Privacy Policy

Last updated: 7 April 2026

1. Data controller

Bordair is operated as a sole trader business based in the United Kingdom. For the purposes of the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018, the data controller is Bordair.

Address: Russellcroft Road, Welwyn Garden City, AL8 6QY, Hertfordshire, United Kingdom

Contact: hello@bordair.io

ICO registration reference: ZC116587

2. Information we collect

Account information

When you create an account we collect your email address and a hashed password. We do not store passwords in plain text.

API usage data

When you use the Bordair API we log: a one-way SHA-256 hash of the input text (we never store the raw input), the scan result (threat level, confidence, detection method), timestamp, and input length. These logs are tied to your API key and are visible in your dashboard.

Payment information

Payments are processed by Stripe, Inc. We do not store credit card numbers or bank details on our systems. Stripe acts as an independent data controller for payment data under their own privacy policy.

Website analytics & advertising

With your consent, we use Google Analytics 4 and Google Ads to understand how visitors find Bordair and to measure the effectiveness of our advertising. These services set cookies and may process your data, including via Google Consent Mode. We do not transmit any personal data (such as your email, name, or API key) to these services. You can accept or reject these cookies via the banner shown on your first visit, and analytics/advertising cookies are not set unless you accept. Google acts as an independent data controller under its own privacy policy.

Bordair's Castle & Colosseo (the game)

Anonymous Castle players are tracked via IP address and a browser fingerprint to enforce rate limits and prevent abuse. This data is automatically deleted after 7 days. Anonymous game progress is stored locally in your browser (localStorage) and is not sent to our servers. Authenticated players' Castle progress is linked to their account.

Unlike the scanning API, our adversarial game stores the text you submit while playing. When you make an attempt in Castle, Bordair's Ghost, or the Colosseo, the prompt (and any extracted text from images, documents, or audio you submit) is retained so we can power leaderboards, prevent replay of winning attempts, generate the model's in-character responses, and moderate the game. Champions you create in the Colosseo are stored and shown publicly, including to players who attack them. Do not put personal, confidential, or sensitive information into game attempts or Champions - treat everything you type into the game as content you are choosing to share with us and, for published Champions, with other players.

3. Legal basis for processing (UK GDPR Article 6)

We process your personal data under the following lawful bases:

  • Contract performance (Article 6(1)(b)) - to provide the API service you signed up for, authenticate requests, and manage your account
  • Legitimate interests (Article 6(1)(f)) - to enforce rate limits, prevent abuse, maintain service security, and improve detection accuracy using aggregate anonymised metadata. Our legitimate interest does not override your rights because the scanning API processes only minimal data and never stores raw input text. (Game attempts in Castle / Ghost / Colosseo are processed on the same legitimate-interest basis to run the game, leaderboards, and moderation, as described in section 2.)
  • Legal obligation (Article 6(1)(c)) - where we are required to retain data or disclose information by law

4. Data we do NOT collect

To be explicit:

  • We never store the raw text, image, document, or audio content submitted to the scanning API - only a one-way hash, the result, and metadata (this does not apply to the optional adversarial game, Castle / Ghost / Colosseo, which stores game attempts as described above)
  • We do not use your data to train our models on a per-user basis - only aggregate, anonymised scan metadata is used
  • We do not sell or rent personal data to any third party
  • We do not set advertising or analytics cookies without your consent, and we never send your email, name, or API key to Google Analytics or Google Ads

5. Data sharing and sub-processors

We share data only with the following parties, strictly as needed to provide the Service:

PartyPurposeData sharedLocation
Amazon Web Services (AWS)Infrastructure hostingAll service data (encrypted)UK / EEA
Stripe, Inc.Payment processingEmail, payment detailsUS (with EU data residency options)
Anthropic, PBCLLM-based prompt analysis (Bordair's Castle)User-submitted prompts during Castle gameplayUS
Resend, Inc.Transactional email deliveryEmail addressUS

If this list changes, we will update this policy and notify registered users.

6. Data processing location

Personal data and scan content submitted to the Bordair API is processed within the United Kingdom / European Economic Area. We do not currently transfer personal data outside the UK or EEA in the course of providing the service. If this changes in the future, we will update this policy and rely on appropriate safeguards under UK GDPR (such as Standard Contractual Clauses) where required.

7. Data retention

Data typeRetention period
Scan logs (hashed)90 days, then automatically deleted
Account informationDeleted immediately upon account deletion request, along with all associated scan logs and Castle progress
Payment recordsAs required by UK tax law (typically 6 years)
Castle progressDuration of active account, deleted on account deletion
Game attempt content (Castle / Ghost / Colosseo prompts and Champions you create)Retained while your account is active to run the game, leaderboards, and moderation; deleted on account deletion
Anonymous player data (IP, fingerprint)7 days, then automatically deleted
Verification/reset codes15 minutes (expired codes are automatically cleared)

8. Data security

We implement appropriate technical and organisational measures to protect your data:

  • All data in transit is encrypted with TLS 1.2+
  • Passwords are hashed using industry-standard algorithms (never stored in plain text)
  • API keys are generated using cryptographically secure random number generators
  • Raw user input is never stored - only irreversible SHA-256 hashes
  • Infrastructure runs in isolated containers with no persistent storage of user content

9. Your rights under UK GDPR

Under the UK GDPR, you have the following rights:

  • Right of access (Article 15) - request a copy of the personal data we hold about you
  • Right to rectification (Article 16) - request correction of inaccurate personal data
  • Right to erasure (Article 17) - request deletion of your personal data ("right to be forgotten")
  • Right to restriction (Article 18) - request that we restrict processing of your data
  • Right to data portability (Article 20) - export your data in a structured, machine-readable format via the data export feature in your dashboard or API
  • Right to object (Article 21) - object to processing based on legitimate interests

To exercise any of these rights, email hello@bordair.io. We will respond within one month as required by UK GDPR.

10. California residents (CCPA)

If you are a California resident, the California Consumer Privacy Act (CCPA) provides you with additional rights:

  • Right to know - what personal information we collect, use, and disclose
  • Right to delete - request deletion of your personal information
  • Right to opt-out of sale - we do not sell personal information to third parties
  • Right to non-discrimination - we will not discriminate against you for exercising your CCPA rights

To make a CCPA request, email hello@bordair.io.

11. Children

The Service is not directed at children under the age of 16. We do not knowingly collect personal data from anyone under 16. If you believe a child under 16 has provided us with personal data, please contact us at hello@bordair.io and we will delete it promptly.

12. Cookies

We use the following cookies:

  • Strictly necessary - session authentication - to keep you logged in to the dashboard (SameSite=Lax, Secure attributes). Essential for the Service to function; these do not require consent under UK GDPR.
  • Analytics & advertising (consent-based) - Google Analytics 4 and Google Ads cookies, used only after you accept them via our cookie banner. These help us measure traffic and advertising performance. They are set in a denied-by-default state under Google Consent Mode until you consent, and you can decline them entirely.

CSRF protection is provided via SameSite cookie attributes and header-based API authentication rather than a separate cookie. We do not use advertising or analytics cookies unless you have given consent.

13. Automated decision-making

The Bordair API uses automated processing (machine learning models) to classify inputs as potentially malicious or benign. This processing is performed on the content you submit via the API, not on your personal data. The scan results are informational and the decision to block or allow content is made by your application, not by Bordair.

14. Changes to this policy

We may update this policy from time to time. Material changes will be communicated via email to registered users at least 14 days before taking effect. The "last updated" date at the top of this page will always reflect the current version.

15. Complaints

Bordair is registered with the UK Information Commissioner's Office (ICO) under registration reference ZC116587.

If you are unhappy with how we handle your data, you have the right to lodge a complaint with the ICO:

We would appreciate the opportunity to address your concerns before you contact the ICO. Please email us at hello@bordair.io first.

16. Contact

For any privacy-related questions, data requests, or concerns:

Email: hello@bordair.io