AILeash is built on aggressive data minimisation. Wherever the platform can do its job with a cryptographic fingerprint instead of content, it holds only the fingerprint. This is not a bolted-on privacy feature — it is the architecture:
| Data | Content | Purpose · lawful basis |
|---|---|---|
| Governed events | user_id (customer-supplied identifier), action label, amount, country code, device_id, two 0–1 risk signals, optional authority token | Delivering the contracted decision and evidence service · performance of contract |
| Sealed chain records | Event, verdict, reasons, jurisdiction tag, timestamp, hashes | The tamper-evident evidence record that is the product itself · performance of contract; customers' legitimate interest in verifiable records |
| Account data | E-mail address, hashed API key, plan status, device counts | Account operation, alerts, billing · performance of contract |
| Billing data | Handled by Stripe; we hold no card numbers | Payment collection · performance of contract |
| Notary seals | SHA-256 fingerprints; for identity seals marked public, the limited display fields the user chooses to include; masked payment display fields | The public notarisation service · consent (the user submits the seal) |
| Contact messages | What the sender chooses to write | Responding · legitimate interest |
user_id and device_id fields are supplied by the customer. Our documentation instructs customers to send pseudonymous identifiers (e.g. user_4471), never names, e-mail addresses or other direct identifiers. Where a customer follows this, chain records contain no directly identifying personal data. Customers acting as controllers remain responsible for what they choose to transmit; Monop Content acts as processor for event data processed on customers' instructions.The hosted platform runs on Railway cloud infrastructure with the database on a persistent encrypted volume; connections are TLS-encrypted in transit; backups are taken daily. Sub-processors are listed in §7. Hosting region details and current sub-processor terms are available on request at justin@monopcontent.com.
Account and billing data are retained for the life of the account plus the period required by tax and accounting law. Contact messages are retained only as long as needed to respond.
Chain records require an honest explanation rather than a boilerplate one. The chain is append-only by design — its evidential value exists precisely because records cannot be deleted or altered. This is why the platform is architected so that chain records should contain no directly identifying personal data: fingerprints, pseudonymous identifiers and hashes are sealed; content and identities are not. Where a valid erasure request nonetheless touches sealed data (for example, display fields a user chose to make public on an identity seal), we honour it by erasing the stored display data while the cryptographic fingerprint — which identifies no one — remains in the chain. This preserves both the data subject's rights and the integrity of the record for everyone else.
Requests for access, rectification, erasure, restriction or portability go to justin@monopcontent.com and are answered within one calendar month. For event data processed on a customer's behalf, requests are handled with, and routed via, the customer as controller. UK data subjects may complain to the ICO; EU data subjects to their national supervisory authority.
| Provider | Purpose | Data touched |
|---|---|---|
| Railway | Application hosting and database volume | All hosted-platform data at rest and in transit |
| Stripe | Billing and payment processing | Billing identity and payment card data (held by Stripe, not by us) |
| Brevo | Transactional e-mail (alerts, receipts, contact) | E-mail addresses and message content of e-mails sent |
Sub-processors will not be added or changed without this document being updated — and each revision of this document is fingerprinted and sealed into the chain, so its history is tamper-evident.