New: Protect your data from both sides of AI with our unified perimeter defense. Start building free →

Privacy & Data Policy

Last updated: September 2026

1. Privacy Policy Overview

At AIGuard, privacy is not just a policy—it is our core architecture. This document explains how we collect, process, and secure the data that flows through our AI proxy infrastructure.

Information We Collect

We collect information strictly necessary to provide the service and maintain compliance audits, including:

  • Account credentials (email address, API keys secured via hashing).
  • Website domains provided for RoboGate crawler auditing and firewall rules.
  • Non-identifiable telemetry metadata (request IDs, token counts, timestamps, latency).
  • Billing configurations (processed securely through PCI-DSS compliant merchants).

Zero Data Brokering: We do not sell your information. Our business model relies on subscription fees, not data mining. We process data solely to execute PII tokenization and threat detection for your application.

2. Memory-Only Processing & Tokenization

AIGuard is designed around the principle of zero-trust architecture. Our system acts as an intermediate proxy between your application and third-party LLMs.

How Data is Handled

  • Volatile Memory: When a user prompt containing PII arrives at our server, the tokenization and entity extraction happen entirely in volatile RAM.
  • Zero-Disk Storage for Prompts: Your raw prompt text, including the unmasked PII, is never written to disk or stored in any database.
  • Token Mappings: The temporary mapping (e.g., mapping [NAME_001] back to "John Doe") is held securely in active memory for the duration of the request cycle and is destroyed immediately upon returning the LLM response to you.

This architecture inherently prevents AIGuard from becoming a liability vector. In the event of a breach, there are no databases containing your users' raw prompts to be compromised.

3. Data Retention & Logging

Compliance Metadata

While we do not store raw prompts, we do store cryptographic request metadata (such as timestamps, risk scores, and the types of PII detected) to generate PDF audit reports. This data is handled asynchronously via secure background workers.

Automated Cleanup Cycles

Under GDPR Storage Limitation principles, we enforce automated data retention lifecycles based on your subscription tier:

  • Free & Starter Plans: Metadata is retained for a limited operational window (e.g., 7 to 30 days) before being automatically purged.
  • Pro & Enterprise Plans: Security audit logs are retained for longer compliance periods (up to 365 days) to satisfy cyber-liability insurance and HIPAA/PCI-DSS auditing requirements.

4. Your Privacy Rights

Depending on your location, you possess rights under regional frameworks (GDPR, CCPA, HIPAA):

  • Right to trigger account and metadata erasure (right to be forgotten).
  • Right of administrative data access and audit trail export.
  • Right to object to telemetry processing operations.

To exercise these rights, or to configure an Enterprise Bring-Your-Own-Database (BYOD) deployment for total data sovereignty, please contact our team at contact@aiguard.solutions.

Policy Updates

We may update this Privacy Policy as regulatory frameworks (such as the EU AI Act) evolve. We will notify you of any material changes via your dashboard. If you have any questions regarding this policy, please reach out to support@aiguard.solutions.