1. Who We Are & Scope
Kruthika.fun is an AI companion service operated by the Kruthika team (the “Operator”). For the purposes of applicable data-protection law, the Operator is the data controller for the limited personal data described in this Policy. This Policy covers the web application, the public website, the blog and all associated pages. It does not cover third-party services that operate under their own privacy policies (see §6).
Plain-language summary: chats stay on your device; we keep only stripped-down technical logs to run and secure the Service; you can wipe everything at any time from your browser.
2. AI Transparency Notice
You are interacting with an automated artificial-intelligence system. Kruthika is a fictional, simulated persona — there is no human on the other side of the conversation and every reply is machine-generated. This disclosure is provided in line with the transparency obligations of Article 50 of the EU Artificial Intelligence Act and similar emerging standards.
- Message text is transmitted over TLS 1.3 to an AI inference provider solely to generate a reply.
- Providers process prompts only to produce responses; they do not use them to train their public models.
- Please do not share sensitive personal data (health, financial, government-ID or intimate details) in chat. The safest place for private context is your own device — which is exactly where our memory feature stores it.
3. Data We Collect
| Category | Examples | Where it lives |
|---|---|---|
| Chat content | Messages you send; AI replies generated for you | Processed in transit; never stored in a readable user database. Conversation continuity is kept locally on your device. |
| Local device data | Chat memory, name/nickname you share, language preference, relationship-stage notes | Your browser only (localStorage). Never uploaded by us. |
| Technical telemetry | Truncated/anonymised IP address, user-agent, device & OS class, referring page, visited paths, response latency | Our servers (MySQL) — uptime, abuse prevention and aggregate analytics. |
| Consent records | Your cookie/consent choices and timestamp | Cookie + server-side record (12 months). |
| Push identifiers (optional) | OneSignal subscription / external ID, if you enable notifications | OneSignal + our database, until you unsubscribe. |
| Blog interactions | Anonymous page-view counts; optional opt-ins you choose | Aggregated analytics tables. |
We do not require an account, real name, email, phone number or payment details to chat. We never knowingly collect special-category data (health, biometrics, religion, sexuality) — please avoid sharing it.
4. Legal Bases for Processing (GDPR Art. 6)
| Purpose | Legal basis |
|---|---|
| Deliver the chat Service you request | Performance of a contract / steps at your request |
| Security, fraud & abuse prevention, rate limiting | Legitimate interests (and legal obligation where applicable) |
| Aggregate analytics & uptime monitoring | Legitimate interests (anonymised/truncated data) |
| Non-essential cookies & contextual advertising | Consent (withdrawable at any time) |
| Web push notifications | Consent (withdrawable by disabling notifications) |
| Compliance with legal obligations & lawful requests | Legal obligation |
5. How We Use Data
- To operate the Service: generate replies, remember context locally, route voice/TTS when enabled.
- To keep the Service safe: detect abuse, enforce fair-use quotas, block malicious traffic.
- To improve reliability: aggregate latency/error metrics — individual users are not profiled.
- To deliver optional notifications you have explicitly enabled.
What we never do: sell your data; build advertising profiles on you; share chats with advertisers; or use your conversations to train public AI models.
6. Service Providers & Sub-processors
To run a free, global Service we rely on carefully selected processors. Each processes data only on our instructions under a data-processing agreement, and none is authorised to use your chat content for its own purposes.
| Function | Providers | Data involved |
|---|---|---|
| AI inference (reply generation) | Google Gemini · Cloudflare Workers AI · Groq · Cerebras · SambaNova · OpenRouter · NVIDIA NIM · Mistral · Cohere · DeepSeek | Prompt content, in transit, to produce a reply |
| Text-to-speech (optional voice notes) | ElevenLabs · Sarvam AI | The specific text being voiced |
| Hosting & database | Hostinger (Node.js runtime, MySQL) | Technical telemetry, configuration |
| Edge cache | Upstash Redis | Non-personal cached config/blog payloads |
| Web push (opt-in) | OneSignal | Subscription ID, notification content |
| Contextual advertising (consent-based) | Adsterra | Non-personalised ad serving; no chat data |
The active provider cascade is configurable from our admin panel and may change as providers add or remove free capacity; this table reflects categories of processors rather than an exhaustive moment-in-time list.
8. Data Retention
- Chat memory: stored locally on your device until you clear it (“Clear Chat” or browser wipe).
- Raw technical logs: purged on a rolling 90-day schedule; only aggregated counts survive.
- Backups: rolling 14-day window, then destroyed.
- Consent records: 12 months (proof-of-compliance).
- Push identifiers: until you unsubscribe or the subscription expires.
9. International Data Transfers
Our processors operate globally (data centres in the US, EU and India), so your information may be processed outside your country of residence. Where personal data leaves the EEA/UK, transfers rely on adequacy decisions, the European Commission’s Standard Contractual Clauses, participation in the EU–US Data Privacy Framework where certified, or equivalent safeguards required under India’s DPDP Act and other applicable laws.
10. Your Privacy Rights
Subject to your local law, you have the right to:
- Access & portability — obtain a copy of the data associated with your session.
- Rectification — correct inaccurate information (most data is editable directly in chat or your browser).
- Erasure — delete locally stored chats instantly, and ask us to purge residual telemetry.
- Restrict / object — object to processing based on legitimate interests.
- Withdraw consent — for cookies (banner/3-dot menu) and notifications (browser settings).
- Non-discrimination — exercising these rights never degrades your Service quality.
Because the design is privacy-first, most “requests” are self-service: clearing your browser storage erases everything personal we could associate with you. For anything else, email privacy@kruthika.fun; we respond within 30 days (GDPR), 45 days (CCPA) or sooner where Indian law requires.
| Region | Primary framework(s) |
|---|---|
| European Union (DE, FR, IT, ES, NL, PL, SE) | GDPR + ePrivacy Directive (cookies) |
| United Kingdom | UK GDPR & Data Protection Act 2018 |
| Brazil | LGPD |
| Canada | PIPEDA |
| United States | CCPA/CPRA (California) and applicable state laws |
| India | Digital Personal Data Protection Act, 2023 · IT Act & Intermediary Guidelines |
| Australia | Privacy Act 1988 (APPs) |
| Japan | APPI |
| South Korea | PIPA |
| Singapore | PDPA |
| Indonesia | PDP Law (Law No. 27/2022) |
| Thailand | PDPA |
| Malaysia | PDPA 2010 |
| Philippines | Data Privacy Act of 2012 |
| Vietnam | Decree 13/2023 (Personal Data Protection) |
| Pakistan / Bangladesh | Applicable local law (frameworks in development) |
| Nigeria | Nigeria Data Protection Act, 2023 |
| South Africa | POPIA |
| UAE | Federal PDPL (Decree-Law 45/2021) |
| Saudi Arabia | PDPL |
| Türkiye | KVKK (Law No. 6698) |
| Argentina | Ley 25.326 de Protección de Datos |
| Mexico | LFPDPPP |
Provided for transparency about frameworks that commonly apply to our users by region; not legal advice.
11. California Notice (CCPA/CPRA)
Notice at collection. In the preceding 12 months we collected the following categories of personal information from California consumers: internet/electronic activity (truncated IP, device/browser metadata, page interactions) and inferences drawn from it (aggregate reliability metrics). No sensitive personal information, as defined by §1798.140(ae), is collected.
- We do not “sell” or “share” personal information as defined by the CCPA/CPRA. Advertising is contextual and consent-gated; chat content is never disclosed to advertisers.
- Right to know / delete / correct / opt-out — exercise via privacy@kruthika.fun. Because chats live on your device, deletion is typically instant via clearing site data.
- Non-discrimination: we never restrict quality or features for exercising CCPA rights.
We do not act on Do Not Track signals — no uniform standard exists; if one becomes legally binding we will update this Policy.
12. Children’s Privacy
The Service is intended for adults and is not directed to children under 13 (or under 16 in the EEA, or under 18 where local law requires — see our Terms, §4 Eligibility). We do not knowingly collect personal information from children. If you believe a minor has provided data, contact us and we will delete it promptly.
13. Data Security
- TLS 1.3 encryption in transit; strict Transport Security with preload.
- Nonce-based Content-Security-Policy with
strict-dynamic; XSS sanitisation on all inputs. - Parameterised SQL only (no string-built queries); least-privilege database grants.
- Admin sessions: HMAC-signed HttpOnly cookies; scrypt-hashed passwords; rate-limited login.
- Anonymised/truncated IPs at ingestion; daily backups retained 14 days.
No system is perfectly secure. If a breach affecting your rights occurs, we notify affected users and competent authorities within the timelines required by GDPR Art. 33–34 and equivalent laws.
14. Changes to This Policy
We may update this Policy to reflect changes in the Service or law. The “Last Updated” date at the top always shows the current version. Material reductions in privacy protection will be flagged with an in-app notice for reasonable advance notice before taking effect. Continued use after changes take effect constitutes acceptance of the updated Policy.
15. Contact & Grievance Officer
Grievance Officer (India)
Email: grievance@kruthika.fun
Designated under India’s IT Rules & DPDP Act. Acknowledgement within 72 hours; resolution within 30 days.
EU/UK residents may also lodge a complaint with their national supervisory authority. This Policy is provided for transparency and does not constitute legal advice.