KChat — Privacy Policy

Effective Date: 8 September 2026 Last Updated: 8 September 2026 Version: 1.0 (public beta edition)


This Policy explains what personal data KChat collects, why, who we share it with, how long we keep it, and what rights you have. It also explains, because it is the point of the product, what we do not collect.

Who we are. Karya, a partnership firm registered under the Indian Partnership Act, 1932 (Reg. No. 3263 of 2026), of New Delhi, India ("we", "us", "our"). We are the controller (Data Fiduciary under India's DPDP Act) for the data described in §4, except where §2 says otherwise.

Region-specific rights are in the annexes: EEA/UK · United States · India


1. The short version


2. Our role

2.1. We are the controller for your account, sign-in, device, billing, usage, security, and support data — everything in §4.

2.2. We are a processor for the content of each request the app sends through our gateway. We relay it to the AI provider and return the answer. We store none of it. For any personal data about other people that you include in a request, you are the controller, you decide the purpose, and you are responsible for having a lawful basis. A separate Data Processing Addendum applies only where we and a business customer agree it in writing.

2.3. We are nothing at all for the content stored on your computer. It never reaches us. You alone control it.


3. What stays on your device

The app runs a database on your computer, bound to your machine only, in your user profile — on macOS ~/Library/Application Support/KChat, on Windows %APPDATA%\KChat. It holds:

What we cannot do with this data: read it, monitor it, back it up, restore it, hand it to anyone, or delete it for you. What you should do: turn on FileVault or BitLocker (the app does not separately encrypt the database), export regularly, and delete the folder yourself when you no longer want it. Uninstalling the app leaves it in place.


4. What we collect and why

This is everything our servers hold about you.

Data Why Where it lives How long Lawful basis
Email address, display name, identity-provider subject ID, email-verified status Create and secure your account Our identity provider; our gateway database Until you delete the account; backup copies rotate within 30 days Contract
Password Sign you in Our identity provider only, hashed. We never see it. Until changed or account closed Contract
Sign-in timestamps Security; show you recent activity Gateway database Account lifetime Legitimate interest (security)
Company name Enterprise contact and support. Entered by us, or inferred from your work-email domain (never from personal mail providers) Gateway database Account lifetime Legitimate interest
Device name (your computer's hostname, truncated) and one gateway key per signed-in device Let you see and sign out your devices; attribute usage to a device Gateway database Until you sign the device out or close the account Contract
Plan, allowance, top-up balance, account status, subscription and payment references Run your plan; prevent double-charging; issue invoices Gateway database; Razorpay Account lifetime; financial records up to 8 years (Indian tax law) Contract; legal obligation
Per-request usage rows: time, tokens in/out/cached, cost, device, model alias Meter your allowance; bill correctly Gateway database 30 days, then deleted Contract
Daily usage totals per account Billing evidence; cost accounting Gateway database Financial record Contract; legal obligation
Portal session cookie Keep you signed in to the account portal httpOnly cookie + gateway database 30 days Contract
IP address Rate-limit sign-in, search, and crash-report endpoints Not written to access logs. Held transiently in the rate limiter Minutes Legitimate interest (security)
Crash reports — app version and sanitised stack trace only Fix crashes Gateway logs 90 days Consent (off by default)
Support emails Answer you Mailbox 24 months Legitimate interest
Daily backups of the gateway database Disaster recovery Restricted backup volume 30 days rolling Legitimate interest

We do not collect: the text of your requests or the model's answers; your files; your memories; payment card numbers (Razorpay handles those; we never see them); date of birth; government identifiers; biometric data; precise location; advertising identifiers; or any behavioural analytics.


5. How AI processing works

This is the most important section for a product like ours. Please read it.

5.1. What is sent. To answer, the app transmits the current message, the earlier turns of the same chat up to a context limit, the extracted text of files attached to that chat, and the memories that apply if memory is on. It never sends your other chats, your whole Library, your name, or your email. The model does not know who is asking.

5.2. Scanned pages. A PDF with no text layer is read by rendering each page to an image and sending it to the model for transcription. The transcription is stored on your device as the file's text.

5.3. Memory. Facts about you are extracted from your chats by the model. Where an embedding model is used to index them, the memory text is sent through the gateway for embedding under the same terms as any request. The memories and vectors are stored only on your device. Memory can be turned off per chat or globally, and every memory can be viewed, edited, or deleted in the app.

5.4. Where the processing happens. We use an open-weights language model through OpenRouter. Chat requests may be handled only by the approved GLM-5.3-Flash endpoints operated by Modal, Baseten, DeepInfra, or Novita. The processing location can vary by endpoint; we do not promise a particular country for inference. Embeddings use a separate OpenRouter route restricted to eligible zero-retention endpoints.

5.5. No training on your data. We do not use your content to train, fine-tune, or improve any AI model. Every provider request requires OpenRouter's zero-data-retention policy and denies data-collection endpoints. If no endpoint satisfies those rules, the request fails instead of being sent elsewhere.

5.6. What our gateway keeps. Our gateway is configured so that request and response text is never logged, never written to usage records, and never included in error logs. This configuration is checked by our automated tests. The gateway keeps, per request, the time, token counts, cost, and device — §4.

5.7. We cannot read your content. Not "we choose not to" — the content is on your computer and passes through our gateway only in transit, unlogged. The exceptions are the model provider, which processes it under zero retention, and the public search engines described in §6.

5.8. AI output. Every reply is AI-generated. See the AI Transparency Notice.


Web search is off by default. When you enable it for a chat, or turn on the account-level automatic search setting:

  1. The app removes common personal identifiers — email addresses, phone numbers, card and account numbers, postal addresses, and your own name — from the query before it leaves your computer. If nothing is left, no search runs.
  2. Unless you have enabled automatic search, the app shows you the exact terms and asks you to approve.
  3. The terms go to our gateway, which passes them to a private search service we run ourselves, and then fetches the result pages itself. No search vendor is involved, and the gateway does not log the terms or the URLs it fetched.
  4. Our search service forwards the terms to public search engines (currently Google and Bing), which see them from our gateway's address. Those engines are outside the model provider's zero-retention commitment and process the terms under their own policies.

The lawful basis is your request to search (contract). Do not include confidential information in a query you allow to be searched.


7. Who we share data with

We share the minimum necessary with vendors who process data on our behalf under contract. By category:

Category Location What they get
AI routing and inference — OpenRouter; chat endpoints at Modal, Baseten, DeepInfra, or Novita; eligible embedding endpoints Varies by endpoint The content of each request, in transit, with zero-retention and no-data-collection routing required. No account data.
Identity provider United States Email address, password (hashed by them), display name, verification status
Payment processor (Razorpay) India Name, email, account reference, plan, amount. Card details go directly to them — we never receive or store them.
Hosting provider — Hetzner Online GmbH, gateway, database, private search Helsinki, Finland All gateway-side data in §4; request content in transit
GitHub — installer downloads and automatic updates United States Your computer's IP address and app version when it downloads or checks for an update
Public search engines (web search only, when enabled) Various Sanitised search terms, from our gateway's address
Exchange-rate feed Nothing about you. We fetch a public USD–INR rate once an hour to price rupee charges.

Named list on request. We identify each provider by name, with its location and the safeguards that apply, to any customer who asks — support@the-karya.com. Business customers under a Data Processing Addendum also receive 30 days' notice before we add or replace one, with a right to object.

We also disclose data where legally required — to comply with a valid court order or legal process, to enforce our Terms, or to protect the rights, property, or safety of our users, the public, or us. Where we are legally permitted to tell you first, we will. Note that we cannot produce your content in response to a legal demand, because we do not have it.

If we are involved in a merger, acquisition, reorganisation, incorporation, or sale of assets — including any conversion of Karya to a successor entity of any form — account data may transfer as part of it, with notice to you beforehand.

We do not sell your personal data. We do not share it for cross-context behavioural advertising. We do not use it for advertising at all.


8. International transfers

We are based in India. Our identity provider is in the United States, our gateway is hosted by Hetzner in Helsinki, Finland, and inference goes through OpenRouter to an eligible endpoint whose processing location may vary. Depending on where you are and which endpoint handles a request, your data may therefore leave your region.

Our vendor terms include the European Commission's Standard Contractual Clauses (2021) and the UK International Data Transfer Addendum where applicable. We also use technical and organisational safeguards — encryption in transit, zero-retention routing for inference, no logging of content at the gateway, and data minimisation. The underlying vendor transfer terms are available on request. We do not currently publish a separate KChat transfer impact assessment.

Where you are in India, transfers outside India are made in accordance with the conditions permitted under the DPDP Act.


9. How long we keep data

Retention is set out per data type in §4. The principles:

Deletion is a real database delete, not a soft flag. Limited copies may persist in rolling backups for up to 30 days before those backups rotate.


10. Security

On your computer: the database accepts connections only from your own machine and requires a password that the app generates once and stores in your operating system's keychain or credential manager. Your gateway key is stored the same way and never shown in the interface. The code sandbox runs in an isolated runtime with no network or file-system access. Encryption at rest is provided by FileVault or BitLocker — turn it on.

Between your computer and us: TLS in transit. Sign-in uses OpenID Connect with PKCE through your system browser; the app never sees your password. One revocable key per device.

At the gateway: request and response logging switched off and tested; model and provider identifiers stripped from responses; per-route rate limiting; request-size limits; administrative access restricted to signed-in, allowlisted administrator accounts; daily rolling database backups.

No system is completely secure and we do not claim otherwise. If we become aware of a breach affecting your personal data, we will notify you and the relevant regulator where the law requires. Because your content is not on our systems, a breach of our gateway cannot expose your chats or files.

Report a vulnerability: support@the-karya.com.


11. Your rights

Wherever you are, you can:

We respond within 30 days. We may need to verify your identity first — we will ask for the minimum needed. Exercising these rights is free; we may charge only for manifestly unfounded or excessive repeat requests.

Some data cannot be deleted on request: financial records we must keep for tax law, and a minimal record that an account was closed (so it is not silently recreated).

Region-specific rights and how to exercise them: Annex A, Annex B, Annex C.

Contact: support@the-karya.com


12. Cookies

Our public website sets no cookies. The account portal sets one strictly necessary session cookie to keep you signed in, and our payment processor sets its own cookies during checkout. We use no advertising, remarketing, behavioural-analytics, or profiling cookies, and we embed no third-party trackers or social pixels.

Because we set no non-essential cookies, we do not show a consent banner. If that ever changes, we will ask for your consent first and honour Global Privacy Control signals. Details: Cookie Notice.


13. Children

The Service is for people aged 18 and over. We do not ask for your date of birth and do not verify age. We do not knowingly collect data from children, and we do no tracking or targeted advertising directed at anyone.

If you believe a child has created an account, contact support@the-karya.com and we will close it.


14. Changes

We may update this Policy. For material changes we will notify you by email or in-product at least 15 days before they take effect, and post the updated version with a new date. Previous versions are available on request.


15. Contact

Karya — New Delhi, India

Privacy and data requests support@the-karya.com
Grievance Officer (India) Aarya Banthiasupport@the-karya.com
Security support@the-karya.com


Annex A — EEA/UK (GDPR)

A.1. Controller. Karya, address above. We have no establishment in the EU or UK. You can reach us directly, in English, at support@the-karya.com, and we respond to data protection requests within 30 days — see §11.

A.2. Lawful bases. Set out per data type in §4. In summary: contract (Art 6(1)(b)) for account, relaying requests, metering, and billing; legal obligation (Art 6(1)(c)) for tax and accounting; legitimate interests (Art 6(1)(f)) for security, abuse prevention, and cost accounting — we have balanced these against your rights and you may object at any time; consent (Art 6(1)(a)) for crash reports, which you may withdraw at any time without affecting prior processing.

A.3. Your rights. Access (Art 15), rectification (16), erasure (17), restriction (18), portability (20), objection (21) — including an absolute right to object to direct marketing — and the right not to be subject to solely automated decisions with legal or similarly significant effects (22).

A.4. Automated decision-making. We do not make decisions producing legal or similarly significant effects about you by automated means. The AI answers your questions at your instruction; it does not evaluate, score, or make decisions about you. The allowance hard stop is a contractual usage limit, not a decision about you.

A.5. Transfers. See §8. The underlying vendor transfer terms are available on request. A separate KChat transfer impact assessment is not currently available.

A.6. Complaints. You may complain to your national supervisory authority. In Ireland, the Data Protection Commission (dataprotection.ie); in the UK, the Information Commissioner's Office (ico.org.uk). We would appreciate the chance to resolve it first.

A.7. No statutory requirement to provide data — but we cannot provide the Service without account data.


Annex B — United States

B.1. Scope. This annex applies to residents of US states with comprehensive privacy laws, including California, Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, and others as they take effect. We extend these rights to all US residents regardless of whether we currently meet a given state's applicability threshold.

B.2. We do not sell or share your personal information. We have not sold or shared personal information for cross-context behavioural advertising in the preceding 12 months, and we do not do so now. We do not process personal information for targeted advertising or profiling in furtherance of decisions producing legal or similarly significant effects.

B.3. Categories collected (CCPA/CPRA terminology): identifiers (name, email, device name, IP transiently); commercial information (plan, purchases, top-ups); internet activity (usage counts). The content of your requests passes through our systems in transit only and is not collected. We collect no sensitive personal information as defined by the CPRA. Sources, purposes, and recipients are in §4 and §7.

B.4. Your rights. To know, access, and obtain a portable copy; to correct; to delete; to opt out of sale, sharing, and targeted advertising (nothing to opt out of — see B.2); to limit use of sensitive personal information (none collected); and to be free from discrimination for exercising any of these. Exercise them at support@the-karya.com.

B.5. Global Privacy Control. We do not sell or share data, use targeted advertising, or set non-essential cookies, so a GPC signal has no processing to stop.

B.6. Authorised agents. An authorised agent may submit a request on your behalf with written proof of authorisation; we may ask you to verify directly.

B.7. Appeals. If we refuse a request, you may appeal by replying to our decision or writing to support@the-karya.com with "Appeal" in the subject. We respond within 45 days. If we deny the appeal you may complain to your state Attorney General.

B.8. Response times. We confirm within 10 business days and substantively respond within 45 days, extendable once by a further 45 days with notice.

B.9. Shine the Light (California Civil Code §1798.83). We do not disclose personal information to third parties for their own direct marketing.

B.10. Children. The Service is 18+. We do not knowingly collect data from anyone under 18 and therefore do not sell or share the data of consumers under 16.


Annex C — India (DPDP Act)

C.1. Data Fiduciary. Karya, address above. Grievance Officer: Aarya Banthia, support@the-karya.com.

C.2. Notice and consent. We give this notice before or at collection, in clear plain language, itemising the data and the purpose. Where we rely on your consent — crash reporting — it is free, specific, informed, unconditional, and unambiguous, given by affirmative action, and withdrawing it is as easy as giving it — from the app's settings or by email. Withdrawal does not affect processing already carried out. You may request this notice in English or any language in the Eighth Schedule to the Constitution.

C.3. Legitimate uses. Beyond consent, we process for the legitimate uses the Act permits — including where you voluntarily provide data for a specified purpose, and for compliance with law and judgments.

C.4. Your rights as a Data Principal. To access a summary of your personal data and our processing; to correction, completion, updating, and erasure; to nominate another individual to exercise your rights if you die or become incapacitated; and to grievance redressal.

C.5. Grievance redressal. Write to the Grievance Officer. We acknowledge promptly and respond within the timelines the Act and Rules prescribe. If you are not satisfied, you may complain to the Data Protection Board of India — but you must raise it with us first.

C.6. Children. We do not knowingly process the data of anyone under 18 and undertake no tracking or targeted advertising directed at children.

C.7. Erasure. We erase personal data when the purpose is no longer served, when you withdraw consent, or when retention lapses — unless the law requires us to keep it.

C.8. Breach. We will notify the Data Protection Board and affected Data Principals where and within the timelines the DPDP Act requires.

C.9. Transfers. Made in accordance with the conditions permitted under the DPDP Act. See §8.