Legal

Privacy Policy

How we handle your data and your prompts

Last updated: September 6, 2026

Early access notice

Dsyfer Shield is in active development and offered as an early-access service. Features may change or be withdrawn, no uptime commitment applies, and AI-generated outputs can be inaccurate or incomplete. See AI disclosures for details.

Sybersafe, LLC, operating as Dsyfer (“Dsyfer,” “we,” “us”), provides Dsyfer Shield, a private AI gateway. This policy explains what information we collect through the Shield website and service, how we use and share it, how long we keep it, and the choices you have.

Shield exists so that sensitive content does not leak into public AI tools. That promise shapes this policy: the sections on gateway traffic and model providers are the ones that matter most, and we have written them plainly rather than burying them.

1.Information we collect

Account information. Name, email address, organization name and role when you create an account, join the waitlist, request an AI readiness review, or request an investor packet.

Gateway traffic. The prompts, files and other content you submit through Shield, and the output returned to you (together, “Customer Data”).

Operational metadata. Timestamps, model and route selected, token counts, latency, error codes, policy decisions (for example that a request was blocked or redacted), and the account or API key that made the request.

Technical and site data. IP address, browser and device information, pages visited, referring pages, and similar log data.

Communications. Messages you send to us and records of support interactions.

2.How gateway traffic is handled

  • We do not use Customer Data to train foundation models, and we do not sell it.
  • Requests are transmitted to the AI provider you or your administrator select, in order to generate a response.
  • Where a zero-data-retention route is configured and supported by the provider, request content is processed in memory for the duration of the request and is not written to durable storage by Dsyfer.
  • By default we retain operational metadata about each request (see above) even when request content is not retained, because that metadata is what makes usage reporting, billing, abuse prevention and incident investigation possible.
  • Prompt and response content is logged only where you or your administrator explicitly enable content logging — for example to retain an audit trail — or, transiently, where required to investigate a security incident or a suspected violation of our terms.
  • Retention settings, redaction rules and permitted routes are configurable for enterprise deployments.

Because zero-data-retention behaviour depends on the selected provider and route, do not assume it applies to every model. See Zero Data Retention for how routes are configured, and contact us before submitting regulated data on a free or early-access plan — the Terms of Service restrict that use.

3.Model providers and other subprocessors

Shield is a gateway. When you send a request, the content necessarily reaches the AI provider that serves the model you chose. Those providers act as subprocessors and apply their own terms, retention practices and security controls.

  • AI model providers — process request content to generate responses for the model you or your administrator select.
  • Cloud hosting and database providers — host the application, accounts and configuration.
  • Email delivery providers — send activation, notification and transactional email.
  • Bot-protection and security providers — verify that signup requests come from a person.
  • Analytics and error-monitoring providers — help us understand usage and diagnose faults.

A current list of subprocessors, including the AI providers enabled for your account, is available on request at shield@dsyfer.com. Subprocessors are permitted to use information only to perform services for us.

4.How we use information

  • To provide, operate, secure and support the Service.
  • To create and administer your account and send activation and service email.
  • To enforce usage allowances, prevent abuse and investigate security incidents.
  • To produce usage and governance reporting for you and your administrators.
  • To improve the reliability and performance of the Service using aggregated or de-identified metrics.
  • To respond to your enquiries and, where you have asked to hear from us, to send information about Shield.
  • To comply with legal obligations and enforce our terms.

We do not use Customer Data for advertising, and we do not sell or share personal information for cross-context behavioural advertising.

5.Retention

  • Account information: for the life of the account and up to 24 months afterwards, unless you request earlier deletion.
  • Operational metadata: typically 12 months, then deleted or aggregated.
  • Prompt and response content: not retained on zero-data-retention routes. Where content logging is enabled, retained for the period configured for your account.
  • Website and security logs: typically 90 days.
  • Records we must keep for legal, tax or dispute-resolution reasons: for the period required by law.

6.Your rights and choices

Depending on where you live, you may have the right to access, correct, delete, restrict or object to processing of your personal information, to receive a portable copy, and to withdraw consent. You may also ask us to stop sending marketing email at any time by using the unsubscribe link or writing to us.

To exercise a right, email shield@dsyfer.com. We will verify your request and respond within the time required by applicable law. If you use Shield through your employer, direct requests about workspace data to your administrator; we act on their instructions for that data.

7.Security

We use encryption in transit and at rest, access controls, least-privilege administrative access, logging and monitoring, and vendor review. Our controls are designed to align with recognised frameworks; alignment is not the same as certification, and we will tell you plainly which reports exist if you ask. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

To report a vulnerability or a suspected incident, email shield@dsyfer.com.

8.Cookies and similar technologies

The Shield website uses strictly necessary cookies to operate, and — where you consent — analytics cookies to understand how the site is used. You can accept or decline non-essential cookies from the banner on the site and change your browser settings at any time. Declining non-essential cookies does not affect access to the Service.

9.International transfers

We are based in the United States and process information there. If you access the Service from the European Economic Area, the United Kingdom or another region with data-transfer rules, your information may be transferred to and processed in the United States and other countries whose laws differ from your own. Where required, we rely on appropriate safeguards such as standard contractual clauses.

10.Children

The Service is not directed to anyone under 18 and we do not knowingly collect personal information from children. If we learn that we have, we will delete it. Parents and guardians may contact us at the address below.

11.Links to other sites

The Service may link to sites we do not operate, including model provider documentation. We are not responsible for their content or privacy practices, and we encourage you to review their policies.

12.Changes to this policy

We may update this policy. Material changes will be reflected in the “last updated” date above and, where practicable, communicated by email or in-product notice.

13.Contact us

Questions, requests or complaints about this policy can be sent to shield@dsyfer.com or by mail:

Privacy Requests
Sybersafe, LLC (Dsyfer)
PO Box 2366
Chandler, Arizona 85244

Questions about this document? Write to shield@dsyfer.com.

Terms of ServicePrivacy PolicyAI disclosures