Privacy and cookies
Last updated 2026-09-30.
This page explains what PolicyPilot stores, which cookies it uses, and who else is involved in serving the site. It is written to be read, not to be skimmed past.
What we store
- Your account: your name, email address and a hashed password (bcrypt). We never see or store the password itself.
- Your organisation's work: the policies you paste or upload, assessments, control statuses, risks, evidence records and obligations. This belongs to your organisation and is visible only to its members.
- An audit log of changes made in your organisation, including sign-ins and the IP address they came from. The log is append-only by design.
- Uploaded files are read in memory to extract their text and are not kept — only the extracted text is saved.
Cookies and local storage
- Session cookie (
policypilot.sid) — keeps you signed in and protects forms against cross-site request forgery. Strictly necessary. Visitors who are not signed in get a short-lived one (about two hours). - Theme preference — stored in your browser's local storage if you switch between light and dark mode. It never leaves your device.
AI review
The gap analysis itself runs on our server and does not need an AI model. This instance currently has no AI provider configured, so nothing you upload is sent to one.
Deleting your data
An organisation admin can delete policies, risks, evidence and obligations at any time. To close an account or remove an organisation entirely, email privacy@sabiapps.com.
Not legal advice
PolicyPilot tells you what your documents say against a framework's controls. It is not an audit and not legal advice.