# Data and approval policy

Canonical: https://savrn.com/cloud/docs/platform-data-policy

SAVRN Cloud · Coming soon. Public documentation and a browser simulation are available; connected services are not yet available.

Permission to use a source, execute a task and release a model are separate decisions in SAVRN Cloud. This guide identifies where those decisions belong and explains why a browser-local approval does not establish institutional authorization or an approved data-processing environment.

**SAVRN Cloud · Coming soon · Public preview · Browser-local simulation · No live compute or payments**

## Choose appropriate inputs

Use invented examples or public text throughout this application. Prompts, project names, task descriptions and generated records can persist in browser localStorage. This public preview does not establish encryption, retention, institutional approval or a compliant processing environment.

A useful test task uses a fictional department, a short public passage or a synthetic dataset. Keep student records, patient information, controlled research, confidential sponsor materials and production secrets out of this public preview. Browser-local storage is not an approved institutional data boundary.

## Trace decisions

[Work Orders](https://savrn.com/cloud/console/#/work-orders), [Approvals](https://savrn.com/cloud/console/#/approvals), [Datasets](https://savrn.com/cloud/console/#/datasets) and [Candidates](https://savrn.com/cloud/console/#/candidates) show where permission decisions belong. Review the specific record and proposed purpose before recording a local decision. Dataset approval, execution approval and model-release approval represent different decisions.

An approved local record demonstrates the interaction. It does not authorize real processing or create a legally effective institutional approval.

## Before connected services launch

Record processing, storage, logging and control-plane locations separately. Define which data categories each deployment may handle, how permissions are checked, who can inspect outputs and when records are deleted. Block silent routing to an external supplier when policy requires another placement. A private endpoint or owned GPU does not alone prove data residency or compliance. Publish the actual controls and evidence in the [deployment matrix](https://savrn.com/cloud/docs/trust-deployment-matrix), with unsupported claims left explicit.
