KChat — Privacy Policy
Effective Date: 8 September 2026 Last Updated: 8 September 2026 Version: 1.0 (public beta edition)
This Policy explains what personal data KChat collects, why, who we share it with, how long we keep it, and what rights you have. It also explains, because it is the point of the product, what we do not collect.
Who we are. Karya, a partnership firm registered under the Indian Partnership Act, 1932 (Reg. No. 3263 of 2026), of New Delhi, India ("we", "us", "our"). We are the controller (Data Fiduciary under India's DPDP Act) for the data described in §4, except where §2 says otherwise.
Region-specific rights are in the annexes: EEA/UK · United States · India
1. The short version
- Your chats, files, memories, prompts, and settings are stored on your own computer, inside the app. We hold no copy. We cannot read them, back them up, or recover them.
- The only content that leaves your computer is what the model needs to answer: the current chat, attached file text, and applicable memories. It goes through our gateway and OpenRouter only to an inference endpoint that satisfies our zero-data-retention and no-data-collection rules. It is not stored as prompt or answer content by our gateway or OpenRouter.
- Our gateway stores your account, plan, and usage counts — tokens and cost, never the text.
- We do not use your content to train AI models, and our routing excludes endpoints that retain or train on it.
- We run no advertising, no analytics, no tracking pixels, and we do not sell or share your data.
- Web search is off by default. When you turn it on, search terms go to public search engines, which are outside the zero-retention promise.
- Crash reports are off by default and never contain content.
2. Our role
2.1. We are the controller for your account, sign-in, device, billing, usage, security, and support data — everything in §4.
2.2. We are a processor for the content of each request the app sends through our gateway. We relay it to the AI provider and return the answer. We store none of it. For any personal data about other people that you include in a request, you are the controller, you decide the purpose, and you are responsible for having a lawful basis. A separate Data Processing Addendum applies only where we and a business customer agree it in writing.
2.3. We are nothing at all for the content stored on your computer. It never reaches us. You alone control it.
3. What stays on your device
The app runs a database on your computer, bound to your machine only, in your
user profile — on macOS ~/Library/Application Support/KChat, on Windows
%APPDATA%\KChat. It holds:
- every chat and message;
- uploaded files, their extracted text, and your permanent Library;
- memories the app has learned about you, and their vectors;
- prompts, skills, settings, and your local sign-in session;
- a local copy of your name, email, and avatar from sign-in.
What we cannot do with this data: read it, monitor it, back it up, restore it, hand it to anyone, or delete it for you. What you should do: turn on FileVault or BitLocker (the app does not separately encrypt the database), export regularly, and delete the folder yourself when you no longer want it. Uninstalling the app leaves it in place.
4. What we collect and why
This is everything our servers hold about you.
| Data | Why | Where it lives | How long | Lawful basis |
|---|---|---|---|---|
| Email address, display name, identity-provider subject ID, email-verified status | Create and secure your account | Our identity provider; our gateway database | Until you delete the account; backup copies rotate within 30 days | Contract |
| Password | Sign you in | Our identity provider only, hashed. We never see it. | Until changed or account closed | Contract |
| Sign-in timestamps | Security; show you recent activity | Gateway database | Account lifetime | Legitimate interest (security) |
| Company name | Enterprise contact and support. Entered by us, or inferred from your work-email domain (never from personal mail providers) | Gateway database | Account lifetime | Legitimate interest |
| Device name (your computer's hostname, truncated) and one gateway key per signed-in device | Let you see and sign out your devices; attribute usage to a device | Gateway database | Until you sign the device out or close the account | Contract |
| Plan, allowance, top-up balance, account status, subscription and payment references | Run your plan; prevent double-charging; issue invoices | Gateway database; Razorpay | Account lifetime; financial records up to 8 years (Indian tax law) | Contract; legal obligation |
| Per-request usage rows: time, tokens in/out/cached, cost, device, model alias | Meter your allowance; bill correctly | Gateway database | 30 days, then deleted | Contract |
| Daily usage totals per account | Billing evidence; cost accounting | Gateway database | Financial record | Contract; legal obligation |
| Portal session cookie | Keep you signed in to the account portal | httpOnly cookie + gateway database | 30 days | Contract |
| IP address | Rate-limit sign-in, search, and crash-report endpoints | Not written to access logs. Held transiently in the rate limiter | Minutes | Legitimate interest (security) |
| Crash reports — app version and sanitised stack trace only | Fix crashes | Gateway logs | 90 days | Consent (off by default) |
| Support emails | Answer you | Mailbox | 24 months | Legitimate interest |
| Daily backups of the gateway database | Disaster recovery | Restricted backup volume | 30 days rolling | Legitimate interest |
We do not collect: the text of your requests or the model's answers; your files; your memories; payment card numbers (Razorpay handles those; we never see them); date of birth; government identifiers; biometric data; precise location; advertising identifiers; or any behavioural analytics.
5. How AI processing works
This is the most important section for a product like ours. Please read it.
5.1. What is sent. To answer, the app transmits the current message, the earlier turns of the same chat up to a context limit, the extracted text of files attached to that chat, and the memories that apply if memory is on. It never sends your other chats, your whole Library, your name, or your email. The model does not know who is asking.
5.2. Scanned pages. A PDF with no text layer is read by rendering each page to an image and sending it to the model for transcription. The transcription is stored on your device as the file's text.
5.3. Memory. Facts about you are extracted from your chats by the model. Where an embedding model is used to index them, the memory text is sent through the gateway for embedding under the same terms as any request. The memories and vectors are stored only on your device. Memory can be turned off per chat or globally, and every memory can be viewed, edited, or deleted in the app.
5.4. Where the processing happens. We use an open-weights language model through OpenRouter. Chat requests may be handled only by the approved GLM-5.3-Flash endpoints operated by Modal, Baseten, DeepInfra, or Novita. The processing location can vary by endpoint; we do not promise a particular country for inference. Embeddings use a separate OpenRouter route restricted to eligible zero-retention endpoints.
5.5. No training on your data. We do not use your content to train, fine-tune, or improve any AI model. Every provider request requires OpenRouter's zero-data-retention policy and denies data-collection endpoints. If no endpoint satisfies those rules, the request fails instead of being sent elsewhere.
5.6. What our gateway keeps. Our gateway is configured so that request and response text is never logged, never written to usage records, and never included in error logs. This configuration is checked by our automated tests. The gateway keeps, per request, the time, token counts, cost, and device — §4.
5.7. We cannot read your content. Not "we choose not to" — the content is on your computer and passes through our gateway only in transit, unlogged. The exceptions are the model provider, which processes it under zero retention, and the public search engines described in §6.
5.8. AI output. Every reply is AI-generated. See the AI Transparency Notice.
6. Web search
Web search is off by default. When you enable it for a chat, or turn on the account-level automatic search setting:
- The app removes common personal identifiers — email addresses, phone numbers, card and account numbers, postal addresses, and your own name — from the query before it leaves your computer. If nothing is left, no search runs.
- Unless you have enabled automatic search, the app shows you the exact terms and asks you to approve.
- The terms go to our gateway, which passes them to a private search service we run ourselves, and then fetches the result pages itself. No search vendor is involved, and the gateway does not log the terms or the URLs it fetched.
- Our search service forwards the terms to public search engines (currently Google and Bing), which see them from our gateway's address. Those engines are outside the model provider's zero-retention commitment and process the terms under their own policies.
The lawful basis is your request to search (contract). Do not include confidential information in a query you allow to be searched.
7. Who we share data with
We share the minimum necessary with vendors who process data on our behalf under contract. By category:
| Category | Location | What they get |
|---|---|---|
| AI routing and inference — OpenRouter; chat endpoints at Modal, Baseten, DeepInfra, or Novita; eligible embedding endpoints | Varies by endpoint | The content of each request, in transit, with zero-retention and no-data-collection routing required. No account data. |
| Identity provider | United States | Email address, password (hashed by them), display name, verification status |
| Payment processor (Razorpay) | India | Name, email, account reference, plan, amount. Card details go directly to them — we never receive or store them. |
| Hosting provider — Hetzner Online GmbH, gateway, database, private search | Helsinki, Finland | All gateway-side data in §4; request content in transit |
| GitHub — installer downloads and automatic updates | United States | Your computer's IP address and app version when it downloads or checks for an update |
| Public search engines (web search only, when enabled) | Various | Sanitised search terms, from our gateway's address |
| Exchange-rate feed | — | Nothing about you. We fetch a public USD–INR rate once an hour to price rupee charges. |
Named list on request. We identify each provider by name, with its location and the safeguards that apply, to any customer who asks — support@the-karya.com. Business customers under a Data Processing Addendum also receive 30 days' notice before we add or replace one, with a right to object.
We also disclose data where legally required — to comply with a valid court order or legal process, to enforce our Terms, or to protect the rights, property, or safety of our users, the public, or us. Where we are legally permitted to tell you first, we will. Note that we cannot produce your content in response to a legal demand, because we do not have it.
If we are involved in a merger, acquisition, reorganisation, incorporation, or sale of assets — including any conversion of Karya to a successor entity of any form — account data may transfer as part of it, with notice to you beforehand.
We do not sell your personal data. We do not share it for cross-context behavioural advertising. We do not use it for advertising at all.
8. International transfers
We are based in India. Our identity provider is in the United States, our gateway is hosted by Hetzner in Helsinki, Finland, and inference goes through OpenRouter to an eligible endpoint whose processing location may vary. Depending on where you are and which endpoint handles a request, your data may therefore leave your region.
Our vendor terms include the European Commission's Standard Contractual Clauses (2021) and the UK International Data Transfer Addendum where applicable. We also use technical and organisational safeguards — encryption in transit, zero-retention routing for inference, no logging of content at the gateway, and data minimisation. The underlying vendor transfer terms are available on request. We do not currently publish a separate KChat transfer impact assessment.
Where you are in India, transfers outside India are made in accordance with the conditions permitted under the DPDP Act.
9. How long we keep data
Retention is set out per data type in §4. The principles:
- Your content — not held by us. It lives on your computer for as long as you keep it.
- Account data — until you delete the account. The live Gateway account, WorkOS identity, inference user, and Device Keys are then removed; required payment and tax records are retained separately.
- Per-request usage rows — 30 days.
- Daily usage totals and financial records — as long as tax and accounting law requires (in India, typically up to 8 years). These cannot be deleted on request.
- Crash reports — 90 days.
- Backups — 30-day rolling window.
- Everything else — deleted when the purpose is served.
Deletion is a real database delete, not a soft flag. Limited copies may persist in rolling backups for up to 30 days before those backups rotate.
10. Security
On your computer: the database accepts connections only from your own machine and requires a password that the app generates once and stores in your operating system's keychain or credential manager. Your gateway key is stored the same way and never shown in the interface. The code sandbox runs in an isolated runtime with no network or file-system access. Encryption at rest is provided by FileVault or BitLocker — turn it on.
Between your computer and us: TLS in transit. Sign-in uses OpenID Connect with PKCE through your system browser; the app never sees your password. One revocable key per device.
At the gateway: request and response logging switched off and tested; model and provider identifiers stripped from responses; per-route rate limiting; request-size limits; administrative access restricted to signed-in, allowlisted administrator accounts; daily rolling database backups.
No system is completely secure and we do not claim otherwise. If we become aware of a breach affecting your personal data, we will notify you and the relevant regulator where the law requires. Because your content is not on our systems, a breach of our gateway cannot expose your chats or files.
Report a vulnerability: support@the-karya.com.
11. Your rights
Wherever you are, you can:
- Access what we hold about you. Your plan, usage, devices, and invoices are visible in the account portal; Download account data provides the gateway-side copy in a machine-readable file.
- Correct inaccurate details.
- Delete your account and its gateway record with Delete account permanently in the account portal or App after confirming your signed-in email. Your content on your computer is yours to delete, and uninstalling the app does not do it for you.
- Object or withdraw consent where processing relies on it — crash reporting can be turned off in the app at any time.
- Complain to us, and to your data protection regulator.
We respond within 30 days. We may need to verify your identity first — we will ask for the minimum needed. Exercising these rights is free; we may charge only for manifestly unfounded or excessive repeat requests.
Some data cannot be deleted on request: financial records we must keep for tax law, and a minimal record that an account was closed (so it is not silently recreated).
Region-specific rights and how to exercise them: Annex A, Annex B, Annex C.
Contact: support@the-karya.com
12. Cookies
Our public website sets no cookies. The account portal sets one strictly necessary session cookie to keep you signed in, and our payment processor sets its own cookies during checkout. We use no advertising, remarketing, behavioural-analytics, or profiling cookies, and we embed no third-party trackers or social pixels.
Because we set no non-essential cookies, we do not show a consent banner. If that ever changes, we will ask for your consent first and honour Global Privacy Control signals. Details: Cookie Notice.
13. Children
The Service is for people aged 18 and over. We do not ask for your date of birth and do not verify age. We do not knowingly collect data from children, and we do no tracking or targeted advertising directed at anyone.
If you believe a child has created an account, contact support@the-karya.com and we will close it.
14. Changes
We may update this Policy. For material changes we will notify you by email or in-product at least 15 days before they take effect, and post the updated version with a new date. Previous versions are available on request.
15. Contact
Karya — New Delhi, India
| Privacy and data requests | support@the-karya.com |
| Grievance Officer (India) | Aarya Banthia — support@the-karya.com |
| Security | support@the-karya.com |
Annex A — EEA/UK (GDPR)
A.1. Controller. Karya, address above. We have no establishment in the EU or UK. You can reach us directly, in English, at support@the-karya.com, and we respond to data protection requests within 30 days — see §11.
A.2. Lawful bases. Set out per data type in §4. In summary: contract (Art 6(1)(b)) for account, relaying requests, metering, and billing; legal obligation (Art 6(1)(c)) for tax and accounting; legitimate interests (Art 6(1)(f)) for security, abuse prevention, and cost accounting — we have balanced these against your rights and you may object at any time; consent (Art 6(1)(a)) for crash reports, which you may withdraw at any time without affecting prior processing.
A.3. Your rights. Access (Art 15), rectification (16), erasure (17), restriction (18), portability (20), objection (21) — including an absolute right to object to direct marketing — and the right not to be subject to solely automated decisions with legal or similarly significant effects (22).
A.4. Automated decision-making. We do not make decisions producing legal or similarly significant effects about you by automated means. The AI answers your questions at your instruction; it does not evaluate, score, or make decisions about you. The allowance hard stop is a contractual usage limit, not a decision about you.
A.5. Transfers. See §8. The underlying vendor transfer terms are available on request. A separate KChat transfer impact assessment is not currently available.
A.6. Complaints. You may complain to your national supervisory authority. In Ireland, the Data Protection Commission (dataprotection.ie); in the UK, the Information Commissioner's Office (ico.org.uk). We would appreciate the chance to resolve it first.
A.7. No statutory requirement to provide data — but we cannot provide the Service without account data.
Annex B — United States
B.1. Scope. This annex applies to residents of US states with comprehensive privacy laws, including California, Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, and others as they take effect. We extend these rights to all US residents regardless of whether we currently meet a given state's applicability threshold.
B.2. We do not sell or share your personal information. We have not sold or shared personal information for cross-context behavioural advertising in the preceding 12 months, and we do not do so now. We do not process personal information for targeted advertising or profiling in furtherance of decisions producing legal or similarly significant effects.
B.3. Categories collected (CCPA/CPRA terminology): identifiers (name, email, device name, IP transiently); commercial information (plan, purchases, top-ups); internet activity (usage counts). The content of your requests passes through our systems in transit only and is not collected. We collect no sensitive personal information as defined by the CPRA. Sources, purposes, and recipients are in §4 and §7.
B.4. Your rights. To know, access, and obtain a portable copy; to correct; to delete; to opt out of sale, sharing, and targeted advertising (nothing to opt out of — see B.2); to limit use of sensitive personal information (none collected); and to be free from discrimination for exercising any of these. Exercise them at support@the-karya.com.
B.5. Global Privacy Control. We do not sell or share data, use targeted advertising, or set non-essential cookies, so a GPC signal has no processing to stop.
B.6. Authorised agents. An authorised agent may submit a request on your behalf with written proof of authorisation; we may ask you to verify directly.
B.7. Appeals. If we refuse a request, you may appeal by replying to our decision or writing to support@the-karya.com with "Appeal" in the subject. We respond within 45 days. If we deny the appeal you may complain to your state Attorney General.
B.8. Response times. We confirm within 10 business days and substantively respond within 45 days, extendable once by a further 45 days with notice.
B.9. Shine the Light (California Civil Code §1798.83). We do not disclose personal information to third parties for their own direct marketing.
B.10. Children. The Service is 18+. We do not knowingly collect data from anyone under 18 and therefore do not sell or share the data of consumers under 16.
Annex C — India (DPDP Act)
C.1. Data Fiduciary. Karya, address above. Grievance Officer: Aarya Banthia, support@the-karya.com.
C.2. Notice and consent. We give this notice before or at collection, in clear plain language, itemising the data and the purpose. Where we rely on your consent — crash reporting — it is free, specific, informed, unconditional, and unambiguous, given by affirmative action, and withdrawing it is as easy as giving it — from the app's settings or by email. Withdrawal does not affect processing already carried out. You may request this notice in English or any language in the Eighth Schedule to the Constitution.
C.3. Legitimate uses. Beyond consent, we process for the legitimate uses the Act permits — including where you voluntarily provide data for a specified purpose, and for compliance with law and judgments.
C.4. Your rights as a Data Principal. To access a summary of your personal data and our processing; to correction, completion, updating, and erasure; to nominate another individual to exercise your rights if you die or become incapacitated; and to grievance redressal.
C.5. Grievance redressal. Write to the Grievance Officer. We acknowledge promptly and respond within the timelines the Act and Rules prescribe. If you are not satisfied, you may complain to the Data Protection Board of India — but you must raise it with us first.
C.6. Children. We do not knowingly process the data of anyone under 18 and undertake no tracking or targeted advertising directed at children.
C.7. Erasure. We erase personal data when the purpose is no longer served, when you withdraw consent, or when retention lapses — unless the law requires us to keep it.
C.8. Breach. We will notify the Data Protection Board and affected Data Principals where and within the timelines the DPDP Act requires.
C.9. Transfers. Made in accordance with the conditions permitted under the DPDP Act. See §8.