Privacy
Privacy Policy
Version 2.1 · in force from 4 August 2026 · a binding agreement between you and Klair Tech, Hyderabad, India
The short version
Klair Tech processes personal data when you use Insighter. For enterprise organizations the organization is the data fiduciary and we act on its instructions. We do not train models on your content, we do not sell it, and we name every subprocessor.
This summary is for orientation. The clauses below are the agreement.
This policy explains what personal data Insighter collects, why, where it goes, how long it stays, and the rights you have. It applies to the Insighter product, the public website, and the API.
1. Scope
This policy covers personal data processed by Klair Tech ("Company", "we") when you use Insighter. For enterprise organizations, the organization is the data fiduciary for content processed through its account and we act on its instructions; a data processing addendum is available on request.
2. Information we collect
- Account details: name, email address, and sign-in records.
- Organization and workspace membership and roles.
- Credit, billing, and usage records, including per-run metering.
- Content you choose to upload or connect for analysis, including files, database results, and documents from connected sources.
- Conversations with the agent, feedback you give on answers, and preferences the agent stores at your instruction (viewable and erasable from your profile).
- Technical logs needed to operate and secure the service.
We do not collect data from your connected sources except to answer the questions you ask or to carry out an action you authorized. Databases, warehouses and files are read-only. Sources that can act are switched off until someone with manage access enables them, one operation at a time.
3. How information is used
Personal data is used to run the analyses you request, operate your account and organization, meter and bill usage, send transactional email (sign-in, invitations, alerts you configure, receipts, low balance notices), and keep the service secure. We do not sell personal data and we do not use your content for advertising or to train AI models.
4. AI processing
Questions and the relevant data context are sent to our AI model providers, AWS Bedrock and Anthropic, to generate answers. They process this data to answer the request and do not train on it under their terms for business customers. A provider may retain a copy briefly for its own abuse detection, as AWS documents for Bedrock, and that copy is not used to train models and is not available to us. Consequential actions require your explicit consent in the product, and an audit trail records them. AI outputs can be wrong; they are decision support, not professional advice.
5. Data from connected services
You may connect third party services so Insighter can answer questions about the data in them. We request the narrowest permission that supports the feature you use, we access those services only to run the analysis you ask for or to carry out an action you authorized, and the connection can be removed at any time from the Data page, which revokes our access.
Connecting a service means data travels in both directions. To answer your question we send that service the request and the context it needs, and it sends its response back to us. Those providers decide for themselves what they do with what they receive, under their own terms and privacy policies. We do not control their data practices and we are not responsible for them. You are responsible for confirming you may connect the source and have its data processed here.
Some sources need no credential at all, such as public documentation and reference servers. Anything sent to one of those reaches an operator we have no agreement with, no confidentiality undertaking from, and no deletion commitment from. Treat them as public and do not send confidential or personal data through them. The Data page marks which sources these are.
Google user data. When you connect Google Drive, Sheets, Docs, Slides or Analytics, our default connection uses the per file scope (drive.file), where you choose specific files in the Google Picker and we can read only those. Broader read only access (drive.readonly) is requested only if you explicitly choose to connect an entire Drive, and Analytics read only access (analytics.readonly) is requested only when you connect Google Analytics. We never request write or delete permissions on Google data, and we never create, modify or delete anything in your Google account.
Insighter's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically, data obtained through Google APIs is used only to provide and improve the features you requested, is not sold, is not transferred to others except as necessary to provide the service, to comply with law, or as part of a merger or acquisition with your consent, is not used for advertising, and is not read by humans except with your explicit consent, for security purposes, to comply with law, or where the data is aggregated and anonymized.
Content retrieved from a connected service to answer a question is held only for as long as that analysis needs it: query results and files fetched during a conversation live in that conversation's isolated workspace and are removed with it. Access tokens are encrypted at rest and are never shown back to you or to anyone else after they are stored.
6. Sharing and subprocessors
We share personal data only with the subprocessors needed to run the service:
- Amazon Web Services: hosting, storage, email, and model inference through Bedrock. Mumbai region, with inference in the Asia Pacific regions described below.
- Anthropic: AI model inference, United States. Used as the backup path when Bedrock is unavailable.
- Supabase: managed database.
- Razorpay: payment processing, India. Card details never touch our servers.
- Google: analytics on our public website only, through Google Analytics and Tag Manager, and only if you accept analytics cookies. No product content reaches it.
The current list, with the purpose and location of each, is kept on the subprocessors page. Services you connect yourself, such as a warehouse or a vendor tool server, are not subprocessors: they are your own systems or your own vendors, and clause 5 describes how data moves to and from them.
We may also disclose data where law requires, with notice to you where legally permitted.
7. International transfers
Our infrastructure runs in the AWS Mumbai region. Model inference runs on AWS Bedrock through an Asia Pacific regional profile, which means a request may be handled in Mumbai or in another AWS Asia Pacific region. When Bedrock is unavailable we fall back to Anthropic's own API in the United States. Transfers are limited to countries not restricted by the Government of India under the DPDP Act, and contractual safeguards apply to each subprocessor. Where you connect a third party service yourself, data also moves to wherever that provider operates, which is governed by their terms rather than ours.
8. Security
Connector credentials are encrypted at rest with per-organization keys held in a managed key service. Sessions are isolated per user and per workspace. Databases, warehouses and files are read-only: queries are checked to be SELECT-only before they run, and nothing in Insighter writes to them. A source that can act, such as a connected vendor tool server, starts switched off and stays off until someone with manage access enables it, one tool at a time. Once enabled, an action either waits for a person to approve it or is recorded for review afterwards, and the class of actions that destroy data, move money or change who has access is never available at all. Administrative functions are role-gated and audited. If a breach affects your personal data we will notify you and the relevant authorities as the law requires, including the Data Protection Board of India where applicable.
9. Retention
Account data and conversations are retained while your account is active. After account deletion, personal data is removed from our active systems within 30 days. Backups, where our infrastructure providers maintain them, follow their standard retention cycle and are not used to restore deleted personal data except for disaster recovery. Audit and billing records are kept for the period the law requires. Agent memories about you can be erased by you at any time from your profile.
10. Your rights and controls
You can export everything we hold about you, remove connectors and files, erase the agent's memories, and delete your account from the Profile page without asking us. You may also request access, correction, or erasure, object to processing, withdraw any consent-based processing, and nominate a person to exercise your rights in case of death or incapacity as provided by the DPDP Act. Requests made through the contact page are acknowledged within 48 hours.
11. Cookies
Insighter uses essential cookies for sign-in and, only with your consent, analytics cookies. The separate Cookie Policy lists each cookie and its purpose and explains how to change your choice.
12. Children
Insighter is not intended for anyone under 18 and we do not knowingly process children's data. If we learn that we hold such data we will delete it promptly.
13. Grievance redressal
Concerns about personal data are handled by our Grievance Officer, Klair Tech, Hyderabad, India, reachable through the contact page with the subject "Grievance". We acknowledge grievances within 48 hours and resolve them within 30 days. If you are not satisfied, you may complain to the Data Protection Board of India.
14. Changes to this policy
Material changes are announced in the product and require fresh acceptance before continued use. The version and effective date at the top identify the current text; earlier versions are available on request.
Something here unclear, or your legal team needs a signed copy? Ask us and a person will answer.
Contact us