1. Scope & who we are
This policy explains how Kamyab Infotech Pvt Ltd, trading as Kamyab Infotech, of 822 Hemkunt Chambers, 89 Nehru Place, New Delhi, Delhi 110019, India, handles personal data in connection with the ThreadClarity website at threadclarity.kamyab.co.in and the ThreadClarity application.
It is written primarily against the Digital Personal Data Protection Act, 2023 ("DPDP Act") and the Information Technology Act, 2000 and rules made under it.
We wear two hats, and the difference matters:
- For your account, billing and support data, we are the Data Fiduciary. We decide why and how it is processed, and this policy is our notice to you.
- For the contents of the chat exports you upload, you are the Data Fiduciary and we are your Data Processor. We process that content only on your instructions, to give you the output you asked for. See section 3.
2. What we collect
| Category | What it actually is | Where it comes from |
|---|---|---|
| Account data | Email address, name, phone number, a salted password hash (never the password itself), your plan, and usage counters such as exports used this month and AI analyses run today. | You, at sign-up and in settings. |
| Uploaded chat exports | The export archive you upload and everything parsed out of it: message text, sender display names, timestamps, reply relationships, reactions, polls, attachments and media references. | You, when you create a job. |
| Generated output | Detected threads, thread titles, AI summaries and analyses, and the Markdown, CSV, DOCX, XLSX and HTML viewer files produced for you. | Derived from your upload. |
| Payment metadata | Razorpay payment, order, subscription and invoice identifiers, amount, currency, payment method type and status. We never receive or store your card number, CVV, UPI PIN or netbanking credentials — those go directly to Razorpay. | Razorpay, after a transaction. |
| Credentials you configure | Your AI provider API key (BYOK) and, if you set one up, credentials for an external storage destination you want exports delivered to. Both are encrypted at rest. | You, in settings. |
| Waitlist data | If you join the waitlist on the marketing site: name, email, WhatsApp number, optional Telegram username, submission timestamp and the IP address of the submission. | You, via the waitlist form. |
| Operational logs | Job status and progress, error messages, request timestamps and IP addresses used for rate limiting and abuse prevention. | Automatically, as you use the Service. |
We do not buy personal data from data brokers, and we do not sell or rent your data to anyone.
3. Third-party data in your uploads
A chat export is a record of a conversation between people. When you upload one, you are giving us the personal data of other people — Data Principals who are not our users, have no account with us, and have not agreed to anything. That data can include their names, phone numbers, profile photos, message content, shared documents, images, voice notes and location pins.
You warrant that you have a lawful basis to upload it. By uploading a chat export you confirm, each time, that you are entitled to hold that export and to have us process it — because you were a participant in the conversation, because you own or administer the account or workspace it came from, because you have the relevant consents or notices in place, or because another lawful ground under the DPDP Act or applicable law covers you. This warranty is set out in section 5 of our Terms of Service.
What that means in practice:
- You are the Data Fiduciary for the people in your chat export. If one of them asks who has their data, why, and for how long, that question is yours to answer.
- We process that content strictly on your instructions and for no independent purpose of our own. We do not analyse it for our own benefit, do not profile the people in it, do not build any cross-customer dataset from it, and do not use it to train any AI model.
- We do not send you marketing based on the contents of your uploads, and we do not contact anyone we find inside them.
- Our staff do not read your chat content as a matter of routine. Access is limited to named personnel, is logged, and happens only where strictly necessary to fix a fault you have reported, to restore data, or to comply with a lawful order.
- If a third party contacts us directly about data inside a customer's upload, our normal response is to identify the customer who uploaded it and refer the request to them, while assisting them as their processor. Where the law requires us to act ourselves, we will.
If you are not sure you have the right to upload a particular archive, do not upload it. Take advice first.
4. Purpose & legal basis
| Purpose | Data used | Basis under the DPDP Act |
|---|---|---|
| Creating and running your account; authenticating you | Account data | Consent, given at sign-up, and performance of our contract with you |
| Parsing your export, detecting threads and generating output | Uploaded exports, generated output | Your explicit instruction to process, as our customer; we act as processor |
| Running AI analysis when you enable it | Chat excerpts, your API key | Your specific opt-in instruction (AI is off unless you configure a key) |
| Taking payment, issuing invoices, meeting tax obligations | Account data, payment metadata | Performance of contract and compliance with legal obligation |
| Sending service, security and billing notices | Email address | Legitimate use for the purpose for which you gave it |
| Preventing abuse, fraud and denial-of-service; enforcing our terms | IP address, operational logs | Legitimate use — security of the Service |
| Keeping you on the waitlist and telling you when access opens | Waitlist data | Consent, given when you submit the form; withdrawable at any time |
Where our basis is consent, you can withdraw it at any time (see section 9). Withdrawal does not affect processing already carried out, and may mean we can no longer provide part or all of the Service.
5. AI processing (bring your own key)
AI features are off by default. Nothing is sent to any AI provider unless you have saved an API key of your own and asked for an analysis.
When you do enable it, excerpts of your chat content — the messages in the threads being analysed — are transmitted from our servers to the provider you selected, using your key. Supported providers are:
- Google (Gemini) —
generativelanguage.googleapis.com, also used for the optional semantic-search embedding feature and for image description. - OpenAI —
api.openai.com. - Anthropic (Claude) —
api.anthropic.com.
That transmission is a disclosure to a third party. Once the data reaches your provider, their privacy policy, retention schedule and training practices govern it, under the account and terms that you hold with them — not ours. We recommend you check whether your provider tier retains prompts or uses them for model improvement, and configure it accordingly, before analysing sensitive archives.
Your API key is stored encrypted at rest and is used only to make analysis requests you triggered. You can remove it from your settings at any time.
6. Processors & sub-processors
We keep the list of third parties deliberately short.
| Party | What they do for us | What they receive |
|---|---|---|
| Razorpay Software Private Limited (India) | Payment processing for credits and retention plans | Your name, email, phone and the payment instrument you enter on their checkout. We receive back only transaction metadata. |
| Zoho Corporation (India) | Transactional and support email over Zoho Mail SMTP; optionally Zoho CRM for waitlist and customer records | Your name, email address and the contents of our correspondence with you. |
| Your chosen AI provider (Google, OpenAI or Anthropic) | AI analysis you explicitly request, on your own API key | Excerpts of the chat content being analysed. Nothing if you do not enable AI. |
| Cloudflare, Inc. | Turnstile anti-bot verification on the waitlist form, and network protection | A verification token and connection metadata such as IP address. |
| Our hosting provider | Runs the servers and storage on which the Service operates | Data at rest on the server, under contract and with no right of independent use. |
| Storage destination you configure | Delivers finished exports to a location you nominate, if you set one up | Only the export files you direct there. Optional and off by default. |
If we add or replace a processor that handles your data, we will update this page. We may also disclose data where we are legally compelled to — for example, in response to a valid order from an Indian court or a competent authority — and, where we are permitted to do so, we will tell you first.
7. Data retention & deletion
ThreadClarity is built to not keep your chat data. Deletion runs automatically on a schedule; it is not something you have to ask for.
| What | How long we keep it | How it goes |
|---|---|---|
| Generated exports and reports (Markdown, CSV, DOCX, XLSX, HTML viewer, media manifests) | 7 days from creation, unless an active retention plan covers them | Deleted automatically by a scheduled cleanup job that removes any export output older than seven days. |
| Uploaded archive file (the ZIP you sent us) | Deleted as soon as it has been extracted; in any case within 24 hours | Removed immediately after extraction, with a cleanup sweep for anything abandoned mid-upload. |
| Working files from processing (temporary extraction directories) | Until the job finishes or fails | Removed when the job completes; orphaned directories are purged by the same cleanup sweep. |
| Reports under an active retention plan | For as long as the plan is active, plus the post-cancellation grace period | Deleted after the grace period set out in the Refund & Cancellation Policy. |
| Account data | Until you delete your account, then removed within 30 days | Deleted on request or on account closure. |
| Payment and invoice records | As long as Indian tax and company law requires — currently up to 8 years | Retained as a legal obligation even after account deletion. This is financial metadata, not chat content. |
| Waitlist entries | Until you ask us to remove you, or until the waitlist is closed and cleared | Deleted on request to the Grievance Officer. |
Because the standard retention window is short, download and store your own copy of any export you want to keep, or subscribe to a retention plan. We cannot recover an export once the cleanup job has deleted it.
8. Security
We take reasonable security safeguards proportionate to the sensitivity of chat archives, including: transport encryption (HTTPS/TLS) for everything in transit; encryption at rest for AI provider keys and storage credentials; salted password hashing; signed session tokens that can be invalidated on password change; per-user isolation so a job belongs to the account that created it; rate limiting on authentication and heavy endpoints; webhook signature verification on payment callbacks; and aggressive automatic deletion, which is itself a security control — data we no longer hold cannot be breached.
No system is perfectly secure. You help by using a strong, unique password, keeping your AI provider key scoped and rotated, and downloading and removing output you no longer need hosted.
9. Your rights under the DPDP Act
As a Data Principal you have the right to:
- Access — obtain a summary of the personal data we hold about you, the processing we carry out, and the identities of other Data Fiduciaries and Processors with whom it has been shared.
- Correction and completion — have inaccurate or misleading data corrected, incomplete data completed, and out-of-date data updated. Most account fields you can edit yourself in settings.
- Erasure — have your personal data deleted where it is no longer needed for the purpose it was collected for, and withdraw the consent on which processing relies. We must keep payment records for the statutory period described in section 7.
- Withdraw consent — as easily as you gave it. Removing your AI key stops AI processing; deleting your account stops the rest.
- Grievance redressal — raise a complaint with our Grievance Officer and get a substantive response.
- Nominate — nominate another individual to exercise these rights on your behalf in the event of your death or incapacity.
How to exercise them
Email dj@kamyab.co.in from the address registered on your account, telling us which right you want to exercise and what you want us to do. We may ask a question or two to confirm it is really you before acting on a deletion or access request.
We will acknowledge within 72 hours and provide a substantive response within 30 days. There is no fee. If we cannot do what you asked, we will tell you why and what your options are.
If you are unhappy with our response, you may complain to the Data Protection Board of India once it is operational. Doing so does not affect any other legal remedy.
10. Grievance Officer
Under section 13 of the DPDP Act and rule 3(2) of the IT (Intermediary Guidelines) Rules, our designated Grievance Officer is:
- Name
- Dhvani Janveza
- Designation
- Grievance Officer & Data Protection Contact
- Entity
- Kamyab Infotech Pvt Ltd (Kamyab Infotech)
- dj@kamyab.co.in
- Postal address
- 822 Hemkunt Chambers, 89 Nehru Place, New Delhi, Delhi 110019, India
- Acknowledgement
- Within 72 hours of receipt
- Resolution
- Within 30 days of receipt
Please put "DPDP grievance" in the subject line so it is routed correctly.
11. Breach notification
If a personal data breach occurs, we will notify the Data Protection Board of India and every affected Data Principal, in the form and within the timelines the DPDP Act and its rules require, without waiting for our investigation to conclude.
Our notice to you will describe, as far as we know it: what happened and when; the categories of data involved; the likely consequences; what we have done to contain it and prevent recurrence; and what we recommend you do — for example, changing your password or revoking an AI provider key.
Because you are the Data Fiduciary for the contents of your uploads, if a breach affects your uploaded chat data we will notify you promptly and give you the information you need to meet your own notification duties to the people in that data.
13. Children's data
ThreadClarity is not for children. We do not knowingly create accounts for anyone under 18, and we do not use the Service to track, profile or advertise to children — which the DPDP Act prohibits outright.
We cannot inspect your uploads, so we cannot detect whether a chat export contains messages from a child. If it does, you are responsible for the verifiable consent of that child's parent or lawful guardian, and for any additional obligations the DPDP Act places on you as Data Fiduciary. Do not upload archives centred on children's communications unless you are certain of your legal position.
If you believe we hold a child's data without the required consent, write to the Grievance Officer and we will delete it.
14. International transfers
Your account data, uploaded exports and generated output are stored on infrastructure in India by default. Payments (Razorpay) and email (Zoho) are handled by Indian companies on Indian infrastructure.
The one routine cross-border transfer is AI processing: if you enable it, chat excerpts go to Google, OpenAI or Anthropic and may be processed outside India, in the regions those providers operate. This happens only on your explicit instruction, on your own API key, and you can avoid it entirely by not configuring an AI key.
Transfers are made in accordance with section 16 of the DPDP Act and will not be made to any territory that the Central Government restricts by notification.
15. Changes to this policy
We will update this policy when our processing, our processors, or the law changes. The "Last updated" date at the top always reflects the current version. For material changes we will give you at least fifteen (15) days' notice by email or in-app notice before they take effect, and where a change requires fresh consent, we will ask for it.
Related documents: Terms of Service · Refund & Cancellation Policy · Contact.