Privacy Policy

Last updated June 26, 2026

The short version

Emil is a screening layer between you and AI models. We process the text you send to detect and redact sensitive data and to screen for harmful content. We do not retain the full content you submit, we do not sell your data, and your content is never used to train any model.

What we collect

  • Account data: your email and basic profile from Google sign-in (or your SSO provider).
  • API keys: stored only as a one-way hash — we cannot recover the raw key.
  • Screening records (audit trail): for each request we store the decision, risk score, policy used, violation codes, latency, and a short redacted preview (first 80 characters) — not your full content.
  • Usage counts for billing, and billing data handled by our payment processor.

How content is processed

When you submit text, Emil runs deterministic detectors (PII, secrets, prompt injection) in memory, and content-safety and policy classification run on Emil’s own GPU infrastructure. Your text is never sent to a third-party AI provider (such as OpenAI, Anthropic, or OpenRouter) for screening. The full text is processed transiently and is not stored by Emil beyond the redacted audit preview described above. Content is never used to train any model.

Subprocessors

We rely on a small set of vendors to run the service:

  • Vercel — application hosting.
  • Supabase — authentication and database (account, audit records, usage).
  • Stripe — payment processing.
  • Resend — transactional email.

Retention

Audit records are retained for your account so you can review and export them, and deleted on account closure or on request. Raw submitted content is not retained beyond transient processing.

Your rights

You can export your audit log at any time from the dashboard, and request access to or deletion of your account data by emailing us.

Contact

Questions about privacy? Email privacy@heyemil.com.