Skip to content
CA PRO ToolkitAudit & compliance
Features AI Audit Security Terms
Add to Chrome
Legal

Privacy Policy

Effective date: 1 January 2026. This policy explains what information CA PRO Toolkit collects, how it is used, and the choices you have.

Who we are What we collect How we use it Documents & AI Sharing Your rights Contact

1. Who we are

CA PRO Toolkit ("we", "us", "our") is a Chrome extension and connected backend service that helps Chartered Accountant firms manage audit, compliance, and firm workflow. For any privacy question or data request, contact saifullahfaizan786@gmail.com.

2. Scope

This policy applies to the CA PRO Toolkit browser extension, its full-page workspace and Web View, the standalone tool pages, and the backend API at api.caprotoolkit.in. It also covers support and account communication handled by email.

3. Information we collect

  • Account and contact information: your name and email address from Google Sign-In, used to authenticate you and to communicate about your account and support.
  • Firm and workspace data: the tasks, clients, reminders, reconciliations, cases, engagements, reviews, and other records you and your firm create in the product.
  • Document text you submit: text you paste, upload, or choose to review. File text is extracted on your device first; only text you send is processed.
  • Technical and diagnostic data: browser type and version, device and operating-system information, and basic logs used for security, compatibility, and troubleshooting.
  • Messages you send us: the content of emails and feedback you submit.

4. Information we do not collect

  • We do not sell your personal data.
  • We do not track your activity across other websites.
  • We do not retain uploaded source files after their text has been processed.
  • We do not intentionally collect sensitive personal data such as government IDs or biometrics.

5. How we use your information

  • To authenticate you, enforce firm roles and permissions, and keep your data secure.
  • To provide, maintain, and improve the product and its features.
  • To send service-related communication and respond to your requests.
  • To detect, prevent, and investigate abuse, fraud, and security issues.

6. Document processing, AI, and OCR

Document review is designed to be local-first. When you review a file, its text is read on your device before anything is sent. Sending content to the AI assistant or to the online text reader (OCR) is optional and always requires your explicit consent for that action. High-impact values such as dates, amounts, and conclusions remain unconfirmed until a person confirms them, and the product does not file to any government portal.

7. Authentication and sessions

Sign-in uses Google Sign-In. A secure token is stored in your browser's extension storage to keep you signed in. Where email verification is used, one-time passwords are short-lived and used only for authentication.

8. Local storage on your device

Some information (session state, preferences, and cached data such as looked-up guidance) is stored locally in your browser to improve performance. You can clear this through your browser at any time; some features may reset afterward.

9. Cookies and similar technologies

The extension relies on browser extension storage rather than advertising cookies. The marketing website may use minimal, privacy-respecting analytics. We do not use cross-site advertising trackers.

10. Sharing and service providers

We share information only with service providers required to operate the product, or where legally required, or to investigate security issues. These providers include:

  • Google for sign-in and identity verification.
  • Email delivery provider for account, reminder, and support email.
  • AI provider for optional, consent-gated audit and case assistance.
  • Online text reader (OCR) for optional, consent-gated reading of scanned files.
  • Hosting provider for the backend API and website.

Members of your shared firm can see the firm records you contribute, according to their role.

11. Data security

Connections use industry-standard encryption in transit. Access is protected by token-based authentication and server-side role and permission checks. No method of transmission or storage is perfectly secure, but we apply reasonable safeguards to protect your information.

12. Data retention

We keep information for as long as needed to provide the product, support your firm, and meet security and legal obligations. When it is no longer required, we delete or anonymise it where feasible.

13. Your rights

  • Request a copy of the personal data we hold about you.
  • Request correction or deletion of your data.
  • Opt out of non-essential communication (essential service messages may still be sent).

To exercise any right, email saifullahfaizan786@gmail.com.

14. Children

CA PRO Toolkit is a professional tool intended for firms and is not directed to children. We do not knowingly collect data from children.

15. Changes to this policy

We may update this policy from time to time. Material changes will be reflected by a new effective date. Continued use of the product after an update constitutes acceptance of the revised policy.

16. Contact

Questions or requests: saifullahfaizan786@gmail.com. See also our Terms & Conditions.

CA PRO ToolkitAudit & compliance

Audit review, compliance and firm workflow for Chartered Accountants, in one Chrome extension.

Product

FeaturesAI AuditSecurityFAQ

Legal

Privacy PolicyTerms & Conditions

Connect

Chrome Web StoreWebsiteContact
© 2026 CA PRO Toolkit. All rights reserved. CA PRO Toolkit assists professional review and organisation. It does not provide professional, legal, or filing services, and does not submit to any government portal.