Privacy

What we keep, and why

Audit AI (auditai.sh) is run by its founder, a private individual based in Bangkok, Thailand. Questions and deletion requests: hello@auditai.sh. Last updated 22 September 2026.

The database check

The snapshot you paste on /check is sent to our server, checked, and thrown away. We do not store it and do not write it to our logs; the logs get counts only, such as how many tables a snapshot had. The snapshot holds names, rules, grants and the source of SECURITY DEFINER functions, never a row of your data.

Scanning a repository

When you scan a public repository by link, we keep the repository name, the commit, the result, and a hash of your IP address made with a secret salt, so we can limit abuse without keeping the address itself. The report is a public page: anyone with its link can open it. If you mark a finding as right or wrong, we keep your verdict, your note and the same hash. If you ask for a proof, we also keep the contact you leave.

Orders

For an order we keep your email, for an audit the repository and any note you add, the price, the payment method, the payment provider's reference, the order's status and the salted hash of your IP address. The order page opens with a key only you hold; we keep a hash of that key, not the key. When an order is paid, a short notice with your email, the repository and your note goes to our private Telegram chat.

The night watch

For a watch we keep your project's ref and pooler host, the password of the role you created, encrypted with a key that is not stored next to it, and what each check found: the names of the tables, policies and functions that are open, with the fix, and how many there were. Not your data, and not the snapshot a check is made from. Stopping the watch deletes the password and everything it recorded. When a watch expires, or we stop it because the role gained rights, we delete the password at once and keep the record of what the checks found until you ask us to delete it.

Email and the contact form

If you leave your email on the site, we keep it, what you told us you build with, and the salted hash of your IP address. If you write to hello@auditai.sh or security@auditai.sh, your message is forwarded to our inbox at Apple iCloud Mail and a copy is kept in our database so we can answer it; a short notice with your name, address, subject and the start of the message goes to our private Telegram chat. For Fix & re-check, the snapshot you send stays with your message until you ask us to delete it. We send you email only about what you asked for: an answer, an order, a watch.

What we do not do

No analytics scripts, no advertising cookies, no tracking pixels. We do not sell or rent anything you give us, and we do not use it to advertise to you.

Who processes it for us

Deleting your data

Write to hello@auditai.sh with what you want deleted, for example a report link, an order code or your email address. We delete it within 30 days and tell you when it is done. We keep what we need for a payment or a refund for as long as the law requires.

Changes

When this page changes, the date at the top changes with it. The terms of sale and refund policy are on their own page.