Privacy Policy
How sovrgn collects, uses, and protects your information — and how the sovereign-routing model constrains where your data is processed.
1. Who we are and scope
To be drafted The legal entity behind sovrgn (per instance/jurisdiction) and what this policy covers.
2. Information we collect
To be drafted Account details (email, organisation), API-key metadata, and request metadata. Distinguish account data from inference payloads.
3. How we use information
To be drafted Operating the service, billing, security/abuse prevention, and support — and the lawful basis for each.
4. Inference data and residency
To be drafted What happens to prompts/outputs, where they are processed (the sovereign-routing residency model), and the fail-closed guarantee.
5. Sharing and third parties
To be drafted The model providers routed behind the switch, infrastructure processors, and that no data is sold.
6. Data retention
To be drafted How long account, billing, and any logged metadata are kept, and deletion timelines.
7. Security
To be drafted How keys are stored (hashed), encryption in transit/at rest, and access controls.
8. Your rights
To be drafted Access, correction, deletion, portability, and how to exercise them — per applicable law (e.g. GDPR/CCPA/Privacy Act).
9. International transfers and residency
To be drafted How the sovereign-routing model constrains cross-border processing, and any safeguards for offshore fall-through (there is none when residency is pinned).
10. Cookies and analytics
To be drafted What is set on the site itself, and any analytics used.
11. Children
To be drafted The minimum-age position and that the service is not directed to children.
12. Changes to this policy
To be drafted How updates are made and notified.
13. Contact
To be drafted How to reach sovrgn (and any data-protection contact) about privacy.
Questions about these terms? Contact us. Other documents: Terms of Service · Privacy Policy · Model Terms.