Privacy policy.
What we collect, why, who we share it with and how we protect it. Last updated 5 October 2026.
Who is responsible
Policy Audit is a service provided by Manan Awasthi, a sole proprietor based in India. Contact details are on the Contact page.
runs this site and decides how pilot data is handled. For questions about your data, corrections or deletion requests, contact .
The operator's name and contact are not yet published. Until they are, pilot inquiries and the private workspace stay closed; do not send policy text or other data.
What we collect
- No accounts, cookies or analytics. The site sets no cookies and loads no tracking or advertising scripts.
- No saved sample history. Running the sample asks the server to compute a fixed fictional example. The application does not save a visitor run history. Hosting may process technical request logs as described below.
- Audit inquiries and email. The inquiry form prepares a draft in your email app for you to review and send; nothing is submitted to this site. When you email us we receive your name, email address and whatever you choose to write. Policies or test evidence you choose to email are stored in our inbox under the correspondence retention described below.
- Payments. After agreeing the audit scope, we send a PayPal invoice. PayPal processes the payment and shares invoice details and payment records with us, such as your name, email address, billing details, amount and payment status. We never see or store your full card number. Agreed bank-transfer payments produce bank and invoice records.
- Free policy check. When you submit policy text on the check page, it is sent to the server once to find rules and generate example test cases, then discarded. Results appear only in your browser tab. Nothing is saved and no account is created.
- Private refund workspace. An invite code enables supported English refund-policy extraction, review, connector download and fixture-evidence analysis. The code and workspace results stay in the current tab's memory, without browser storage. Policy text, reviewer name and selected test evidence are sent to the server when you submit the relevant step. The application does not retain these requests or save run history. The downloaded connector includes a signed audit-access file that lets you submit captures for its reviewed bundle for 30 days; it works only with the invite that created it. You can download your starter and reports to keep them.
- Other action audits. These use manually reviewed local test bundles and agreed report delivery. Your agent and model calls run in your environment. Before work starts, we agree how policy text and synthetic fixture captures will be shared and retained for the audit.
- Local capture and evidence sharing. The downloadable connector runs your agent against simulated tools in your environment. It does not upload automatically. Policy-relevant test state, original tool arguments and captured fixture effects are needed for server analysis; inspect selected files before sharing. Use synthetic test records, never production customer records or credentials.
- Downloaded reports. Reports retain reviewer labels, policy identifiers, case labels, rule results and relevant expected-versus-actual values. They are not anonymized or automatically safe to publish. Inspect each package before sharing it and use synthetic identifiers.
- Hosting logs. The site is hosted on Vercel, which, like any web host, processes technical request data such as IP address, browser type and the pages requested, to serve and protect the site. See Vercel’s own privacy policy for how it handles this data.
How we use it
Only to reply to you, to scope, deliver and invoice an audit or pilot, to keep the site running and secure, and to meet legal and tax obligations. We do not sell or rent your information, and we do not use it for advertising.
Who we share it with, and how
- Vercel hosts this website and processes request data to serve it.
- PayPal processes invoice payments and receives the details needed to take a payment.
- Yahoo Mail hosts our email inbox, so it stores the emails you send us.
- Authorities, only when Indian law requires it.
Information reaches these providers over encrypted (HTTPS/TLS) connections, directly from your browser or from us. Each provider handles it under its own privacy policy. We share nothing else with anyone without your permission.
Security practices
- The whole site is served over HTTPS.
- The hosted application has no database and no saved run history. Policy and evidence requests are processed in memory or temporary storage for that request. Email and payment records are separate from this processing.
- The refund workspace requires a private invite code. Signed review access in the downloaded connector expires after 30 days and is bound to the invite that created it. The operator can revoke an invite.
- The site sets no cookies and loads no third-party scripts.
- Only the operator can access our email and payment records.
Pilot correspondence
Please do not send customer data, personal data about your users, API keys, credentials or production logs through the form or by email. Data handling for customer work is agreed in writing before a pilot begins.
How long we keep it
We keep emails for as long as the conversation or pilot needs them. We keep invoices and payment records for as long as Indian tax law requires. You can ask us to delete anything else at any time.
Your rights and grievances
You can ask to see, correct or delete the information we hold about you, or withdraw consent to its use. Our grievance officer is Manan Awasthi; contact details are on the Contact page. We respond within 30 days.
Changes
We may update this policy; the date at the top shows the latest version. Terms for pilots and use of the site are in the Terms and conditions.