Privacy policy

Last updated: September 17, 2026.

This policy describes information handled by the Interdict AI website and service. Privacy requests can be addressed to Bo Yates at support@interdictai.com.

What we retain

Raw prompts and responses are not stored in ordinary audit records. We do retain account information, billing identifiers, configuration, and operational audit metadata to run the service. This is not a zero-data-retention service.

Account and support information

We collect the email address, company name, and password you provide during registration. Passwords are stored as hashes. We also process verification and password-reset records, account settings, support messages, and billing identifiers when you choose a paid plan.

Requests routed through Interdict

The gateway processes request and response content to apply your configured policies. Allowed or redacted content is sent to the model provider you select. If you enable an external verification destination, the information needed for that verification is sent to that destination. Your configuration determines what is blocked, redacted, or allowed.

Ordinary audit records contain operational metadata, such as provider, model, detected identifier types, enforcement actions, timing, and usage. They do not contain raw prompts or responses. This does not mean the service processes no personal information or that infrastructure and diagnostic logs contain no information.

Browser tools

The local PII scanner processes the text you enter in your browser. Its scan does not send that text to the gateway or a model provider. Website hosting still processes the network information needed to serve the page.

Service providers and billing

We use service providers for hosting, database storage, transactional email, and payment processing. The application integrates Resend for email and Stripe for paid checkout. Payment details entered in Stripe checkout are handled by Stripe; Interdict stores billing identifiers and subscription status. Model providers and configured verification services have their own data practices.

Cookies and website measurements

Authentication uses cookies to maintain and secure your session. The site integrates Vercel Analytics and Speed Insights for website usage and performance measurements. Browser settings can restrict cookies, but doing so may prevent sign-in from working.

Uses and disclosures

Information is used to operate and secure the service, apply your policies, support accounts, measure usage, and administer billing. Information may be disclosed to service providers supporting those purposes, to destinations you configure, or as required by law.

Retention and requests

Account, operational, support, and billing records are retained for service operation, security, and applicable recordkeeping needs. Different records may have different retention periods. Contact us to request access, correction, or deletion, or to ask about retention for your intended workload. We may need to verify your identity and explain records that must be retained. Deleting an account and canceling a paid subscription are separate requests.

Sensitive data and changes

Use fictional data while evaluating the service. Contact us before routing regulated production data to establish the necessary arrangements. This policy is not a business associate agreement or a data processing agreement.

We will update this page when our practices change and identify the update date. Material changes affecting an existing account will be communicated through the service or account email.

Questions? support@interdictai.com

Pricing · Privacy · Terms · Cancellation