Privacy Policy
Effective date: 19 July 2026 · Last updated: 19 July 2026 · Version 1.0
This policy describes how
Sovereign Chain Ltd ("Sovereign Chain", "we", "us") collects, uses, and safeguards personal data when you use
Quorum — our multi-LLM consensus platform available at
api.quorum-ai.dev and via the Model Context Protocol connector for AI clients such as Claude and Cursor.
1. Data controller
Sovereign Chain Ltd is the data controller for personal data processed through Quorum.
- Legal entity: Sovereign Chain Ltd
- UK Companies House: 16139802
- ICO registration: ZC182670
- Registered office: United Kingdom (full address available on request)
- Contact for privacy questions: privacy@quorum-ai.dev
2. Data we collect
2.1 Account data
- Email address (for account creation, billing, service notifications)
- Hashed API keys (for authentication — plaintext keys never stored)
- Subscription tier and billing status
- Payment metadata received from Stripe (last four digits of card, billing country — never the full card number)
2.2 Usage data
- Query text you submit to Quorum consensus endpoints
- Selected model providers and configuration parameters
- Model responses, agreement scores, and audit-chain hashes
- Timestamps, IP address, and request identifiers
- Aggregate error and performance metrics
2.3 Automatically collected
- Standard HTTP request headers (User-Agent, referer)
- API request rate metrics for abuse prevention
3. AI-specific disclosures
Quorum is an AI-mediated service. This section explains what happens to your query text when it flows through third-party language models.
3.1 What happens to your query
- Your query is transmitted from Quorum to one or more third-party LLM providers (see sub-processor list below), under the terms of your subscription tier.
- Each provider processes the query per its own privacy policy and API terms.
- Provider responses are collected, agreement-scored using Cohen's kappa, and returned to you.
- By default, the query, responses, and audit hash are retained in your account for 90 days for reproducibility.
3.2 Training data
- Sovereign Chain does NOT use your queries or responses to train models of its own.
- We use commercial API tiers of third-party providers whose default terms exclude your data from training their models. See the sub-processor table for provider-specific policies and links.
- You are responsible for reviewing each provider's own data-usage terms if you have strict data-residency or training-exclusion requirements.
3.3 Sensitive data
Do not submit personal data of others, protected health information, credit-card numbers, or other confidential content through Quorum unless you have a lawful basis to do so and have agreed a separate Data Processing Agreement with Sovereign Chain (available on the Enterprise tier).
4. Sub-processors
When you submit a consensus query, we route it to third-party LLM providers based on your configuration. Each provider is a sub-processor:
Model selection controls jurisdiction. You can restrict which providers Quorum routes queries to via the providers parameter on any API call — for example, EU-only routing by selecting Mistral, Anthropic (EU), and Google Cloud regions only.
5. Legal basis for processing (UK GDPR Article 6)
| Processing | Lawful basis |
| Providing the Quorum service | Contract (Article 6(1)(b)) |
| Billing and payment | Contract and legal obligation (Article 6(1)(b), (c)) |
| Security, fraud prevention, rate limiting | Legitimate interests (Article 6(1)(f)) |
| Service notifications | Contract (Article 6(1)(b)) |
| Marketing emails (opt-in only) | Consent (Article 6(1)(a)) |
6. Retention
- Query and response data: 90 days by default; extendable for Enterprise tier under a signed DPA
- Audit-chain hashes and cryptographic evidence records: 7 years (aligned with UK financial-services recordkeeping norms — override on request)
- Account data: for the duration of your subscription plus 12 months after cancellation
- Billing records: 7 years (statutory requirement)
- Aggregated non-identifiable metrics: indefinitely
7. Your rights (UK GDPR)
- Access — request a copy of your personal data
- Rectification — correct inaccurate data
- Erasure ("right to be forgotten") — request deletion, subject to retention obligations
- Restriction of processing
- Data portability — receive your data in a structured, machine-readable format
- Object to processing based on legitimate interests
- Withdraw consent for marketing emails at any time
- Lodge a complaint with the UK Information Commissioner's Office — ico.org.uk
To exercise any right, email privacy@quorum-ai.dev. We respond within 30 days as required by law.
8. International transfers
Some sub-processors are outside the UK/EEA (notably US, Canada, China, Singapore). We rely on:
- UK-approved Standard Contractual Clauses (SCCs) where required
- Provider-specific transfer mechanisms (e.g., EU–US Data Privacy Framework where applicable)
- Your explicit configuration when you select providers outside your preferred jurisdiction
9. Security
- All traffic is TLS 1.3 encrypted in transit
- API keys are stored as SHA-256 hashes (plaintext never persisted)
- Audit chain uses Ed25519 signatures for tamper-evident logging
- Cloud Run and Firestore use Google-managed encryption at rest
- Access to production systems is restricted to authorized personnel with two-factor authentication
- Data breaches materially affecting your data will be reported to the ICO within 72 hours as required by law, and to you without undue delay
10. Cookies
The Quorum API (api.quorum-ai.dev) does not set cookies. The marketing site may set functional cookies for session management and (with your consent) analytics. See the cookie banner on the marketing site for details.
11. Children
Quorum is not directed at children under 16 and we do not knowingly collect their personal data. If you believe we have, contact us and we will delete it.
12. AI-generated output disclaimer
Outputs produced by Quorum are advisory and generated by machine-learning systems that may produce inaccurate, biased, or misleading content. Quorum output is not a conformity assessment under Regulation (EU) 2024/1689 (EU AI Act), and Sovereign Chain Ltd is not a Notified Body under Article 31 of that Regulation. You remain responsible for verifying and acting on Quorum output.
13. Changes to this policy
Material changes will be notified by email to registered users at least 30 days before taking effect. Historic versions are available at api.quorum-ai.dev/privacy/versions.
14. Contact
© 2026 Sovereign Chain Ltd. Registered in the United Kingdom, Companies House 16139802. ICO registration ZC182670.