Privacy
Privacy policy.
Kasah is designed to reduce the real private data sent through supported text and document requests before provider egress. Detection can miss context-dependent sensitive data, so Kasah reduces disclosure risk rather than promising complete removal.
- Kasah covers typed and pasted text plus supported text and metadata in PDF, DOCX, XLSX, PPTX, and CSV requests
- The desktop app keeps reversible mappings in an encrypted local vault and restores them only on confirmed read-only display surfaces
- Kasah's Groq-hosted privacy engine receives the original supported text to produce protection operations
- ChatGPT receives the version with detected values replaced or generalized; undetected sensitive data can remain
- Voice, camera, screen sharing, and identity-dependent actions are outside Kasah 0.1.6
- Native-composer drafts remain visible to ChatGPT's own same-origin page code while you type
- Kasah's application telemetry schema is limited to named operational fields such as setup state, error class, latency, route outcome, file-size bucket, and protected item counts. Some short string values pass a syntax allowlist, so Kasah does not yet claim semantic PII exclusion from telemetry
Infrastructure & subprocessors
Kasah currently sends original supported text to Groq's chat-completions service running openai/gpt-oss-120b. Groq's published policy says standard inference requests are not retained by default, but it may temporarily log inputs and outputs for system reliability or abuse review for up to 30 days. Automatic prompt caching for openai/gpt-oss-120b cannot be manually disabled, uses volatile memory, and expires after two hours without use; Groq says cached prompt data is not stored persistently or shared between organizations. Kasah does not claim that organization-level Zero Data Retention is enabled without current deployment evidence.
Groq's current services agreement says it does not use inputs or outputs for model training unless a customer explicitly permits it. These are Groq's published terms, not controls Kasah can prove from repository code, and they can change. Review Groq's data-retention documentation, prompt-caching documentation, and services agreement. Provider facts on this page were checked on July 30, 2026.
Kasah's website and API run on Vercel. Upstash Redis stores hashed account-derived rate-limit counters with short expirations. Kasah's current application has no prompt-review interface or prompt datastore, but requests still pass through Vercel and Groq infrastructure under their applicable terms.
Abandoned text requests
If you abandon a supported text request while protection is running, Kasah prevents that request from being forwarded to ChatGPT. Kasah 0.1.6 does not cancel the already-running privacy-engine operation. Groq processing, caching, or billing may continue, and encrypted local mapping or statistics updates may complete.
ChatGPT data handling
ChatGPT’s retention and training behavior depends on your plan and Data Controls. OpenAI says consumer content may be used to improve models unless the user opts out, while Business, Enterprise, Edu, and API content is not used for training by default. Those settings govern the protected request ChatGPT receives. Review OpenAI's data-use policy and business-data commitments.
Account data
Clerk processes authentication, account, and session data. Kasah disables Clerk's optional SDK telemetry. No payment information is required for the private pilot. When paid billing launches, payment processing will be handled by Stripe under Stripe's privacy policy.
Data Kasah stores
- Extension-session token digests are stored in Upstash for up to 31 days. The stored keys use digests of the Clerk user, session, and token identifiers rather than the raw identifiers.
- Rate-limit and account-control counters expire automatically, with the longest current counter lifetime up to 25 hours.
- A hashed invite-redemption record contains a user-derived digest and redemption time and has no automatic expiration.
- When billing is enabled, completed Stripe webhook idempotency records expire after 30 days. Stripe controls its own customer and payment records under its privacy policy.
- Operational logs can include a truncated hashed user identifier and bounded operational fields on Vercel. The deployed project's retention is not established by Kasah's application source.
- Encrypted local restoration mappings are retained for up to 1,000 conversations and have no time-based expiration. Those mappings and their encryption key stay in the Kasah data directory on your Mac.
Requests and deletion
To make an access, correction, or deletion request for Kasah-controlled account data, email info@kasah.ai from the primary email address on your Kasah account. We verify your identity before acting on the request. Leaving the pilot removes access; it is not an account-data deletion request.
Kasah's remote request process cannot delete local restoration data on your Mac, data already held by ChatGPT, or Groq processing, cache, or log data controlled under those providers' policies. Uninstall and local-data removal are separate customer-controlled steps. Kasah will report which Kasah-controlled records were handled and which provider or local limitations remain.