Privacy
Privacy policy.
Kasah is designed to reduce the real private data sent through supported text and document requests before provider egress. Detection can miss context-dependent sensitive data, so Kasah reduces disclosure risk rather than promising complete removal.
- Kasah covers typed and pasted text plus supported text and metadata in PDF, DOCX, XLSX, PPTX, and CSV requests
- The desktop app keeps reversible mappings in an encrypted local vault and restores them only on confirmed read-only display surfaces
- Kasah's Groq-hosted privacy engine receives the original supported text to produce protection operations
- ChatGPT receives the version with detected values replaced or generalized; undetected sensitive data can remain
- Voice, camera, screen sharing, and identity-dependent actions are outside Kasah 0.1.6
- Native-composer drafts remain visible to ChatGPT's own same-origin page code while you type
- Kasah's application telemetry schema is limited to named operational fields such as setup state, error class, latency, route outcome, file-size bucket, and protected item counts. Some short string values pass a syntax allowlist, so Kasah does not yet claim semantic PII exclusion from telemetry
Infrastructure & subprocessors
Kasah currently sends original supported text to Groq's chat-completions service running openai/gpt-oss-120b. Groq's published policy says standard inference requests are not retained by default, but it may temporarily log inputs and outputs for system reliability or abuse review for up to 30 days. Automatic prompt caching for openai/gpt-oss-120b cannot be manually disabled, uses volatile memory, and expires after two hours without use; Groq says cached prompt data is not stored persistently or shared between organizations. Kasah does not claim that organization-level Zero Data Retention is enabled without current deployment evidence.
Groq's current services agreement says it does not use inputs or outputs for model training unless a customer explicitly permits it. These are Groq's published terms, not controls Kasah can prove from repository code, and they can change. Review Groq's data-retention documentation, prompt-caching documentation, and services agreement. Provider facts on this page were checked on July 30, 2026.
Kasah's website and API run on Vercel. Upstash Redis stores hashed account-derived rate-limit counters with short expirations. Kasah's current application has no prompt-review interface or prompt datastore, but requests still pass through Vercel and Groq infrastructure under their applicable terms.
Abandoned text requests
If you abandon a supported text request while protection is running, Kasah prevents that request from being forwarded to ChatGPT. Kasah 0.1.6 does not cancel the already-running privacy-engine operation. Groq processing, caching, or billing may continue, and encrypted local mapping or statistics updates may complete.
ChatGPT data handling
ChatGPT’s retention and training behavior depends on your plan and Data Controls. OpenAI says consumer content may be used to improve models unless the user opts out, while Business, Enterprise, Edu, and API content is not used for training by default. Those settings govern the protected request ChatGPT receives. Review OpenAI's data-use policy and business-data commitments.
Account data
Clerk processes authentication, account, and session data. Kasah disables Clerk's optional SDK telemetry. No payment information is required for the private pilot. When paid billing launches, payment processing will be handled by Stripe under Stripe's privacy policy.
Data Kasah stores
- Your processing-agreement version and acceptance time are stored in Clerk account metadata with no automatic expiration. Signing in, activating pilot access, or syncing alone does not give this agreement. Review the disclosure and choose whether to agree on the account page before enabling cloud protection. This record is included in Kasah-controlled account-data requests described below; it does not contain your prompts or document contents.
- Extension-session token digests are stored in Upstash for up to 31 days. The stored keys use digests of the Clerk user, session, and token identifiers rather than the raw identifiers.
- Rate-limit and account-control counters expire automatically, with the longest current counter lifetime up to 25 hours.
- A hashed invite-redemption record contains a user-derived digest and redemption time and has no automatic expiration.
- When billing is enabled, completed Stripe webhook idempotency records expire after 30 days. Stripe controls its own customer and payment records under its privacy policy.
- Operational logs can include a truncated hashed user identifier and bounded operational fields on Vercel. The deployed project's retention is not established by Kasah's application source.
- Encrypted local restoration mappings are retained for up to 1,000 conversations and have no time-based expiration. Least-recently-updated conversations are removed when that cap is exceeded, so Kasah cannot restore an evicted conversation's old replacements from those deleted mappings. Each retained conversation supports up to 5,000 reversible mappings and a 512 KiB serialized mapping-data budget. Further text or file protection that would exceed either limit is blocked instead of trimming saved mappings. The 512 KiB budget is not a per-file-size limit. Those mappings and their encryption key stay in the Kasah data directory on your Mac.
CSV preview snapshots are retained separately: at most 8 per conversation within 256 KiB, with additional row, cell, and character bounds. Older or oversized previews can be omitted while response mappings remain intact.
Requests and deletion
To make an access, correction, or deletion request for Kasah-controlled account data, email info@kasah.ai from the primary email address on your Kasah account. We verify your identity before acting on the request. Leaving the pilot removes access; it is not an account-data deletion request.
Kasah's remote request process cannot delete local restoration data on your Mac, data already held by ChatGPT, or Groq processing, cache, or log data controlled under those providers' policies. Uninstall and local-data removal are separate customer-controlled steps. Kasah will report which Kasah-controlled records were handled and which provider or local limitations remain.
Contact
For support, describe the issue using invented example data, the Kasah version, and the visible status or error. Do not send original prompts, documents, filenames, screenshots, passwords, API keys, access tokens, or invite codes. Do not include other people's information. For a suspected security or privacy incident, use the subject Kasah security report and start with the affected feature and a description without private content. Do not post private incident details publicly.