Privacy Policy
Chidakashi Kavach
Last updated: 6 October 2026
This Privacy Policy explains how RN Chidakashi Technologies Pvt. Ltd. ("Chidakashi", "we", "us") collects, uses, shares and protects information when you use Chidakashi Kavach: the website at safety.chidakashi.ai, the dashboard, the API at api.safety.chidakashi.ai and the Kavach SDKs (together, the "Service").
Kavach is a content safety service for businesses. You write safety rules ("policy sets"), and the Service checks text and images that you send against them and returns a verdict. This Privacy Policy covers two kinds of information:
- Account information: information about you and your organization, which we use to run your account.
- Customer content: the policy sets, text and images you or your applications send to the Service. We process it on your behalf, to provide the Service to you.
By creating an account or using the Service, you agree to this Privacy Policy and to our Terms of Service.
1. Information we collect
Information you give us
- Account details: your name, email address and password, or your Google account details if you sign in with Google, and the name of your organization and your role in it.
- Billing details: your organization's billing name, address and tax details, and the purchases you make. Card and payment details are entered directly with our payment processor; we don't receive or store full card numbers.
- Messages: what you send us when you contact us for support or otherwise.
Customer content
- Policy sets: the rules you write, and the versions of them we prepare for checking.
- Content you check: the text and images you, your applications or your users send to the Service for checking, and the verdicts and reasons we return.
Information collected automatically
- Usage information: the checks you run (their number, type, verdict, and the amount of processing each used), the policy sets and API keys you create or delete, and the actions you take in the dashboard.
- Technical information: IP addresses, browser and device type, request times, and the pages and API routes requested, which our servers record in logs.
- Cookies: see section 7.
We don't knowingly collect sensitive personal data, such as health, financial or biometric information, as account information. Customer content may contain any kind of information, depending on what you choose to send us (see section 4).
2. How we use information
We use information to:
- Provide the Service: run checks and return verdicts, keep your policy sets, and authenticate you and your API keys.
- Bill for the Service: keep your organization's credit balance, process purchases and refunds, and keep records required by law.
- Keep the Service working and secure: monitor its performance, find and fix errors, prevent abuse and fraud, and enforce rate limits and our Terms of Service.
- Improve the Service: understand how it's used, and check and improve the quality of verdicts.
- Communicate with you: about your account, billing, changes to the Service or these policies, and your support requests.
- Meet legal obligations: comply with applicable law, and respond to lawful requests from authorities.
We don't sell personal information, and we don't use customer content for advertising.
3. How we handle customer content
- Content you send for checking is processed by our models to produce a verdict. We don't keep the content of checks in our main database: we keep only counts and usage figures about them.
- For monitoring and quality, records of the model calls made for text checks, including the text checked, may be kept by our observability provider (see section 5) for a limited time. Images are not kept in these records.
- Policy sets are kept until you delete them, or until your project or organization is deleted.
- We use customer content only to provide, secure and improve the Service for you. We don't share it with other customers, and we don't use it to train models for anyone else.
4. Your responsibilities for customer content
You decide what content to send to the Service. If it includes personal data about other people, such as your own users, you're responsible for having a lawful basis to send it to us and for giving them any notice the law requires. We process that content on your behalf and under your instructions, as set out in our Terms of Service.
5. How we share information
We share information only as needed to run the Service, with:
- Service providers who process it for us, under contracts that require them to protect it:
- Google Cloud: hosting, databases and AI models (including Vertex AI, which processes policy sets when they're saved)
- PropelAuth: sign-up, sign-in and account management
- Chargebee and its payment processors: billing, payments and invoices
- PostHog: product analytics, logs and monitoring of model calls
- Within our group of companies, for the purposes in this Privacy Policy.
- Authorities and others, when the law requires it, or to protect the rights, property or safety of Chidakashi, our customers or others.
- A buyer or successor, if our business is merged, acquired or sold, subject to this Privacy Policy.
6. International transfers
We're based in India, and the Service is hosted on Google Cloud in the United States. Our service providers may process information in other countries too. Wherever information is processed, we take steps to protect it as described in this Privacy Policy and as required by applicable law.
7. Cookies
The website uses cookies and similar technologies:
- Essential cookies, to keep you signed in and secure your session. The Service doesn't work without them.
- Analytics cookies (PostHog), to understand how the website and dashboard are used, such as which pages are viewed.
You can block or delete cookies in your browser's settings. If you block essential cookies, you won't be able to sign in.
8. Data retention
We keep information only as long as needed for the purposes in this Privacy Policy:
- Account and organization information: for as long as the account exists, and for a reasonable time afterwards to handle any remaining questions or disputes.
- Policy sets and API keys: until you delete them, or your project or organization is deleted.
- Usage counts: for as long as the organization exists, so the dashboard can show history.
- Billing records: as long as tax and accounting law requires.
- Logs and monitoring records: for a limited time, generally no more than 90 days.
When information is no longer needed, we delete it or make it anonymous.
9. Security
We protect information with measures that include encryption in transit (HTTPS) and of database connections, access controls, storing only a hash of each API key, and limiting access to staff and providers who need it. No system is perfectly secure, though, so we can't guarantee absolute security. Keep your password and API keys safe: anyone who has an API key can use the Service as your project.
10. Your rights
Depending on where you are, you may have the right to:
- access the personal information we hold about you, and get a copy of it
- correct information that's inaccurate or incomplete
- have your information deleted
- withdraw your consent, where we rely on it
- object to or restrict some processing
- nominate someone to exercise your rights if you're unable to
To use these rights, contact us (section 13). Many details can also be changed in your account settings. We may need to verify your identity first, and some information may have to be kept when the law requires it. For customer content that includes your users' information, we'll refer requests from them to you, as the customer who sent it.
11. Children
The Service is for businesses and their staff. It's not directed at children, and you must be at least 18 to create an account. We don't knowingly collect personal information from children as account holders.
12. Changes to this Privacy Policy
We may update this Privacy Policy from time to time. If we make significant changes, we'll tell you by email or in the dashboard before they take effect. The date at the top shows when it was last updated. Continuing to use the Service after a change means you accept the updated policy.
13. Contact and grievances
For questions about this Privacy Policy, to use your rights, or to raise a concern, contact:
RN Chidakashi Technologies Pvt. Ltd.
Flat No. 4, Plot No. 82, Stambhtirth, Rafi Ahmed Kidwai Marg, Wadala (West), Mumbai 400031, India
Email: legal@miko.ai
Grievance Officer: [Name], legal@miko.ai
We'll acknowledge grievances within 24 hours and aim to resolve them within 15 days, as required by Indian law.