Trust & Security
Nothing leaves your laptop except the question.
Your work stays on your laptop
KChat stores your chats, files, memories, prompts, and settings in a database inside the app, on your own computer. We run no server that holds a copy.
- No sync. No cloud backup by us. No way for our staff to read it. This is not a policy choice we could quietly reverse; the data is simply not on our systems.
- Nothing is ever public. There are no share links and no published pages.
- Delete means delete. Deleting a chat, a file, or a memory removes it from your computer. Deleting the app's data folder removes everything.
- Which means we cannot recover it either. Export regularly. The app writes every chat as readable Markdown and every Library file as its original bytes to a folder you own.
Stated plainly: your data is protected by your laptop's disk encryption, not by us. KChat does not separately encrypt its database. Turn on FileVault or BitLocker. Someone with your unlocked laptop can read your chats.
What leaves, and what sees it
| What | Who sees it | What they keep |
|---|---|---|
| The current chat, attached file text, applicable memories — the content the model needs to answer | Our gateway, in transit; then the model provider | Gateway: token counts and cost, never the text. Provider: nothing — zero data retention |
| Scanned PDF pages, rendered to images | Same path | Same |
| Your account, plan, usage percentage, signed-in device names | Our gateway | Until you close your account |
| Web-search terms, with personal identifiers stripped on your laptop first — only if you turn search on | Our gateway, our private search service, then public search engines | Gateway: not logged. Search engines: their own policies apply |
| App version and a sanitised stack trace — only if you opt in to crash reports | Our gateway | 90 days |
| Your computer's address when it downloads the installer or checks for updates | GitHub, where we publish releases | GitHub's own policies |
A request never contains your other chats, your file library, your name, or your email address. The model does not know who is asking.
We never train on your content
| We do not train AI models on your data. | Ever. Not for us, not for anyone. |
| Our routing excludes endpoints that train on it. | Every request requires OpenRouter's zero-retention policy and denies data-collection endpoints. |
| Zero retention at the AI provider. | Requests are processed in memory and discarded. Not logged, not stored. |
| Zero content at the gateway. | Prompt and answer logging is switched off and verified by our automated tests. Spend records carry tokens and cost only. |
| We do not sell or share your data. | No advertising. No data brokers. No exceptions. |
Our AI provider choice
We use an open-weights model, and we deliberately do not use the model author's own API.
Requests go through OpenRouter and may be handled only by our approved GLM-5.3-Flash endpoints: Modal, Baseten, DeepInfra, or Novita. Each request requires OpenRouter's zero-data-retention policy, denies data-collection endpoints, and refuses fallbacks outside that list. Processing location can vary by endpoint; we do not make a geographic-residency promise for inference.
Same model, with a routing boundary that fails closed when no permitted endpoint is available. OpenRouter's current retention documentation and the approved provider list are available to any customer who asks.
The app shows one assistant and never exposes the model or provider name. We can change either without an app update, and we tell business customers 30 days ahead.
Security
| Encryption in transit | TLS 1.2+ between the app and our gateway, and between the gateway and the provider |
| Encryption at rest | Your laptop's: FileVault or BitLocker. Stated honestly above. |
| Local database | Listens only on your own machine, requires a password the app generated once and keeps in your system keychain or credential manager |
| Sign-in | OpenID Connect with PKCE through your system browser. The app never sees your password. Email verification required. |
| Device keys | One per signed-in laptop, held in the keychain, never shown in the interface. List and revoke any device, or all, from your account page. |
| Payments | Never in the app. Razorpay, an RBI-licensed payment aggregator, in your browser. Card data never touches our systems. |
| Code sandbox | Runs on your laptop in an isolated WebAssembly runtime: no network, no file system beyond the files handed to it |
| Gateway hardening | Content logging off; model and provider identifiers stripped from responses; per-route rate limits; request-size caps; admin interface requires a signed-in session and an allowlisted administrator email |
| Backups | Gateway database only — account and usage. Daily Postgres dumps, 30-day rolling. There is no backup of your content, because we do not have it. |
| Web search privacy | Emails, phone numbers, card and account numbers, addresses, and your name are removed from queries on your laptop before they leave. You approve each search unless you choose automatic search. |
Report a vulnerability: support@the-karya.com. Good-faith research is welcome and we will not pursue legal action against researchers who follow our disclosure rules.
Compliance
| Framework | Status |
|---|---|
| GDPR / UK GDPR | Controller and processor roles, rights, retention, vendors, and transfer safeguards are documented in the Privacy Policy. A customer DPA is not currently published. |
| India DPDP Act | Grievance Officer appointed; consent, rights, and erasure processes in place |
| US state privacy laws | Rights extended to all US residents; we do not sell or share; Global Privacy Control honoured |
| EU AI Act | Article 50 transparency — AI interaction disclosed; no content is published by us |
| SOC 2 | Not currently held. We do not make a blanket SOC 2 claim for every inference or infrastructure provider. |
| Code signing | Not yet, during the public beta. Installers are unsigned; your operating system will warn you. Signed releases come before general availability. |
We publish what we have and what we do not. We do not hold SOC 2, and we will not imply otherwise. If you need it for procurement, tell us — it helps us prioritise.
Your rights
From your account page you can see your plan, usage, devices, and invoices, sign out any laptop, download the account data held by the gateway, and delete the account permanently after confirming your email. Your content is on your laptop and remains yours to export or delete separately.
We respond to data requests within 30 days.
- Privacy questions and data requests: support@the-karya.com
- Grievance Officer (India): Aarya Banthia
- EU, EEA, and UK residents: contact us directly at the same address — we have no EU establishment and respond in English within 30 days
For procurement
| Document | Availability |
|---|---|
| Data Processing Agreement | Not currently published |
| Vendor transfer terms | Described in the Privacy Policy; underlying vendor terms on request |
| Sub-processor list, with names and locations | On request, with 30 days' notice of change and a right to object |
| Model provider's written zero-retention policy | On request |
| Transfer Impact Assessment | Not currently available |
| Security overview | This page and /security; detail on request |
| Enterprise agreement and service level | On request |
| Open-source component and licence list | In the app, and on request |
| Penetration test report | Not currently available |
| Independent accessibility audit | Not currently available — see the Accessibility Statement |
Contact support@the-karya.com and we will turn a security questionnaire around quickly. Most of the answers are "not applicable — the data is not on our systems", and we are happy to explain why.
What we do not do
Sometimes the absence is the point.
- ❌ No hosting of your chats, files, or memories
- ❌ No share links or public pages
- ❌ No advertising, remarketing, or ad tech
- ❌ No behavioural analytics, session recording, or heatmaps
- ❌ No device fingerprinting
- ❌ No selling or sharing personal data
- ❌ No training AI on your content
- ❌ No cookie banner, because we set no non-essential cookies
- ❌ No third-party scripts or fonts on our public pages
- ❌ No dark patterns on cancellation — cancel online, in the same number of clicks it took to subscribe
Karya · New Delhi, India Partnership firm, Reg. No. 3263 of 2026