Legal
The rule we hold ourselves to: we store what we need to bill a call, keep a record you can verify, and fix what breaks. Not the text of your answers.
Effective 6 September 2026. Paragon Reflex is a product line of Univault Technologies LLC, Salt Lake City, Utah, United States. In this page “we” is Univault Technologies LLC and “you” is whoever is reading, calling the API, or holding a key. Questions and requests go to [email protected] and the founder reads them.
This is the same sentence the public model card carries, and it is the whole policy in miniature. Per API call we store token counts, cost, latency, status, the rules you sent, the verdict rows with the judge’s reasons, and the SHA-256 hash of the answer. The prompt and the answer text pass to the model tier under its API terms and are not stored by us on this path. Certificates are unlisted and readable by anyone holding the link.
Everything below is that sentence with the edges filled in. Where a section grants us less than the short version implies, the narrower reading is the one that binds us.
When you call /v1/chat/completions on api.paragonreflex.com, three things happen to your data.
It goes to the model tier. Your prompt, any images, and the rules travel to the frontier model tier that serves the answer. That tier processes them under its own API terms. We pass them through; we do not keep a copy of the prompt or the answer text on this path.
We write a usage row. One row per call, holding:
This row is how billing, rate limits and the daily spend cap work. Without it we cannot tell you what you spent.
We write a certificate. If the call carried rules, the record holds:
The hash is the point. It is a one-way fingerprint: it proves a given answer is the judged answer and cannot be turned back into the answer. That is how a record can be verifiable and content-free at once.
Your rules are yours and they are deletable. Rules live outside the model weights. A rule you stop sending is gone from the next call, and rules stored on your tenant can be deleted on request.
We do not train on your content. Nothing you send becomes training data for a model we ship to anyone else. The one exception is the one you would have to ask for: if you buy an adapter trained on your own material, that is trained on your data, for you, under a signed agreement that says so, and it is not served to anyone else. Absent that signature, your content is never in a training corpus.
Every certificate has a page at paragonreflex.com/c/… and a JSON form at
api.paragonreflex.com/v2/c/…. Both are unlisted, not private:
the identifier is long and unguessable, the pages carry noindex so search engines
do not list them, and there is no directory of them. But anyone you give the link to can open
it, with no key and no account. That is deliberate — the link is how you show a third party
the rules were kept, and it has to work for someone who has no relationship with us.
What this means for you: treat a certificate link the way you would treat any share link. Your rules are printed on that page. If your rules contain something you would not hand to a stranger, do not circulate the link, and ask us to revoke it.
Revocation: mail us the certificate id and we will take the page down. The hash chain keeps the fact that a record existed and was revoked; the contents stop being served.
Analytics. We run our own analytics rather than sending you to a third-party ad network. It records pageviews and clicks: the page, the referrer, any UTM campaign tags on the link you arrived by, an approximate location (country, region, city) that our edge provider derives from your IP address, and browser, operating system and device class. It also records a random visitor identifier so a return visit is not counted as a new person.
On our own server side we additionally record whether a step worked — did the parse succeed, how long it took, how many of your rules were readable, did the key mint and the mail send. These are counts, timings and outcomes only. By construction that path never records a rule’s text, an answer, or an email address.
Cookies and browser storage. Everything we set is first-party. We run no advertising cookies and no cross-site trackers, and nothing here is sold or shared.
Two actual cookies:
Two things kept in your browser’s own storage, which is not a cookie and is not sent to us automatically:
Do Not Track. We do not sell personal information and we run no cross-site advertising trackers, so there is nothing here for a DNT signal to switch off.
The free tier gives a browser ten verdicts a day with no account. Keeping that honest needs some notion of “who”, and we use the weakest one that works: alongside the cookie, we record a keyed hash of your IP address, not the address itself. The hash is computed with a secret only we hold, cannot be reversed to an IP, and is used for nothing but counting free runs against abuse.
When you request a key, reserve a dev kit, or send an interest form, we get your email address and whatever you typed into the form. We use it to answer you, to send your key, and to tell you about the thing you asked about. We do not sell it, rent it, or add it to a list you did not ask for. Ask us to delete it and we will.
Payments run through Stripe. Your card number goes to Stripe and never touches our servers — we could not store it if we wanted to. What we keep is an order row: what you bought, the amount, the currency, the time, Stripe’s reference for the payment, the email on the receipt, and for a physical order the shipping address you gave. We keep these because tax and accounting law requires it.
These are service providers acting on our instructions. We do not sell personal information to anyone, and we have never done so.
Where it lives. The rules layer, the judge and the record run at the Cloudflare edge; the model tier is hosted in the United States. If you are outside the United States, using the service means your data is processed there.
Whatever jurisdiction you are in, one address does all of it: [email protected]. You can ask us for a copy of what we hold about you, ask us to correct it, ask us to delete it, ask us to revoke a certificate, or ask us to stop mailing you. We answer within 30 days and we do not charge for it. We will not treat you worse for asking.
If you are in the EEA or the UK, our basis for processing is performance of a contract for anything tied to a key or an order, and legitimate interest for analytics and abuse control. If you are in California, we do not sell or share personal information as those terms are defined there.
This is a developer and business product and is not directed at children. Do not use it if you are under 16. If we learn we hold a child’s personal information, we delete it.
When this page changes in substance, the effective date at the top changes with it, and if the change is material we mail the address on every live account. We do not quietly widen what we collect.
Univault Technologies LLC, Salt Lake City, Utah, United States.
[email protected]
— privacy requests, data requests and security reports all land there.
See also the terms of service.