Any service that does not prominently show who is responsible, don't even bother using it. If the owners are not willing to put themselves on their own company website, you should not be using that service/site.
We don't have any reason to hide. We simply missed it. We are engineers at heart, trying our hand at the business side of things for the first time. You can find us here: https://www.linkedin.com/in/kraten/ https://www.linkedin.com/in/jai-singhal/
How does we prioritize privacy protection?
(grammar)
At Hansei, safeguarding your privacy is paramount. Your data is end-to-end encrypted and can only be accessed by you. You can delete your data anytime from our servers. Query and response data are stored to improve our services, adhering to our comprehensive privacy policy(https://hansei.app/privacy-policy). Queries and responses also pass through OpenAI and are subject to their privacy policy as well.
Most companies don't have a privacy officer, they have a data officer, and they don't worry about privacy, they worry about data loss, IP loss.
Even then, you both dissemble and flat lie in this answer, with the contradictions evident in the response itself.
End to end encrypted? What end to what end, and in what way that's not just SSL/TLS over the https request?
Accessed only by you? Not by, say, an embeddings tool, or not by, say, OpenAI where they "also pass through"? What about DBAs, SREs, Dev/QA, and the Founder/CEO?
More specifically, how do you (in logic, not policy) prevent yourself from being able to access the company's data even in case of break glass need, such as a law enforcement warrant? If someone uploads a document store of CSAM or bomb building instructions, you're claiming you cannot be responsive to a search warrant or national security letter? Think carefully before you answer. Being able to say this while performing a service using the data can take years of work and code/config/infra/system automation.
Understood you say nobody can access but then query and response (are you saying response doesn't contain data?) are stored "to improve services". In what way, other than -- ultimately -- humans learning this data incidentally, while "improving"?
This answer is transparently end-to-end nonsense to a CDO or CISO. The only way it could have been worse is if you'd had that "we take your security very seriously" stock phrase with an appeal to military/bank grade security or bits of encryption there.