transmitted or processed, and it does not cover information you voluntarily include in a support report or an AI provider's own retention.
The local companion stores account/session state and a decision cache. Cached decisions and explanations can contain information derived from reviewed content; cache expiry is not a promise of immediate forensic erasure. Browser extension storage also holds settings and operational state.
What we do not collect automatically for support
Problem reports do not automatically attach screenshots, raw logs, browsing history, passwords, or access tokens. Please do not type sensitive credentials or unnecessary personal information into your report.
Services involved in delivering protection
Google Cloud hosts our account and review services. Stripe handles payments. Our email delivery service, Resend, delivers submitted problem reports to support. The configured AI provider processes the content needed for a cloud review.
Our no-training commitment describes Sanctity Guard's own use. An external provider's training and retention terms depend on the service, account, and configuration. Google states that Gemini Paid Services do not use prompts and responses to improve its products; other tiers and providers can have different terms. If you bring your own provider key, review your provider's terms and account settings. We do not promise that every third-party service has zero retention.
Google Gemini terms · Stripe privacy · Resend privacy
These services may process information in locations outside your state or country. We do not promise exclusive storage in a particular region in this testing release.
Security built into the service
Our safeguards include authenticated access, protected credential storage, encrypted cloud connections, checks on account and device authorization, and limits on what application diagnostics record. We use automated tests and dependency checks to catch regressions and known issues before releases.
Security improvements are released in stages. A cloud update does not automatically install a client update, and protections depend on the version installed on each device. We are testing further client hardening and signed software delivery before public release; these are not represented as already available on every test installation.
No product can guarantee that all inappropriate content is blocked or that all security risks are eliminated. We describe safeguards here without publishing credentials, internal access details, or operational configurations.
Your choices and requests
You can review available account and streaming preferences, choose whether to include a page address in a report, and stop submitting cloud reviews by discontinuing the service. In organization-managed deployments, your administrator controls some settings and device enrollment.
Account, billing, security, and support records have different purposes. We have not published a single retention period covering all of them. If you request deletion, some records may need to remain for legal, billing, fraud-prevention, or security purposes; third-party retention is governed separately. Uninstalling the software does not itself cancel a subscription or delete your cloud account.
For privacy questions or an access/deletion request, use the extension's support-report function and begin the description with “Privacy request.” We may need to verify account ownership before acting. Do not include passwords or payment-card details.
If we change how we use customer information, we will update this notice. A future training feature would require a separately explained policy and consent process; this notice does not authorize one.