Privacy Notice

Last updated: 18 August 2026

This notice explains what ServeX Guard Cloud collects, why, where it is stored and how long it is kept. The controller is El Mahdi El Aimani, an individual trading as ServeX Guard, Rabat, Morocco. Questions and rights requests: mahdielaimani@gmail.com.

The short version. Evaluation runs on your machines, not ours. By default the monitoring SDK sends us a numeric vector of your production traffic and never the text itself, so your end users' questions and answers do not reach our database at all. Data is stored in the European Union. We do not sell data and we do not train models on it.

1. The architecture, because it decides everything below

ServeX Guard has two parts. The open-source CLI runs on your own machines and CI runners and performs all detection locally: PII scanning, prompt-injection checks, RAGAS evaluation. The Cloud receives results that have already been computed. It contains no detection logic and never sees your dataset unless you choose to send it.

2. What we collect

Account data

DataWhyBasis
Email addressSign-in, alerts, service noticesContract
Password (hashed by Supabase Auth)AuthenticationContract
Plan, tier, billing identifiers from PaddleProvisioning the right featuresContract
API key hash (SHA-256), key prefix, last-used timeAuthenticating uploads; showing you which key is liveContract

We do not receive or store your card details. Paddle handles payment and shares back only a customer and subscription identifier.

CI run data

When you run the CLI with --upload we store the report it produced: metric scores (faithfulness, answer relevancy, context recall), counts of PII and injection findings, pass/fail status, the git commit SHA and branch, and the full JSON report as your source of truth.

That report is generated from your evaluation dataset. If your dataset contains personal data, and your CLI configuration includes it in the report, it reaches us. Keep test fixtures synthetic. That is the correct practice regardless of this Service.

Production samples (Pro)

This is the part that matters most, so it is stated exactly:

The consequence: for a bank or health provider, end-user questions never land in our database. This is a deliberate design choice, not a policy promise.

Technical logs

Our hosting provider records standard request logs (IP address, timestamp, path, status, user agent) for security and debugging, on the basis of our legitimate interest in keeping the Service available and secure.

3. What we never do

4. Where data is stored

Application data is held in a Supabase Postgres database in the European Union (Ireland, eu-west-1). The API runs in the same region so requests do not cross regions in normal operation.

5. Sub-processors

ProviderPurposeData reaching them
SupabaseDatabase, authenticationAll stored application data
VercelAPI and dashboard hostingRequest traffic and logs
PaddleMerchant of record, payments, taxBilling details you enter at checkout
ResendTransactional and alert emailYour email address and message content
Hugging FaceEmbedding generationSampled text, at the moment of embedding only, not retained by us

Where a provider processes data outside the EEA, transfers rely on Standard Contractual Clauses or an equivalent safeguard. We will give notice before adding a sub-processor that materially changes this list.

6. How long we keep it

DataRetention
CI runs, Free plan7 days
CI runs, Pro plan180 days (six months)
Production sample vectors30 days
Daily drift scoresYour plan's retention window
Account and billing recordsWhile the account exists, then as tax law requires

Retention is enforced by a scheduled purge job that deletes expired rows, not merely by hiding them in the dashboard. Deleting your account removes your projects, runs, samples and keys.

7. Security

No system is perfectly secure. If we become aware of a breach affecting your personal data we will notify you and any competent supervisory authority as the law requires.

8. Cookies

We use no advertising or analytics cookies. The dashboard stores your Supabase session in the browser's local storage so you stay signed in; clearing site data signs you out. Paddle sets its own cookies during checkout, governed by Paddle's privacy policy.

9. Your rights

Subject to applicable law (including the GDPR for users in the EEA and UK, and Law 09-08 for users in Morocco), you may request access, correction, deletion, restriction, portability, or object to processing based on legitimate interest. Write to mahdielaimani@gmail.com; we respond within 30 days. You may also complain to your national data protection authority.

10. If you are our customer's customer

When a business uses ServeX Guard to monitor its own AI system, that business is the controller of the underlying data and we are its processor. Direct requests to them; we will support them in answering you.

11. Children

The Service is for businesses and is not directed at anyone under 18. We do not knowingly collect children's data.

12. Changes

We will post any update here with a new date, and give notice by email for material changes.

13. Contact

El Mahdi El Aimani, an individual trading as ServeX Guard
Rabat, Morocco
mahdielaimani@gmail.com