STEINWALL Guardian STEINWALL Guardian

Privacy Policy

Effective 25 September 2026Operated by Sebastian Keil · STEINWALLcontact: [email protected]
In plain terms

STEINWALL Guardian analyzes messages you submit for harassment, threats and fraud. Content is stored encrypted under your own key on STEINWALL's server and analyzed by AI models that STEINWALL runs itself, on its own computer or on rented GPU capacity. We do not sell your data and do not use it for advertising.

What we process, and why
DataSourcePurpose
Pasted textYou type or paste it inAnalyzed for harassment, threats, fraud
Uploaded images / video clips / voice notesYou upload themConverted to text, then analyzed the same way
TikTok profile (open ID, display name, avatar)TikTok Login Kit, scope user.info.basic, only after you connectShow which account is linked
Account data (username, e-mail, password)You provide it at registrationLogin; password stored only as a salted hash
1

Who is responsible

STEINWALL Guardian is operated by Sebastian Keil, STEINWALL, Lindenallee 2, 14050 Berlin, Germany (contact: [email protected]). The service is available at guardian.steinwallai.com.

2

Where your data lives

Your case records are stored encrypted on STEINWALL's own server, in a separate store per account. The encryption key is derived from your password and a recovery phrase generated only for you. STEINWALL cannot read stored case contents without your key. If you lose both your password and your recovery phrase, your data cannot be recovered.

While you are logged in and an analysis is running, the server necessarily processes the submitted content in memory in order to analyze it.

3

How the analysis works, and who helps us

Text, image, video-frame and voice analysis run on AI models (Qwen3 via Ollama, faster-whisper) that STEINWALL operates itself. Depending on load, an analysis runs either on STEINWALL's own computer or on a GPU that STEINWALL rents from Modal Labs, Inc. (USA) as a processor, where the same self-hosted model is run. Content sent there is processed only to return the analysis result. We do not send your content to OpenAI, Google, Anthropic or other third-party AI providers, and we do not use it to train AI models.

Transfers to the USA are based on the provider's data processing terms and EU Standard Contractual Clauses.

4

The TikTok connection, specifically

STEINWALL Guardian offers two optional TikTok connections. You decide whether you use them.

  • Login (TikTok Login Kit): scope user.info.basic only – your TikTok open ID, display name and avatar, used to link your Guardian account to your TikTok profile and to show which account is connected.
  • Comment check (TikTok API for Business, Accounts API): if you connect your own TikTok account for the comment check, Guardian reads – read-only – your basic account information and account insights (for example follower numbers), the list of your own videos and the comments under your own videos. The comments are checked for insults, threats, harassment, spam and scam links, and the result is shown only to you in your Guardian account. Comments that are flagged can be saved as a case record in your encrypted store (section 7); harmless comments are not kept as case records.
  • Guardian does not post, reply, comment, delete or send anything on TikTok on your behalf, and it does not access other people’s accounts or your direct messages.
  • You can disconnect at any time in Guardian (Konten → Trennen) or in your TikTok account settings; disconnecting revokes and deletes the stored TikTok tokens.
5

The Instagram connection (Meta), specifically

Optionally you can connect your own Instagram professional account through Instagram Login (Meta Platforms). Guardian requests only these permissions and uses them only to read:

  • instagram_business_basic – your Instagram account ID, username and profile picture, to show which account is connected.
  • instagram_business_manage_comments – to read the comments on your own posts so that Guardian can flag insults, threats, harassment and scam.
  • instagram_business_manage_messages – to read messages sent to your own account so that Guardian can flag threats and scam.

The comment and message check is activated only after Meta has approved these permissions in its App Review; until then only the profile connection works. Data received from Meta is used only to provide this check to you. It is not sold, not used for advertising, not shared with third parties and is handled in line with the Meta Platform Terms. Guardian does not post, reply, delete or send anything on Instagram. You can disconnect at any time in Guardian (Konten → Trennen) or in Instagram under Settings → Apps and websites; disconnecting deletes the stored Instagram tokens.

6

Sharing and sale of data

We do not sell your data, we do not share it with advertisers or data brokers, and we do not use it for advertising. Service providers involved: Cloudflare, Inc. (transport of web traffic to the service) and Modal Labs, Inc. (rented GPU, see section 3).

7

Retention and deletion

Case records are kept until you delete them. Deleting a case removes it from your encrypted store. Because your encryption key is not stored in plain form, we cannot restore deleted data.

7a

How to delete your data (data deletion instructions)

  1. Single cases: open the case in Guardian and delete it.
  2. TikTok or Instagram data: in Guardian go to Konten and click Trennen (disconnect). This revokes access and deletes the stored tokens. You can also remove STEINWALL Guardian in TikTok, or in Instagram under Settings → Apps and websites.
  3. Your whole account and all stored data – yourself, immediately: in Guardian open Tarife, scroll to Konto löschen, enter your password and the word LOESCHEN and confirm. Your account, all case records and all connection tokens are deleted at once and connected platforms are disconnected; this cannot be undone.
  4. Alternatively by e-mail: send an e-mail to [email protected] with the subject “Delete my Guardian data” and your Guardian username. We delete your account, all case records and all connection tokens within 30 days and confirm the deletion by e-mail.
8

Your rights

If you are in the EEA or UK you have the rights of access, rectification, erasure, restriction, portability and objection (GDPR Art. 15–21), and the right to lodge a complaint with a supervisory authority. Contact us at the address below. Legal basis: performance of the contract (Art. 6(1)(b) GDPR) and, for the optional TikTok connection, your consent (Art. 6(1)(a) GDPR), which you can withdraw at any time.

9

Changes to this policy

If this policy changes, the effective date at the top of this page will be updated.

10

Contact

Questions about this policy or your data: [email protected].