Data we process
The public sandbox processes the JSON submitted for a decision and a one-way daily network identifier used for abuse prevention. Anonymous envelopes are not stored as transaction evidence.
Signed-in accounts store the account email and optional display name supplied by Sign in with ChatGPT, API-key hashes, plan status, decision metadata, idempotency keys, receipt hashes and usage timestamps. Secret API keys are shown once and stored only as cryptographic hashes.
Billing
Stripe processes checkout, payment methods, tax information, invoices and subscription management. MandateShield stores Stripe customer and subscription identifiers but does not receive full card or bank details.
Purpose and retention
Data is used to authenticate accounts, enforce replay protection, provide receipts, meter usage, prevent abuse and operate the service. Receipt retention follows the selected plan. Account and billing records may be retained where required for security, tax or legal obligations.
Your controls
API keys can be revoked and billing can be cancelled from the dashboard without contacting support. Account-data requests are initiated from the authenticated dashboard so identity can be verified without collecting additional documents.
Security
Do not submit personal shopping history, prompts, payment credentials, private keys, cardholder data or bank information to the pre-flight API. MandateShield is intended for policy metadata only.