Our Privacy Commitment

Our products read your email, your goals, and your video. That only works if privacy is designed in — not promised afterwards.

Redaction before the model

Sensitive data is redacted before it reaches any AI model. In Compose, our PALADIN named-entity recognition system strips names, phone numbers, addresses, financial data, and other identifiers from email content before it is sent to a language model. The model sees the shape of your message, not the people in it.

Minimal OAuth scopes

We request the narrowest set of permissions a product needs to function, and nothing held “just in case”. OAuth tokens are stored encrypted. You can disconnect a product from your Google account at any time, and access ends immediately.

CASA Tier 2 security certified

Our Google Workspace applications are assessed under the Cloud Application Security Assessment programme at Tier 2 — the independent security review Google requires of applications that handle restricted user data.

Never sold, never shared

We do not sell your personal information or your content to third parties, and we do not use it to train models. Our revenue comes from subscriptions and one-time purchases — not from data.

You control retention

Deleting your account starts a 30-day soft delete, after which data is permanently removed. Usage logs are retained for 90 days. Payment records are kept for seven years where law requires it.

Per-product policies

Each product publishes its own full privacy policy covering the data it handles:

Compose · SimaraGuard · Vicharalaya · WinRec · SimaRecord

Questions about how we handle your data? Write to prashant@simarahitam.com.