Legal & Privacy
AI Disclosure and Transparency Notice
This notice is provided in the interest of transparency and to satisfy applicable transparency obligations, including Article 50 of the EU Artificial Intelligence Act (Regulation (EU) 2024/1689), for the AI chat and data-masking gateway service (the "Service", "Filterit") provided by the operator of filterit (the "Operator"). It supplements the Terms of Service and Privacy Policy.
1. You Are Interacting With an AI System
1.1 The Service uses artificial-intelligence systems. When you use the chat, documents, the Email Assistant and mail automation, meetings or the review grid, your masked content is processed by a general-purpose large-language model operated by a third party, currently Anthropic, PBC (Claude, United States), and the responses you see are generated by AI, not by a human. Detection of personal data, OCR, speech-to-text and visual redaction run on systems operated by the Operator; no language model of a third party is involved in them.
1.2 This notice constitutes the clear disclosure that you are interacting with an AI system, as required by Article 50 of the EU AI Act. The disclosure is also surfaced in the user interface: each answer is labelled "AI response" and the chat shows a standing notice that AI can make mistakes.
1.3 Systems used. Language model: Anthropic Claude (the current model name is listed on the sub-processor page; it changes with provider releases). Detection: rule-based validators for national identifiers, Microsoft Presidio with the spaCy models el_core_news_lg and en_core_web_lg, the GLiNER model urchade/gliner_multi_pii-v1, and a Greek named-entity model trained by the Operator, all run on the Operator's infrastructure. OCR: Tesseract. Speech-to-text (optional, meetings and voice notes): faster-whisper, self-hosted. The Service does not perform emotion recognition, biometric categorisation or the generation of deepfakes.
2. AI Outputs May Be Inaccurate
2.1 AI-generated content can be incorrect, incomplete, outdated, biased, or entirely fabricated (so-called "hallucinations"). The Service may produce plausible-sounding text that is wrong.
2.2 You should independently verify any factual, technical, or important information before relying on it or acting on it. Do not assume an Output is accurate merely because it is fluent or confident.
3. Not Professional Advice
3.1 The Service does not provide legal, medical, financial, tax, or other regulated professional advice, and no AI Output should be treated as such or as a substitute for a qualified professional.
3.2 No client, professional, fiduciary, or advisory relationship is created by your use of the Service. For decisions with legal, health, financial, or safety implications, consult a qualified professional.
4. Masking / Pseudonymisation Is Best-Effort
4.1 The Service attempts to detect and mask personal data before sending content to AI providers, replacing identifiers with reversible tokens (e.g. [NAME_1]). This is pseudonymisation, not anonymisation. The data remains personal data and the original values are retained encrypted in the Vault (see Privacy Policy Section 2).
4.2 Detection is automated and best-effort and may miss or misclassify personal data, including where an optional detector is offline, where text is OCR-derived, or where the language/format is unusual. As a safety measure the pipeline is designed to fail closed (refusing the request if a detector is unreachable rather than sending content un-masked, unless an API client explicitly asked for degraded processing), but this is not a guarantee that masking is complete or correct.
4.3 You must not submit personal data you are not authorised to share, and you must verify masking/redaction yourself before relying on it.
5. Human Oversight and Responsibility
5.1 You remain the human in control. You are responsible for reviewing, verifying, and deciding how to use any AI Output, and for any actions you take based on it, including any draft produced by the Email Assistant, which you review and send, and any draft that mail automation prepares in your mailbox.
5.2 The Service is a tool to assist you; it does not make decisions on your behalf and does not perform solely-automated decision-making with legal or similarly significant effects on you.
6. How the AI Processing Works (Summary)
6.1 Your message or file is received; personal data is detected automatically; identifiers are replaced with reversible tokens; the masked content is sent to the third-party AI provider; the AI generates a response; the tokens are replaced with the original values; the response is shown to you. If you choose the RAW or Original option, the content is sent without masking. Email threads (if you use the Email Assistant) are fetched live and not stored; only masked drafts are stored. When web search is on in a conversation (it is on by default and can be switched off in the chat settings), the model may decide to search and writes the search query itself; placeholders are removed from the query but it is not run through masking, and it goes from our server through a search aggregator we run (SearXNG) to public search engines (Google, Bing, DuckDuckGo and others in the default set); the results come back to the model unmasked, and the query is not written to the egress log.
6.2 Every send to the AI provider is recorded in a hash-chained, content-free audit log (destination, size, hash, masked preview); web search queries are not part of it. Further detail on data handling, sub-processors, and international transfers is in the Privacy Policy and on the sub-processor page.
7. Questions
7.1 For questions about this notice or the AI systems used: contact@filterit.app. Data-protection enquiries: contact@filterit.app (we have not appointed a data protection officer).