Back to Console Login

Privacy Policy

DPDP & GDPR Aligned

Last Updated: 11 September 2026  |  Version: 2026-09-11-v1

EXCLUSIVE BETA NOTICE — IMMEDIATE & PERMANENT ACCOUNT DELETIONKrend collects no fees and does not process payment information during the Beta. Account deletion executed from your dashboard permanently cascades across all production data immediately with zero grace period.

1. Who We Are, and the Two Roles We Play

Krend provides an API and dashboard for AI-powered review analysis. We handle personal data in two distinct roles:

  • As a processor: for review content our business Customers submit through the API (which may include personal data about their end-users/reviewers).
  • As a controller / data fiduciary: for our direct Customers' account information (name, email, authentication tokens, API keys).

2. Beta Notice

Krend is currently an exclusive beta. We do not collect payment information, and no fees are currently charged. Fresh consent will be sought before any new data collection tied to payment begins.

3. What We Collect

  • Account data: name, email, authentication tokens (via Supabase Auth OAuth/credentials), business organization name.
  • Review content submitted via API: review text, ratings, optional customer IDs, metadata supplied by Customers.
  • Usage & security data: API request timestamps, IP addresses, user agents, rate-limiting and abuse-prevention telemetry.
  • Consent records: immutable audit log proving what document version and text hash you accepted and when (see Section 7).

4. How We Use It

We process data solely to provide the Service (ingest, analyze, and display review intelligence), maintain infrastructure security and tenant isolation, prevent abuse and fraud, and comply with applicable laws.

5. Who We Share It With & AI Sub-Processors

Review content is transmitted to our AI inference sub-processors to generate Analysis:

  • Groq: Retains API request inputs and outputs for up to 30 days for operational reliability, system debugging, and abuse monitoring before automated purging, per the Groq API Privacy Policy. Groq does not use customer API data to train or fine-tune models.
  • Velona (velona.in): Operates as an AI gateway. Under Velona's published Privacy Policy (Section 6), inputs, prompts, outputs, and metadata are retained "as long as reasonably necessary" for security, fraud detection, billing verification, and operational purposes. Velona does not publish a specific numerical retention limit and relays data to underlying third-party model providers.
  • Infrastructure Providers: Supabase (authentication, database hosting), Upstash (Redis rate-limiting), and hosting infrastructure.
  • No Data Sales: We do not sell or rent personal information to any third party.

7. How We Record Consent (Immutable Audit Trail)

When you accept this Privacy Policy and our Terms of Service, we record the specific document versions, the SHA-256 hash of the exact document text shown, a timestamp, IP address, and User-Agent. This record is stored in an append-only compliance table (consent_records). This compliance record is retained even after account deletion, as required by legal compliance frameworks to prove consent historically occurred. If documents are materially updated, fresh affirmative consent is required before accessing the Service.

8. Account Deletion — IMMEDIATE AND PERMANENT, NO RECOVERY

During the Beta, account deletion has no grace period.

  • You can initiate account deletion directly from Settings. It requires re-authentication and typed confirmation.
  • Upon confirmation, your account, API keys, reviews, bugs, derived insights, and analysis runs are permanently and irreversibly deleted from our production database immediately via atomic foreign-key cascade.
  • Surviving compliance records: We retain only the proof that deletion occurred (account_deletion_logs) and your historical consent log (consent_records). These compliance records survive account deletion and contain no review content.
  • Third-party retention limitation: While Krend deletes all data immediately from our systems, content previously processed by third-party AI sub-processors (Groq and Velona) may remain in their operational and security logs for their standard retention windows (up to 30 days for Groq; undefined/as-necessary for Velona per Section 5). Krend cannot unilaterally purge third-party inference logs on demand.

9. Security Measures

Our security controls are audited and implemented directly in the production codebase:

  • Authentication: Supabase Auth with Google OAuth and password authentication. JWTs are validated locally using cached JWKS public keys, eliminating external network dependencies for token validation. Sessions support signed HttpOnly cookies.
  • Tenant Isolation: Strict multi-tenancy enforced at the database layer via business_id scoping on all queries. Automated test suites verify cross-tenant data leakage is prevented.
  • API Key Protection: Generated with 24 bytes of cryptographic randomness. Plaintext keys are shown once and never persisted or logged. Database stores only SHA-256 hex digests with a 15-character prefix, verified with timing-safe constant-time comparison.
  • Multi-Tiered Rate Limiting: Redis-backed rate limiting (300 req/min global, 60 req/min review ingest, 5 accounts/hr provisioning). Incident monitoring alerts on repeated unauthorized attempts and triggers client lockout after 5 failed logins.
  • Transport Security & Headers: HTTPS/TLS, Strict-Transport-Security (1-year max-age, preload), X-Frame-Options: DENY, nosniff, strict CSP, and non-caching headers on all API responses.
  • Data Redaction: Application logger automatically redacts authorization headers, session cookies, and credentials.
  • Dependency Hygiene: Automated vulnerability audits (npm audit). Production runtime dependencies are clean with zero known vulnerabilities.

10. Contact

For questions or requests regarding your personal data or this Privacy Policy:

Contact Email: anav183862@gmail.com

Part B — Regional Supplements

B1. India — DPDP Act, 2023 Supplement

Applies to Data Principals in India. Krend acts as a Data Fiduciary for account data.

  • Consent: Free, specific, informed, unconditional, and unambiguous affirmative action — never pre-ticked.
  • Rights: Access, correction, and erasure via immediate account deletion in Settings.
  • Contact Email: anav183862@gmail.com

B2. European Economic Area & UK — GDPR Supplement

Legal bases include contract performance for service delivery and legitimate interests for security and abuse prevention. International transfers to AI sub-processors rely on standard contractual clauses.

B3. United States — CCPA/CPRA Supplement

We do not sell personal information. Self-serve deletion via Settings permanently removes all personal information immediately.