Privacy policy
Veil by Goldspire · Last updated 14 July 2026
Who operates Veil
Veil is operated by Goldspire Ventures Ltd. This notice explains how Veil processes information when you use the browser extension, portal, cloud account features, support service or organization administration tools.
What Veil does locally
Veil inspects text you select, paste or type in supported web applications to identify sensitive patterns and offer protective actions. Detection, masking, encryption and decryption run in the browser.
- Highlighted plaintext, full page content, email bodies and clipboard contents are not sent to Goldspire for detection or local protection.
- Personal and Business passphrases are entered and retained on approved browsers. They are not uploaded to Veil cloud and cannot be recovered by Goldspire.
- Local settings, encrypted local passphrase material, approved-site rules, snoozed sites, Personal learning decisions and recent diagnostics may be stored in browser extension storage.
Cloud information we process
The information processed depends on the features you choose:
- Accounts and browser approval: email address, account or organization identifier, browser-generated device identifier, browser/platform information, verification timestamps and revocation status.
- Organization administration: Business workspace name, administrator email, membership, sub-teams, policy settings, join-code records and device status.
- Protected shares and tokens: ciphertext, recipient identifiers, category, expiry, read limits and delivery status. Goldspire does not receive the customer-held passphrase used to decrypt locally protected content.
- Organization security events: category, severity, host domain, source, action, confidence, timestamp, device identifier and member email. Matched text and decrypted content are rejected by the API.
- Billing: plan, subscription status, customer and subscription identifiers. Payment-card data is processed by Stripe and is not stored by Goldspire.
- Support: the message and contact details you submit, plus the diagnostic metadata shown to you at submission. When Goldspire Support AI is enabled, the submitted message and metadata may be sent to our contracted AI provider for policy-bound classification and reply drafting. Contact details are excluded from the model input where practical, and substantive replies remain owner-approved.
Browser approval and account security
Every browser installation that accesses Personal or Business cloud data must be approved from the relevant mailbox. Approval links expire and are bound to the requesting browser. Organization administrators can revoke Business browsers. Account and device information is used to provide access control, detect misuse and operate the service.
Diagnostics and learning
Automatic client diagnostics remain on the browser and leave the device only when you explicitly submit a support request. Personal Copilot learning decisions remain local in Veil 1.5. Organization security events are metadata-only and may be required by the organization’s active policy. Protection updates are validated before use and rejected if authenticity cannot be established.
Service providers and international transfers
Goldspire uses infrastructure, database, email-delivery, billing, source-control and monitoring providers to operate Veil. The current provider summary is available in the Veil Trust Center. Where data is transferred outside the European Economic Area, Goldspire uses an applicable legal transfer mechanism and appropriate safeguards.
Retention
Account, organization and billing records are retained while the service relationship is active and for the period reasonably required for legal, security, accounting and dispute purposes. Verification tokens expire automatically. Support, security and backup retention periods are summarized in the Veil Trust Center. Local browser data remains until you clear it or uninstall Veil.
Your choices and rights
You can disable Veil on a site, clear extension data, disconnect a browser or uninstall the extension. Depending on applicable law, you may request access, correction, deletion, restriction, portability or objection by contacting . An organization may be the controller for workforce data processed through its Veil deployment; in that case, submit employment-related requests to the organization first.
Security limitations
Veil provides field-level browser protection in supported Chrome and Edge web fields and editors. It is not end-to-end encrypted email, does not protect a compromised endpoint, and does not hide message metadata such as sender, recipient, subject, time or approximate length. Detection can produce false positives and false negatives.
Veil 1.5 does not inspect the contents of attachments, images or scans, audio, native desktop or mobile applications, or unsupported custom and canvas-based editors. On supported AI sites, it can pause or block a file action without reading or reporting the filename, file type, path or contents. Structured-format coverage varies by country and language; the current boundaries are summarized in the Veil Trust Center.
Contact
Goldspire Ventures Ltd · Privacy: · Security reports: