Privacy Policy
Last updated: August 11, 2026 · Governed by GDPR and German law
1. Controller (Verantwortlicher)
SafAI has two providers, depending on your subscription. Both are named in full in the Legal Notice.
Individual subscriptions — “the Provider”
Kritesh Shridhar, Ferdinand-Weiß-Str. 54, 79106 Freiburg im Breisgau, Germany
Email: kritesh@shridhar.de
Business and enterprise subscriptions — “EcoReady” (contracting party and biller for business and enterprise subscriptions)
EcoReady, c/o Campus Technologies Freiburg GmbH, Stefan-Meier-Str. 8, 79104 Freiburg, Germany
EcoReady is the controller for account, seat, and billing data of business and enterprise customers.
How the personal data that SafAI detects is handled — and the narrow cases in which any of it reaches us — is described in Section 2.
2. Core Principle: Local-First Processing
SafAI is designed with privacy as its foundation. In the SafAI desktop app and browser extension, all detection and scrubbing happens on your own device. Your original prompts — including any personal data they contain — are never sent to us or to any third party for processing by SafAI. Only anonymised (scrubbed) text leaves your device when you submit a prompt to an AI chat service.
Enterprise deployments. Business and enterprise agreements may include server-side components, such as a gateway that protects the tools and data an AI assistant connects to. Where one is used, detection runs on the customer’s own infrastructure as named in that agreement, rather than on the end user’s device. Who acts as controller and who as processor for that processing is set out in the enterprise agreement and its data processing agreement.
In both cases, neither provider receives or stores the personal data SafAI detects, or the mappings between those values and their placeholders. We do not operate a cloud detection pipeline and do not process the content of your conversations.
One exception, and only if you choose it: if you use the “Report missed word” function to tell us that our scrubber missed something, the word or phrase you flag is sent to us so we can improve detection. That is the only route by which detected content reaches us. See Section 3.4.
We do separately process account and subscription data (Section 3.1), feedback you send us (Section 3.2), anonymous service-health telemetry such as error codes and app version (Section 3.5), a record when your vault reaches 80% of its limit (Section 3.6), — only if you switch it on — which detection categories we got wrong (Section 3.7), and a voluntary crash report if document cleaning fails and you confirm sending it (Section 3.8). For enterprise customers, EcoReady also holds audit records of which tools were called; those records are metadata only and do not include request content. None of this includes your prompts or the personal data SafAI detects in them.
3. Data We Collect and Why
3.1 Account and Subscription Data
When you create an account or subscribe, we collect:
- Email address
- Subscription plan and status
- Stripe customer and subscription ID (reference only — no card data)
- Subscription start and end dates
Purpose: To manage your subscription, verify access, and provide customer support.
Legal basis: Performance of a contract (Art. 6(1)(b) GDPR).
Retention: For the duration of your subscription plus 3 years for accounting and legal compliance obligations under § 147 AO (German Fiscal Code).
3.2 Feedback Data
When you submit feedback — through the SafAI desktop app, the browser extension, the contact form on this website, or the admin dashboard — we collect:
- Your feedback message (free text you enter)
- Your email address (automatically associated from your account to allow us to respond and to administer discount programs for feedback plan subscribers)
- App version at time of submission
- Which surface you sent it from (for example the desktop app, the extension, or this website), so we can reproduce the problem
Purpose: Product improvement, responding to your feedback, and administering feedback-based subscription discounts. Feedback is emailed to our support team when you submit it, so that we see it and can reply.
Legal basis: Legitimate interests (Art. 6(1)(f) GDPR) — improving the product and fulfilling discount commitments; performance of a contract where a discount plan applies (Art. 6(1)(b) GDPR).
Retention: Up to 2 years, or until you request deletion.
Note: Please do not include sensitive personal data or third-party personal information in your feedback messages.
3.3 Data Stored Locally on Your Device
The SafAI desktop application stores account information (email, subscription plan, validity date) locally on your device in an application data directory. This data is used solely to display your account status within the app and validate your subscription. It is not accessible to us remotely and is not transmitted anywhere without your action.
3.4 SafAI Browser Extension (Chrome)
The optional SafAI browser extension for supported AI chats works only together with the SafAI desktop app. It does not process your prompts on its own.
- Local connection only: The extension communicates with the SafAI desktop app on your device via a local connection. It does not send chat or prompt content to SafAI servers.
- Supported sites: The extension runs only on supported AI chat interfaces (e.g., ChatGPT, Claude, Gemini) to offer scrubbing in the chat UI.
- Account status: Subscription verification is handled through the desktop app and its local services. The extension does not independently upload conversation content for account checks.
- Missed-detection reports: If you use the “Report missed word” function, the extension sends us the specific word or phrase you flag, together with your email address, subscription plan, operating system, browser user agent, and extension version. This is transmitted only when you actively choose to submit a report. Because you are reporting text that our scrubber failed to detect, that text may itself contain personal data.
Please do not submit missed-detection reports containing another person’s personal data, or any sensitive information (for example health, financial, or credential data). Report the pattern where you can rather than the value itself.
Legal basis: Performance of a contract (Art. 6(1)(b) GDPR) for subscription verification; legitimate interests (Art. 6(1)(f) GDPR) for the local privacy function when you choose to use it, and for improving detection accuracy from reports you choose to send.
Retention (missed-detection reports): Up to 2 years, or until you request deletion.
3.5 Subscription and Service Health Telemetry
The SafAI desktop app and the browser extension send anonymous, non-PII telemetry events to monitor subscription verification reliability and service health. These events are:
- Event types: subscription check results (success, network failure, inactive subscription), forced logouts, detection-engine crashes, local service errors.
- Data sent: event type, error code, app version, and platform (e.g. “darwin”). Events sent by the desktop app also include a pseudonymized hash (SHA-256) of your email address. Events sent by the browser extension contain no email address or hash of one.
- No chat content, PII entities, or browsing data is included in telemetry.
Purpose: To monitor subscription verification reliability, detect service degradation, and improve application stability.
Legal basis: Legitimate interests (Art. 6(1)(f) GDPR) — ensuring service integrity and reliability.
Retention: Telemetry events are retained for up to 90 days. The pseudonymized hash cannot be reversed to identify you without access to the original email, which is stored separately under Section 3.1.
3.6 Vault Usage Thresholds
SafAI stores the mappings between your personal data and the placeholders that replace it in a local vault. When a session first reaches 80% of the vault limit, the desktop app records that fact so that we can contact you about your plan before the limit is reached.
- Data sent: your account email address, the time, the percentage used, and how that usage divides between mappings that can be replaced automatically and mappings that cannot.
- Recorded once per session per threshold, not on every use.
- No chat content, no document content, no personal data detected by SafAI, and none of the text it was found in is included.
Purpose: To tell you when you are approaching your vault limit, and to contact you about raising it. This is a commercial purpose, and we state it plainly rather than describing it as service health.
Legal basis: Legitimate interests (Art. 6(1)(f) GDPR) — informing customers about the limits of the service they are paying for. You may object at any time by contacting us.
Retention: Up to 24 months.
3.7 Detection Quality (optional, off unless you turn it on)
SafAI can tell us when it labels something incorrectly — for example, that it marked a company name as a person’s name. This is switched off by default. Nothing is sent unless you turn it on in Setup or in Account settings, and turning it off stops transmission immediately.
- Data sent: the action you took (added, edited, or removed a detection), the category involved and the category you changed it to, which surface it happened on, your account, and the app and detection versions.
- Never sent: the detected value or any part of it, the surrounding text, your prompt, your document, the position or length of anything in your text, or the placeholder that replaced it. The data we receive is structurally incapable of carrying them.
Purpose: To measure how accurately detection performs in real use, so that mislabelled and missed categories improve over time.
Legal basis: Consent (Art. 6(1)(a) GDPR). You may withdraw it at any time; withdrawal does not affect data already processed.
Retention: Up to 24 months.
Business and enterprise customers: this setting is chosen by your organisation’s administrator and applies to everyone in the organisation. You can see the setting that applies to you in Account settings, but you cannot change it yourself. Contact your administrator for details. The arrangement is described in the data processing agreement between EcoReady and your organisation.
3.8 Voluntary Crash Reports
If document cleaning fails, you can choose to send a crash report from the error screen. Nothing is sent unless you preview the payload and confirm. This is a separate channel from telemetry (Section 3.5), vault-usage records (Section 3.6), and detection-quality events (Section 3.7).
- Data sent: a machine-readable error code, app version, operating system, that detection ran on-device, the file type (extension only), a coarse file-size bucket, and an optional short note you typed after seeing the preview.
- Never sent: the file name, the file contents, extracted text, stack traces, or any personal data SafAI detected.
Purpose: To diagnose extraction failures we cannot see from on-device processing.
Legal basis: Consent (Art. 6(1)(a) GDPR). You may simply not send a report.
Retention: Up to 24 months.
4. Data We Do NOT Collect
- The content of your AI prompts or conversations
- The PII entities detected or scrubbed by the extension
- Browsing history or visited URLs
- Device identifiers, or data used to build an advertising or tracking profile
- Payment card details (handled entirely and exclusively by Stripe)
The single exception is a missed-detection report you choose to submit, which contains the word or phrase you flag and the technical details listed in Section 3.4. Absent such a report, none of the above leaves your device.
5. Infrastructure and Sub-processors
We use the following processors (Auftragsverarbeiter) under Art. 28 GDPR. Each processes personal data only for the stated purpose and on our documented instructions.
Supabase (database hosting): Stores account, subscription, device registration, and feedback data in PostgreSQL hosted in the EU Central 1 (Frankfurt, Germany) region. Account data remains in the EU. A Data Processing Agreement (DPA) is in place. Purpose: account and subscription management, feedback storage. Legal basis: Art. 6(1)(b) and (f) GDPR.
Stripe (payments): Processes payment transactions independently. We receive only a subscription reference ID and your email address from Stripe webhooks — no card data. Stripe is PCI-DSS Level 1 certified. Stripe's privacy policy governs payment data: stripe.com/privacy. Purpose: billing and subscription payments. Legal basis: Art. 6(1)(b) GDPR.
Cloudflare (website hosting and CDN): Hosts our marketing website and provides security and content delivery. Cloudflare processes IP addresses and request metadata in transit. Purpose: website availability, performance, and security (including DDoS protection). Legal basis: Art. 6(1)(f) GDPR. Cloudflare acts as a processor under Art. 28 GDPR.
Google Analytics (website analytics, optional): With your consent via our cookie banner, we use Google Analytics (measurement ID G-VF11XFK4LZ) to collect aggregate website usage statistics. IP anonymization is enabled. Analytics storage is denied until you opt in; you can withdraw consent at any time via the cookie banner. Purpose: understanding aggregate traffic and improving the website. Legal basis: Art. 6(1)(a) GDPR (consent). Google's privacy policy: policies.google.com/privacy.
LarkSuite (business email and CRM): Hosts business email and customer relationship tools used for legal, support, and enterprise correspondence (e.g., kritesh@shridhar.de, safai@shridhar.de). Purpose: handling enquiries, support, and customer communication. Legal basis: Art. 6(1)(b) and (f) GDPR.
Brevo (transactional email): Delivers one-time password (OTP) emails for SafAI desktop app sign-in and sign-up. The marketing website does not offer account login. Purpose: authentication emails for the desktop app. Legal basis: Art. 6(1)(b) GDPR.
Neeto (live chat widget): When enabled, provides a live chat widget on our website. Messages you send through the widget are processed by Neeto to deliver chat functionality. Purpose: website support chat. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in providing support); Art. 6(1)(b) GDPR where your message relates to an existing contract.
Cal.com (meeting booking): When you choose to book a demo or enterprise call, the scheduling interface is provided by Cal.com. Cal.com processes the name, email, and meeting details you submit in order to create the booking. The embed script loads only after you click a booking control. Cal.com's privacy policy: cal.com/privacy. Purpose: scheduling product demos and enterprise conversations. Legal basis: Art. 6(1)(b) GDPR.
6. Cookies and Tracking
We use cookies and similar technologies to ensure the security and functionality of our website. Optional analytics run only with your consent.
- Essential cookies: Required for site security and processing payments via Stripe. These cannot be disabled.
- Google Analytics (optional): With your consent, we use Google Analytics to collect aggregate, anonymized traffic data. IP anonymization is enabled. Analytics storage remains denied until you accept via the cookie banner. You can change your choice at any time through the banner.
- Neeto chat: The live chat widget may set cookies or use local storage when you interact with it.
- Cal.com (booking): Opening a demo booking control loads Cal.com's scheduler, which may set cookies required to complete the booking.
We do not use advertising networks, tracking pixels for retargeting, or data brokers.
7. International Data Transfers
Account and subscription data stored via Supabase remain in the European Union (Frankfurt, Germany).
Some processors listed in Section 5 may process data outside the EEA (for example, Stripe, Google, Brevo, Cloudflare, LarkSuite, Neeto, or Cal.com). Where such transfers occur, they are governed by appropriate safeguards under GDPR — typically EU Standard Contractual Clauses (SCCs) under Art. 46(2)(c) GDPR and/or adequacy decisions — as offered by the respective processor. You may request further information about safeguards by contacting us.
8. Your Rights (Betroffenenrechte)
Under the GDPR, you have the following rights regarding your personal data:
- Right of access (Art. 15 GDPR): Request a copy of all personal data we hold about you.
- Right to rectification (Art. 16 GDPR): Request correction of inaccurate or incomplete data.
- Right to erasure / "right to be forgotten" (Art. 17 GDPR): Request deletion of your data, subject to overriding legal retention obligations.
- Right to restriction of processing (Art. 18 GDPR): Request that we limit how we use your data.
- Right to data portability (Art. 20 GDPR): Receive your data in a structured, commonly used, machine-readable format.
- Right to object (Art. 21 GDPR): Object at any time to processing based on our legitimate interests.
- Right to withdraw consent: Where processing is based on your consent, withdraw it at any time without affecting the lawfulness of prior processing.
To exercise any of these rights, contact: kritesh@shridhar.de. We will respond without undue delay and within one month as required by Art. 12 GDPR.
9. Right to Lodge a Complaint (Beschwerderecht)
You have the right to lodge a complaint with the competent supervisory authority at any time. The supervisory authority for Baden-Württemberg is:
Der Landesbeauftragte für den Datenschutz und die Informationsfreiheit Baden-Württemberg
Lautenschlagerstraße 20, 70173 Stuttgart, Germany
Tel: +49 711 615541-0
www.baden-wuerttemberg.datenschutz.de
This right exists without prejudice to any other administrative or judicial remedy.
11. Use of Company Logos (Professional Accounts)
If you sign up for a paid plan using a professional email address (e.g., yourname@company.com), we may display your company’s logo on our website to indicate that your organization uses SafAI. This is based on our legitimate interest in marketing (Art. 6(1)(f) GDPR). This does not apply to personal accounts using generic domains (e.g., @gmail.com).
Anonymity and Opt-out: We do not reveal your personal identity, name, or specific account details in connection with this logo. You have the right to object to this use at any time. To opt out, please email kritesh@shridhar.de and we will remove the logo within 5 business days.
12. Changes to This Policy
We may update this Privacy Policy to reflect changes in our service or applicable law. Material changes will be communicated via the SafAI website. The date at the top of this page indicates the most recent revision. Continued use of SafAI after a material update constitutes acceptance of the revised policy.