kritify
Draft — pending review. The structure is complete and addresses the obligations we have today; the wording should be confirmed by counsel before being relied on publicly.

Privacy Policy

Effective 2026-06-26. We'll update this date whenever the content meaningfully changes and email anyone with an active account at least 7 days before a material change takes effect.

1. Who we are

kritify ("we", "us") is an AI-assisted website builder operated from India. We help small business owners describe what they want and turn that into a published website. The legal entity behind kritify is [to be confirmed once registered].

Questions about privacy, requests for export or deletion, and complaints can be sent to hello@kritify.one. We respond within 30 days; usually much sooner.

2. What we collect and why

We collect only the data we need to make the platform work for you:

  • Account information — your email address, password hash (we never see your raw password), and, if you sign in with Google, the public profile fields Google shares with us. Used to identify you between visits and to send account-related email.
  • Project content — everything you describe in chat, your captured business outcomes, tone, palette, page list, contact details (phone and WhatsApp), uploaded references, and the generated site content. Used to render and store your project, and to let you resume work between sessions.
  • Billing metadata — your subscription plan, payment status, and the identifiers Razorpay assigns to your customer and subscription. We never see or store full card numbers; those stay with Razorpay (their privacy policy applies to that data).
  • Usage signals — which features you used and broad counts (e.g. number of projects, number of regenerations). We do not track individual clicks or mouse movements.
  • Cookies — one session cookie to keep you logged in and one preference cookie to remember your language.
  • IP address and basic request metadata — kept in short-lived server logs for security investigation and abuse prevention. Older than 30 days is purged.

3. Who we share it with

We share specific pieces of your data with the third-party services that make kritify possible. We don't sell your data to anyone, and we don't share it with advertising networks.

  • Anthropic — we send your project state (chat messages, outcomes, tone, page list) to Claude to generate site copy. Anthropic processes this under their own privacy terms.
  • Unsplash — we send anonymous search queries (e.g. "fresh kitchen food prep") to fetch background photos for your site. We do not send any personal data to Unsplash.
  • Razorpay — we share the subscription and payment metadata required to process payments for paid plans.
  • Google — only if you choose to sign in with Google. We receive your email and basic profile.
  • Google Cloud Platform — our servers and database run on GCP in the [region to be confirmed] region. GCP acts as our infrastructure processor.

4. How long we keep it

Account information stays for as long as your account is active, plus up to 30 days after deletion (for cancellation and billing support), after which it is permanently removed.

Project content stays until you delete the project. Deletion runs through a 7-day grace window during which you can recover the project, after which it is permanently removed (current version is hard-delete; soft-delete-with-grace is in progress).

Server logs and request metadata are purged after 30 days. Billing metadata is retained for 7 years to meet Indian tax-record requirements.

5. Your rights

Depending on where you live, you have the right to access, correct, export, and delete the personal information we hold about you. You can also withdraw consent to processing (we'll close your account in that case) and lodge a complaint with your local data protection authority.

To exercise any of these rights, email hello@kritify.one. We verify your identity using the email address on file and respond within 30 days.

6. Cross-border transfers

We're based in India and our infrastructure runs on Google Cloud Platform. Some of our processors (Anthropic, Razorpay, Unsplash, Google) are headquartered outside India. When your data travels to those countries it's protected by the contractual and security commitments those vendors make to us in their own terms of service.

7. How we keep it safe

Passwords are hashed with bcrypt before being stored. Sensitive integration credentials are encrypted at rest with a dedicated key management system. Access to production data is restricted to the engineering team and is logged for audit. We do not promise that no breach can ever happen — no platform can — but we work to make one unlikely and to detect it quickly if it does.

8. When this policy changes

We'll update the effective date at the top whenever the content changes. For material changes (new processors, new data categories, changed retention) we'll email anyone with an active account at least 7 days before the new version takes effect. For typo fixes and clarifications we'll just update the page.

9. Contact

For anything in this policy — questions, complaints, requests — write to hello@kritify.one. A real person reads it.