The KINDI service exists to mask personal data before text reaches a frontier language model. This policy states the uses that are out of scope and the conduct that will end an account.
This policy applies to every use of the KINDI service, including the text masking and redaction API, the file-redaction endpoints, the language-model proxy, the glossaries and reference logos you save to your account, the dashboard, the playground, the administrative console, and any reference implementation distributed by KINDI. It is incorporated into the Terms of Service by reference; a breach of this policy is a breach of the Terms.
You may not submit, process, store, or generate content through the service that is, or that is intended to enable:
Regardless of content, you may not:
The service operates under per-account rate limits and a free daily quota, in the amount shown in your account’s billing section after sign-up. KINDI may reduce a rate limit, shorten a quota, or block a request pattern at any time if we determine, on reasonable grounds, that the pattern threatens the service's stability or another customer's availability. We will inform the affected account at the earliest practicable moment.
KINDI is designed to process text from regulated industries, including healthcare, financial services, and legal services. If you submit text that contains sensitive personal data as defined by the PDPL, including health data, you represent that:
KINDI's Data Processing Addendum states our matching Processor obligations.
KINDI offers an optional proxy that forwards your masked text to a frontier language model on your behalf. The proxy is engaged only when you route a request through it. The dashboard demo runs on KINDI’s own provider keys under per-account and system-wide caps; production use requires your own provider key. Where you use it with your own provider key, you are responsible for:
The dashboard demo path, which runs on KINDI’s own operated provider account, is provided for evaluation only. You may not script it, share access to it, or use it to circumvent the cost of running your own key; KINDI applies per-account and system-wide limits to the demo path and may withdraw it from any account that abuses it. For production use, bring your own provider key.
Concerns about the use of the KINDI service by another party, including suspected breach of this policy, should be submitted via the contact form at kindi.me/contact. Security vulnerabilities should be submitted through the same form under the security topic; KINDI acknowledges those within one business day.
On a confirmed breach of this policy, KINDI may, at its sole discretion and proportionate to the breach: warn the account holder, throttle or block the offending request pattern, suspend the account, terminate the account, retain relevant records as required by law, and report the conduct to the appropriate authority. KINDI will not refund unused balance on an account terminated for a breach of this policy.