KINDI · A bureau for handling sensitive language.

In-Kingdom PII masking for frontier LLMsRiyadh · Kingdom of Saudi ArabiaPreview
KINDI.me
09 Aug 2026 · 1448-02-26 HRiyadh · --:-- AST
PL. 25 · § 01
§ I.

Scope

This policy applies to every use of the KINDI service, including the text masking and redaction API, the file-redaction endpoints, the language-model proxy, the glossaries and reference logos you save to your account, the dashboard, the playground, the administrative console, and any reference implementation distributed by KINDI. It is incorporated into the Terms of Service by reference; a breach of this policy is a breach of the Terms.

PL. 25 · § 02
§ II.

Prohibited content and uses

You may not submit, process, store, or generate content through the service that is, or that is intended to enable:

  • conduct unlawful under the law of the Kingdom of Saudi Arabia, including any conduct prohibited by the Anti-Cyber Crime Law (Royal Decree M/17, 2007);
  • child sexual abuse material, in any form, regardless of jurisdiction;
  • the targeting of individuals with harassment, threats, or defamation;
  • the planning, facilitation, or instruction of violence, terrorism, or attacks on critical infrastructure;
  • the production of weapons of mass destruction, biological agents, chemical agents, or material that lowers the barrier to such production;
  • the unauthorised disclosure of classified state secrets or military information;
  • the impersonation of a real person, organisation, or public authority in a manner that would mislead a reasonable recipient.
PL. 25 · § 03
§ III.

Prohibited technical conduct

Regardless of content, you may not:

  • circumvent or attempt to circumvent any rate limit, billing control, authentication mechanism, or access control;
  • extract, reverse-engineer, or attempt to extract the detection models, parameters, or training data behind the service;
  • scrape, crawl, or otherwise mass-download KINDI properties outside the documented public API;
  • interfere with the service's availability for any other customer, including by submitting deliberately malformed requests at volume;
  • use the service to test or develop a competing product while bound by these Terms;
  • share an API key with a party that has not accepted these Terms, or sub-license access without written permission from KINDI.
PL. 25 · § 04
§ IV.

Quotas and abuse

The service operates under per-account rate limits and a free daily quota, in the amount shown in your account’s billing section after sign-up. KINDI may reduce a rate limit, shorten a quota, or block a request pattern at any time if we determine, on reasonable grounds, that the pattern threatens the service's stability or another customer's availability. We will inform the affected account at the earliest practicable moment.

PL. 25 · § 05
§ V.

Sensitive industries

KINDI is designed to process text from regulated industries, including healthcare, financial services, and legal services. If you submit text that contains sensitive personal data as defined by the PDPL, including health data, you represent that:

  1. you are the Controller of that data, or have a written processing agreement with the Controller that permits the submission;
  2. you have a lawful basis under the PDPL for the processing you are asking KINDI to perform;
  3. the data subject has been informed of your use of an automated masking service to the extent required by your own privacy notice; and
  4. you have applied any additional safeguards required for sensitive personal data, including the access-control minimisation expected of health data under the PDPL Implementing Regulations.

KINDI's Data Processing Addendum states our matching Processor obligations.

PL. 25 · § 06
§ VI.

Use of the LLM proxy

KINDI offers an optional proxy that forwards your masked text to a frontier language model on your behalf. The proxy is engaged only when you route a request through it. The dashboard demo runs on KINDI’s own provider keys under per-account and system-wide caps; production use requires your own provider key. Where you use it with your own provider key, you are responsible for:

  • the validity of the provider key you supply, the cost of the inference it authorises, and compliance with the terms of the model provider whose key you use;
  • keeping that key confidential and rotating it if you believe it has been exposed; KINDI passes the key through for the single request and does not store it, but cannot protect a key you have disclosed elsewhere;
  • the content of the prompts you send and the use you make of the model’s response, to the same standard as every other use of the service under this policy.

The dashboard demo path, which runs on KINDI’s own operated provider account, is provided for evaluation only. You may not script it, share access to it, or use it to circumvent the cost of running your own key; KINDI applies per-account and system-wide limits to the demo path and may withdraw it from any account that abuses it. For production use, bring your own provider key.

PL. 25 · § 07
§ VII.

Reporting abuse

Concerns about the use of the KINDI service by another party, including suspected breach of this policy, should be submitted via the contact form at kindi.me/contact. Security vulnerabilities should be submitted through the same form under the security topic; KINDI acknowledges those within one business day.

PL. 25 · § 08
§ VIII.

Enforcement

On a confirmed breach of this policy, KINDI may, at its sole discretion and proportionate to the breach: warn the account holder, throttle or block the offending request pattern, suspend the account, terminate the account, retain relevant records as required by law, and report the conduct to the appropriate authority. KINDI will not refund unused balance on an account terminated for a breach of this policy.