Privacy Policy

Aedelgard, a service of Millenion AB (org.nr 556887-8697), Sweden · last updated 2026-08-20

This policy explains what Millenion AB ("we", "us") collects when you use Aedelgard, and the unusual lengths the architecture goes to in order to collect as little as possible. We are the data controller under the GDPR.

1. The privacy principle

Your memory is envelope-encrypted at rest (AES-256-GCM) and bound to your Aedelgard key — no other party can open your vault without it. We do not sell, train on, or browse your data, and no human reads it. The standard hosted service runs inference on Aedelgard's model access; your prompt and the relevant memory are decrypted in-process to construct each request, so this is not yet operator-blind end-to-end encryption — that lives in the local body running your own provider key. Because your Aedelgard key is the only credential and we keep no email or password, if you lose it we cannot recover your key or your data.

2. What we collect

Inference: The standard service runs model inference on Aedelgard's Anthropic account — no Claude key required from you. Your prompts and relevant memory are decrypted in-process and sent to Anthropic's API; Anthropic's own privacy policy governs their handling. In body mode with your own provider key, inference runs directly from your hardware — we are not in that path and never see those prompts.

Billing data: during the founding window we collect no billing data at all — no card, no checkout. When paid hosting begins, billing is processed by Stripe: we receive a payment confirmation and a subscription status; we do not receive or store your full card details.

Operational data: minimal technical logs needed to run and secure the Service (e.g. request timing, error traces). We do not require an email, name, or password to use the Service.

3. What we do not collect

No account email or password (there is no login). No advertising identifiers. No selling of data to third parties. Your vault is sealed by a key derived from your Aedelgard key (HKDF); at rest it cannot be opened without it. During an active inference request the process decrypts what it needs — the full operator-blind guarantee applies only in body mode with your own provider key.

4. Processors

Anthropic (model inference via Aedelgard's account for the hosted service; via your own key in body mode) · Stripe (payments) · Amazon Web Services (hosting, EU region). Each processes data on our behalf under their own terms.

5. Your rights

Under the GDPR you may request access to, correction of, or erasure of personal data we hold about you. Because we keep no email or password and your data is isolated per tenant, the personal data we can act on directly is limited to billing and operational records; your vault is reached through your Aedelgard key. Contact us to exercise these rights.

6. Retention

Billing records are retained as required by Swedish accounting law. Operational logs are kept only as long as needed for security and reliability.

7. Contact

Data requests and questions: contact@aedelgard.com · Millenion AB, Sweden.

This policy reflects how Aedelgard works today and is in force. Material changes will be reflected here and dated above.