Legal

Privacy Policy

Effective and last updated: September 26, 2026.10 min readKranth AI, Inc.

Kranth AI, Inc. ("Kranth", "we", "us") is a Delaware C-corporation. We operate the Kranth synthetic-audience service at kranth.com, kranth.ai, app.kranth.ai, api.kranth.com, and related subdomains (the "Service").

This policy describes how we process personal information collected through the Service, our marketing site, and related activities. It covers U.S. state privacy laws and the GDPR and UK GDPR.

California / state privacy rights: see "State privacy rights" below.
European users: see "Notice to European users" below.

Controller: Kranth AI, Inc., c/o Stable, 2810 N Church St STE 89663, Wilmington, DE 19802, United States.
Privacy: [email protected] · Security: [email protected] · Support: [email protected]

We have not appointed an EU or UK Article 27 representative or a Data Protection Officer. Email [email protected].


#Personal information we collect

#Information you provide

CategoryExamplesWhy
Contact / accountName, email, password hash, Nexus user_id, Google/GitHub sign-in ids (if you use them), avatar URL, workspace nameIdentify you; transactional email
BillingStripe customer ID, last 4 of card (held by Stripe, not us), billing address (Stripe Tax)Payment, VAT/sales tax
User-generated contentSim and debate submissions (idea_text, topics, persona count, model), interview answers and transcripts, library entriesRun the Service you asked for
IntegrationsTelegram chat id, Slack workspace id + name, Discord webhook URL, Linear API key, GitHub App installationDeliver notifications and verdicts you connected
CommunicationsSupport email, in-product ticketsRespond to you
Email preferencesYour marketing opt-out and notification settingsRespect your choices about what we send

We do not ask for government ID, Social Security numbers, precise geolocation, or payment card numbers. Do not submit sensitive personal data (health, race, religion, biometrics, criminal history) through the Service.

#Third-party sources

  • Sign-in providers you choose (Google, GitHub, Vylth Nexus): username, email, avatar, as their OAuth scopes allow.
  • Stripe: payment metadata after checkout.
  • You: when you connect Slack, Discord, Telegram, Linear, or the GitHub App.

We do not buy lists from data brokers.

#Business contacts

If you work at a company we think Kranth could help, we may find your name, work email, company and role on public sources such as company websites and public professional profiles, and send you an individual business email. We keep a record of who we contacted and when, and a suppression list so anyone who opts out is never contacted again. Reply to any of those emails or write to [email protected] to opt out.

#Automatic collection

  • Device / request: hashed IP (server-side salt; never stored raw), approximate location (country and city) derived from the IP address, user-agent, request IDs, device/OS/browser class.
  • Online activity (marketing site): path, referrer, UTM parameters, cookieless first-party page views.
  • Network telemetry: Nginx access logs, journalctl, alert markers.
  • Conversion tags on the marketing site: Google Ads, Microsoft Advertising (Bing UET), and X (Twitter) pixels. These parties may receive your IP and set their own cookies. See Cookies.

We do not collect precise geolocation. We do not run session-replay tools. We do not have a native mobile SDK.

If you invite a teammate, we collect the email you type so we can send the invite. Do not invite someone without their permission.

We do not knowingly collect data from anyone under 16.


#What we do not do

  • We do not sell personal information for money.
  • We do not rent personal information.
  • We do not store raw IP addresses.
  • We do not train on your content unless you explicitly opt in. Off by default. Enterprise plans contractually never train.
  • We do not profile you for housing, credit, employment, or similarly significant decisions.
  • We do not run Google Analytics, Mixpanel, or PostHog.

#AI training data

Both the org training_opt_in flag and the per-run flag must be true before reaction text leaves per-run scope. A run's null inherits the org flag. The org flag defaults to false.

When both are true, synthesized report + reaction texts may be archived to Cloudflare R2 at {org_id}/sims/{sim_id}.json as candidate data for our Wisdom model. Archive writes are currently disabled system-wide. Opting in today takes effect only when we announce activation.

Flip the org flag in /app/settings. Off stops new writes. Email [email protected] to purge already-archived rows (30 days).


#How we use personal information

PurposeLegal basis (Europe)
Run sims, debates, recon, interviews; stream reactions; render verdictsContract
Account, auth, API keys, team seatsContract
Charge cards, tax, invoices (via Stripe)Contract / legal obligation
Transactional email (verify, reset, run-complete, billing, invites)Contract
Product and marketing email to account holders, with an unsubscribe in every messageLegitimate interests, or consent where the law requires it
Individual business emails to prospective customersLegitimate interests
Safety classifier on submissions (Groq)Legitimate interests (abuse / illegal content)
Rate limits, audit log, incident responseLegitimate interests / legal obligation
First-party cookieless analyticsLegitimate interests (understand which pages work)
Conversion measurement (Google / Microsoft / X tags on the marketing site)Legitimate interests; you can block tags in the browser or email us to opt out of tag-based measurement
De-identified aggregate metrics (counts, percentiles)Legitimate interests
Optional AI training (only if you opt in)Consent
Comply with law, subpoena, enforce termsLegal obligation / legitimate interests

We send occasional product and marketing email to account holders. Every message carries a one-click unsubscribe, and opting out stops it for good. Transactional email continues while you have an account.

We do not use personal information for automated decisions that produce legal or similarly significant effects. A simulation verdict is not a decision about you as a consumer.


#How we share personal information

RecipientWhatWhy
LLM providers you pick (Anthropic, Google, Together, Groq, xAI; GPT-family via OpenRouter)Prompt + idea textRun the job
GroqEvery submissionSafety classifier
GoogleSim textEmbeddings for simulation retrieval (Gemini embedding model)
CartesiaDebate / interview speech; live mic audio if you choose SpeakTTS / STT. Type mode sends them nothing inbound
CloudflareRequest traffic, R2 objectsCDN, DNS, TLS, storage
Vylth NexusSSO identitySign-in
StripeBilling metadataPayments. Card data is Stripe's
ResendEmail address + messageTransactional, product and marketing email
MailstrelA prospect's name and work emailSending our individual business emails
GitHub / GoogleIf you use them to sign in or install the GitHub AppAuth / PR-as-sim
Slack / Discord / Telegram / LinearOnly if you connect themNotifications you asked for
DiceBearAnonymized avatar seedAvatars
Google FontsVisitor IP (font file request)Marketing-site fonts
Google Ads, Microsoft Advertising, XMarketing-site visitors (IP / cookie / conversion event)Ad conversion measurement
Professional advisorsAs neededLegal, audit, tax
AuthoritiesAs requiredLawful process
Business transfereesIf we sell or merge the companyDiligence / successor operation

Full list with residency: /subprocessors. We email 30 days before adding a subprocessor that processes personal data.

We have no corporate parent or affiliates that receive customer data today.

Public share links (/s/…, /d/…) expose what you choose to publish, including voice audio for shared voice debates. You can unpublish. Search engines may cache public pages.


#Cookies and similar technologies

Authentication uses one first-party HttpOnly cookie (_kss). Details and the conversion-tag table: /cookies. This policy incorporates the Cookie Notice.

We do not currently respond to browser "Do Not Track" as a global switch. Some first-party conversion helpers no-op when DNT is set; the third-party tags in index.html still load unless you block them.


#Retention

DataHow long
Sims, debates, interviews and recon runsUntil you delete them. There is no automatic time-based purge
Account and workspaceUntil you delete them. Deletion removes them from our database immediately
Audit logLife of the workspace; de-identified on account delete
StripeStripe's policy
R2 training archive (if enabled + opted in)Until opt-out or org delete + 30 days
Web server access logs15 days
Application logs30 days
Stripe webhook replay records30 days
Database backups7-day rotation, so deleted data is gone from backups within 7 days
Business-contact records and the suppression listAs long as we need them to honor your opt-out

We retain personal information only as long as needed for the purposes above, legal claims, or law. Then we delete, anonymize, or isolate it (backups) until deletion is possible. We do not attempt to re-identify de-identified data except to test our process.

Full detail: the Data Retention Policy.


#Security

TLS 1.2+ in transit. API keys argon2id-hashed. MFA secrets AES-256-GCM at column level. R2 encrypted at rest by Cloudflare. Webhooks HMAC-SHA256. Append-only audit log.

Internet transmission is not guaranteed secure. Report issues to [email protected] (24h ack, 5-day triage). Policy: /vulnerability-disclosure.


#Your choices (all users)

  • Update name, email, org name in /app/settings.
  • Export a run: GET /v1/sims/{id}/export.
  • Delete the workspace in /app/settings (danger zone) or email [email protected].
  • Opt out of AI training in /app/settings.
  • Opt out of marketing email with the unsubscribe link in any of them. Transactional email continues.
  • Disconnect integrations in settings.
  • Block third-party tags in the browser.
  • Email [email protected] to opt out of conversion-tag measurement on our side (we will stop firing first-party conversion helpers for that account; we cannot control tags already loaded on a visit).

Declining required account data means we cannot provide the Service.


#State privacy rights

This section applies to residents of U.S. states with comprehensive privacy laws (including California, Colorado, Connecticut, Virginia, Nevada, Texas, and others as they come into force), to the extent those laws apply to us.

Rights may include: know / access, correct, delete, portability, appeal a denial, and nondiscrimination. They are not absolute.

Sale. We do not sell personal information for money. Nevada residents may email [email protected] to opt out of any future sale.

Sharing / targeted advertising. We do not run an interest-based ad network on the product. The marketing site loads Google Ads, Microsoft Advertising, and X conversion tags, which some state laws treat as "sharing" or targeted-advertising measurement. Email [email protected] with subject "Opt out of sharing" to request we stop account-level conversion fires. We do not yet honor Global Privacy Control (GPC) signals in software.

Profiling. We do not profile you for decisions with significant legal or similar effects.

Sensitive personal information. We do not collect it to infer characteristics about you. Do not submit it.

Shine the Light (California). We do not disclose personal information to third parties for their own direct marketing. Requests: email [email protected] with "Shine the Light Request", your name, mailing address, and a statement that you are a California resident.

How to exercise. Email [email protected]. We verify by control of the email on the account. We may ask for more if the request is high-risk. Authorized agents: written permission or power of attorney. We will say if we deny and why.

CCPA categories (last 12 months)

PI we collectCCPA categoryDisclosed to (business purpose)Sold / shared
Account identifiersIdentifiersNexus, Google/GitHub (if used), ResendNot sold. Conversion tags may share device/IP on the marketing site
Email, nameIdentifiers / customer recordsResend, StripeNo
Billing metadataCommercial informationStripeNo
Idea text, reactionsCustomer contentLLM providers you pick, Cartesia if voiceNo
Hashed IP, UA, pathInternet / electronic activityCloudflare, conversion tags on marketingSharing via conversion tags as above
Inference / scoresInferencesStored in your workspaceNo

#Notice to European users

This section applies to individuals in the EEA and the United Kingdom. "Personal information" includes "personal data" under the GDPR / UK GDPR.

Controller: Kranth AI, Inc. (contact above). No Art. 27 representative and no DPO.

Legal bases: see the table under "How we use personal information."

Your rights: access, correct, delete, portability, restrict, object (including to legitimate-interests processing and to any future direct marketing), withdraw consent. Email [email protected]. We may need to confirm it is you.

Supervisory authority: you may complain to your local DPA. UK: Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF, +44 303 123 1113, https://ico.org.uk.

Transfers. We are a U.S. company. Primary application data lives in the EU (Germany), hosted by Contabo. Some subprocessors (Stripe, Resend, LLM providers, Cloudflare edge, Cartesia) process data in the U.S. or other countries. The U.S. is not covered by an adequacy decision in every case. We use Standard Contractual Clauses (and UK IDTA / Swiss addenda where required) with subprocessors, or another lawful mechanism. Email [email protected] for a copy of the relevant safeguards.

No sensitive data and no automated decisions with legal effect, as stated above.


#Children

The Service is not directed to anyone under 16. If you believe a minor created an account, email [email protected] and we will delete it.


#Other sites

Links and integrations (Nexus, Stripe Checkout, GitHub, Slack, and the rest) are third parties. Their policies apply on their properties.


#International users (non-Europe)

We are headquartered in the United States. Information may be processed in the U.S., Germany, and other countries where our providers operate. Those laws may differ from yours.


#Changes

Material changes: 30 days' email to the account owner. Non-material: we bump this date. Prior versions: [email protected]. Using the Service after the effective date means this version applies to that use.


#Disputes

Delaware law. State or federal courts in Delaware, unless your local consumer law gives you a stronger right.


#How to contact us

Email[email protected]
MailPrivacy, Kranth AI, Inc., c/o Stable, 2810 N Church St STE 89663, Wilmington, DE 19802, United States

If anything is unclear, ask. We would rather rewrite this than have you guess.

You read the whole thing. Most people don't. Thank you.

Questions about this document? [email protected] · Back to the top