PENDING FINAL LEGAL REVIEW. This policy describes our actual data flow and is accurate to the implementation. It is undergoing final review by counsel and may be revised; the current version is always the one published here.
Privacy Policy
Effective date: 4 September 2026
1. Who we are
Untraceable AI ("we", "us") provides confidential AI tooling for regulated fields. This policy explains what we process and how.
2. What we process, and where it goes
This section describes the actual data flow and must match the implementation:
- Document content. Your documents and their real values stay in your own
Microsoft 365 tenant. Cloaking runs in your browser: each sensitive value is
replaced with a token label (e.g.
[SLC_1]) on your own device, before anything is transmitted. We receive only cloaked text, and only in transit on its way to the AI provider — we never receive or store your raw values, and no AI model ever sees them. - Tokens and audit metadata — database storage. Token labels, run identifiers, and audit records are stored in our database, and that database follows your project's region. A project set to United States residency is stored on our United States server (East US 2); a project set to Canada is stored on our Canadian server (Canada Central). If you select a region for which we have not provisioned a server, the request is refused rather than served from another region — we do not silently store your records elsewhere. Europe is not currently offered. These records contain token labels, run identifiers and audit metadata — never the underlying sensitive values, which do not leave your own Microsoft 365 tenant at all.
- Where processing happens. Compute follows your project's region: United States projects are served from our United States region (East US 2), Canadian projects from Canada Central. AI inference is separate and does not follow your project's region. Most of the models we offer — including the Claude and GPT families — run in United States regions, or on deployments that may process in more than one region, whichever region your project is set to. Gemini 2.5 Pro is currently the only model we serve from a Canadian region (Montreal). In every case the model receives cloaked text only: token labels, never your underlying values. Which model a project uses, and where it runs, is shown in the app and on our security page.
- Where your documents sit is governed by you, not by this setting. Your documents never leave your own Microsoft 365 tenant, and the residency setting above does not control where inside Microsoft 365 they are placed. They are written to the SharePoint site of the Microsoft 365 account you connect, so their location is determined by your own Microsoft 365 configuration and by which account you sign in with. If you need your documents held in a particular region, configure that in Microsoft 365; selecting a project region here will not do it.
- What this means for residency. The material point is that your confidential values never leave your own Microsoft 365 tenant, so no confidential value crosses a border regardless of which model or region is used. What may be processed or stored outside your selected region is cloaked text and audit metadata. We state the regions above precisely so you can assess that for yourself rather than take a general assurance.
- Account data. Your sign-in identity (from Microsoft Entra External ID) and the consent records described below.
The following could be modified post pilot: controller/processor roles, lawful basis, retention periods, and any regional disclosures.
3. Website analytics and cookies
We use analytics on our public marketing website only — pages such as the home page, pricing, product and guide pages. They are not used anywhere in the application. No analytics script is loaded on any signed-in page, and none runs on the pages where you work with documents.
The tools are Google Analytics (aggregate traffic measurement) and Microsoft Clarity (page interaction and session replay, used to see where the marketing site is confusing). Clarity's text masking is enabled, so page text is not captured in a recording.
Enforcement is technical, not a policy promise: analytics is loaded from an explicit allow-list of public pages. If you move from a marketing page into the application, recording is stopped and stays off for the rest of that browsing session, even if you navigate back.
These tools set cookies on the marketing site (_ga, _clck, _clsk) and
collect the usual website analytics data — approximate location derived from IP
address, browser and device type, referring page, and the pages you visit.
Microsoft Clarity processes this data on Microsoft's infrastructure in the
United States. This is separate from, and has no bearing on, the data-residency
guarantee described in section 2, which governs your project data.
4. Consent records
When you accept these documents we record which version you accepted and when, for compliance and audit purposes. You can review your acceptances at any time on your Account → Legal & Agreements page.
5. Data retention and deletion
We retain the cloak-level and audit records described above for 6 years, or for a period you define, in line with regulated-industry standards. These records contain token labels, run identifiers and audit metadata.
The conversational tools retain no prompt or response text at all. That text is purged when a session closes; our servers keep who ran it, when, which model answered and which cloak decisions were made — not the words.
Deletion is by request rather than self-service: email us and we delete the records we hold within 48 hours, then confirm. This applies to the audit records on our side. Your documents and their real values live in your own Microsoft 365 tenant — you can delete that SharePoint folder yourself at any time, without us.
6. Sharing
We do not sell your data. We use sub-processors solely to provide the Service: Microsoft (Azure for compute, storage, gateway and key management; Microsoft 365, which is your own tenant) and the AI model providers, which receive cloaked text only and never a confidential value. The current model providers are listed on our security page. The analytics providers named in section 3 receive marketing-website usage data only.
7. Your rights
Depending on your jurisdiction you may have rights to access, correct, or delete your personal data. Contact us to exercise them.
8. Contact
Privacy questions: [email protected].