Legal

Privacy Policy

Kriya is a keyboard. A keyboard sees everything you type — so the only version of this product worth building is one that does not keep it. This page explains, in plain words, exactly what leaves your phone, what never does, and how you get it all back or erased.

Effective: 26 July 2026 Last updated: 26 July 2026 App: com.kriya.keyboard

The promise this whole policy rests on

We never read what you type. The keyboard runs entirely on your device. Text is sent to our server only in the one moment you hold the Kriya Bar and ask the agent to do something — and even then we keep only a short preview of the request, never the whole conversation.

On this page

  1. Who we are
  2. How the keyboard actually works
  3. What we collect
  4. What we never collect
  5. Passwords, OTPs & sensitive fields
  6. How we use your data
  7. AI processing (Google Gemini)
  8. Connected apps & permissions
  9. Payments & transaction data
  10. How our database keeps users apart
  11. Security
  12. Where your data lives
  13. How long we keep things
  14. Who else touches your data
  15. Your rights under the DPDP Act
  16. Deleting your account
  17. Children
  18. This website
  19. Changes to this policy
  20. Contact & grievance officer

1. Who we are

Kriya AI Keyboard ("Kriya", "we", "us") is an Android keyboard and companion app published by Harshad Salunke, an independent developer based in India. In the language of India's Digital Personal Data Protection Act, 2023 ("DPDP Act"), we are the Data Fiduciary for the personal data described here, and you are the Data Principal.

This policy covers the Kriya Android application and keyboard (package com.kriya.keyboard), our backend API, and this website. It does not cover the other apps you type into — Gmail, WhatsApp, your bank app — those have their own policies.

2. How the keyboard actually works

This is the most important section, because it is what makes every promise below possible. Kriya has two clearly separated modes:

Offline · default

Typing

Every key press, autocorrect, swipe, emoji and language switch is handled by native code on your phone. Nothing is uploaded. Nothing is logged. With the AI features untouched, Kriya makes no network call at all — you can use it in aeroplane mode forever.

You must ask

The agent

Only when you hold the Kriya Bar (spacebar) and give a command does the selected or typed text travel — over HTTPS — to our server and to the AI model, so it can rewrite, translate, draft or schedule for you. No hold, no upload.

There is no background sync, no inbox mirror, no "learning upload", and no analytics event that carries text. Our server logs record method, path, status code, duration and a hashed user reference — never request bodies, never query strings, never a single word you typed.

3. What we collect

We collect only what a specific feature genuinely needs.

DataWhy we have itWhen it is collected
Account identity
Name, email address, Google account ID
To create your account so your skills, quota and history follow you across devices. When you sign in with Google. We use Supabase Auth; we never see or store a password — there are no passwords in our system.
Profile & preferences
Chosen languages, theme, UPI ID (if you save one), agent preferences
To set up your keyboard and let the agent fill in details like your UPI ID when you ask for a payment QR. When you enter them in the app. The UPI ID is optional and entered by you.
Skills you create or install
The instruction text of a skill, its name, its key binding
To run the skill and sync it to your other devices. A skill is a prompt you wrote — it is your content. When you build a skill or install one from the Skill Hub.
Action history previews
Roughly the first six words of your command, a short preview of the result, and the receipt of what was done
So the History screen can show you what the agent did on your behalf, and so you can undo trust decisions. After each agent action. Never the full text, and it auto-expires on the schedule you choose (see §13).
Connected app tokens
OAuth access/refresh tokens for Google, Notion, Zoom or Slack
So the agent can create the calendar event or draft the email you asked for. Only if you explicitly connect that app. Stored encrypted at rest and never returned by any API — the app only ever sees "connected as name@gmail.com".
Usage counters
Number of AI actions used today / this week / this month
To enforce the free daily quota and the premium fair-use allowance, and to show you how many actions are left. Incremented after each successful agent action. It is a number, not a record of what you did.
Billing records
Subscription status, plan, expiry, payment gateway event IDs
To know whether your subscription is active, and to meet Indian tax and accounting law. When you subscribe or renew. See §9 — we never receive your card or UPI credentials.
Audit log
Names of actions performed (e.g. "calendar event created"), timestamps, hashed user reference
Security and abuse investigation, and so we can answer "what did this account do" without reading content. Automatically, with action names only — never the content of the action.
Technical diagnostics
App version, Android version, device model, crash traces, coarse error data
To fix crashes and keep the keyboard fast on budget phones. On error. Crash traces are code paths, not your content.

4. What we never collect

This list is not aspirational. Each line is a rule enforced in the code, not a promise in a document.

We storeWe never store
Profile — name, email, languages, UPI ID, preferencesYour keystrokes or typing stream
Skills you made or installedThe full text of your agent conversations
Short history previews, per your retention settingAnything typed into a password or OTP field
Encrypted OAuth tokens for apps you connectedPlaintext OAuth tokens, ever
Billing events and your entitlement rowCard numbers, CVV, UPI PIN or bank credentials
Audit log of action namesUser content inside any log or analytics event
Usage counts (a number)Your clipboard contents
Contact you send us in a support emailYour contacts, photos, files, call logs or SMS

We do not sell your personal data. We do not share it with advertisers or data brokers. We do not build advertising profiles. Kriya has no ad SDK.

5. Passwords, OTPs & sensitive fields

When Android tells the keyboard that a field is a password field, an OTP field, or otherwise sensitive, Kriya shows a shield icon and switches itself off: the Kriya Bar, the agent, clipboard features and all typing-learning features are disabled before any UI is drawn. In those fields Kriya is a plain, dumb, offline keyboard — which is exactly what it should be.

Kriya also does not use Android's accessibility services, and does not read the contents of the screen or other apps.

6. How we use your data

We do not use your content to train AI models — ours or anyone else's — and we do not use your data for advertising.

The legal basis

Under the DPDP Act we process your personal data on the basis of the consent you give when you sign in, connect an app, or hold the Kriya Bar to run an action — and, for a limited set of records such as tax invoices and fraud prevention, on the basis of legitimate uses permitted by law. You may withdraw consent at any time (§15); withdrawing it is as easy as giving it.

7. AI processing (Google Gemini)

When you invoke the agent, the text you selected or typed — plus the relevant part of your instruction and any context you deliberately saved (such as your name or UPI ID in "My Context") — is sent to Google's Gemini API to generate the result. This is a sub-processor relationship: Google processes the request on our behalf under the Google Cloud / Gemini API terms, which state that paid API content is not used to train Google's models.

8. Connected apps & permissions

Not available in version 1.0

Connected apps are in private preview. In the version on Google Play you can read what each connector would be allowed to do, but the Connect button is switched off — no account can be linked, no permission is requested, and Kriya holds no access to anyone's Google, Notion, Zoom or Slack account. The section below describes how they will work when they are switched on in a later update; it is published in advance so you can read the terms before you are ever asked to agree to them.

Connecting Google, Notion, Zoom or Slack is entirely optional — Kriya is fully usable without connecting anything. When you do connect one, we ask for the narrowest permissions that make the feature work:

ProviderWhat the agent can doPermissions requested
Google Create calendar events (with a Meet link), list your upcoming events when you ask, create a Gmail draft, send an email after your Confirm tap, read mail only when your command needs it ("what did Rahul mail me?") calendar.events, gmail.compose, gmail.readonly, openid email
No Drive, contacts, photos or Docs access.
NotionCreate a page or noteYou pick exactly which pages Kriya may touch, on Notion's own consent screen.
ZoomSchedule a meeting and return the join linkmeeting:write
SlackSend a message as you, to a channel you name, after you see the exact text and tap Confirmchat:write only — we cannot read your messages, channels or files.

Two rules that never bend

Reads are demand-driven: the agent may look at your mail or calendar only in service of the command you just typed. There is no background scanning, no mirroring of your inbox, and no schedule on which we go looking.

Disconnecting (Profile → Connected apps → open the card → Disconnect) revokes the token on the provider's side and deletes our encrypted copy. Deleting your account does the same for every connected provider.

Google user data — Limited Use disclosure

Kriya AI Keyboard's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Because Kriya requests Gmail scopes, we publish a separate, complete disclosure of exactly what we access, why each scope is needed, what we store, and how to revoke access: How Kriya uses Google user data →

9. Payments & transaction data

Kriya's free tier costs nothing and needs no payment details at all. If you subscribe to Premium (₹99/month or ₹999/year), here is exactly how the money and the data move.

  1. You choose a plan in the app

    Payment is taken by Cashfree Payments (an RBI-authorised Indian payment aggregator) or by Google Play Billing, depending on the option you pick.

  2. Your card / UPI details go to the gateway, not to us

    You enter them on Cashfree's or Google's own hosted page. They never pass through our servers and we never store them. We have no ability to charge your card ourselves; a UPI Autopay or card mandate lives with the gateway, and you can revoke it there.

  3. The gateway tells our server the payment succeeded

    Cashfree sends a cryptographically signed webhook; we verify the signature before believing it. Google Play purchases are verified against Google's Play Developer API. An unverified or unsigned payment message grants nothing.

  4. We update one row and store the receipt trail

    Your entitlement (tier, status, expiry date) flips to Premium. We keep the billing event record — event ID, plan, amount, timestamp, status — because Indian tax and accounting law requires us to keep transaction records.

  5. Your app picks it up

    The app re-checks your entitlement and unlocks Premium. Payments do not "unlock the app" directly — only a verified webhook or a verified purchase can change that row.

Transaction dataHeld by usHeld by the gateway
Card number / CVV / UPI PIN / bank loginNeverYes — under PCI-DSS / RBI rules
Your name and email on the subscriptionYesYes
Plan, amount, currency, transaction ID, dateYes — tax recordYes
Subscription status, renewal date, cancellationYesYes
Refund and chargeback recordsYesYes

Cashfree and Google are independent controllers of the payment data they hold — see Cashfree's privacy policy and Google's privacy policy. Refunds and cancellation are covered on our Refund & Cancellation Policy page.

10. How our database keeps users apart

Worth being specific about, because "your data is safe" means nothing without a mechanism:

11. Security

No system is perfectly secure, and it would be dishonest to claim otherwise. If a personal data breach occurs, we will notify the Data Protection Board of India and affected users as required by the DPDP Act. If you believe you have found a vulnerability, please email harshadsalunke2002@gmail.com — responsible disclosure is genuinely appreciated.

12. Where your data lives

Kriya is built for India and hosted in India. Your account, skills, history and billing records are stored in a Mumbai (India) region database, with the application server in an Indian region as well.

Two exceptions, both necessary and both narrow: the AI model (Google Gemini) and any app you choose to connect (Google, Notion, Zoom, Slack) may process the specific request on their own global infrastructure. Payment processing happens on Cashfree's or Google's systems. Any such transfer happens only to countries not restricted by the Government of India under section 16 of the DPDP Act.

13. How long we keep things

DataRetention
Action history previewsYou choose: 24 hours, 7 days, 30 days, or keep until deleted. A background sweep enforces your choice even if you never open the app. You can also delete any single action from its detail page.
Account, profile, skills, preferencesUntil you delete your account.
Connected app tokensUntil you disconnect that app or delete your account — whichever comes first.
Usage countersRolling daily / weekly / monthly counters; deleted with the account.
Billing & tax recordsUp to 8 years after the transaction, as required by Indian tax and accounting law. Retained in a minimised form — the transaction, not your content.
Audit logAction names with a hashed user reference; the readable link to you is removed when you delete your account.
Aggregated / anonymised analyticsUp to 12 months. Contains no personal identifiers and cannot be traced back to you.
Crash reportsUp to 90 days.

14. Who else touches your data

We use a small number of processors, each for one job:

WhoWhat forWhat they get
Supabase (Mumbai region)Sign-in and databaseYour account record and app data
Google (Gemini API)The AI that produces your resultOnly the text of the action you invoked
Google (Play, Sign-In, Workspace APIs)Distribution, sign-in, and the Gmail/Calendar features you connectPurchase tokens; your Google identity; scoped calendar/mail access
Cashfree PaymentsSubscription payments in IndiaName, email, payment instrument (held by them, not us)
Our hosting provider (Indian region)Running the API serverEncrypted data in transit and at rest
Notion / Zoom / SlackOnly if you connect themOnly the action you asked for

Beyond these, we disclose personal data only when compelled by valid Indian legal process, or to protect the rights and safety of users. We will tell you when we are legally permitted to.

If Kriya is ever acquired or merged, your data may transfer to the new owner — bound by this same policy, and you will be notified in advance with the chance to delete your account first.

15. Your rights under the DPDP Act

Right to access

See a summary of what we hold about you, and who we shared it with.

How: Profile → Privacy & data → Download my data. You get the whole thing as one JSON file, immediately.

Right to correction & erasure

Fix anything wrong; delete anything you no longer want kept.

How: edit your profile in the app; delete a single action from its detail page; or delete everything (§16).

Right to withdraw consent

Disconnect any app, turn off any feature, or delete your account. Withdrawing is as easy as consenting.

Right to grievance redressal

Complain directly to us first — see §19. We respond within 30 days.

Right to nominate

Nominate someone to exercise your rights in the event of death or incapacity. Email us and we will record it.

Right to complain to the Board

If we do not resolve it, you may escalate to the Data Protection Board of India.

Your duties as a Data Principal, per the Act: give authentic information, don't impersonate someone else, and don't file frivolous complaints.

16. Deleting your account

You can delete your Kriya account and all associated data yourself, from inside the app, in under a minute — no email, no waiting for us to act. Every step, everything that gets deleted, everything that is legally retained, and the alternative route if you can't open the app are set out on a dedicated page:

How to delete your account & data →

17. Children

Kriya is not directed at children. Under the DPDP Act, processing the personal data of a child (under 18) requires verifiable parental consent, and we do not have a mechanism for that — so we do not knowingly create accounts for anyone under 18, and we do not track, profile or serve targeted advertising to children in any case. If you believe a child has created an account, email us and we will delete it promptly.

18. This website

This site is static and hosted on GitHub Pages. It sets no cookies, runs no analytics, and has no trackers or third-party scripts. GitHub may log standard server information (such as IP address) when serving the page — see GitHub's privacy statement.

19. Changes to this policy

When we change how we handle data, we update this page and move the "Last updated" date at the top. For any change that materially affects your rights or expands what we collect, we will give notice inside the app before it takes effect and, where the law requires it, ask for fresh consent. Older versions are visible in this site's public GitHub history.

20. Contact & grievance officer

For any privacy question, data request, correction, or complaint, contact the Grievance Officer directly. This is a one-person company, so it reaches the developer himself.

If you are not satisfied with our response, you may escalate to the Data Protection Board of India under the Digital Personal Data Protection Act, 2023.