Privacy Policy

Product: Sahi  •  Version: [1.0]  •  Effective:01/04/2026

Sahi reads what you type in order to check it. That makes this the most important document we publish, so it is written to be understood rather than to be defensible. It explains what Sahi can see, what actually leaves your device, what is stored, and what your organisation's administrators can and cannot see.

Sahi is supplied by Caresoft Systems Private Limited ("Caresoft", "we"), Mumbai, India.

Understand this before installing.

Sahi works by reading the text you type in the places you enable it — your email, your messages, your web forms. That is not a side effect; it is the whole function. If you would not be comfortable with that text being checked, do not enable Sahi in that place.

What follows is our account of how we limit that access, what we exclude, and what we never do with it.

1. Three ways Sahi runs

How your text is handled depends entirely on which of these your organisation has chosen. Check with your administrator if you are not sure.

ModeWhere checking happensDoes text leave your network?
On-premiseYour own servers, inside your networkNo — never
Cloud, AI offOur servers in India, rule-based checking onlyTo our servers in India only
Cloud, AI onOur servers in India, plus an AI model for advanced suggestionsTo our servers, and to the AI provider for the passage being checked

On-premise means what it says. The full checking engine runs on hardware you control. No text, no metadata and no usage information reaches Caresoft. It works with the internet disconnected. If your organisation has chosen this mode, most of the rest of this policy simply does not apply to your text.

2. Who is responsible for what

SituationController / Data FiduciaryCaresoft
You use Sahi through your employer's accountYour organisationData processor
You use Sahi as an individual subscriberCaresoftController
On-premise installationYour organisationSoftware supplier only — no access
Our website and enquiry formsCaresoftController

Where your organisation is the controller, its own policies govern what it does with the account, and requests about your data should go to it first. Terms between Caresoft and organisations are in the Data Processing Addendum.

3. What Sahi can access

In the places you enable it, Sahi can read the text in the field you are typing in. Concretely:

Sahi does not read other browser tabs, files on your device, your browsing history, your clipboard, your contacts, or anything outside the field being checked.

4. What Sahi never reads

These exclusions are applied on your device, before any processing or transmission:

• Password fields and any field the browser marks as a password
• Payment card fields — card number, expiry, CVV
• OTP and authentication code fields
• Any field a site marks as sensitive, or as excluded from autofill and spell checking
• Any site, domain or field your organisation has added to its exclusion list

Administrators can extend the exclusion list — by domain, by URL pattern, or by field — so that entire systems can be placed out of scope. We recommend organisations handling clinical, legal or financial records do exactly that for their most sensitive screens.

If you ever see Sahi appear on a field where it should not, tell us at [email protected]. We treat that as a defect, not a feature request.

5. What actually leaves your device

In cloud mode, when a check runs we send the passage being checked — not your whole mailbox, not the rest of the page, not the recipient, not the subject line, not attachments.

Where AI-assisted suggestions are enabled, the passage being checked is also sent to our AI provider to generate the suggestion. Your organisation's administrator can turn AI off entirely — for everyone, or for particular departments — in which case no text is ever sent to any AI provider. Rule-based checking continues to work with AI off.

6. What we store, and for how long

ItemStored?Retention
The text you typedNot storedHeld in memory for the duration of the check, then discarded
Cached check resultsYes, keyed by a hash of the passage[7] days, then pruned automatically. Used to avoid re-checking identical text
Counts of checks, words, errors by typeYes[13] months
Whether a suggestion was accepted or dismissedYes, as a count[13] months
Account details and settingsYesLife of the account, then [90] days
Error and diagnostic logsYes, with text redacted[30] days
System logs required by lawYesMinimum 180 days, held in India

On the cache. To avoid re-checking the same sentence repeatedly we keep results against a hash of the passage for a short period. This does mean a checked passage is recoverable from cache during that window. It is encrypted, access-controlled, pruned nightly, and can be disabled entirely for an organisation on request. We would rather explain it than not mention it.

7. Training and AI

We do not use your text to train, fine-tune or evaluate any model — not our own, not a third party's. Your writing is not raw material for our product.

Our contract with the AI provider prohibits them from using text sent for suggestions to train their models.

8. What your administrator can see

If you use Sahi through your employer, you should know exactly what they can and cannot see. Vendors are often vague here. We would rather be blunt.

Your administrator can seeYour administrator cannot see
• That you have an account, and your department
• How many checks and words you ran
• How many suggestions you accepted or dismissed
• Error categories — for example, how often subject-verb agreement fires
• When you last used Sahi
• Usage against the organisation's plan limits
• The text of anything you wrote
• Who you were writing to
• Which site, document or message you were in
• Any individual sentence, correction or suggestion
• Anything from a field on the exclusion list

The Insights report shows repeated phrases across an organisation, so a team can spot patterns worth training on. It is off by default, must be switched on deliberately by the organisation, aggregates across a minimum number of people before any phrase appears, and never attributes a phrase to an individual.

Organisations enabling it should tell their staff. We provide the wording; whether it is used is the organisation's responsibility, and in some jurisdictions notifying employees is a legal requirement rather than a courtesy.

9. Account and usage data

Name, work email, organisation and department, role, password (stored only as a salted and peppered one-way hash), plan and limits, per-person API key, settings and exclusion rules, device and browser type, and the usage counts described above.

10. Browser and app permissions

PermissionWhy it is needed
Access to sites you enableTo read the field you are typing in and place the suggestion back. Off by default on every site you have not enabled
StorageTo keep your settings and exclusion list on your device
Managed configurationOnly for organisation deployments — lets your IT team apply policy centrally

We request the narrowest permissions the function requires. Sahi's use of any data obtained through browser platform APIs is limited to providing and improving the user-facing writing features you have enabled; it is not transferred to others except as needed to provide those features or to comply with law; it is not used for advertising; and it is not used to train generalised AI models. No human at Caresoft reads your text except with your explicit consent for a specific support request, or where required by law.

11. Why we process it

12. Sharing

13. Where data is held

Cloud processing and storage is within India, including backups. Support and engineering access is from India. Where AI suggestions are enabled, the passage may be processed by the AI provider outside India under contractual safeguards; organisations requiring no cross-border processing should disable AI or choose on-premise. On-premise installations hold everything on your own infrastructure.

14. Security

TLS for all transmission; encryption at rest; passwords hashed with a per-install pepper in addition to a per-user salt; origin-locked embed keys and per-person API keys; role-based access across four administrative levels; multi-factor authentication for administrative access; tenant isolation; no production data in development or test environments; text redacted from logs; nightly cache pruning; vulnerability scanning and periodic penetration testing; and a documented incident response plan.

15. If something goes wrong

16. Your rights and controls

16.1 Controls in the product

16.2 Legal rights

Subject to applicable law you may request access, correction, erasure, a portable copy, restriction of or objection to processing, and withdrawal of consent, and may nominate someone to act for you. You may complain to the Data Protection Board of India.

Where you use Sahi through your employer, raise requests with them first — they are the controller. We will assist them. For individual subscriptions, write to [email protected]; we verify identity and respond within 30 days.

There is generally very little text of yours for us to give you, correct or delete — because we do not keep it. That is the point of Section 6.

17. Children

Sahi is intended for adults and for organisational use. We do not knowingly collect personal data from children, and we do not carry out tracking or targeted advertising directed at children. Where an educational institution deploys Sahi for students, it is responsible for the consents required and should consider on-premise or AI-off configuration.

18. Contact and Grievance Officer

Privacy: [email protected]
Support: [email protected]

Grievance Officer (Information Technology Act, 2000; Digital Personal Data Protection Act, 2023)
Name: Rajeev Pillai
Address: 311, Mahesh Industrial Estate , Silver Park, Mira Road East , Thane -401107
Acknowledgement within 24 hours; resolution within 15 days.

Caresoft Systems Private Limited, [registered office address], CIN U72900MH2022PTC387875.

19. Changes

We may update this policy. Material changes will be notified prominently and in advance (at least 30 days prior to taking effect) via email or inside the product interface.