# Privacy Policy **Template — not legal advice. Review and adapt with qualified counsel before relying on this document.** Last updated: 2026-07-09 This Privacy Policy explains how GetDeaddicted LLC ("we", "us", "our") collects, uses, and protects information when you use Trishul, an LLM guardrail middleware and API proxy available at https://trishul.aiskillhub.info (the "Service"). It is written to address the requirements of India's Digital Personal Data Protection Act, 2023 ("DPDP Act") and the EU/UK General Data Protection Regulation ("GDPR"), among other laws. ## 1. Who We Are GetDeaddicted LLC operates Trishul and, for your account and website data, acts as the **Data Fiduciary / Data Controller**. When you route your application traffic through the hosted Service, we act as a **Data Processor** on your behalf with respect to the content in that traffic; those processing terms are set out in our Data Processing Addendum (dpa.md). ## 2. Data We Collect **Account data.** When you sign up, we collect your email address and authentication details, and, for paid tiers, billing metadata (handled by our payment processors — see Section 5). **API usage metadata.** For each request we may log timestamps, request and response sizes, endpoint, tier, quota consumption, guardrail decisions (for example, "PII masked" or "tool call held for approval"), latency, and error codes. This metadata supports metering, security, debugging, and abuse prevention. **Transient prompt and response content.** To apply guardrails, the Service processes the prompts your application sends and the model responses it receives. This content is processed **in memory, transiently**, only to run the rails (injection detection, PII masking, policy checks, egress verification). We do not use your prompt or response content to train models. **Website and cookies.** Our marketing site and dashboard may use strictly necessary cookies for sessions and, where applicable, privacy-respecting analytics (see Section 4). ## 3. How Prompt and Response Content Is Handled - Content is processed **in memory to apply guardrails** and is not persistently stored as part of normal operation. Any short-lived buffering exists only for the duration needed to evaluate and forward the request. - **Self-hosted / VPC deployments keep prompt and response content entirely within your own environment.** In that mode we do not receive your content at all. - **Raw secrets are never intentionally stored or echoed back.** Trishul is designed to detect and mask sensitive values rather than persist them, and to avoid reflecting secrets into logs or responses. - Where a guardrail action requires human-in-the-loop tool-call approval, the minimal metadata needed to present and record that decision may be retained per your configuration. ## 4. Cookies and Analytics We use cookies that are strictly necessary to keep you signed in and to secure the dashboard. If we use analytics, we aim to use privacy-respecting, aggregated measurement and to minimize or avoid cross-site tracking. Where required by law, we obtain consent before setting non-essential cookies. You can control cookies through your browser settings. ## 5. Sub-Processors We rely on a limited set of sub-processors to run the hosted Service, which may include: - **Model gateway / upstream provider** — to forward verified requests to the LLM you have configured (in gateway mode we do not hold your third-party model provider key); - **Cloud hosting and infrastructure** — to run the Service; - **Payment processors** — Razorpay (India) and Stripe (global) for billing (note: payments are not yet live); - **Email / transactional communications** — to send account and service notices. A current list is available on request at getdeaddictedllc@gmail.com. Sub-processors are bound by contractual data-protection obligations. ## 6. How We Use Data We use data to: provide, secure, and improve the Service; meter usage and enforce quotas; detect and prevent abuse and attacks; communicate with you about your account; comply with legal obligations; and, where applicable, process payments. Our legal bases under GDPR include performance of a contract, our legitimate interests in operating and securing the Service, consent (where required), and legal obligation. Under the DPDP Act we process personal data on the basis of your consent or other legitimate uses permitted by the Act. ## 7. Data Retention - Account data is retained for as long as your account is active and for a reasonable period afterward to meet legal, tax, and security obligations. - API usage metadata is retained for a limited period for metering, security, and debugging, then deleted or aggregated. - Transient prompt and response content is not retained as part of normal operation beyond the processing needed to apply guardrails. We delete or anonymize personal data when it is no longer needed for the purposes above, unless a longer retention period is required by law. ## 8. Your Rights **Under the DPDP Act (India):** you may request access to, correction of, completion of, updating of, and erasure of your personal data; you may withdraw consent; and you may nominate another individual to exercise your rights in the event of death or incapacity. You may also make a complaint to the Data Protection Board of India. **Under the GDPR (EU/UK):** you have rights of access, rectification, erasure, restriction, portability, and objection, and the right to withdraw consent and to lodge a complaint with your supervisory authority. To exercise any right, contact us at getdeaddictedllc@gmail.com. We will respond within the timeframes required by applicable law. Where you route traffic through us as a Processor, requests about that content should be directed to the relevant Controller (our customer), whom we will assist. ## 9. Data Residency For hosted customers, we process data in the region(s) where our infrastructure is deployed. Customers with data-residency requirements can use our **self-host / VPC option**, which keeps prompt and response content within the customer's chosen environment. Enterprise customers may agree specific residency terms. ## 10. Security We apply technical and organizational measures appropriate to the risk, including encryption in transit, access controls, least-privilege principles, secret-masking in the processing pipeline, and monitoring. No system is perfectly secure; we work to promptly detect, respond to, and, where required, notify you of security incidents. ## 11. Children's Data The Service is intended for businesses and developers and is not directed to children. We do not knowingly collect personal data of children. Under the DPDP Act, processing of a child's data requires verifiable parental consent; if you believe a child has provided us data, contact us so we can delete it. ## 12. International Transfers Where personal data is transferred across borders, we rely on lawful transfer mechanisms such as adequacy decisions or Standard Contractual Clauses (SCCs), and we apply supplementary measures where appropriate. Details are set out in our Data Processing Addendum. ## 13. Contact and Grievance Officer For privacy questions, requests, or complaints, contact: GetDeaddicted LLC Email: getdeaddictedllc@gmail.com **Grievance Officer (DPDP Act):** In accordance with the DPDP Act, our Grievance Officer can be reached at getdeaddictedllc@gmail.com. We will acknowledge and address grievances within the timelines prescribed by law. ## 14. Changes to This Policy We may update this Policy from time to time. Material changes will be reflected by an updated "Last updated" date and, where appropriate, direct notice to account holders.