padmiHome

Legal

Privacy Policy

This policy explains how Padmi handles information when providing live, adaptive guidance inside customer-controlled software.

Effective September 1, 2026

1. Scope and our role

This Privacy Policy applies to the Padmi website, the Padmi walkthrough service, the installable Padmi script, and related support and demo experiences (together, the “Service”). Questions and privacy requests may be sent to team@padmi.ai.

For information a customer submits to configure and administer Padmi, Padmi generally acts as a controller. When Padmi processes information from a customer's application to provide guidance on that customer's instructions, the customer is the controller and Padmi acts as its processor or service provider. A customer's own privacy notice also applies to its application and users.

2. Information we process

Website, customer, and support information

We may process contact and organization details, account and authentication identifiers, authorized application origins, Padmi configuration, subscription or order information, and messages sent to support. We also process ordinary device, browser, network, referral, timestamp, security, and diagnostic information needed to operate the Service.

Guidance requests and bounded product context

When a user asks Padmi a question, Padmi may process the question, bounded recent guide conversation, and a minimized semantic snapshot of the interface currently visible to that user. That snapshot may include allowlisted accessibility roles, accessible names, visible non-input labels, structural relationships, bounded control state, and route information scrubbed of secrets. Padmi uses this context to ground guidance in the live product rather than relying on a fixed tour.

Value-free lifecycle events

We may process session and request identifiers, the semantic identity of a highlighted control, timestamps, connection and error events, whether a user followed or diverged from a suggested action, and whether guidance completed, stopped, or abstained. These events are designed to describe the walkthrough lifecycle without recording entered values.

3. Information Padmi is designed not to collect

Padmi's default runtime does not send:

  • passwords, payment values, session or authentication tokens, cookies, browser-storage contents, or secrets embedded in URLs;
  • typed field contents, raw keystrokes, hidden inputs, or unrestricted page HTML;
  • arbitrary JavaScript, CSS selectors, style dumps, or screenshots by default; or
  • unbounded page text or complete documents.

Ordinary form controls expose only bounded type and presence signals, such as whether a field is filled. Sensitive fields are fully masked. Optional screenshot processing is disabled by default and would require separate customer configuration and privacy review.

4. How we use information

  • Provide, ground, stream, and improve adaptive walkthroughs.
  • Authenticate installations, enforce exact-origin and tenant policy, and prevent misuse.
  • Verify that a proposed target is live, visible, allowed, and relevant before showing guidance.
  • Maintain sessions, diagnose failures, measure reliability, and provide customer support.
  • Comply with legal obligations and protect Padmi, customers, users, and the public.

We do not sell personal information or use customer application context for cross-context behavioral advertising.

5. AI processing and user control

Padmi may send a user's question and the bounded semantic context described above to AI and embedding providers acting on our behalf. Model output is treated as an untrusted proposal: it cannot supply executable code, selectors, or direct browser automation. Padmi validates every target against the current page and customer policy.

Padmi highlights and explains; it does not click, type, upload, submit, purchase, delete, publish, pay, or message for the user. Destructive or externally visible actions remain controlled by the user.

6. Browser storage and the AWS demo

Padmi may use cookies or browser storage for security, session state, preferences, and navigation continuity. The public AWS experience is a synthetic demonstration. It does not connect to AWS, use an AWS account, or call AWS APIs. Its simulated resources and reversible changes remain in the visitor's browser storage until the visitor clears them.

7. How we disclose information

We disclose information only as needed to operate the Service:

  • to infrastructure, hosting, storage, security, observability, support, communications, and AI-processing providers acting on our behalf;
  • to the customer that made Padmi available, including its authorized administrators, subject to that customer's settings and agreement;
  • at a customer's or user's direction;
  • to advisers, authorities, or other parties when reasonably necessary to comply with law, protect rights and safety, or investigate abuse; and
  • in connection with a financing, merger, acquisition, reorganization, or sale of assets, subject to appropriate safeguards.

8. Retention

We retain information only for as long as reasonably needed to provide the Service, follow customer instructions and contractual retention settings, maintain security and audit records, resolve disputes, and satisfy legal obligations. Retention varies by data category and customer agreement. We delete or de-identify information when it is no longer required, subject to limited backups and records needed for security, fraud prevention, or law.

9. Your choices and rights

Depending on where you live, you may have rights to access, correct, delete, restrict, object to processing of, or receive a portable copy of personal information. You may also withdraw consent where consent is the processing basis and appeal a decision where applicable.

Send requests to team@padmi.ai. If Padmi processes your information for a customer, we may direct the request to that customer or assist it in responding. We may verify your identity before completing a request.

10. Security and international processing

We use administrative, technical, and organizational safeguards designed to protect information. These include minimized data contracts, exact-origin installation checks, tenant policy, server-side credentials, and deterministic validation before guidance is rendered. No system is perfectly secure, and we cannot guarantee absolute security.

Padmi and its providers may process information in the United States and other countries. Where required, we use lawful transfer mechanisms and contractual safeguards.

11. Children

The Service is intended for businesses and their authorized users. It is not directed to children under 13, and we do not knowingly collect personal information from children under 13. Contact us if you believe a child has provided information so we can review it.

12. Changes and contact

We may update this policy as the Service changes. We will revise the effective date and provide additional notice when required. Questions, requests, and privacy concerns may be sent to team@padmi.ai.

Your use of Padmi is also governed by our Terms of Service.

© 2026 Padmi
How it worksPrivacyTermsContact