Redaction before the model
Sensitive data is redacted before it reaches any AI model. In Compose, our PALADIN named-entity recognition system strips names, phone numbers, addresses, financial data, and other identifiers from email content before it is sent to a language model. The model sees the shape of your message, not the people in it.
Minimal OAuth scopes
We request the narrowest set of permissions a product needs to function, and nothing held “just in case”. OAuth tokens are stored encrypted. You can disconnect a product from your Google account at any time, and access ends immediately.
CASA Tier 2 security certified
Our Google Workspace applications are assessed under the Cloud Application Security Assessment programme at Tier 2 — the independent security review Google requires of applications that handle restricted user data.
Never sold, never shared
We do not sell your personal information or your content to third parties, and we do not use it to train models. Our revenue comes from subscriptions and one-time purchases — not from data.
You control retention
Deleting your account starts a 30-day soft delete, after which data is permanently removed. Usage logs are retained for 90 days. Payment records are kept for seven years where law requires it.
Per-product policies
Each product publishes its own full privacy policy covering the data it handles:
Compose · SimaraGuard · Vicharalaya · WinRec · SimaRecord
Questions about how we handle your data? Write to prashant@simarahitam.com.