Privacy Notice
Last updated: 18 August 2026
This notice explains what ServeX Guard Cloud collects, why, where it is stored and how long it is kept. The controller is El Mahdi El Aimani, an individual trading as ServeX Guard, Rabat, Morocco. Questions and rights requests: mahdielaimani@gmail.com.
The short version. Evaluation runs on your machines, not ours. By default the monitoring SDK sends us a numeric vector of your production traffic and never the text itself, so your end users' questions and answers do not reach our database at all. Data is stored in the European Union. We do not sell data and we do not train models on it.
1. The architecture, because it decides everything below
ServeX Guard has two parts. The open-source CLI runs on your own machines and CI runners and performs all detection locally: PII scanning, prompt-injection checks, RAGAS evaluation. The Cloud receives results that have already been computed. It contains no detection logic and never sees your dataset unless you choose to send it.
2. What we collect
Account data
| Data | Why | Basis |
|---|---|---|
| Email address | Sign-in, alerts, service notices | Contract |
| Password (hashed by Supabase Auth) | Authentication | Contract |
| Plan, tier, billing identifiers from Paddle | Provisioning the right features | Contract |
| API key hash (SHA-256), key prefix, last-used time | Authenticating uploads; showing you which key is live | Contract |
We do not receive or store your card details. Paddle handles payment and shares back only a customer and subscription identifier.
CI run data
When you run the CLI with --upload we store the report it produced: metric scores
(faithfulness, answer relevancy, context recall), counts of PII and injection findings, pass/fail
status, the git commit SHA and branch, and the full JSON report as your source of truth.
That report is generated from your evaluation dataset. If your dataset contains personal data, and your CLI configuration includes it in the report, it reaches us. Keep test fixtures synthetic. That is the correct practice regardless of this Service.
Production samples (Pro)
This is the part that matters most, so it is stated exactly:
- The SDK samples a fraction of your production traffic (10% by default).
- The sampled text is sent to our API, converted to a 1024-dimension numeric vector by the embedding provider, and the text is then discarded rather than written to the database. Only the vector is stored.
- An embedding is a lossy numeric summary. The original wording cannot be reconstructed from it.
- Storing the text alongside the vector is possible but off by default
(
STORE_SAMPLE_TEXT=false). It is only ever enabled by explicit configuration.
The consequence: for a bank or health provider, end-user questions never land in our database. This is a deliberate design choice, not a policy promise.
Technical logs
Our hosting provider records standard request logs (IP address, timestamp, path, status, user agent) for security and debugging, on the basis of our legitimate interest in keeping the Service available and secure.
3. What we never do
- Sell or rent your data, or share it for advertising.
- Use your data to train machine-learning models, ours or anyone else's.
- Read your project data except where you ask us to help with a specific support issue, or where the law requires it.
- Run advertising or third-party analytics trackers on this site.
4. Where data is stored
Application data is held in a Supabase Postgres database in the European Union (Ireland, eu-west-1). The API runs in the same region so requests do not cross regions in normal operation.
5. Sub-processors
| Provider | Purpose | Data reaching them |
|---|---|---|
| Supabase | Database, authentication | All stored application data |
| Vercel | API and dashboard hosting | Request traffic and logs |
| Paddle | Merchant of record, payments, tax | Billing details you enter at checkout |
| Resend | Transactional and alert email | Your email address and message content |
| Hugging Face | Embedding generation | Sampled text, at the moment of embedding only, not retained by us |
Where a provider processes data outside the EEA, transfers rely on Standard Contractual Clauses or an equivalent safeguard. We will give notice before adding a sub-processor that materially changes this list.
6. How long we keep it
| Data | Retention |
|---|---|
| CI runs, Free plan | 7 days |
| CI runs, Pro plan | 180 days (six months) |
| Production sample vectors | 30 days |
| Daily drift scores | Your plan's retention window |
| Account and billing records | While the account exists, then as tax law requires |
Retention is enforced by a scheduled purge job that deletes expired rows, not merely by hiding them in the dashboard. Deleting your account removes your projects, runs, samples and keys.
7. Security
- All traffic is served over HTTPS with HSTS.
- Row Level Security is enabled on every table, so one customer's query cannot return another's rows even if application code were wrong.
- API keys are stored only as SHA-256 hashes; we cannot read them back.
- Billing webhooks are rejected unless their signature verifies, so nobody can forge a payment.
- Rate limits and request-size caps apply to every endpoint.
No system is perfectly secure. If we become aware of a breach affecting your personal data we will notify you and any competent supervisory authority as the law requires.
8. Cookies
We use no advertising or analytics cookies. The dashboard stores your Supabase session in the browser's local storage so you stay signed in; clearing site data signs you out. Paddle sets its own cookies during checkout, governed by Paddle's privacy policy.
9. Your rights
Subject to applicable law (including the GDPR for users in the EEA and UK, and Law 09-08 for users in Morocco), you may request access, correction, deletion, restriction, portability, or object to processing based on legitimate interest. Write to mahdielaimani@gmail.com; we respond within 30 days. You may also complain to your national data protection authority.
10. If you are our customer's customer
When a business uses ServeX Guard to monitor its own AI system, that business is the controller of the underlying data and we are its processor. Direct requests to them; we will support them in answering you.
11. Children
The Service is for businesses and is not directed at anyone under 18. We do not knowingly collect children's data.
12. Changes
We will post any update here with a new date, and give notice by email for material changes.
13. Contact
El Mahdi El Aimani, an individual trading as ServeX Guard
Rabat, Morocco
mahdielaimani@gmail.com