Sovereign — Privacy Policy
This Privacy Policy explains how ProofChain LLC ("ProofChain," "we," "us," "our") handles information in connection with Sovereign ("the Application"). ProofChain is a limited liability company registered in the State of Wyoming, United States.
Sovereign is designed to be local-first. Its central privacy principle is that your email content and the intelligence derived from it stay on your device. This policy is written to be accurate about that design, including its limits.
1. Summary in Plain Terms
- Your emails, the summaries and data Sovereign derives from them, your relationships, commitments, calendar, and scores are stored only on your device, in a local database.
- We do not operate a server that stores your email content.
- To generate AI features, the text needed for a specific request is sent — through a privacy proxy we operate — to a third-party AI provider. The proxy is designed to strip identifying information and does not retain your content.
- You connect your own email account using your own credentials.
- We do not sell your data. We do not use your data to train AI models. We do not show advertising.
- If you delete the Application, the locally stored data is removed with it.
The sections below give the detail required for transparency and for compliance with the EU General Data Protection Regulation (GDPR) and similar laws.
2. Who Is the Data Controller
For the limited personal data we process directly — principally your subscription and billing information, your activation record, and any support correspondence — ProofChain LLC is the data controller.
For the email content and derived data that Sovereign processes and stores locally on your device, you exercise practical control: that data does not reach our servers, and we cannot access it. You act as the controller of your own email content; Sovereign is the tool through which you process it.
Contact: support@mailframe.org
Registered address: 5830 E 2ND ST #7000, Casper, WY 82609, United States
3. What Data Is Involved, and Where It Lives
3.1 Data stored only on your device (not accessible to us)
When you use Sovereign, the following are stored locally in a database on your device and are not transmitted to or stored by ProofChain:
- Email messages, threads, subjects, senders, and body content fetched from your connected account(s)
- Summaries, briefs, classifications, and other AI-derived outputs
- Relationship health data, commitment records, and calendar/event data derived from your email
- Your Sovereign Score and related metrics
- Behavioral observations used to calibrate the Application to your patterns
- Your settings and preferences
- Your email provider access tokens, stored in your operating system's secure credential store
We cannot see, retrieve, or recover any of this data. If you lose your device or delete the Application, we cannot restore it.
3.2 Data processed to deliver AI features
Some Sovereign features (such as generating a brief or synthesizing a situation) require AI processing that does not run on your device. For those features:
- The specific text needed for the request is sent from your device to a privacy proxy operated by ProofChain.
- The proxy forwards the request to a leading, U.S.-based AI provider under an enterprise agreement, using our credentials, so that your identity and the provider's credentials are not linked to your content. Our agreement with this provider contractually prohibits the use of your content to train AI models.
- The proxy is designed to strip identifying request metadata and does not store the content of your requests or their outputs. Its logging is content-free.
- The third-party AI provider processes the request to generate a response and, under our agreement with them, does not use the input or output to train their models and retains it only briefly in accordance with their API privacy terms.
We are transparent that this is a real data flow: to deliver AI features, the relevant text does leave your device and is processed by a third party. "Local-first" means your data is not stored off your device and no AI-provider credentials are held on your device — it does not mean that no data ever leaves your device. Features that rely on this flow are identifiable within the Application, and certain categories of your data can be excluded from AI access through the Application's settings.
3.3 Data we process directly (on our systems)
We process a limited set of personal data to run the business:
| Data | Purpose | Where |
|---|---|---|
| Email address, activation code, subscription status | Account activation and access control | Our activation service |
| Payment details, billing history | Processing your subscription | Stripe (we do not store card numbers) |
| Referral records (issuer and referred email, status) | Operating the referral program | Our activation service |
| Waitlist submissions (email, profession, description) | Managing access requests | Our waitlist provider |
| Support correspondence | Responding to you | Our email/support system |
| Crash and error reports (production only, opt-in) | Diagnosing faults | Our error-monitoring provider; metadata only, no email content |
4. Legal Bases for Processing (GDPR)
Where GDPR applies, we rely on the following legal bases:
- Performance of a contract — to activate your account, process payment, and provide the Application.
- Legitimate interests — to secure the Application, prevent abuse of the referral program, and diagnose faults, balanced against your rights.
- Consent — for optional features you explicitly enable, such as the weekly digest email or crash reporting, and for any AI processing of categories you have chosen to include. You may withdraw consent at any time.
- Legal obligation — where we must retain records for tax or accounting purposes.
5. Third-Party Processors
We rely on the following third parties. Each processes only what is necessary for its function:
- Stripe, Inc. — payment processing.
- Our AI provider — a leading U.S.-based AI company, engaged under an enterprise agreement that prohibits training on your content and provides for only brief, API-level retention; AI processing of the text sent for AI features occurs via our privacy proxy.
- Our hosting/proxy provider — operating the privacy proxy and activation service.
- Our email delivery provider — sending the optional weekly digest and transactional email.
- Our error-monitoring provider — production crash reporting (opt-in, metadata only).
- Google — where you connect a Gmail account, Sovereign interacts with Google's APIs on your behalf, under Google's own terms.
6. International Transfers
ProofChain is established in the United States, and some processors operate outside the European Economic Area. Where your personal data is transferred outside the EEA, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses or an equivalent mechanism.
Note that your email content and derived data, being stored locally on your device, are not subject to any such transfer by us — they remain where your device is.
7. Data Retention
- On-device data: retained on your device until you delete it or uninstall the Application. We have no role in its retention.
- Account and subscription data: retained for the life of your subscription and for as long afterward as required for legal, tax, and accounting purposes.
- Waitlist data: retained until you are admitted or until you ask us to remove it.
- Privacy proxy: does not retain the content of AI requests.
- Error reports: retained for a limited diagnostic period.
8. Your Rights
Where GDPR or a comparable law applies, you have the right to:
- access the personal data we hold about you;
- rectify inaccurate data;
- erase your data ("right to be forgotten");
- restrict or object to processing;
- data portability;
- withdraw consent for consent-based processing;
- lodge a complaint with your local data protection authority.
Because most of the data Sovereign generates lives only on your device, you can exercise access, portability, and erasure over that data directly: the Application provides an export function, and uninstalling removes it. For the limited account, billing, and waitlist data we hold, contact us at support@mailframe.org and we will respond within the period required by law.
9. Security
- On-device data is stored in a local database; your email access tokens are held in your operating system's secure credential store.
- Optional application-lock features (PIN, and platform biometric where available) can restrict access to the Application, and, where enabled, encrypt the local database at rest.
- Communication with the privacy proxy and with third-party services uses encrypted connections.
- We apply reasonable technical and organizational measures to the limited data we process directly.
No method of storage or transmission is completely secure, and we cannot guarantee absolute security.
10. Children
Sovereign is not intended for anyone under 18, and we do not knowingly process the data of children.
11. No Sale of Data, No Ad Targeting, No Model Training
We do not sell your personal data. We do not use it for advertising. We do not use your email content or derived data to train AI models, and our agreement with our AI provider prohibits them from doing so with content sent through our proxy.
12. Changes to This Policy
We may update this Policy. Where changes are material, we will notify you through the Application or by email. The "last updated" date reflects the latest revision.
13. Contact
ProofChain LLC
5830 E 2ND ST #7000, Casper, WY 82609, United States
Data enquiries: support@mailframe.org
← Back to Sovereign