What Cairn holds, why, and what it never captures.
Cairn takes screenshots of software for a living, so the interesting question is not our cookie banner — it is what ends up inside an image and who can retrieve it afterwards.
Roles — who is the controller needs counsel
For the content you put into Cairn and the conversations your customers have with you, you are the controller and Cairn is the processor. We process it on your instruction, under a data processing agreement, and we do not decide what it is for.
For your own account — the person who signed up, billing, support correspondence with us — Cairn is the controller. That is a much smaller dataset and it is the only place we act on our own behalf.
What capture records, and what it refuses to record
This is the section that matters most, because it is the one that differs from every other vendor in this category.
- Capture records the label of a form field — "Card number" — and never the value entered into it. Input masking happens at the source, in the client, before anything is transmitted.
- Screenshots are captured with policy redaction applied at ingest, before any human being can view the image. Enforced rules are not a review step someone can skip.
- Enterprise workspaces can run strict originals: the original image is encrypted at rest, never served, and permanently deleted once a redacted derivative exists.
- What does still land in an image is whatever else was on screen. That is your responsibility as controller, and it is why the redaction tiers and the blocklist exist — use them before you capture production.
Customer data inside the platform
Contacts, conversation transcripts, tickets, and the knowledge you author are stored per workspace. Every tenant-scoped record carries a workspace scope enforced at the model layer, and automated cross-tenant probes run against the build.
Conversation mining, which turns resolved conversations into draft articles, is opt-in per workspace. Drafts pass a PII scrub before a human sees them, and contact data is never included verbatim in a generated draft.
AI processing needs counsel
Retrieval and answer generation involve sending the relevant knowledge chunks and the conversation context to a model provider. The specific provider, the region, and the contractual terms on training will be named in the subprocessor list at launch.
What we can commit to now: your content is not used to train a shared model, retrieval is scoped to the audience of the asker, and every answer records the sources it drew on so the processing is auditable rather than opaque.
Your rights, and your customers’ rights
Cairn ships tooling for export and erasure rather than asking you to file a ticket and wait. As controller you can service a data subject request yourself — find the contact, export what is held, erase it, and have the erasure propagate.
- Export: machine-readable export of a contact and their full conversation history.
- Erasure: deletion of a contact and their messages, propagating to derived artefacts including embeddings and mined drafts.
- Access log: an exportable audit log answering who viewed what and when — the question a legal team actually asks.
International transfers and residency needs counsel
EU data residency is available to Enterprise workspaces on request and is not a standing capability of the platform. If your review requires guaranteed in-region processing today, ask us and we will tell you precisely what is possible rather than gesturing at a roadmap.
Transfer mechanisms, standard contractual clauses and the transfer impact assessment are drafted with counsel before launch.
Subprocessors final list at launch
These are the categories of processor the product requires. Named vendors, regions and DPA links are confirmed at launch — publishing a name we then change would be worse than publishing the category now.
- Cloud hosting
- Application servers, object storage for screenshots and exports, managed PostgreSQL and Redis.
- Model provider
- Retrieval-augmented answer generation, step-text drafting, summaries and translation.
- Email delivery
- Transactional email, the email support channel, and export delivery.
- Messaging providers
- WhatsApp, Messenger, Instagram, Telegram and SMS channel delivery — each is the channel owner’s own processor.
- Payments
- Subscription billing and credit top-ups. Cairn never stores card numbers.
- Error and performance
- Application error reporting and performance monitoring, with PII scrubbed at the client.
Retention and deletion
Deletion propagates to derived artefacts, including embeddings — which is the part most vendors leave vague. A deleted guide does not linger in a vector index answering questions.
- Screenshot originals
- Retained per workspace policy. Under strict originals, encrypted at rest, never served, deleted once a redacted derivative exists.
- Conversation transcripts
- Retained for the workspace retention window you configure, then deleted with their attachments.
- Contacts
- Deleted on request, propagating to messages, mined drafts and embeddings.
- Embeddings and indexes
- Deletion of source content removes its vectors. A deleted guide cannot answer a later question.
- Audit logs
- Retained longer than content by design, because their purpose is answering "who saw what" after the fact. Window confirmed at launch.
- Account and billing records
- Retained as long as required by tax and accounting obligations, then deleted.
Two things worth knowing before you evaluate us
Masked capture means the field label is recorded and the value typed into it never is — architecturally, with tests, not as a setting. And audience enforcement happens at retrieval, so an internal document cannot surface in a customer-facing answer even if someone links it. Both are described in full on the security page.