Privacy model
What happens to what you type.
Veil minimises what leaves your device. It is not an anonymity network and it does not make cryptographic guarantees. This page says precisely what it does.
The request path
- 1. In your browser, the composer scans your message and attachments’ text and replaces detected values with placeholders like [PERSON_1]. The mapping is stored in IndexedDB with that conversation.
- 2. Our server receives the sanitized conversation, picks the model, forwards it to the provider and streams the answer back. It records token counts for billing — never the text.
- 3. The model provider sees the sanitized conversation and our server’s IP address. We don’t send user identifiers. Each provider’s own API data policy applies.
- 4. Back in your browser, placeholders in the answer are swapped for the real values. Each message has a receipt showing what was sent.
- Solana connector: wallet reads run in your browser; results pass through the same filter before the model sees them. Transfers are previews you approve in your wallet.
What the filter looks for
| Category | Placeholders | How |
|---|---|---|
| Names | PERSON · NAME | Cue phrases (“my sister Aoife”, “email Tom”), honorifics, a dictionary of common given names; Strict adds every remaining proper noun |
| Places | CITY · PLACE · COUNTRY | Major cities, “I live in …” style cues; countries in Strict |
| Addresses | ADDRESS · POSTCODE | Street addresses, apartment numbers, Irish Eircodes, UK postcodes, US ZIP codes with context |
| Contact | EMAIL · PHONE · HANDLE · URL | Emails, phone numbers, @handles, URLs with query strings or profile paths (all URLs in Strict) |
| Identifiers | ID · CARD · IBAN · IP | US SSN, Irish PPSN, UK NI numbers, passport numbers with context, Luhn-valid cards, checksum-valid IBANs, IP addresses |
| Crypto | WALLET · TX | Solana, EVM and Bitcoin addresses; transaction signatures |
| Secrets | SECRET | Recovery phrases (BIP-39), Solana keypair arrays, private-key-looking values, API tokens and PEM keys — removed in every mode, including Off |
| Organisations | ORG | “I work at …” cues and suffixes like Ltd, Inc, Bank, University |
| Dates & numbers | DATE · NUM | Birth dates always; every date and number of 3+ digits in Strict |
Stored on our servers
- Accounts: a random id and the SHA-256 hash of your recovery key. No email, name or password.
- Credit ledger and usage counts: model, tokens, credits, time. No prompts or replies.
- Payments: the paying wallet address, amount, and transaction signature (needed to verify and to prevent replay). Payments are public on Solana anyway.
- API keys: SHA-256 hashes, names, and last-used time.
- Token-holder status: “holder until <time>” — not your wallet address.
Not stored
- Conversations, prompts, replies, attachments, generated images or code.
- Placeholder maps (they never leave your browser).
- IP addresses. They’re used transiently, as a keyed hash that rotates daily, for rate limits and the free quota.
- Analytics or advertising identifiers. There are no third-party scripts on this site.
Limitations
- Detection is heuristic and English-centric. Unusual names, nicknames and non-Latin scripts are often missed. Check the receipt.
- Context can still identify you (“the only vet in my village”). Strict mode removes more at the cost of answer quality.
- Images are sent unmodified, including any faces, documents or metadata they contain.
- Off mode sends your text as written (secrets are still removed).
- The API’s server-side privacy option means your raw text reaches our server; it isn’t stored, but it isn’t filtered on your device either.
- Model providers process the sanitized text under their own terms, and may retain it for abuse monitoring.