Trust & Security

Nothing leaves your laptop except the question.


Your work stays on your laptop

KChat stores your chats, files, memories, prompts, and settings in a database inside the app, on your own computer. We run no server that holds a copy.

Stated plainly: your data is protected by your laptop's disk encryption, not by us. KChat does not separately encrypt its database. Turn on FileVault or BitLocker. Someone with your unlocked laptop can read your chats.


What leaves, and what sees it

What Who sees it What they keep
The current chat, attached file text, applicable memories — the content the model needs to answer Our gateway, in transit; then the model provider Gateway: token counts and cost, never the text. Provider: nothing — zero data retention
Scanned PDF pages, rendered to images Same path Same
Your account, plan, usage percentage, signed-in device names Our gateway Until you close your account
Web-search terms, with personal identifiers stripped on your laptop first — only if you turn search on Our gateway, our private search service, then public search engines Gateway: not logged. Search engines: their own policies apply
App version and a sanitised stack trace — only if you opt in to crash reports Our gateway 90 days
Your computer's address when it downloads the installer or checks for updates GitHub, where we publish releases GitHub's own policies

A request never contains your other chats, your file library, your name, or your email address. The model does not know who is asking.


We never train on your content

We do not train AI models on your data. Ever. Not for us, not for anyone.
Our routing excludes endpoints that train on it. Every request requires OpenRouter's zero-retention policy and denies data-collection endpoints.
Zero retention at the AI provider. Requests are processed in memory and discarded. Not logged, not stored.
Zero content at the gateway. Prompt and answer logging is switched off and verified by our automated tests. Spend records carry tokens and cost only.
We do not sell or share your data. No advertising. No data brokers. No exceptions.

Our AI provider choice

We use an open-weights model, and we deliberately do not use the model author's own API.

Requests go through OpenRouter and may be handled only by our approved GLM-5.3-Flash endpoints: Modal, Baseten, DeepInfra, or Novita. Each request requires OpenRouter's zero-data-retention policy, denies data-collection endpoints, and refuses fallbacks outside that list. Processing location can vary by endpoint; we do not make a geographic-residency promise for inference.

Same model, with a routing boundary that fails closed when no permitted endpoint is available. OpenRouter's current retention documentation and the approved provider list are available to any customer who asks.

The app shows one assistant and never exposes the model or provider name. We can change either without an app update, and we tell business customers 30 days ahead.


Security

Encryption in transit TLS 1.2+ between the app and our gateway, and between the gateway and the provider
Encryption at rest Your laptop's: FileVault or BitLocker. Stated honestly above.
Local database Listens only on your own machine, requires a password the app generated once and keeps in your system keychain or credential manager
Sign-in OpenID Connect with PKCE through your system browser. The app never sees your password. Email verification required.
Device keys One per signed-in laptop, held in the keychain, never shown in the interface. List and revoke any device, or all, from your account page.
Payments Never in the app. Razorpay, an RBI-licensed payment aggregator, in your browser. Card data never touches our systems.
Code sandbox Runs on your laptop in an isolated WebAssembly runtime: no network, no file system beyond the files handed to it
Gateway hardening Content logging off; model and provider identifiers stripped from responses; per-route rate limits; request-size caps; admin interface requires a signed-in session and an allowlisted administrator email
Backups Gateway database only — account and usage. Daily Postgres dumps, 30-day rolling. There is no backup of your content, because we do not have it.
Web search privacy Emails, phone numbers, card and account numbers, addresses, and your name are removed from queries on your laptop before they leave. You approve each search unless you choose automatic search.

Report a vulnerability: support@the-karya.com. Good-faith research is welcome and we will not pursue legal action against researchers who follow our disclosure rules.


Compliance

Framework Status
GDPR / UK GDPR Controller and processor roles, rights, retention, vendors, and transfer safeguards are documented in the Privacy Policy. A customer DPA is not currently published.
India DPDP Act Grievance Officer appointed; consent, rights, and erasure processes in place
US state privacy laws Rights extended to all US residents; we do not sell or share; Global Privacy Control honoured
EU AI Act Article 50 transparency — AI interaction disclosed; no content is published by us
SOC 2 Not currently held. We do not make a blanket SOC 2 claim for every inference or infrastructure provider.
Code signing Not yet, during the public beta. Installers are unsigned; your operating system will warn you. Signed releases come before general availability.

We publish what we have and what we do not. We do not hold SOC 2, and we will not imply otherwise. If you need it for procurement, tell us — it helps us prioritise.


Your rights

From your account page you can see your plan, usage, devices, and invoices, sign out any laptop, download the account data held by the gateway, and delete the account permanently after confirming your email. Your content is on your laptop and remains yours to export or delete separately.

We respond to data requests within 30 days.


For procurement

Document Availability
Data Processing Agreement Not currently published
Vendor transfer terms Described in the Privacy Policy; underlying vendor terms on request
Sub-processor list, with names and locations On request, with 30 days' notice of change and a right to object
Model provider's written zero-retention policy On request
Transfer Impact Assessment Not currently available
Security overview This page and /security; detail on request
Enterprise agreement and service level On request
Open-source component and licence list In the app, and on request
Penetration test report Not currently available
Independent accessibility audit Not currently available — see the Accessibility Statement

Contact support@the-karya.com and we will turn a security questionnaire around quickly. Most of the answers are "not applicable — the data is not on our systems", and we are happy to explain why.


What we do not do

Sometimes the absence is the point.


Karya · New Delhi, India Partnership firm, Reg. No. 3263 of 2026