Sahi reads what you type in order to check it. That makes this the most important document we publish, so it is written to be understood rather than to be defensible. It explains what Sahi can see, what actually leaves your device, what is stored, and what your organisation's administrators can and cannot see.
Sahi is supplied by Caresoft Systems Private Limited ("Caresoft", "we"), Mumbai, India.
Understand this before installing.
Sahi works by reading the text you type in the places you enable it — your email, your messages, your web forms. That is not a side effect; it is the whole function. If you would not be comfortable with that text being checked, do not enable Sahi in that place.
What follows is our account of how we limit that access, what we exclude, and what we never do with it.
How your text is handled depends entirely on which of these your organisation has chosen. Check with your administrator if you are not sure.
| Mode | Where checking happens | Does text leave your network? |
|---|---|---|
| On-premise | Your own servers, inside your network | No — never |
| Cloud, AI off | Our servers in India, rule-based checking only | To our servers in India only |
| Cloud, AI on | Our servers in India, plus an AI model for advanced suggestions | To our servers, and to the AI provider for the passage being checked |
On-premise means what it says. The full checking engine runs on hardware you control. No text, no metadata and no usage information reaches Caresoft. It works with the internet disconnected. If your organisation has chosen this mode, most of the rest of this policy simply does not apply to your text.
| Situation | Controller / Data Fiduciary | Caresoft |
|---|---|---|
| You use Sahi through your employer's account | Your organisation | Data processor |
| You use Sahi as an individual subscriber | Caresoft | Controller |
| On-premise installation | Your organisation | Software supplier only — no access |
| Our website and enquiry forms | Caresoft | Controller |
Where your organisation is the controller, its own policies govern what it does with the account, and requests about your data should go to it first. Terms between Caresoft and organisations are in the Data Processing Addendum.
In the places you enable it, Sahi can read the text in the field you are typing in. Concretely:
Sahi does not read other browser tabs, files on your device, your browsing history, your clipboard, your contacts, or anything outside the field being checked.
These exclusions are applied on your device, before any processing or transmission:
• Password fields and any field the browser marks as a password
• Payment card fields — card number, expiry, CVV
• OTP and authentication code fields
• Any field a site marks as sensitive, or as excluded from autofill and spell checking
• Any site, domain or field your organisation has added to its exclusion list
Administrators can extend the exclusion list — by domain, by URL pattern, or by field — so that entire systems can be placed out of scope. We recommend organisations handling clinical, legal or financial records do exactly that for their most sensitive screens.
If you ever see Sahi appear on a field where it should not, tell us at [email protected]. We treat that as a defect, not a feature request.
In cloud mode, when a check runs we send the passage being checked — not your whole mailbox, not the rest of the page, not the recipient, not the subject line, not attachments.
Where AI-assisted suggestions are enabled, the passage being checked is also sent to our AI provider to generate the suggestion. Your organisation's administrator can turn AI off entirely — for everyone, or for particular departments — in which case no text is ever sent to any AI provider. Rule-based checking continues to work with AI off.
| Item | Stored? | Retention |
|---|---|---|
| The text you typed | Not stored | Held in memory for the duration of the check, then discarded |
| Cached check results | Yes, keyed by a hash of the passage | [7] days, then pruned automatically. Used to avoid re-checking identical text |
| Counts of checks, words, errors by type | Yes | [13] months |
| Whether a suggestion was accepted or dismissed | Yes, as a count | [13] months |
| Account details and settings | Yes | Life of the account, then [90] days |
| Error and diagnostic logs | Yes, with text redacted | [30] days |
| System logs required by law | Yes | Minimum 180 days, held in India |
On the cache. To avoid re-checking the same sentence repeatedly we keep results against a hash of the passage for a short period. This does mean a checked passage is recoverable from cache during that window. It is encrypted, access-controlled, pruned nightly, and can be disabled entirely for an organisation on request. We would rather explain it than not mention it.
We do not use your text to train, fine-tune or evaluate any model — not our own, not a third party's. Your writing is not raw material for our product.
Our contract with the AI provider prohibits them from using text sent for suggestions to train their models.
If you use Sahi through your employer, you should know exactly what they can and cannot see. Vendors are often vague here. We would rather be blunt.
| Your administrator can see | Your administrator cannot see |
|---|---|
|
• That you have an account, and your department • How many checks and words you ran • How many suggestions you accepted or dismissed • Error categories — for example, how often subject-verb agreement fires • When you last used Sahi • Usage against the organisation's plan limits |
• The text of anything you wrote • Who you were writing to • Which site, document or message you were in • Any individual sentence, correction or suggestion • Anything from a field on the exclusion list |
The Insights report shows repeated phrases across an organisation, so a team can spot patterns worth training on. It is off by default, must be switched on deliberately by the organisation, aggregates across a minimum number of people before any phrase appears, and never attributes a phrase to an individual.
Organisations enabling it should tell their staff. We provide the wording; whether it is used is the organisation's responsibility, and in some jurisdictions notifying employees is a legal requirement rather than a courtesy.
Name, work email, organisation and department, role, password (stored only as a salted and peppered one-way hash), plan and limits, per-person API key, settings and exclusion rules, device and browser type, and the usage counts described above.
| Permission | Why it is needed |
|---|---|
| Access to sites you enable | To read the field you are typing in and place the suggestion back. Off by default on every site you have not enabled |
| Storage | To keep your settings and exclusion list on your device |
| Managed configuration | Only for organisation deployments — lets your IT team apply policy centrally |
We request the narrowest permissions the function requires. Sahi's use of any data obtained through browser platform APIs is limited to providing and improving the user-facing writing features you have enabled; it is not transferred to others except as needed to provide those features or to comply with law; it is not used for advertising; and it is not used to train generalised AI models. No human at Caresoft reads your text except with your explicit consent for a specific support request, or where required by law.
Cloud processing and storage is within India, including backups. Support and engineering access is from India. Where AI suggestions are enabled, the passage may be processed by the AI provider outside India under contractual safeguards; organisations requiring no cross-border processing should disable AI or choose on-premise. On-premise installations hold everything on your own infrastructure.
TLS for all transmission; encryption at rest; passwords hashed with a per-install pepper in addition to a per-user salt; origin-locked embed keys and per-person API keys; role-based access across four administrative levels; multi-factor authentication for administrative access; tenant isolation; no production data in development or test environments; text redacted from logs; nightly cache pruning; vulnerability scanning and periodic penetration testing; and a documented incident response plan.
Subject to applicable law you may request access, correction, erasure, a portable copy, restriction of or objection to processing, and withdrawal of consent, and may nominate someone to act for you. You may complain to the Data Protection Board of India.
Where you use Sahi through your employer, raise requests with them first — they are the controller. We will assist them. For individual subscriptions, write to [email protected]; we verify identity and respond within 30 days.
There is generally very little text of yours for us to give you, correct or delete — because we do not keep it. That is the point of Section 6.
Sahi is intended for adults and for organisational use. We do not knowingly collect personal data from children, and we do not carry out tracking or targeted advertising directed at children. Where an educational institution deploys Sahi for students, it is responsible for the consents required and should consider on-premise or AI-off configuration.
Privacy: [email protected]
Support: [email protected]
Grievance Officer (Information Technology Act, 2000; Digital Personal Data Protection Act, 2023)
Name: Rajeev Pillai
Address: 311, Mahesh Industrial Estate , Silver Park, Mira Road East , Thane -401107
Acknowledgement within 24 hours; resolution within 15 days.
Caresoft Systems Private Limited, [registered office address], CIN U72900MH2022PTC387875.
We may update this policy. Material changes will be notified prominently and in advance (at least 30 days prior to taking effect) via email or inside the product interface.