Privacy model

What happens to what you type.

Veil minimises what leaves your device. It is not an anonymity network and it does not make cryptographic guarantees. This page says precisely what it does.

The request path

  1. 1. In your browser, the composer scans your message and attachments’ text and replaces detected values with placeholders like [PERSON_1]. The mapping is stored in IndexedDB with that conversation.
  2. 2. Our server receives the sanitized conversation, picks the model, forwards it to the provider and streams the answer back. It records token counts for billing — never the text.
  3. 3. The model provider sees the sanitized conversation and our server’s IP address. We don’t send user identifiers. Each provider’s own API data policy applies.
  4. 4. Back in your browser, placeholders in the answer are swapped for the real values. Each message has a receipt showing what was sent.
  5. Solana connector: wallet reads run in your browser; results pass through the same filter before the model sees them. Transfers are previews you approve in your wallet.

What the filter looks for

CategoryPlaceholdersHow
NamesPERSON · NAMECue phrases (“my sister Aoife”, “email Tom”), honorifics, a dictionary of common given names; Strict adds every remaining proper noun
PlacesCITY · PLACE · COUNTRYMajor cities, “I live in …” style cues; countries in Strict
AddressesADDRESS · POSTCODEStreet addresses, apartment numbers, Irish Eircodes, UK postcodes, US ZIP codes with context
ContactEMAIL · PHONE · HANDLE · URLEmails, phone numbers, @handles, URLs with query strings or profile paths (all URLs in Strict)
IdentifiersID · CARD · IBAN · IPUS SSN, Irish PPSN, UK NI numbers, passport numbers with context, Luhn-valid cards, checksum-valid IBANs, IP addresses
CryptoWALLET · TXSolana, EVM and Bitcoin addresses; transaction signatures
SecretsSECRETRecovery phrases (BIP-39), Solana keypair arrays, private-key-looking values, API tokens and PEM keys — removed in every mode, including Off
OrganisationsORG“I work at …” cues and suffixes like Ltd, Inc, Bank, University
Dates & numbersDATE · NUMBirth dates always; every date and number of 3+ digits in Strict

Stored on our servers

  • Accounts: a random id and the SHA-256 hash of your recovery key. No email, name or password.
  • Credit ledger and usage counts: model, tokens, credits, time. No prompts or replies.
  • Payments: the paying wallet address, amount, and transaction signature (needed to verify and to prevent replay). Payments are public on Solana anyway.
  • API keys: SHA-256 hashes, names, and last-used time.
  • Token-holder status: “holder until <time>” — not your wallet address.

Not stored

  • Conversations, prompts, replies, attachments, generated images or code.
  • Placeholder maps (they never leave your browser).
  • IP addresses. They’re used transiently, as a keyed hash that rotates daily, for rate limits and the free quota.
  • Analytics or advertising identifiers. There are no third-party scripts on this site.

Limitations