A.N.D Sovereign Group UK Limited

Privacy

One policy, covering everything we make and everything we do. The short version: our software runs on your device, and we do not track what you do with it.

No analyticsNo usage trackingNo profiling
We cannot lose what we never collected, and we cannot be made to hand over what we do not hold.

Most of what we make sends us nothing at all. No analytics, no usage tracking, no account required. Your conversations, models, settings, keys and files stay on your machine, under your control.

Where something does reach out, it is named on this page and it carries only what that job needs. Never your content, and never a record of what our software found on your computer.

This policy covers the company and every product. Written in plain English on purpose, because a privacy policy nobody can read is not really a privacy policy.

Product by product

What each thing does, and what it does not.

Sovereign Inference

  • Sends us nothing. No telemetry, no analytics, no account, no activation call.
  • Everything stays in one folder on your machine: chats, memory, settings and keys.
  • Web search and cloud models are off unless you switch them on. When you do, the query or the conversation goes straight to the provider you chose, under their policy, using your key. It does not pass through us and we never receive a copy.
  • Problem reports are made only when you ask for one. They carry the app version, hardware details and recent logs, never your keys or private data, and reach us only if you choose to send one.

Sovereign Security

  • Scan results never leave your machine. There is no cloud console, so there is nowhere for them to go.
  • It does reach out, and here is why. Threat data and updates have to stay current, because security software that never looks outward is worthless within a month. Those connections go to a published list of addresses and carry nothing about you.
  • Licence checks happen on your machine. A minimal ping is sent only if an account passes three days beyond its billing date, and a signal is sent when a critical update exists, because relying on an email you might miss is not good enough for security software.
  • The vault is yours alone. The key comes from your password and exists nowhere else. We cannot open it, and neither can anyone else.
  • Breach checking is local by default. The bundled list needs no lookup at all. If you enable the optional password check, five characters of a hash leave your machine. Never the password.

VPN, Communications and custom work

  • Sovereign VPN collects nothing. No connection records, no traffic records, no activity history tied to a person. If a request for a user's data arrives, there is nothing to give.
  • Sovereign Communications is end to end encrypted. Messages and files are readable only by the people holding the keys. That includes us: we cannot read what passes through it, by design.
  • Custom and enterprise work stays yours. Material you give us is used to build your thing and nothing else. We do not train anything on it, and finished builds carry no telemetry channel back to us.
  • We do not publish a client list and we keep no portfolio.
This website

And the ordinary business of being a company.

Cookies, and why there is no banner

  • This site does not use cookies. None at all, first party or third party, so there is nothing to accept and nothing to refuse. A consent banner would be asking your permission for something that is not happening.
  • Nothing is stored in your browser either. No local storage, no session storage, no fingerprinting.
  • No advertising trackers and no third party analytics following you around. Our visitor counts come from the server, which counts requests rather than people.
  • Fonts are requested from api.fontshare.com and fonts.googleapis.com so pages render as designed. Those are the only external requests an ordinary page makes, and each provider sees only that a font was fetched.
  • Our host keeps standard server logs, as every web host does, for delivering and securing the site.
  • If we ever add something that does set a cookie, this page changes first.

When you write to us

  • We keep your email to answer it, and to carry on the conversation if it turns into work.
  • It is not added to a marketing list. We do not run one.
  • Never send us a password, a licence key or a vault file. We will never ask you for any of them.

Paying for something

  • We do not hold your billing details at all. No card numbers, no payment details, nothing of the kind on any system of ours. They exist only with the payment provider that takes the payment.
  • Payments are handled entirely by a payment provider, under its own terms and its own privacy policy. Your card never touches our systems, because it never reaches them.
  • No regional pricing, so nothing in the payment process has any reason to work out where you are.
How this is enforced

A privacy policy
with a build gate behind it.

If our code reaches an address this policy does not name, the release is refused. It is not a promise about our intentions, it is a check that runs before we are able to ship anything at all. We would rather be stopped by our own machinery than trusted on our word.

Your rights

There is usually nothing for us to hand over, which is rather the point.

Under UK data protection law you have the right to access, correct, delete and port your personal data, and to object to how it is used. Those rights apply fully. It is simply that in most cases we are not holding anything to apply them to, because data created by our software lives on your device where you control it.

What we may actually hold

  • Correspondence you have sent us, and our replies.
  • Billing records for anything you have bought, kept as long as the law requires us to keep them.
  • Material for custom work, for as long as we are building or maintaining the thing you asked for.
  • A problem report, but only if you chose to send us one.

Asking us about it

  • Write to Contact@ANDSovereign.com and a person will answer.
  • We will tell you plainly what we hold, and delete what we are not legally required to keep.
  • If you are not satisfied, you can complain to the Information Commissioner's Office, the UK's data protection regulator.
Questions about this policy

Ask us anything about it.

If something here is unclear, or you want to know exactly what happens to a particular thing, write to us and we will tell you straight. We may update this policy, and material changes will be reflected in the date below.

A.N.D Sovereign Group UK Limited, registered in the United Kingdom.
Last updated: 26 August 2026