Kavi · Privacy

Privacy Policy

The short version: we collect what we need to run your marketing and nothing else. When you connect a social account, we receive a revocable access token, never your password. Your content, your enquiries and your customer data belong to you, are never sold, are never used to train models for anyone else, and are deleted within 30 days of your request.

Who we are

Kavi is a marketing agent and CRM operated by Panigrahana Weddings ("we", "us"), based in Bengaluru, India. For questions about this policy or your data, write to hello@panigrahana.com.

What we collect

Information you give us. Your name, business name, category, city, email address, phone or WhatsApp number, website and social handles, and anything you tell us about your business during onboarding. If you book a demo, we keep what you submitted on that form.

Information from accounts you connect. When you authorise Kavi to publish on a channel, we receive an access token from that platform along with the identifiers needed to publish, such as your page ID, channel ID, business profile ID or board ID. Depending on the platform and the permissions you grant, we may also read basic profile details and the performance metrics of posts we published, so we can report on results.

Information generated by using Kavi. The content we draft and publish for you, the schedule and status of each piece, the enquiries that arrive through your forms, WhatsApp or connected channels, and the stages those enquiries move through in Dwaar.

Website analytics. Standard server logs and basic page analytics for getkavi.ai. We do not run advertising trackers on this site.

What we never collect

We do not ask for and will never store passwords to your social accounts, your email accounts, or your bank or payment credentials. Every channel connection uses OAuth or a scoped API key that you can revoke at any time without changing a password.

How we use it

We use your information to create and publish marketing content on the channels you authorised, to capture and route enquiries in your CRM, to measure which work produced enquiries and bookings, to send you reports and service messages, and to support and improve the product.

We do not sell your data. We do not share it with other Kavi customers. We do not use one customer's business information, content or enquiries to generate content for another customer.

AI processing

Kavi uses third-party AI model providers to draft content and to analyse marketing performance. Our current provider is Anthropic (Claude). Each customer account runs on its own provider key: an account with no key of its own cannot make model calls at all, rather than falling back onto ours.

To draft your content, the model sees what your marketing is about: your business, your venues, your real events, and the knowledge you gave Kavi. Knowledge you mark internal only can shape strategy but is never quoted in anything published. Where Kavi drafts a reply to a specific enquiry, that enquiry's name, phone number or email address may form part of the prompt today. We are building a boundary that swaps those identifiers for placeholders before any prompt leaves our servers; until this page says it is switched on for your account, assume they are included.

We use providers under terms that prohibit training their public models on our customers' data. Kavi learns from your results within your own account only. Where a lesson is general enough to help other accounts, only the technique travels, never the substance: a rule about which kind of page converts can be shared, while names, prices, quoted content and enquiry records cannot, and that line is enforced by database constraints rather than by a promise.

Platform data

Where we access data through a platform's API, we use it only to deliver the features you asked for, and we follow that platform's developer terms. Specifically, data obtained through Google APIs is handled in line with the Google API Services User Data Policy, including its Limited Use requirements. We do not transfer platform data to third parties except the infrastructure providers listed below, and we do not use it for advertising.

Who processes data for us

We rely on a small set of providers, each bound by their own data protection terms. This is the complete list of who receives data on our behalf, and what they receive:

Publishing to a channel necessarily discloses the content to that platform; that is the purpose of the connection, and you control it by connecting or disconnecting the channel. Payment processing, where applicable, is handled by the payment provider directly; we do not store card details. If we add or change a provider on this list we will update this page.

How long we keep it

We keep your account data for as long as your engagement is active, and for up to 12 months afterwards so you can return without losing your history. Access tokens are destroyed when you disconnect a channel, as soon as no other channel you still have connected needs the same login — disconnecting Instagram will not break your Facebook posting, so the token goes when the last channel using it does. Demo request details are kept for 24 months unless you ask us to remove them sooner.

What deletion does not reach. Four honest limits, because "deleted everywhere" is easy to write and hard to mean.

Everything we control, we delete on request and give you a signed record of. Your Kavi account has a Your data tab where you can see exactly what we hold, export all of it with a checkable fingerprint, read the counters showing what reached an AI model, verify that your history has not been altered, and start a deletion yourself.

Your rights

You can ask us for a copy of your data, ask us to correct it, ask us to delete it, or withdraw a permission you granted, at any time. Write to hello@panigrahana.com and we will respond within 30 days. See how to request deletion for the specific steps, including deleting data we obtained from a connected social account.

You can also revoke Kavi's access directly from the platform itself at any time, in the security or connected-apps settings of your Meta, Google, LinkedIn or Pinterest account. Revoking there stops publishing immediately.

Security

Credentials. Access tokens and API keys are stored encrypted in the database, under a passphrase held outside it, and are decrypted only for the moment a job needs them. Each customer's channel credentials, AI provider key and WhatsApp number are separate; one customer's account cannot use another's. Where a credential is missing, the job stops and waits rather than borrowing someone else's.

Separation between customers. Every read and write is scoped to a single customer account on the server, and row-level security policies in Postgres exist behind that as a second layer, written deny-by-default so a table with no explicit permission grants nothing. We do not claim cryptographic separation: today the guarantee is enforced by access control, not by each customer holding a key we cannot use.

A history that cannot be quietly rewritten. Changes to CRM records are written to an append-only, hash-chained log. Each entry carries the hash of the one before it, so an altered or deleted entry breaks the chain visibly, and the database refuses updates and deletes on it, including from us.

Passwords. We never ask for, receive or store a password for any account of yours. Channels connect through the platform's own authorisation screen or a scoped key you generate. For the few places with no API at all, a person posts from a browser they are already signed into; the tables that track those accounts carry database constraints that reject a password, cookie, session or token being written into them at all.

Our own access. Our engineers and support staff can read customer data in order to operate and support the service, and we would rather state that plainly than imply we cannot. Access is limited to the people who need it. We do not offer end-to-end or zero-knowledge encryption and will not describe Kavi that way.

Being built, and not yet in force. Encryption of each customer's CRM records under a key unique to that customer is built but not switched on; the same applies to the automatic removal of names, phone numbers and email addresses from AI prompts described above, and to independent certification such as SOC 2. We hold no security certification today. When any of these becomes true, this page will say so and you can ask us to demonstrate it.

Children

Kavi is a business tool and is not directed at anyone under 18. We do not knowingly collect data from children.

International transfers

We operate from India and use infrastructure providers who may process data in other countries, including the United States and the European Union. Where required, transfers rely on the standard protections offered by those providers.

Changes

If we make a material change to this policy we will update the date at the top and, where the change affects how we handle your data, tell you by email.

Questions about your data?

Write to us and a human replies. We will tell you exactly what we hold and remove it if you ask.

hello@panigrahana.com