Shadow Warden AI — Gateway v7.9 — Explore the API Reference
Legal

Privacy Notice

Effective September 20, 2026

This notice describes what Shadow Warden AI does with personal data, in the terms GDPR Article 13 asks for. It covers what the service does today. Where something is not yet in use, this notice says so rather than describing it as if it were.

1. Who is responsible

Shadow Warden AI, established in Israel, decides how and why the data described here is processed. For anything in this notice, including every request under section 6, write to privacy@shadow-warden-ai.com.

2. What is collected

Two things, and nothing else:

  • Your account. When you sign up we store the email address you give us and a bcrypt hash of your password. We do not store the password itself and cannot recover it.
  • Request metadata. When a prompt passes through the gateway we record what kind of request it was, how long it was, how long it took, and what the filter decided.

Prompt content is never written to disk or to any log. It is analysed in memory and discarded. This is a property of how the gateway is built, not a policy applied afterwards — there is no store to purge it from, and no copy for us to read.

No payment data is collected. No payment provider is currently connected to this service, so nothing of that kind reaches us or anyone else.

3. Why, and on what legal basis

  • Account data, to give you access to the service you asked for — performance of a contract, Art. 6(1)(b).
  • Request metadata, to operate the gateway, spot abuse and keep it working — legitimate interests, Art. 6(1)(f). You may object; see section 6.

4. How long it is kept

  • Request metadata: 30 days, then deleted automatically.
  • Account data: for as long as the account exists. Delete the account and it goes with it.

5. Where it is held, and who else sees it

On servers operated by Hetzner Online GmbH in Germany, inside the EEA. We do not sell personal data, and we do not share it with third parties for their own purposes. Prompt content is never transmitted anywhere by the gateway — it goes to an AI provider only when you route it there yourself, under your own agreement with that provider.

6. Your rights

You may ask for a copy of your data, ask us to correct it, ask us to delete it, ask us to restrict how we use it, ask for it in a portable form, or object to processing we base on legitimate interests. Write to privacy@shadow-warden-ai.com and we will answer within 30 days.

You can also complain to the data protection supervisory authority where you live or work. Exercising a right here does not affect that.

7. Automated decisions

The gateway decides automatically whether to allow or block a request, from the content of that request. That decision governs a prompt, not a person: it produces no legal effect and nothing comparable to one. You can ask us why a particular request was blocked.

8. Changes

If this notice changes materially we will change the effective date above and say so on this page. The underlying record — our Article 30 register and the Data Protection Impact Assessment this notice is drawn from — is published at /doc/compliance.

Related: Terms of Service · Trust Center · GDPR DPIA