CAPrivAI ← Back to CAPrivAI

Privacy Policy

Last updated: July 2026  |  Effective date: July 2026

1. Who We Are

CAPrivAI ("we", "our", "us"), operated by PriveAI Digital Pvt Ltd, is a privacy-protection service that helps users detect and remove sensitive information from content, text and documents before it is shared with AI systems or other third parties.

2. What We Collect

We collect only what is necessary to provide, secure, and improve the service:

3. What We Do NOT Collect

4. How Your Content Is Processed

Documents and text you submit are processed on CAPrivAI's own backend servers over HTTPS/TLS to identify and mask sensitive information. This processing is performed in memory and the raw content is never written to disk, logged, or retained after the response is returned to you.

Standard analysis does not send your raw content to a third-party AI provider. CAPrivAI may use server-side pattern matching, checksum validation, document-structure analysis, entity resolution, and an on-server open-source model operated within CAPrivAI infrastructure.

If you explicitly choose to use the "Send to AI" feature and have granted consent, only the sanitised output (after masking) is forwarded to the third-party AI provider you select. The original content and any detected sensitive values are never sent to third parties. External AI features are off by default. If consent cannot be confirmed, CAPrivAI treats that as no consent and does not make the external AI call.

Before any external AI request is made, CAPrivAI applies an additional validation gate to re-check the outbound payload and block the request if sensitive content is still detected.

5. Data Retention

6. Your Rights

You may at any time:

To request data deletion without logging in, visit our account deletion page or email privacy@privai.digital.

7. Cookies & Storage

Authentication currently uses short-lived access tokens and rotating refresh tokens stored in browser localStorage, protected by CSP, MFA options, token expiry, and refresh-token rotation. Migration to HttpOnly cookie-based sessions is tracked as future security work. We do not use advertising cookies or third-party tracking cookies. Local storage may also be used for UI preferences (theme, language).

8. Third-Party Services

We use the following third-party services:

9. Security

Passwords are hashed with bcrypt (cost factor 12). Access tokens expire after 15 minutes. Refresh tokens are rotated on every use and stored as hashes. All connections use HTTPS/TLS. No sensitive detection output is ever logged. MFA/TOTP secrets and Apple OAuth refresh tokens are encrypted at rest using AES-256-GCM.

10. Children

CAPrivAI is not directed at children under 13 (or 16 in the EU/UK). We do not knowingly collect personal data from children.

11. Changes to This Policy

We will notify users of material changes via in-app notice or email before they take effect. The "Last updated" date at the top of this page reflects the most recent revision.

12. Contact

Privacy questions: privacy@privai.digital
Security concerns: security@privai.digital