Skip to content

Privacy at this deployment

What stays yours, and what belongs to the shared corpus.

This document covers people who use this deployed search and anyone whose material appears in its results. It separates personal search activity from the documents, domains and assessments that make up the deployment’s shared body of material.

The load-bearing boundary

Your activity is not the shared corpus.

Personal activity remains attached to the person who created it. The deployment shares the admitted material and policy work required to search its configured vertical.

private to you

  • Your queries
  • Your search history
  • Your collections
  • Your saved searches and their alerts
  • Your personal source preferences
  • Your service-key usage
  • The results you interacted with

shared to this deployment

  • Admitted documents and their extracted content
  • Domain assessments and site classifications
  • Coverage decisions
  • Source and vertical policies

Shared analytics carries aggregate counts only; it never carries query text or an identified person’s behaviour.

Available from your account

Your account gives you direct controls.

No retention period is stated here because none is configured. These routes are the places where you inspect, export or remove your own material.

A large export may be processed as a job. The account area tells you when it is ready.

Conditional and fail-closed

Processing only runs for a stated purpose.

A class can be part of the product contract without pretending that a provider, model or jurisdiction has already been selected.

classexternal search lookupwhen it runsOnly when the owned corpus has a coverage or freshness gap.configurednot configured
classcontent extractionwhen it runsOnly after material is admitted and fetched under the deployment’s source policy.configurednot configured
classembeddingwhen it runsOnly for admitted extracted content entering the owned index.configurednot configured
classanswer generationwhen it runsOnly after retrieved evidence is fixed; it may abstain or remain disabled.configurednot configured
classpaymentswhen it runsOnly when a person chooses a paid account path.configurednot configured
classemailwhen it runsOnly for account notices or alerts a person has enabled.configurednot configured

An unvalidated combination of jurisdiction profile, provider and source class fails closed. It cannot fetch, store, display or generate, and remains visible as blocked instead of being silently dropped.

Evidence in, auditable decision out

Requests leave a recorded trail.

Each request is recorded with its evidence, adjudicated by this deployment’s staff and kept with an auditable outcome.

  • Correct a domain assessment

    request path · evidence attached

    The disputed assessment and supporting material are recorded with the staff decision and its outcome.

  • Remove or delist material

    request path · evidence attached

    The material, reason and supporting evidence remain linked to the adjudicated outcome.

  • Object as a source

    request path · evidence attached

    The source objection is recorded, reviewed by staff and resolved through the same auditable path.

When a correction is granted, the changed assessment can trigger remeasurement and propagate to the index.

jurisdiction
not configured
legal basis
not configured
response time
not configured

What is available now

When no public channel exists.

No public contact channel is configured for this deployment.

No email address, postal address, named officer or response time is implied by this page.

  • availableThe report and correction paths described above.
  • availableYour account area at /settings.