Privacy Policy

Last updated: 1 April 2026

1. Introduction

OremAI is a product of Keovation Solutions (Pty) Ltd, a company registered in South Africa. We are committed to protecting your personal information in accordance with the Protection of Personal Information Act, 2013 (POPIA) and all other applicable South African privacy legislation.

This Privacy Policy explains what information we collect, how we use it, how we store and secure it, and what rights you have regarding your data when you use the OremAI platform.

2. Information We Collect

We collect the following categories of personal information:

  • Account information: Full name, email address, phone number, and billing details provided during registration or checkout.
  • Scan input data: Name, email address, and other identifiers you provide to initiate a digital footprint scan.
  • Scan results and exposure data: Information discovered about you from publicly accessible sources, data broker listings, and online databases, including exposure scores and risk indicators.
  • Removal request records: Details of data removal requests we submit on your behalf to third-party data brokers.
  • Usage data: Pages visited, features used, and session metadata (collected via server-side analytics only).
  • Communication records: Messages sent via our contact form, support enquiries, and related correspondence.

3. How We Use Your Information

We use your personal information for the following purposes:

  • Performing digital footprint scans to identify where your personal data is exposed online.
  • Calculating your exposure risk score based on the severity and breadth of data found.
  • Submitting data removal requests to data brokers and third-party platforms on your behalf.
  • Monitoring for re-listing of your data after removal has been completed.
  • Processing payments and managing your subscription.
  • Sending you important service notifications (scan results, removal status updates, billing confirmations).
  • Improving the OremAI platform based on aggregated, anonymised usage patterns.

4. Data Storage and Security

We take the security of your personal information seriously and employ industry-standard measures to protect it:

  • Database: Your data is stored in Supabase, a secure PostgreSQL-based cloud platform, with row-level security policies ensuring users can only access their own data.
  • Encryption: All data is encrypted at rest using AES-256 encryption and in transit using TLS 1.3.
  • Hosting: We use South African-hosted infrastructure where possible to ensure data sovereignty. Where international infrastructure is required, we ensure appropriate safeguards are in place.
  • Access control: Only authorised personnel with a legitimate business need can access personal information. Access is logged and audited.

5. Third-Party Services

OremAI integrates with the following third-party services to deliver its core functionality:

  • Firecrawl: Used for web scanning and data discovery to identify where your personal information appears online. Firecrawl processes scan queries but does not retain your personal data beyond the scan session.
  • Supabase: Provides authentication, database storage, and real-time functionality. Supabase processes data in accordance with their Data Processing Agreement.
  • Vercel: Hosts the OremAI web application. Server-side rendering and API routes execute on Vercel infrastructure.

We do not sell, rent, or trade your personal information with any third party for marketing purposes.

6. Your Rights Under POPIA

As a data subject under the Protection of Personal Information Act, you have the following rights:

  • Right of access: You may request confirmation of whether we hold personal information about you and request a copy of that information.
  • Right to correction: You may request that we correct or update any inaccurate or incomplete personal information.
  • Right to deletion: You may request that we delete your personal information, subject to any legal obligations requiring us to retain certain records.
  • Right to object: You may object to the processing of your personal information on reasonable grounds.
  • Right to withdraw consent: Where processing is based on your consent, you may withdraw that consent at any time.
  • Right to lodge a complaint: You may lodge a complaint with the Information Regulator of South Africa if you believe your rights have been infringed.

7. Data Retention

We retain your personal information as follows:

  • Scan data and exposure results: Retained for 12 months from the date of the scan, after which it is automatically purged. You may request earlier deletion at any time.
  • Account data: Retained for as long as your account is active. Upon account deletion, all personal data is permanently removed within 30 days.
  • Billing records: Retained for 5 years as required by the South African Tax Administration Act.
  • Communication records: Retained for 12 months following the last communication.

8. Cookies and Tracking

OremAI uses minimal cookies and tracking mechanisms. We do not use third-party advertising trackers, behavioural analytics, or fingerprinting technologies.

  • Authentication tokens: Session cookies required to keep you securely logged in.
  • Preference cookies: Used to remember your display preferences (such as theme settings).

We do not use Google Analytics, Facebook Pixel, or any similar third-party tracking tools.

9. Changes to This Policy

We may update this Privacy Policy from time to time. When we make material changes, we will notify you via email or through a prominent notice on the OremAI platform. We encourage you to review this page periodically.

10. Contact Us

If you have questions about this Privacy Policy or wish to exercise any of your rights, please contact us:

  • Email: privacy@oremai.co.za
  • Company: Keovation Solutions (Pty) Ltd
  • Jurisdiction: Republic of South Africa