Legal

Privacy Policy

ThreadClarity processes chat archives, so this policy has to deal with an unusual problem: most of the personal data we handle belongs to people who never signed up. Section 3 explains what that means for you and for them.

Last updated: 3 September 2026 Effective: 3 September 2026 Digital Personal Data Protection Act, 2023

1. Scope & who we are

This policy explains how Kamyab Infotech Pvt Ltd, trading as Kamyab Infotech, of 822 Hemkunt Chambers, 89 Nehru Place, New Delhi, Delhi 110019, India, handles personal data in connection with the ThreadClarity website at threadclarity.kamyab.co.in and the ThreadClarity application.

It is written primarily against the Digital Personal Data Protection Act, 2023 ("DPDP Act") and the Information Technology Act, 2000 and rules made under it.

We wear two hats, and the difference matters:

  • For your account, billing and support data, we are the Data Fiduciary. We decide why and how it is processed, and this policy is our notice to you.
  • For the contents of the chat exports you upload, you are the Data Fiduciary and we are your Data Processor. We process that content only on your instructions, to give you the output you asked for. See section 3.

2. What we collect

CategoryWhat it actually isWhere it comes from
Account data Email address, name, phone number, a salted password hash (never the password itself), your plan, and usage counters such as exports used this month and AI analyses run today. You, at sign-up and in settings.
Uploaded chat exports The export archive you upload and everything parsed out of it: message text, sender display names, timestamps, reply relationships, reactions, polls, attachments and media references. You, when you create a job.
Generated output Detected threads, thread titles, AI summaries and analyses, and the Markdown, CSV, DOCX, XLSX and HTML viewer files produced for you. Derived from your upload.
Payment metadata Razorpay payment, order, subscription and invoice identifiers, amount, currency, payment method type and status. We never receive or store your card number, CVV, UPI PIN or netbanking credentials — those go directly to Razorpay. Razorpay, after a transaction.
Credentials you configure Your AI provider API key (BYOK) and, if you set one up, credentials for an external storage destination you want exports delivered to. Both are encrypted at rest. You, in settings.
Waitlist data If you join the waitlist on the marketing site: name, email, WhatsApp number, optional Telegram username, submission timestamp and the IP address of the submission. You, via the waitlist form.
Operational logs Job status and progress, error messages, request timestamps and IP addresses used for rate limiting and abuse prevention. Automatically, as you use the Service.

We do not buy personal data from data brokers, and we do not sell or rent your data to anyone.

3. Third-party data in your uploads

The important part

A chat export is a record of a conversation between people. When you upload one, you are giving us the personal data of other people — Data Principals who are not our users, have no account with us, and have not agreed to anything. That data can include their names, phone numbers, profile photos, message content, shared documents, images, voice notes and location pins.

You warrant that you have a lawful basis to upload it. By uploading a chat export you confirm, each time, that you are entitled to hold that export and to have us process it — because you were a participant in the conversation, because you own or administer the account or workspace it came from, because you have the relevant consents or notices in place, or because another lawful ground under the DPDP Act or applicable law covers you. This warranty is set out in section 5 of our Terms of Service.

What that means in practice:

  • You are the Data Fiduciary for the people in your chat export. If one of them asks who has their data, why, and for how long, that question is yours to answer.
  • We process that content strictly on your instructions and for no independent purpose of our own. We do not analyse it for our own benefit, do not profile the people in it, do not build any cross-customer dataset from it, and do not use it to train any AI model.
  • We do not send you marketing based on the contents of your uploads, and we do not contact anyone we find inside them.
  • Our staff do not read your chat content as a matter of routine. Access is limited to named personnel, is logged, and happens only where strictly necessary to fix a fault you have reported, to restore data, or to comply with a lawful order.
  • If a third party contacts us directly about data inside a customer's upload, our normal response is to identify the customer who uploaded it and refer the request to them, while assisting them as their processor. Where the law requires us to act ourselves, we will.

If you are not sure you have the right to upload a particular archive, do not upload it. Take advice first.

4. Purpose & legal basis

PurposeData usedBasis under the DPDP Act
Creating and running your account; authenticating youAccount dataConsent, given at sign-up, and performance of our contract with you
Parsing your export, detecting threads and generating outputUploaded exports, generated outputYour explicit instruction to process, as our customer; we act as processor
Running AI analysis when you enable itChat excerpts, your API keyYour specific opt-in instruction (AI is off unless you configure a key)
Taking payment, issuing invoices, meeting tax obligationsAccount data, payment metadataPerformance of contract and compliance with legal obligation
Sending service, security and billing noticesEmail addressLegitimate use for the purpose for which you gave it
Preventing abuse, fraud and denial-of-service; enforcing our termsIP address, operational logsLegitimate use — security of the Service
Keeping you on the waitlist and telling you when access opensWaitlist dataConsent, given when you submit the form; withdrawable at any time

Where our basis is consent, you can withdraw it at any time (see section 9). Withdrawal does not affect processing already carried out, and may mean we can no longer provide part or all of the Service.

5. AI processing (bring your own key)

AI features are off by default. Nothing is sent to any AI provider unless you have saved an API key of your own and asked for an analysis.

When you do enable it, excerpts of your chat content — the messages in the threads being analysed — are transmitted from our servers to the provider you selected, using your key. Supported providers are:

  • Google (Gemini)generativelanguage.googleapis.com, also used for the optional semantic-search embedding feature and for image description.
  • OpenAIapi.openai.com.
  • Anthropic (Claude)api.anthropic.com.

That transmission is a disclosure to a third party. Once the data reaches your provider, their privacy policy, retention schedule and training practices govern it, under the account and terms that you hold with them — not ours. We recommend you check whether your provider tier retains prompts or uses them for model improvement, and configure it accordingly, before analysing sensitive archives.

Your API key is stored encrypted at rest and is used only to make analysis requests you triggered. You can remove it from your settings at any time.

6. Processors & sub-processors

We keep the list of third parties deliberately short.

PartyWhat they do for usWhat they receive
Razorpay Software Private Limited (India)Payment processing for credits and retention plansYour name, email, phone and the payment instrument you enter on their checkout. We receive back only transaction metadata.
Zoho Corporation (India)Transactional and support email over Zoho Mail SMTP; optionally Zoho CRM for waitlist and customer recordsYour name, email address and the contents of our correspondence with you.
Your chosen AI provider (Google, OpenAI or Anthropic)AI analysis you explicitly request, on your own API keyExcerpts of the chat content being analysed. Nothing if you do not enable AI.
Cloudflare, Inc.Turnstile anti-bot verification on the waitlist form, and network protectionA verification token and connection metadata such as IP address.
Our hosting providerRuns the servers and storage on which the Service operatesData at rest on the server, under contract and with no right of independent use.
Storage destination you configureDelivers finished exports to a location you nominate, if you set one upOnly the export files you direct there. Optional and off by default.

If we add or replace a processor that handles your data, we will update this page. We may also disclose data where we are legally compelled to — for example, in response to a valid order from an Indian court or a competent authority — and, where we are permitted to do so, we will tell you first.

7. Data retention & deletion

ThreadClarity is built to not keep your chat data. Deletion runs automatically on a schedule; it is not something you have to ask for.

WhatHow long we keep itHow it goes
Generated exports and reports (Markdown, CSV, DOCX, XLSX, HTML viewer, media manifests) 7 days from creation, unless an active retention plan covers them Deleted automatically by a scheduled cleanup job that removes any export output older than seven days.
Uploaded archive file (the ZIP you sent us) Deleted as soon as it has been extracted; in any case within 24 hours Removed immediately after extraction, with a cleanup sweep for anything abandoned mid-upload.
Working files from processing (temporary extraction directories) Until the job finishes or fails Removed when the job completes; orphaned directories are purged by the same cleanup sweep.
Reports under an active retention plan For as long as the plan is active, plus the post-cancellation grace period Deleted after the grace period set out in the Refund & Cancellation Policy.
Account data Until you delete your account, then removed within 30 days Deleted on request or on account closure.
Payment and invoice records As long as Indian tax and company law requires — currently up to 8 years Retained as a legal obligation even after account deletion. This is financial metadata, not chat content.
Waitlist entries Until you ask us to remove you, or until the waitlist is closed and cleared Deleted on request to the Grievance Officer.
Download your output

Because the standard retention window is short, download and store your own copy of any export you want to keep, or subscribe to a retention plan. We cannot recover an export once the cleanup job has deleted it.

8. Security

We take reasonable security safeguards proportionate to the sensitivity of chat archives, including: transport encryption (HTTPS/TLS) for everything in transit; encryption at rest for AI provider keys and storage credentials; salted password hashing; signed session tokens that can be invalidated on password change; per-user isolation so a job belongs to the account that created it; rate limiting on authentication and heavy endpoints; webhook signature verification on payment callbacks; and aggressive automatic deletion, which is itself a security control — data we no longer hold cannot be breached.

No system is perfectly secure. You help by using a strong, unique password, keeping your AI provider key scoped and rotated, and downloading and removing output you no longer need hosted.

9. Your rights under the DPDP Act

As a Data Principal you have the right to:

  • Access — obtain a summary of the personal data we hold about you, the processing we carry out, and the identities of other Data Fiduciaries and Processors with whom it has been shared.
  • Correction and completion — have inaccurate or misleading data corrected, incomplete data completed, and out-of-date data updated. Most account fields you can edit yourself in settings.
  • Erasure — have your personal data deleted where it is no longer needed for the purpose it was collected for, and withdraw the consent on which processing relies. We must keep payment records for the statutory period described in section 7.
  • Withdraw consent — as easily as you gave it. Removing your AI key stops AI processing; deleting your account stops the rest.
  • Grievance redressal — raise a complaint with our Grievance Officer and get a substantive response.
  • Nominate — nominate another individual to exercise these rights on your behalf in the event of your death or incapacity.

How to exercise them

Email dj@kamyab.co.in from the address registered on your account, telling us which right you want to exercise and what you want us to do. We may ask a question or two to confirm it is really you before acting on a deletion or access request.

We will acknowledge within 72 hours and provide a substantive response within 30 days. There is no fee. If we cannot do what you asked, we will tell you why and what your options are.

If you are unhappy with our response, you may complain to the Data Protection Board of India once it is operational. Doing so does not affect any other legal remedy.

10. Grievance Officer

Under section 13 of the DPDP Act and rule 3(2) of the IT (Intermediary Guidelines) Rules, our designated Grievance Officer is:

Name
Dhvani Janveza
Designation
Grievance Officer & Data Protection Contact
Entity
Kamyab Infotech Pvt Ltd (Kamyab Infotech)
Email
dj@kamyab.co.in
Postal address
822 Hemkunt Chambers, 89 Nehru Place, New Delhi, Delhi 110019, India
Acknowledgement
Within 72 hours of receipt
Resolution
Within 30 days of receipt

Please put "DPDP grievance" in the subject line so it is routed correctly.

11. Breach notification

If a personal data breach occurs, we will notify the Data Protection Board of India and every affected Data Principal, in the form and within the timelines the DPDP Act and its rules require, without waiting for our investigation to conclude.

Our notice to you will describe, as far as we know it: what happened and when; the categories of data involved; the likely consequences; what we have done to contain it and prevent recurrence; and what we recommend you do — for example, changing your password or revoking an AI provider key.

Because you are the Data Fiduciary for the contents of your uploads, if a breach affects your uploaded chat data we will notify you promptly and give you the information you need to meet your own notification duties to the people in that data.

12. Cookies & analytics

The marketing site sets no advertising cookies and runs no cross-site tracking or ad-network pixels. What may be set:

  • Strictly necessary — a session token that keeps you signed in to the application, and Cloudflare Turnstile's anti-bot token on the waitlist form. These cannot be switched off without breaking the site.
  • Analytics — if privacy-respecting analytics are enabled on the site, a consent banner is shown first and analytics only load after you accept. You can decline and continue using the site normally.

You can also block or delete cookies in your browser. Blocking the strictly necessary ones will sign you out.

13. Children's data

ThreadClarity is not for children. We do not knowingly create accounts for anyone under 18, and we do not use the Service to track, profile or advertise to children — which the DPDP Act prohibits outright.

We cannot inspect your uploads, so we cannot detect whether a chat export contains messages from a child. If it does, you are responsible for the verifiable consent of that child's parent or lawful guardian, and for any additional obligations the DPDP Act places on you as Data Fiduciary. Do not upload archives centred on children's communications unless you are certain of your legal position.

If you believe we hold a child's data without the required consent, write to the Grievance Officer and we will delete it.

14. International transfers

Your account data, uploaded exports and generated output are stored on infrastructure in India by default. Payments (Razorpay) and email (Zoho) are handled by Indian companies on Indian infrastructure.

The one routine cross-border transfer is AI processing: if you enable it, chat excerpts go to Google, OpenAI or Anthropic and may be processed outside India, in the regions those providers operate. This happens only on your explicit instruction, on your own API key, and you can avoid it entirely by not configuring an AI key.

Transfers are made in accordance with section 16 of the DPDP Act and will not be made to any territory that the Central Government restricts by notification.

15. Changes to this policy

We will update this policy when our processing, our processors, or the law changes. The "Last updated" date at the top always reflects the current version. For material changes we will give you at least fifteen (15) days' notice by email or in-app notice before they take effect, and where a change requires fresh consent, we will ask for it.

Related documents: Terms of Service · Refund & Cancellation Policy · Contact.