Privacy & Security Notice
Plain-language summary of what this site collects, what it does not, the security practices behind it, and how the tools published here handle your data.
Last updated: July 2026
Who maintains this notice
This privacy notice is maintained by Enfuse.io to describe how the enfuse.io website and the tools published on it handle information. It covers this website only — customer deployments of the Sovereign Runtime, App Factory, or MCP services are governed by the contract and data processing terms agreed with that customer.
Questions about this notice can be sent to privacy@enfuse.io.
What we collect on this website
Analytics: we use Google Analytics to understand aggregate traffic patterns — pages viewed, referring source, approximate region, device and browser type. This data is pseudonymous and is not used to identify individual visitors. Blocking analytics in your browser has no effect on site functionality.
Contact: if you email us from a link on this site, we receive the contents of that email and your email address, and retain it for as long as needed to answer and maintain the business relationship.
We do not run advertising pixels, sell data, or operate a login on this marketing site.
The RFP Review Engine
The RFP Review Engine runs in your browser. Documents you load and any analysis produced from them stay in local browser storage on your machine. We do not receive, store, or process the contents of your documents.
The engine uses a bring-your-own-key model: the API key you enter is held transiently in your browser session and is sent only to the model provider you chose (for example Anthropic), directly from your browser. We never see it. Requests you make are subject to that provider's own terms and privacy policy.
Clearing your browser storage removes the session entirely. Exports are manual — nothing is uploaded on your behalf.
Cookies and local storage
Analytics cookies are set by Google Analytics. Local storage is used by the RFP Review Engine to hold your working session between page loads. No cookies are used for advertising or cross-site tracking.
Retention and deletion
Analytics data is retained according to the retention window configured in Google Analytics. Email correspondence is retained for the life of the business relationship and then deleted on request. Browser-local RFP data is under your control and is removed when you clear site data.
Your choices
You can request access to, correction of, or deletion of information we hold about you by emailing privacy@enfuse.io. You can opt out of analytics with any standard browser or extension-level blocker. Depending on where you live, you may have additional statutory rights — tell us what you are requesting and we will respond.
Security practices for this site
Transport: the site and its assets are served over HTTPS. It is a static front-end with no application login, no user database, and no server-side session state to compromise.
Data minimisation as a control: because the RFP Review Engine executes in your browser and uses a bring-your-own-key model, document contents and provider API keys never reach our infrastructure. Keys are held transiently for the session rather than persisted to a server, so there is no central store of customer credentials or bid documents to breach.
Output handling: any model-generated or user-supplied content rendered as rich text is sanitised before display to prevent script injection in the browser.
Third parties: this site depends on a small, deliberate set of third parties — Google Analytics for aggregate traffic, our static hosting provider, and the model provider you choose in the RFP engine. We do not add advertising or data-broker tags.
Change management: the site is built from a version-controlled repository with automated builds and an automated test suite; changes are reviewed before publication and dependencies are updated as advisories emerge.
Shared responsibility
Enfuse.io is responsible for this website, the code we publish, and the practices described above. You are responsible for the documents you choose to load into browser-based tools, the security of the device and browser profile you use, and the terms of the model provider whose key you supply.
Customer deployments of the Sovereign Runtime, App Factory, or MCP services are covered by the security controls, hosting arrangements, and contractual terms agreed for that engagement — not by this page. Ask your engagement contact for the applicable documentation.
Security contact and vulnerability reporting
To report a suspected vulnerability or security issue on this site, email security@enfuse.io with enough detail to reproduce it. We will acknowledge reports and keep you updated on remediation. Please test only against this public website — never against customer environments — and avoid actions that degrade service or access other people's data.
This notice describes current practice and is not a certification or an independent audit. See our legal notice for terms of use and attribution.