Last updated: August 18, 2026
We collect limited service data needed to operate accounts: name, email, authentication provider, API key/account quota metadata, plan and usage counters. Contact and paid-access forms store the details you submit so we can respond.
Text, documents and other content sent to PII-processing endpoints are processed to return the requested protected output. The application is designed not to intentionally persist those payloads as customer content in the account database.
When you use API Security Preflight, supported project source files and dependency manifests/lockfiles are submitted to the PrivoNest API for analysis. The v1.0.5 scan route is designed not to log or intentionally persist submitted source content and does not include source code in JSON/SARIF reports. Source analysis is performed by the PrivoNest API Security Engine rather than an external AI provider.
Dependency intelligence used during a customer scan reads a PrivoNest-owned snapshot. The customer scan path is designed not to query npm or PyPI live with customer package names.
PrivoNest performs PII detection/protection; your application selects the AI provider. Protected aliases/placeholders may be sent to that provider, whose own privacy terms apply. Automatic Guard interception is focused on textual LLM inputs.
Infrastructure and transactional providers are used to operate the service. Verification emails use an email-delivery provider, and Google/GitHub receive information when you choose their OAuth sign-in. Hosting and network providers necessarily process traffic needed to deliver the PrivoNest service.
Do not submit secrets, credentials or source files that are unnecessary for the requested operation. PrivoNest applies server-side API authentication and bounded scan inputs, but you remain responsible for determining what data/code you are authorized to submit.
One-way hashes derived from IP addresses may be used for rate limiting, OTP abuse prevention and form protection instead of storing raw addresses in those controls.
Use the private Contact Us form for privacy questions.