Privacy Policy

Last updated: September 2026 · Applies to DataFit, a product by Sentrive
Plain-language summary: DataFit analyzes the CSV file you upload entirely in memory, for the duration of that one request, and does not save it to disk, a database, or any storage system. We don't have user accounts yet, we don't use cookies, and we don't run analytics. The only third party involved is Google Fonts, which loads two typefaces and — as an inherent part of how web fonts work — receives your device's IP address when it does. This document is a good-faith, accurate description of what the product actually does today. It is not a substitute for review by a qualified lawyer, and you should get one before processing regulated or highly sensitive data through DataFit.

1. What we collect

Uploaded files. When you use the DataFit tool, the CSV file you upload is sent to our backend, parsed into memory, analyzed, and a report is generated and returned to your browser. The file is not written to disk, not stored in a database, and not retained after the request completes. We do not keep a copy.

Nothing else, currently. DataFit does not currently have user accounts, sign-up forms, newsletters, or payment features. We do not collect your name, email, or any other personal information through the product itself. If that changes (e.g. we add accounts or billing), this policy will be updated before that feature launches, and the relevant consent will be collected at that point.

2. What we do with uploaded data

Your uploaded dataset is used for exactly one purpose: generating the readiness report you requested, in that single request. We do not:

If a future version of DataFit introduces optional data retention (e.g. saving past reports to your account), it will be opt-in, clearly disclosed, and covered by an update to this policy before it ships — not enabled silently.

3. Third-party services

Google Fonts (fonts.googleapis.com). DataFit loads two typefaces from Google's font CDN. Loading any web font this way causes your browser to make a direct request to Google's servers, which — as with any web request — includes your IP address. Google's standard font-serving API does not set tracking cookies for this. We have not independently audited Google's own data handling for this request; if you want zero third-party network calls, avoiding the Home and app pages and asking us for a self-hosted build is a reasonable request, and it's an improvement we're considering by default.

We do not currently use any analytics provider, advertising network, session-recording tool, or error-monitoring service that would receive user or dataset data.

4. Cookies

DataFit does not set any cookies. See our Cookie Policy for details.

5. Data security

Uploaded files are validated for type and size before processing, processed only in server memory, and discarded after the response is sent. That said, we want to be direct about the current state of the product rather than overstate it: DataFit does not yet have authentication or rate limiting on its API, which means it is not yet hardened for handling data with strict confidentiality requirements (for example, regulated health, financial, or government data). We do not recommend uploading such data until those protections are in place. This is a limitation of the current build, not a promise about the future.

6. Your rights and choices

Because we do not store your data or maintain accounts today, there is currently nothing to request access to, correct, or delete on our end after your request completes — the dataset simply isn't retained. If DataFit introduces accounts or persistent storage in the future, this section will be updated to explain how to exercise applicable rights (such as access, correction, deletion, or portability) under the laws that apply to you.

7. Where this may apply, and what still needs legal review

Sentrive is developing DataFit with an initial connection to India, so India's Digital Personal Data Protection Act, 2023 (DPDPA) is a reasonable starting point for compliance obligations relevant to Indian users. If DataFit is used by people in the European Union, United Kingdom, United States, or other jurisdictions, additional laws (such as the GDPR or various U.S. state privacy laws) may apply depending on how the service is offered and to whom. We have not yet had this reviewed by a privacy lawyer, and we are flagging that explicitly rather than claiming compliance we haven't verified. If you are evaluating DataFit for a regulated or enterprise use case, please contact us first so we can be honest about what's confirmed versus what still needs review.

8. Children's privacy

DataFit is not directed at children and is not intended for use by anyone under 16. We do not knowingly collect data from children.

9. Changes to this policy

If how DataFit handles data changes — for example, if we add accounts, storage, or analytics — we will update this page and the "Last updated" date above before that change ships, not after.

10. Contact

Questions about this policy or how DataFit handles data: sentrive.ai@gmail.com

Note: Sentrive's registered business details (legal entity name, registration number, registered address) are not yet published here. We are not going to invent these — they will be added once formally established and confirmed, rather than fabricated for the sake of looking complete.