GoValidate.ai

Privacy & Compliance

Browser-first file validation. Raw file contents and cell values stay on your device.

  • Privacy Policy
Last Updated: July 2, 2026

Data Controller

GoValidate.ai is operated by GoValidate ("we," "us," or "our"). For privacy inquiries, contact us at support@govalidate.ai.

1. Browser-First Architecture Guarantee

GoValidate.ai is built as a browser-first application. When you load files (such as CSV, XLSX, or JSON) into our Data Quality, Reconcile, or Editor tools, the validation and processing are executed locally on your device using Web Workers. The raw contents and cell values of your files never leave your browser, are never uploaded to our servers, and are never stored on our infrastructure.

2. Data We Process on Our Servers

While your raw file contents remain local, we process specific categories of data on our servers to verify subscription limits, enforce security policies, and manage account authorization:

  • File Metadata: When you perform validation tasks, the client transmits metadata including file size, file extensions, normalized filename hashes, file integrity hashes (SHA-256), and Indicators of Compromise (such as macro detection results for Excel files). We use this metadata solely to run security policies and enforce validation limits.
  • Authentication & Identity Data: If you register or authenticate, we process your user credentials, email addresses, and secure authentication tokens. For anonymous sessions, a cryptographically signed anonymous identity token is processed.
  • Data Sets Digest Subscriptions: If you sign up for the Federal Contracts weekly digest, we store the email address you submit, the page you submitted it from, and the timestamps of your signup, confirmation, and any unsubscribe. The address is stored under a salted SHA-256 hash of itself, and confirmation and unsubscribe links identify you by that hash rather than by the address. We do not send the digest until you confirm by clicking the link we email you, and every issue carries an unsubscribe link.
  • IP Addresses & Security Logs: We log system calls for security monitoring, rate limiting, and incident response. Any IP addresses and filenames are hashed (SHA-256) before they are written to durable storage to ensure individual identifiers are anonymized.

3. Legal Basis for Processing (GDPR)

Under the General Data Protection Regulation (GDPR), we process personal data on the following legal bases:

  • Contractual Necessity (Article 6(1)(b)): Authentication and identity data are processed as necessary to provide the Service to you.
  • Legitimate Interest (Article 6(1)(f)): File metadata, security logs, and IP address hashes are processed for our legitimate interests in security, fraud prevention, and rate limiting. Behavioral telemetry is processed for our legitimate interest in product improvement, subject to your right to object.
  • Consent (Article 6(1)(a)): Digest subscriptions are processed on your consent, given by confirming the link we email you, and withdrawable at any time through the unsubscribe link in any issue.
  • Legal Obligation (Article 6(1)(c)): We may process data when required to comply with applicable law, regulation, or legal process.

4. Privacy-Safe Behavioral Telemetry

We collect behavioral metrics to improve the usability and performance of GoValidate.ai. Our telemetry is designed to be privacy-safe:

  • Aggregate Metrics: Telemetry outputs contain only numeric counters (such as page views, clicks, and session heartbeats) and opaque data quality categories (such as count of warning columns or generic counts of detected PII types). It never contains raw column names, sample cell values, or raw file parameters.
  • PII Redaction Guard: Our analytics ingestion API automatically runs a redaction filter. If any event contains prohibited key patterns (such as email, credit card numbers, SSNs, or passwords), that event is instantly rejected and dropped.
  • Geo-Fenced Pointer Tracking: Mouse coordinate path tracking is completely disabled for all visitors originating from the European Union (EU), United Kingdom (UK), and European Economic Area (EEA), or when location cannot be determined.
  • Third-Party Analytics: Validated telemetry is stored in our first-party tables for up to 90 days and forwarded to a self-hosted instance of PostHog for UX analysis.

5. Data Sharing & Service Providers

We do not sell, rent, or trade your personal data. We may share limited metadata with trusted service providers (e.g., cloud hosting, analytics infrastructure) who act as data processors under our instruction and are bound by data processing agreements. These providers do not use your data for their own purposes. We may also disclose data when required by law, regulation, or valid legal process.

6. Data Protection

We implement industry-standard security measures, including encryption in transit (HTTPS) and at rest for our server-side metadata and identity tables, to protect against unauthorized access or alteration.

7. Data Retention

Server-side security logs and telemetry metadata are retained for a maximum of 90 days. Identity and authentication data are retained only as long as your account is active, or until you request deletion via our compliance tools. Digest subscription records are retained until you unsubscribe, after which the record is kept only to honour that request and prevent re-subscription without a fresh confirmation.

8. Cookies and Analytics Tools

We use essential cookies to maintain secure sessions and prevent CSRF attacks. We also use analytics tools (such as PostHog) to collect privacy-safe telemetry. You can learn more about our specific cookie usage in our Cookie Policy.

9. Your Rights

We comply with applicable global privacy frameworks, including the General Data Protection Regulation (GDPR) and the California Consumer Privacy Act (CCPA). You have the following rights regarding your personal data:

  • Right to Access & Portability: You have the right to request a copy of the personal metadata we store about your account.
  • Right to Rectification: You have the right to request correction of inaccurate personal data we hold about you.
  • Right to Deletion: You have the right to request the erasure of your account metadata and associated session logs.
  • Right to Object & Restrict Processing: You have the right to object to our processing of your data based on legitimate interest (including behavioral telemetry). You may also request that we restrict the processing of your data in certain circumstances.
  • No Sale of Data: GoValidate.ai does not sell your personal data to third parties as defined under the CCPA/CPRA.

To exercise any of these rights, use the compliance controls below or contact us at support@govalidate.ai.

10. Privacy Controls & Data Apparatus

Use the controls below to retrieve or request deletion of the personal metadata stored in our server-side storage for this browser session.

Detecting local browser identity...

11. Changes to This Policy

We may update this Privacy Policy from time to time. When we make material changes, we will update the "Last Updated" date at the top of this page. We encourage you to review this policy periodically.

12. Contact Us

If you have questions about this Privacy Policy or our data practices, please contact us at support@govalidate.ai.

Product
Legal Privacy Policy Terms of Service Cookie Policy
© 2025-2026 GoValidate.ai • All rights reserved •