Privacy Policy
Last updated: July 29, 2026
Our commitment
Your data stays yours. PII Shield redacts sensitive information before it reaches any AI provider. We process data in compliance with NDPR (Nigeria), POPIA (South Africa), and GDPR (EU).
Data we collect
We collect only what is necessary to provide and improve the Service:
- Account data — name, email, organization details
- Payment data — processed by Paystack, Flutterwave, and M-Pesa. We do not store card numbers.
- Usage data — token consumption, API calls, feature usage
- Technical data — IP address, browser type, request logs
How we use your data
We use your data to:
- Provide and maintain the Service
- Process payments and issue invoices
- Monitor usage and prevent abuse
- Improve model routing, performance, and reliability
- Send service notifications and product updates
PII Shield
Before any request reaches an AI provider, PII Shield scans and redacts sensitive data — names, phone numbers, email addresses, financial details, and government IDs. Redacted data is replaced with tokens that cannot be reverse-engineered.
You can configure PII Shield policies per project to add or remove redaction categories.
Data retention
Account data is retained while your account is active. After account termination, data is deleted within 30 days.
Request logs are retained for 90 days for debugging and abuse prevention. AI-generated outputs are not stored beyond the session unless you explicitly save them.
Data sharing
We do not sell your data. We share data only with:
- AI providers (OpenAI, Anthropic, etc.) — only after PII Shield redaction
- Payment processors (Paystack, Flutterwave, M-Pesa) — for billing only
- Cloud infrastructure providers — for hosting and compute
- Legal authorities — when required by law
Regional infrastructure
We operate regional infrastructure in Nigeria, Kenya, and South Africa to provide lower latency and data sovereignty. Your data is processed in the region closest to you unless routing requires global provider endpoints.
Your rights
Under NDPR, POPIA, and GDPR, you have the right to:
- Access — request a copy of your personal data
- Rectification — correct inaccurate data
- Erasure — request deletion of your data
- Portability — receive your data in a structured format
- Objection — object to certain processing activities
Security
We use TLS encryption for all data in transit. Data at rest is encrypted with AES-256. Access to production systems is restricted and audited. We conduct regular security reviews.
Cookies
We use essential cookies for authentication and session management. We do not use tracking or advertising cookies. You can disable non-essential cookies in your browser settings.
Children’s privacy
The Service is not directed to children under 16. We do not knowingly collect data from children. If you believe a child has provided data, contact us for immediate deletion.
Changes to this policy
We may update this Privacy Policy from time to time. We will notify you of significant changes via email or in-app notification.
Contact
Questions about privacy? Contact our Data Protection Officer at privacy@afcloudai.com or through our contact page.