Klenara is operated from India. This policy describes what personal data we collect about you, why we collect it, how long we keep it, and the controls you have over it. It is written to comply with India's Digital Personal Data Protection Act, 2023 (“DPDP Act”).
1. Data we collect
- Account data: email address, name (optional), password hash (Argon2id; the plain password is never stored), Google account identifier if you sign in with Google, and the timestamps of your last sign-in and account creation.
- Profile data: the display name, public handle, bio, country, timezone, and social links you choose to add. These are visible to other users only if you publish content like an agent.
- Conversation data: the messages you send and the responses Claude generates, including any files you upload. We store these so you can resume conversations and so we can compute your credit usage.
- Persistent memory:short factual snippets that Klenara extracts from your conversations to maintain context across chats. You can review, edit, and delete every memory from Settings → Preferences → Memory, or disable memory entirely.
- Payment data: Razorpay payment IDs, order IDs, the amount and timestamp of each purchase. We do not see or store your card number, CVV, UPI VPA, or any other payment instrument detail — Razorpay handles that directly.
- Technical data: a salted hash of your IP address (we never store the raw IP), browser user-agent, and aggregate performance metrics (LCP, INP, CLS) used to keep the app fast.
- Audit logs: security-relevant events (sign-in, password change, 2FA enrolment, account deletion request) for the purpose of investigating fraud or account takeover.
2. Why we process this data
Under the DPDP Act, every processing purpose is one of: (a) you consented, (b) the processing is necessary to provide a service you requested, or (c) a specific legitimate use applies. Our purposes:
- Provide the service.Send your messages to Anthropic's Claude API and stream the response back. Necessary for the service.
- Bill you. Process payments via Razorpay, issue receipts, track credit balance. Necessary for the service.
- Personalise the assistant.Extract memories and apply custom instructions so future replies fit your context. Consent-based — opt out from Settings → Preferences → Memory.
- Keep accounts secure. Rate-limit sign-in attempts, detect referral abuse, send security-event emails. Legitimate use under DPDP Act §7(b).
- Improve performance.Aggregate Web Vitals telemetry. We use the IP hash but no raw IP; we don't link performance data to your name.
3. Who we share data with
- Anthropic(USA): your prompts and the conversation history relevant to each turn are sent to Anthropic's API to generate replies. Anthropic's privacy policy applies to that processing.
- Razorpay(India): handles every payment. Razorpay's privacy policy applies to payment instrument data.
- Resend (USA): sends transactional email (verification, receipts, password resets) on our behalf. Only your email address and message body are shared.
- Vercel (USA): hosts the application. Receives the same data your browser sends to load the site.
We do not sell your data, use it to train AI models, or share it with advertisers.
4. Retention
- Conversations + memories: kept until you delete them or the account.
- Payment records: retained for 7 years per Indian tax + accounting rules even after account deletion (legal obligation).
- Audit logs: 90 days.
- Web Vitals telemetry: 30 days, then deleted.
- Soft-deleted accounts: kept for a 7-day grace window after a deletion request, then permanently purged by a daily cron.
5. Your rights under the DPDP Act
You have the right to:
- Accessthe personal data we hold about you — download a JSON export from Settings → Privacy → Export your data.
- Correctinaccurate data — edit anything in Settings → Profile, Preferences, or Memory.
- Eraseyour data — delete individual conversations/memories, or the whole account via Settings → Security → Delete account (7-day grace window).
- Withdraw consent for memory extraction or transactional emails at any time.
- Grievance redressal— see §7 below.
6. Security
Passwords are hashed with Argon2id (OWASP 2024 recommended parameters). TOTP secrets and OAuth refresh tokens are encrypted at rest with AES-256-GCM. Backup codes are stored as SHA-256 hashes. IP addresses are salted-hashed before storage. All traffic uses HTTPS. Database connections require TLS.
7. Grievance contact
For data-protection questions or DPDP Act requests, email privacy@klenara.in. We respond within 7 working days. If you're not satisfied with our response, you may approach the Data Protection Board of India.
8. Changes
We'll post material changes to this policy on this page and notify signed-in users by email before the change takes effect. The last updated date at the top reflects the current revision.
Reach the team at hello@klenara.in or DPO at privacy@klenara.in.