Kranth AI, Inc. ("Kranth", "we", "us") is a Delaware C-corporation. We operate the Kranth synthetic-audience service at kranth.com, kranth.ai, app.kranth.ai, api.kranth.com, and related subdomains (the "Service").
This policy describes how we process personal information collected through the Service, our marketing site, and related activities. It covers U.S. state privacy laws and the GDPR and UK GDPR.
California / state privacy rights: see "State privacy rights" below.
European users: see "Notice to European users" below.
Controller: Kranth AI, Inc., c/o Stable, 2810 N Church St STE 89663, Wilmington, DE 19802, United States.
Privacy: [email protected] · Security: [email protected] · Support: [email protected]
We have not appointed an EU or UK Article 27 representative or a Data Protection Officer. Email [email protected].
#Personal information we collect
#Information you provide
| Category | Examples | Why |
|---|---|---|
| Contact / account | Name, email, password hash, Nexus user_id, Google/GitHub sign-in ids (if you use them), avatar URL, workspace name | Identify you; transactional email |
| Billing | Stripe customer ID, last 4 of card (held by Stripe, not us), billing address (Stripe Tax) | Payment, VAT/sales tax |
| User-generated content | Sim and debate submissions (idea_text, topics, persona count, model), interview answers and transcripts, library entries | Run the Service you asked for |
| Integrations | Telegram chat id, Slack workspace id + name, Discord webhook URL, Linear API key, GitHub App installation | Deliver notifications and verdicts you connected |
| Communications | Support email, in-product tickets | Respond to you |
| Email preferences | Your marketing opt-out and notification settings | Respect your choices about what we send |
We do not ask for government ID, Social Security numbers, precise geolocation, or payment card numbers. Do not submit sensitive personal data (health, race, religion, biometrics, criminal history) through the Service.
#Third-party sources
- Sign-in providers you choose (Google, GitHub, Vylth Nexus): username, email, avatar, as their OAuth scopes allow.
- Stripe: payment metadata after checkout.
- You: when you connect Slack, Discord, Telegram, Linear, or the GitHub App.
We do not buy lists from data brokers.
#Business contacts
If you work at a company we think Kranth could help, we may find your name, work email, company and role on public sources such as company websites and public professional profiles, and send you an individual business email. We keep a record of who we contacted and when, and a suppression list so anyone who opts out is never contacted again. Reply to any of those emails or write to [email protected] to opt out.
#Automatic collection
- Device / request: hashed IP (server-side salt; never stored raw), approximate location (country and city) derived from the IP address, user-agent, request IDs, device/OS/browser class.
- Online activity (marketing site): path, referrer, UTM parameters, cookieless first-party page views.
- Network telemetry: Nginx access logs, journalctl, alert markers.
- Conversion tags on the marketing site: Google Ads, Microsoft Advertising (Bing UET), and X (Twitter) pixels. These parties may receive your IP and set their own cookies. See Cookies.
We do not collect precise geolocation. We do not run session-replay tools. We do not have a native mobile SDK.
If you invite a teammate, we collect the email you type so we can send the invite. Do not invite someone without their permission.
We do not knowingly collect data from anyone under 16.
#What we do not do
- We do not sell personal information for money.
- We do not rent personal information.
- We do not store raw IP addresses.
- We do not train on your content unless you explicitly opt in. Off by default. Enterprise plans contractually never train.
- We do not profile you for housing, credit, employment, or similarly significant decisions.
- We do not run Google Analytics, Mixpanel, or PostHog.
#AI training data
Both the org training_opt_in flag and the per-run flag must be true before reaction text leaves per-run scope. A run's null inherits the org flag. The org flag defaults to false.
When both are true, synthesized report + reaction texts may be archived to Cloudflare R2 at {org_id}/sims/{sim_id}.json as candidate data for our Wisdom model. Archive writes are currently disabled system-wide. Opting in today takes effect only when we announce activation.
Flip the org flag in /app/settings. Off stops new writes. Email [email protected] to purge already-archived rows (30 days).
#How we use personal information
| Purpose | Legal basis (Europe) |
|---|---|
| Run sims, debates, recon, interviews; stream reactions; render verdicts | Contract |
| Account, auth, API keys, team seats | Contract |
| Charge cards, tax, invoices (via Stripe) | Contract / legal obligation |
| Transactional email (verify, reset, run-complete, billing, invites) | Contract |
| Product and marketing email to account holders, with an unsubscribe in every message | Legitimate interests, or consent where the law requires it |
| Individual business emails to prospective customers | Legitimate interests |
| Safety classifier on submissions (Groq) | Legitimate interests (abuse / illegal content) |
| Rate limits, audit log, incident response | Legitimate interests / legal obligation |
| First-party cookieless analytics | Legitimate interests (understand which pages work) |
| Conversion measurement (Google / Microsoft / X tags on the marketing site) | Legitimate interests; you can block tags in the browser or email us to opt out of tag-based measurement |
| De-identified aggregate metrics (counts, percentiles) | Legitimate interests |
| Optional AI training (only if you opt in) | Consent |
| Comply with law, subpoena, enforce terms | Legal obligation / legitimate interests |
We send occasional product and marketing email to account holders. Every message carries a one-click unsubscribe, and opting out stops it for good. Transactional email continues while you have an account.
We do not use personal information for automated decisions that produce legal or similarly significant effects. A simulation verdict is not a decision about you as a consumer.
#How we share personal information
| Recipient | What | Why |
|---|---|---|
| LLM providers you pick (Anthropic, Google, Together, Groq, xAI; GPT-family via OpenRouter) | Prompt + idea text | Run the job |
| Groq | Every submission | Safety classifier |
| Sim text | Embeddings for simulation retrieval (Gemini embedding model) | |
| Cartesia | Debate / interview speech; live mic audio if you choose Speak | TTS / STT. Type mode sends them nothing inbound |
| Cloudflare | Request traffic, R2 objects | CDN, DNS, TLS, storage |
| Vylth Nexus | SSO identity | Sign-in |
| Stripe | Billing metadata | Payments. Card data is Stripe's |
| Resend | Email address + message | Transactional, product and marketing email |
| Mailstrel | A prospect's name and work email | Sending our individual business emails |
| GitHub / Google | If you use them to sign in or install the GitHub App | Auth / PR-as-sim |
| Slack / Discord / Telegram / Linear | Only if you connect them | Notifications you asked for |
| DiceBear | Anonymized avatar seed | Avatars |
| Google Fonts | Visitor IP (font file request) | Marketing-site fonts |
| Google Ads, Microsoft Advertising, X | Marketing-site visitors (IP / cookie / conversion event) | Ad conversion measurement |
| Professional advisors | As needed | Legal, audit, tax |
| Authorities | As required | Lawful process |
| Business transferees | If we sell or merge the company | Diligence / successor operation |
Full list with residency: /subprocessors. We email 30 days before adding a subprocessor that processes personal data.
We have no corporate parent or affiliates that receive customer data today.
Public share links (/s/…, /d/…) expose what you choose to publish, including voice audio for shared voice debates. You can unpublish. Search engines may cache public pages.
#Cookies and similar technologies
Authentication uses one first-party HttpOnly cookie (_kss). Details and the conversion-tag table: /cookies. This policy incorporates the Cookie Notice.
We do not currently respond to browser "Do Not Track" as a global switch. Some first-party conversion helpers no-op when DNT is set; the third-party tags in index.html still load unless you block them.
#Retention
| Data | How long |
|---|---|
| Sims, debates, interviews and recon runs | Until you delete them. There is no automatic time-based purge |
| Account and workspace | Until you delete them. Deletion removes them from our database immediately |
| Audit log | Life of the workspace; de-identified on account delete |
| Stripe | Stripe's policy |
| R2 training archive (if enabled + opted in) | Until opt-out or org delete + 30 days |
| Web server access logs | 15 days |
| Application logs | 30 days |
| Stripe webhook replay records | 30 days |
| Database backups | 7-day rotation, so deleted data is gone from backups within 7 days |
| Business-contact records and the suppression list | As long as we need them to honor your opt-out |
We retain personal information only as long as needed for the purposes above, legal claims, or law. Then we delete, anonymize, or isolate it (backups) until deletion is possible. We do not attempt to re-identify de-identified data except to test our process.
Full detail: the Data Retention Policy.
#Security
TLS 1.2+ in transit. API keys argon2id-hashed. MFA secrets AES-256-GCM at column level. R2 encrypted at rest by Cloudflare. Webhooks HMAC-SHA256. Append-only audit log.
Internet transmission is not guaranteed secure. Report issues to [email protected] (24h ack, 5-day triage). Policy: /vulnerability-disclosure.
#Your choices (all users)
- Update name, email, org name in
/app/settings. - Export a run:
GET /v1/sims/{id}/export. - Delete the workspace in
/app/settings(danger zone) or email[email protected]. - Opt out of AI training in
/app/settings. - Opt out of marketing email with the unsubscribe link in any of them. Transactional email continues.
- Disconnect integrations in settings.
- Block third-party tags in the browser.
- Email
[email protected]to opt out of conversion-tag measurement on our side (we will stop firing first-party conversion helpers for that account; we cannot control tags already loaded on a visit).
Declining required account data means we cannot provide the Service.
#State privacy rights
This section applies to residents of U.S. states with comprehensive privacy laws (including California, Colorado, Connecticut, Virginia, Nevada, Texas, and others as they come into force), to the extent those laws apply to us.
Rights may include: know / access, correct, delete, portability, appeal a denial, and nondiscrimination. They are not absolute.
Sale. We do not sell personal information for money. Nevada residents may email [email protected] to opt out of any future sale.
Sharing / targeted advertising. We do not run an interest-based ad network on the product. The marketing site loads Google Ads, Microsoft Advertising, and X conversion tags, which some state laws treat as "sharing" or targeted-advertising measurement. Email [email protected] with subject "Opt out of sharing" to request we stop account-level conversion fires. We do not yet honor Global Privacy Control (GPC) signals in software.
Profiling. We do not profile you for decisions with significant legal or similar effects.
Sensitive personal information. We do not collect it to infer characteristics about you. Do not submit it.
Shine the Light (California). We do not disclose personal information to third parties for their own direct marketing. Requests: email [email protected] with "Shine the Light Request", your name, mailing address, and a statement that you are a California resident.
How to exercise. Email [email protected]. We verify by control of the email on the account. We may ask for more if the request is high-risk. Authorized agents: written permission or power of attorney. We will say if we deny and why.
CCPA categories (last 12 months)
| PI we collect | CCPA category | Disclosed to (business purpose) | Sold / shared |
|---|---|---|---|
| Account identifiers | Identifiers | Nexus, Google/GitHub (if used), Resend | Not sold. Conversion tags may share device/IP on the marketing site |
| Email, name | Identifiers / customer records | Resend, Stripe | No |
| Billing metadata | Commercial information | Stripe | No |
| Idea text, reactions | Customer content | LLM providers you pick, Cartesia if voice | No |
| Hashed IP, UA, path | Internet / electronic activity | Cloudflare, conversion tags on marketing | Sharing via conversion tags as above |
| Inference / scores | Inferences | Stored in your workspace | No |
#Notice to European users
This section applies to individuals in the EEA and the United Kingdom. "Personal information" includes "personal data" under the GDPR / UK GDPR.
Controller: Kranth AI, Inc. (contact above). No Art. 27 representative and no DPO.
Legal bases: see the table under "How we use personal information."
Your rights: access, correct, delete, portability, restrict, object (including to legitimate-interests processing and to any future direct marketing), withdraw consent. Email [email protected]. We may need to confirm it is you.
Supervisory authority: you may complain to your local DPA. UK: Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF, +44 303 123 1113, https://ico.org.uk.
Transfers. We are a U.S. company. Primary application data lives in the EU (Germany), hosted by Contabo. Some subprocessors (Stripe, Resend, LLM providers, Cloudflare edge, Cartesia) process data in the U.S. or other countries. The U.S. is not covered by an adequacy decision in every case. We use Standard Contractual Clauses (and UK IDTA / Swiss addenda where required) with subprocessors, or another lawful mechanism. Email [email protected] for a copy of the relevant safeguards.
No sensitive data and no automated decisions with legal effect, as stated above.
#Children
The Service is not directed to anyone under 16. If you believe a minor created an account, email [email protected] and we will delete it.
#Other sites
Links and integrations (Nexus, Stripe Checkout, GitHub, Slack, and the rest) are third parties. Their policies apply on their properties.
#International users (non-Europe)
We are headquartered in the United States. Information may be processed in the U.S., Germany, and other countries where our providers operate. Those laws may differ from yours.
#Changes
Material changes: 30 days' email to the account owner. Non-material: we bump this date. Prior versions: [email protected]. Using the Service after the effective date means this version applies to that use.
#Disputes
Delaware law. State or federal courts in Delaware, unless your local consumer law gives you a stronger right.
#How to contact us
[email protected] | |
| Privacy, Kranth AI, Inc., c/o Stable, 2810 N Church St STE 89663, Wilmington, DE 19802, United States |
If anything is unclear, ask. We would rather rewrite this than have you guess.