Privacy Policy

Last updated: August 2026

Krixai ("Krixai," "we," "us," or "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, store, and protect information when you use our AI security service, API, dashboard, and website (collectively, the "Service").

As a security company, we hold ourselves to the highest standards of data handling. We process your data to protect it, not to exploit it.

1. Information We Collect

1A. Account Information

1.1
When you create an account, we collect:
  • Email address
  • Name (optional)
  • Company name (optional)
  • Password (hashed, never stored in plaintext)
  • Billing information (processed and stored by Stripe; we do not store credit card numbers)

1B. Usage Data

1.2
We automatically collect:
  • API request metadata (timestamps, endpoints called, HTTP status codes)
  • Detection events (category, sub-type, confidence score, action taken)
  • Request and response sizes (byte counts, not content)
  • Latency measurements
  • IP addresses of API callers
  • Dashboard access logs (pages viewed, features used)

1C. Data Processed in Transit (Not Stored)

1.3
When you use Krixai's proxy or scan endpoints, the following data is processed in real-time but NOT stored:
  • The content of your prompts (user messages, system prompts)
  • The content of LLM responses
  • Your LLM provider API keys

Core Security Principle

We explicitly architect our systems to avoid storing sensitive AI payload data. We do not want your prompts, and we do not store them.

2. What We Do NOT Collect or Store

This section exists because, as a security proxy, we want to be explicit about boundaries:

DataStored?Details
Prompt content NoProcessed in memory for scanning. Never written to disk or database.
LLM responses NoProcessed in memory for output scanning. Never stored.
LLM API keys NoPassed through in memory. Never logged. (Unless using Key Vault, then AES-256 encrypted).
Detection text NoLogs contain metadata (category, confidence) but never the actual text that triggered it.

3. How We Use Your Information

3.1
We use the information we collect to:
  • Provide the Service (scan requests, detect threats)
  • Authenticate your API requests
  • Display detection events in your dashboard
  • Process payments via Stripe
  • Send critical service notifications
  • Improve detection accuracy using aggregate, anonymized metadata
3.2
We do NOT use your information to:
  • Train AI/ML models on your prompt content
  • Sell or share your data with third parties
  • Profile you or your users for advertising

4. Threat Intelligence

4.1
Krixai may offer an opt-in program where anonymized detection patterns (not content) are aggregated across customers to improve detection models.
4.2
This program is strictly opt-in. You will never be enrolled automatically.
4.3
If you opt in, only detection metadata is used. The actual content of the prompt or response is never included.
4.4
You may opt out at any time from your dashboard.

5. Data Retention

5.1
  • Account information: Retained until account deletion + 30 days.
  • Detection logs: Retained per your plan (3 days – 1 year) and automatically deleted.
  • Request content: Retained for 0 seconds. Processed in real-time, never persisted.

6. Data Security

6.1
We implement the following security measures to protect your data:
  • Encryption in transit: All data is transmitted over TLS 1.3
  • Encryption at rest: All stored data is encrypted using AES-256
  • Access control: Internal access restricted to authorized personnel
  • Infrastructure: Hosted on SOC2-certified cloud infrastructure

7. Sub-Processors

7.1
We use the following third-party services to operate Krixai:
  • Stripe: Payment processing
  • Railway / Fly.io: Infrastructure hosting
  • Cloudflare: DNS, DDoS protection, CDN
  • Upstash: Rate limiting (Redis)
  • Resend: Transactional & newsletter email

8. Your Rights

8.1
Depending on your jurisdiction, you may have the right to access, rectify, erase, restrict, or object to the processing of your personal data. To exercise any of these rights, contact us at hello@krixai.com. We will respond within 30 days.

9. International Data

9.1
Krixai processes data in the United States. If you are located outside the United States, your data will be transferred to and processed in the United States.

10. Children's Privacy

10.1
The Service is not intended for use by individuals under the age of 18. We do not knowingly collect personal information from children.

11. Cookies

11.1
We use only essential cookies required for the Service to function, such as authentication sessions. We do not use analytics cookies, advertising cookies, or third-party tracking cookies.

12. Changes

12.1
We may update this Privacy Policy from time to time. We will notify you of material changes via email or a notice on the Service at least 30 days before they take effect.