1. Who we are
CA PRO Toolkit ("we", "us", "our") is a suite of professional tools that helps Chartered Accountant firms manage audit, compliance, and firm workflow. It consists of the CA PRO Toolkit Windows desktop application, the browser extension with its full-page workspace and Web View, the standalone tool pages, and the backend service at api.caprotoolkit.in.
The data controller (the "Data Fiduciary" under the Digital Personal Data Protection Act, 2023) is Saifullah Faizan, sole proprietor, trading as CA PRO Toolkit, at 130A, Dr. Lal Mohan Bhattacharjee Road, Kolkata 700014, West Bengal, India. For any privacy question or data request, see the Grievance officer section below.
2. Scope
This policy applies to all four surfaces named above: the Windows desktop application, the browser extension and its full-page workspace and Web View, the standalone tool pages, and the backend API at api.caprotoolkit.in. It also covers support and account communication handled by email.
3. Information we collect
- Account and contact information: your name and email address from Google Sign-In, used to authenticate you and to communicate about your account and support.
- Firm and workspace data: the tasks, clients, reminders, reconciliations, cases, engagements, reviews, and other records you and your firm create in the product.
- Statutory and tax identifiers of your clients and deductees: PAN, GSTIN and TAN that you enter are stored on the backend and indexed so they can be searched. This includes the PAN of deductees in TDS records. These are collected because the product cannot do reconciliation, TDS review or notice handling without them — but they are collected, they are stored, and we say so here plainly.
- Document text you submit: text you paste, upload, or choose to review. File text is extracted on your device first; only text you send is processed.
- Technical and diagnostic data: application and browser version, device and operating-system information, and basic logs used for security, compatibility, and troubleshooting. On the desktop application a diagnostics file is written only when you ask for one, and only where you choose to save it; nothing is uploaded automatically.
- Messages you send us: the content of emails and feedback you submit.
4. Information we do not collect
- We do not sell your personal data.
- We do not track your activity across other websites.
- We do not use your data, or your clients' data, to train any AI model.
5. How we use your information
- To authenticate you, enforce firm roles and permissions, and keep your data secure.
- To provide, maintain, and improve the product and its features.
- To send service-related communication and respond to your requests.
- To detect, prevent, and investigate abuse, fraud, and security issues.
6. Document processing, AI, and OCR
Document review is designed to be local-first. When you review a file, its text is read on your device before anything is sent. Sending content to the AI assistant or to the online text reader (OCR) is optional and always requires your explicit consent for that action. High-impact values such as dates, amounts, and conclusions remain unconfirmed until a person confirms them, and the product does not file to any government portal.
What masking does and does not do. Before your text is sent to the AI model, the server masks GSTIN, PAN, email addresses, Aadhaar numbers and phone numbers. Names, amounts and addresses are not masked and are sent as written. This is the same statement the application itself shows you at the point of sending, and it is repeated here so the two cannot differ. Do not paste anything you would not be willing to send outside your firm.
7. Authentication and sessions
Sign-in uses Google Sign-In. A secure token is stored in your browser's extension storage to keep you signed in. Where email verification is used, one-time passwords are short-lived and used only for authentication.
8. Local storage on your device
Some information (session state, preferences, and cached data such as looked-up guidance) is stored locally in your browser to improve performance. You can clear this through your browser at any time; some features may reset afterward.
9. Cookies and similar technologies
The extension relies on browser extension storage rather than advertising cookies. The marketing website may use minimal, privacy-respecting analytics. We do not use cross-site advertising trackers.
10. Sharing and service providers
We share information only with the service providers required to operate the product, or where legally required, or to investigate security issues. We name each one. A Chartered Accountant bound by the ICAI duty of confidentiality cannot obtain informed client authorisation without knowing who receives a client's documents, so a generic label such as "an AI provider" is not good enough here.
| Recipient | What it does | Endpoint | When |
|---|---|---|---|
| Sign-in and identity verification | Google Sign-In | Every sign-in | |
| DeepSeek | AI analysis of audit text and case content | api.deepseek.com | Only for the specific action you consent to, per action |
| OCR.space | Reading the text out of a scanned document or photograph | api.ocr.space | Only for the specific file you consent to, per file |
| Resend | Delivering account, reminder, digest and support email | Resend email API | When an email is sent to you |
| Hosting and database provider | Running the backend API and storing your firm's records | Hostinger (backend API) and MongoDB Atlas, Mumbai region, India (database) | Continuously |
Members of your shared firm can see the firm records you contribute, according to their role.
10a. Cross-border transfer
Some of the recipients above process data outside India. Section 16 of the Digital Personal Data Protection Act, 2023 permits transfer of personal data outside India except to a territory the Central Government restricts by notification; we do not transfer to any restricted territory.
- DeepSeek — the API is operated from outside India. Data leaves India when, and only when, you consent to an AI action.
- OCR.space — the API is operated from outside India. Data leaves India when, and only when, you consent to reading a specific file.
- Google and Resend — both operate globally distributed infrastructure and may process data outside India.
- Database (MongoDB Atlas) — hosted in the Mumbai region, India. Your firm's records therefore do not leave India by being stored. This is the one recipient in the table above that involves no cross-border transfer at all.
- Backend API host (Hostinger) — the serving region is not confirmed. We are not stating a region we have not verified. This is a separate question from where the database sits, which is answered above.
The AI and OCR paths are consent-gated per action in code, not merely by policy: the server refuses an OCR request without explicit consent, and refuses an AI audit request without explicit consent, in both cases before any outbound call is made.
10b. What we collect, why, and how to withdraw consent
Set out per purpose, as section 5 of the Digital Personal Data Protection Act, 2023 requires:
| Purpose | Personal data used | How to withdraw |
|---|---|---|
| Authenticating you and enforcing firm roles | Name, email address, session token | Stop using the product; ask the grievance officer to close the account. Withdrawal ends access, because access cannot work without authentication. |
| Providing firm and workspace features | Firm records you create, including client PAN, GSTIN and TAN | Ask the grievance officer. See section 13 for what can and cannot then be erased. |
| AI analysis (optional) | The document text for that one action, with GSTIN, PAN, email, Aadhaar and phone masked | Simply do not consent when asked. Consent is requested per action, so declining once does not affect anything else. |
| Reading a scanned document (optional) | The image or file for that one action | As above — do not consent when asked. |
| Sending you service email | Name, email address | Use the unsubscribe link in a digest email, or ask the grievance officer. Essential account and security messages will still be sent. |
11. Data security
Connections use industry-standard encryption in transit. Access is protected by token-based authentication and server-side role and permission checks. No method of transmission or storage is perfectly secure, but we apply reasonable safeguards to protect your information.
12. Data retention
Set out per class, so this page, the product's own Security screen and the API all state one thing. These are the same classes the product publishes to its own clients, not a separate summary written for this page.
| Class | How long | Why we may keep it |
|---|---|---|
| The extracted text of a notice or document | Removed 30 days after it was stored. The file's name, size, extraction method and date are kept, so the record that it was read survives even though the text does not. | Kept only as long as it is needed to show a document was read. Nothing is retained on a statutory basis here, which is why the text itself goes. |
| AI analysis of a working paper | Removed 30 days after it was produced — unless a finding cites it, in which case it is kept so a conclusion never outlives the basis it cites. | Kept only where a finding depends on it, so a conclusion never outlives its own basis. No statutory basis is claimed for the analysis itself. |
| Working papers, their source evidence rows, and your findings | Kept. This is your firm's work product and is never removed automatically. | Your firm's professional record-retention obligations under the Chartered Accountants Act and ICAI documentation standards. These are the firm's working papers, and the firm — not CA PRO — is the party required to keep them. |
| Reconciliation runs, TDS checks, tasks, clients and the activity trail | Kept as firm records. | Record-keeping obligations under the Income-tax Act and the CGST Act, which require the underlying computations and filings to remain available for inspection. |
| Review history stored on your own device | Under your control — you can clear it at any time, and clearing it cannot be undone. | No basis claimed. It is on your computer and under your control. |
Your own name and email are not in that table, deliberately. No retention basis is claimed for them. They are erasable on request, and no statutory record-keeping obligation is used to justify keeping them — the records above are your firm's work and your clients' statutory data, which is a different thing from your own identity as a user.
On your own PC (desktop application). Your session, your cached records and any unsent changes are stored on that computer, encrypted with Windows DPAPI so that only your Windows account can read them. Cached records expire on their own. You can remove them yourself at any time from the two buttons on the application's Security screen: "Remove out-of-date records" and "Remove all local data".
13. Your rights
Stated per right, with what actually happens rather than what would sound best. Where a right is limited, the limit is named.
- Access (DPDP s.11). You can ask for a copy of the personal data we hold about you, and a summary of who it has been shared with. Write to the grievance officer below.
- Correction (DPDP s.12). You can edit most of your own firm records directly in the product. Your account name and email come from Google Sign-In — correct them at Google and they update here on your next sign-in. Anything you cannot reach yourself, the grievance officer will correct on request.
- Erasure (DPDP s.12(3)) — and its real limits. There is no self-service account deletion. This is deliberate: a firm's audit working papers must not be destroyable by one session, one mistake, or one departing member. A firm, or one member of it, is removed only by our super administrator acting on a written request from the firm. On such a request: your own identity fields (name, email) are erased or replaced with a tombstone; records your firm is required by law to keep are retained, and we will tell you which ones and on what basis. We will not use a statutory-retention argument to keep your name and email address — those are treated separately from the work product and are erasable. The removal covers every record we hold about the firm, not a subset, and it produces a receipt recording, for each type of record, what was erased and what was kept — you can ask the grievance officer for a copy of it.
- Withdrawing consent (DPDP s.6(4)). The AI and OCR paths ask for your consent per action, so declining is simply not consenting when asked. Text already sent and processed before you declined cannot be recalled from the provider; the copy we hold follows the 30-day removal in section 12.
- Grievance redressal (DPDP s.13). See the next section. We will substantively respond within 30 days.
- Opting out of non-essential email. Use the unsubscribe link in a digest email, or write to us. Essential account and security messages will still be sent.
13a. Grievance officer
Under section 13 of the Digital Personal Data Protection Act, 2023:
- Name: Saifullah Faizan
- Designation: Proprietor
- Email: support@caprotoolkit.in
- Postal address: 130A, Dr. Lal Mohan Bhattacharjee Road, Kolkata 700014, West Bengal, India
- Response window: we will substantively respond within 30 days of receiving your request.
14. Children
CA PRO Toolkit is a professional tool intended for firms and is not directed to children. We do not knowingly collect data from children.
15. Changes to this policy
We may update this policy from time to time. Material changes will be reflected by a new effective date. Continued use of the product after an update constitutes acceptance of the revised policy.
What changed on 23 August 2026, and why
Recorded plainly rather than quietly rewritten, because two of these were corrections of statements that were not true:
- Removed a false claim about government identifiers. This policy previously stated, in section 4, that we do not intentionally collect sensitive personal data such as government IDs. PAN, GSTIN and TAN are government-issued identifiers, and the product collects, stores and indexes them. Section 3 now says so.
- Corrected an imprecise claim about uploaded files. Section 4 previously said we do not retain uploaded source files after their text has been processed. The accurate position is now in section 12: extracted text is removed 30 days after it is stored, while the file's name, size, extraction method and date are kept as a record that it was read.
- Brought the Windows desktop application into scope. Sections 1 and 2 previously described the product as a browser extension and backend service only, while users were being asked to accept this policy when signing in to a Windows application it did not mention.
- Named every third-party recipient. Section 10 previously used generic labels ("AI provider", "online text reader"). It now names DeepSeek, OCR.space, Resend and Google, with endpoints, because a Chartered Accountant cannot obtain informed client authorisation without knowing who receives the client's documents.
- Added cross-border transfer, a DPDP section 5 notice, and a grievance officer section. None of the three existed before.
- Made retention and rights specific. Section 12 was "as long as needed"; it is now a per-class table matching what the product itself publishes. Section 13 promised "correction or deletion" without qualification; it now states what erasure actually does and does not do.
16. Contact
General questions: support@caprotoolkit.in. Privacy and data-rights requests: use the Grievance officer above. See also our Terms & Conditions and the Windows download page.