Privacy Policy

Karya, a partnership firm registered in India (Reg. No. 3263 of 2026), operating KaryaClaw under the brand "Karya Infrastructure".

Effective Date: June 6, 2026  ·  Last Updated: September 5, 2026

This Privacy Policy explains how Karya, a partnership firm registered under the Indian Partnership Act, 1932 (Registration No. 3263 of 2026), having its principal place of business at C4/94, Safdarjung Development Area, Delhi 110016, India ("Karya", "we", "us", "our"), which operates the KaryaClaw platform, API, agent services, and website under the brand "Karya Infrastructure", collects, uses, discloses, and safeguards personal data. It should be read together with the KaryaClaw Terms of Service.

We aim to align our practices with the Digital Personal Data Protection Act, 2023 and the Digital Personal Data Protection Rules, 2025 (the "DPDP Law") and the Information Technology Act, 2000 and rules thereunder. The Service is currently offered to users in India; if we expand to other jurisdictions (such as the EU/EEA), we will update this Policy and our practices accordingly. By using the Service, you acknowledge the practices described here. If you do not agree, please discontinue use.

1. Roles and Scope

1.1. For personal data you submit about your own end users or third parties ("Customer Personal Data"), you act as the Data Fiduciary and Karya acts as a Data Processor, processing it only on your documented instructions to provide the Service.

1.2. For account, registration, billing, support, security, and administration data ("Account Data"), Karya acts as the Data Fiduciary. This Policy describes how we handle Account Data and how Customer Personal Data flows through the Service.

2. Data We Collect

2.1 Information you provide

  • Account registration: email address, name, business name, and whether the account is for personal or business use.
  • Agent configuration: bot name, system prompt, language preference, response-length settings, channel configurations (Telegram, Discord, and Signal), and enabled features (web search, memory, voice transcription).
  • Integration connections: OAuth authorisations for GitHub, Vercel, Netlify, and Google Workspace (calendar, contacts, email — read-only).
  • Task and board data: titles, descriptions, statuses, priorities, tags, dependencies, and board configurations.
  • Communications: support requests, feedback, and messages you send us.

2.2 Information collected automatically

  • Session data: IP address, browser user-agent, session token, and session expiry.
  • Security and fraud-prevention logs: sign-in attempts (the email entered, IP address, browser user-agent, and success or failure reason), used to prevent account abuse.
  • API usage data: endpoint, HTTP method, response status, prompt and completion token counts, cost, model identifier, and timestamp.
  • Activity events: event type, action description, associated entity, and timestamp.
  • Instance metadata: agent container status, infrastructure provider, and hostname.

2.3 Information from third parties

  • OAuth profile data: name, email, and avatar from GitHub and Google as authorised during the OAuth flow.
  • Payment status: subscription ID and payment-verification status from Razorpay. We do not receive or store your card details.

3. How We Use Your Data

  • Service delivery: to provide, operate, and maintain the Service, including provisioning and executing AI agents.
  • AI processing: to process inputs through a third-party inference provider for agent functionality.
  • Authentication: to verify identity, manage sessions, and secure account access.
  • Billing: to enforce budget limits, track token usage, process payments, and manage subscriptions.
  • Security: to monitor for abuse, detect threats, enforce rate limits, and investigate Terms violations.
  • Communications: to send transactional emails (verification, payment confirmations) via Resend.
  • Audit trail: to maintain activity logs for security, accountability, and dispute resolution.
  • Improvement: to improve and develop the Service using aggregated and anonymised data only.
  • Legal compliance: to comply with legal obligations and protect our rights.

We do not sell, rent, or trade your personal data, and we do not share it for advertising purposes.

4. AI Data Processing

4.1 Inference processing

User inputs, system prompts, and agent instructions are transmitted through a third-party inference routing service, which may select among multiple downstream model providers to generate Output. We configure production routing to request providers that declare they do not collect prompt data. This reduces exposure but does not give us control over every third party's internal practices; processing remains subject to the applicable providers' terms.

4.2 Chat content storage

Chat message content exchanged between you and your AI agent is not stored in KaryaClaw's central database. Only aggregate token counts (prompt and completion) are retained for billing and usage tracking.

4.3 Agent memory

When you enable memory, the agent may store conversation summaries and contextual information within your isolated container Instance. This data persists for the lifetime of the Instance and is destroyed when the Instance is terminated.

4.4 System prompts

System prompts you provide are stored to operate the agent and are transmitted to the Inference Provider with each interaction. They are treated as your Content.

4.5 Skill execution data

When skills execute through connected integrations, data from those services is processed in-memory by the agent and is not stored beyond what the agent writes to tasks, boards, or activity logs.

4.6 No training use

Karya does not use your conversations, Content, or Output to train AI models. The inference routing service and downstream model providers process submitted data to generate Output under their applicable terms and the routing control described in Section 4.1.

4.7 Output monitoring

We do not routinely monitor or review agent outputs, but reserve the right to access agent activity for security investigations, abuse prevention, or legal compliance.

5. Sharing and Sub-Processors

We share data only as necessary to operate the Service, with: the inference routing service and downstream model providers (input/output processing); the cloud / hosting provider (running Instances); Razorpay (payment processing — subscription ID and payment-verification status); Resend (transactional email — email address); and GitHub, Vercel, Netlify, and Google Workspace (OAuth tokens, encrypted at rest and in transit, for the integrations you authorise). We may also disclose data where required by law, legal process, or to protect rights and safety. In a merger, acquisition, or asset sale, data may transfer as part of the transaction, with prior notice. We do not sell or trade personal data.

6. Data Security

We apply technical and organisational measures including: encryption of OAuth integration tokens at rest (AES-256-GCM with per-token nonces); irreversible hashing of API key secrets (SHA-256) and password hashing using industry-standard algorithms; optional two-factor authentication and passkey (WebAuthn) sign-in; monitoring and rate limiting of sign-in attempts; per-IP and per-API-key rate limiting; CSRF protection via server-side state tokens; security headers and strict CORS; row-level authorisation filtering all queries by authenticated user; input validation and request-size limits; isolation of each agent in a separate container; secure logging that never records secrets; and circuit-breaker handling of upstream failures. No system is completely secure, and we do not warrant absolute security.

7. Data Retention

  • Account data: retained while your account is active. When you delete your account, your account record and associated data are deleted from active systems immediately and your Instance is destroyed.
  • Sessions: expire 48 hours after your last activity (extended while you remain active), with an absolute maximum age of 14 days, after which you must sign in again.
  • Billing and usage records: retained only for the period required by accounting and tax law (in India, typically up to 8 years), then deleted or anonymised — not indefinitely.
  • Audit / activity logs: sign-in attempt logs are retained for 90 days, administrative audit logs for 12 months, transactional email logs for 60 days, and payment webhook records for 30 days, after which they are automatically deleted.
  • Agent containers (Instances): paused when your subscription is cancelled or lapses and preserved for a 7-day reactivation window, then permanently deleted (including agent memory stored within the Instance). Deleting your account destroys your Instance immediately.
  • Integration tokens: deleted immediately when you disconnect an integration or delete your account.
  • Encrypted backups: disaster-recovery snapshots may retain deleted database records for up to 7 years and agent-volume data for up to approximately 6 months under the current backup schedule. They are not used for ordinary product access and are retained only for recovery, security, and legal obligations.

Consistent with the DPDP Law, we erase personal data when the purpose for which it was collected is no longer served, including where you withdraw consent, unless retention is legally required. The backup periods disclosed above apply after deletion from active systems.

8. Your Rights

Under the DPDP Law, and subject to verification of your identity, you have the right to: access a summary of your personal data and our processing; seek correction, completion, updating, and erasure of your personal data; readily withdraw any consent you have given; nominate another individual to exercise your rights in the event of death or incapacity; and access a grievance-redressal mechanism.

Exercising your rights

Contact our Grievance Officer (Section 15). We will respond within the timelines required by the DPDP Law. We may need to verify your identity. You may also request a machine-readable (JSON) export of your Account Data at any time. Where we process Customer Personal Data as a processor, we will refer requests to, or assist, the relevant customer (the Data Fiduciary). Some deletion requests may require account termination, as the agent cannot function without its configuration data.

9. Cookies and Tracking

We use strictly necessary session cookies for authentication; CSRF tokens are held server-side, not as browser cookies. We do not use advertising, remarketing, behavioural-tracking, or profiling cookies, and we do not embed third-party trackers or social pixels on the platform. Our promotion website may use privacy-focused, cookieless analytics. Disabling session cookies will prevent use of the platform.

10. Children's Privacy

The Service is for users aged 18 and over and for business use. We do not knowingly collect personal data from children under 18, and undertake no tracking or targeted advertising directed at children. If we learn we have collected such data, we will delete it. Contact us at support@the-karya.com if you believe a child has provided us data.

11. Integration Data Handling

When you connect OAuth integrations, we store encrypted access tokens solely to provide the requested functionality, along with operational token metadata (team IDs, usernames, authorised scopes). Data accessed through integrations (repositories, deployments, calendar events, contacts, emails) is processed in real time and is not stored beyond what the agent writes to tasks, boards, or activity logs. We request only the minimum scopes necessary, do not use integration data for any other purpose, and delete stored tokens immediately when you disconnect.

12. International Data Transfers

Your data may be processed in jurisdictions where our infrastructure, inference, and other service providers operate. Where we transfer personal data outside India, we do so in accordance with the conditions permitted under the DPDP Law and apply appropriate contractual and technical safeguards with the relevant provider.

13. Basis for Processing

We process personal data on the basis of your consent and for the legitimate uses permitted under the DPDP Law: to perform our contract with you (account, agent operation, billing, support), to secure the Service and prevent abuse, and to comply with our legal obligations. You may withdraw consent at any time, which will not affect the lawfulness of processing carried out before withdrawal.

14. Data Breach Notification

On becoming aware of a personal data breach, we will take reasonable steps to contain and remediate it and will notify the Data Protection Board of India and affected Data Principals where and within the timelines required by the DPDP Law. We maintain incident-response procedures to detect, investigate, contain, and respond to incidents, and will assist our customers in meeting their own obligations.

15. Grievance Officer and Contact

Grievance Officer / Data Protection Contact: Aarya Banthia

  • Karya (operating as Karya Infrastructure)
  • C4/94, Safdarjung Development Area, Delhi 110016, India
  • Email: support@the-karya.com

We will acknowledge and address grievances within the timelines prescribed by the DPDP Law. If unsatisfied, you may complain to the Data Protection Board of India.

16. Changes to This Policy

We may update this Policy. Material changes will be communicated by email or prominent notice at least fifteen (15) days before taking effect, and the updated Policy will be posted at the-karya.com/privacy. Continued use after the effective date constitutes acknowledgement. Prior versions are available on request.