Kavi · Privacy

Privacy Policy

The short version: we collect what we need to run your marketing and nothing else. When you connect a social account, we receive a revocable access token, never your password. Your content, your enquiries and your customer data belong to you, are never sold, are never used to train models for anyone else, and are deleted within 30 days of your request.

Who we are

Kavi is a marketing agent and CRM operated by Panigrahana Weddings ("we", "us"), based in Bengaluru, India. For questions about this policy or your data, write to hello@panigrahana.com.

What we collect

Information you give us. Your name, business name, category, city, email address, phone or WhatsApp number, website and social handles, and anything you tell us about your business during onboarding. If you book a demo, we keep what you submitted on that form.

Information from accounts you connect. When you authorise Kavi to publish on a channel, we receive an access token from that platform along with the identifiers needed to publish, such as your page ID, channel ID, business profile ID or board ID. Depending on the platform and the permissions you grant, we may also read basic profile details and the performance metrics of posts we published, so we can report on results.

Information generated by using Kavi. The content we draft and publish for you, the schedule and status of each piece, the enquiries that arrive through your forms, WhatsApp or connected channels, and the stages those enquiries move through in Dwaar.

Website analytics. Standard server logs and basic page analytics for getkavi.ai. We do not run advertising trackers on this site.

What we never collect

We do not ask for and will never store passwords to your social accounts, your email accounts, or your bank or payment credentials. Every channel connection uses OAuth or a scoped API key that you can revoke at any time without changing a password.

How we use it

We use your information to create and publish marketing content on the channels you authorised, to capture and route enquiries in your CRM, to measure which work produced enquiries and bookings, to send you reports and service messages, and to support and improve the product.

We do not sell your data. We do not share it with other Kavi customers. We do not use one customer's business information, content or enquiries to generate content for another customer.

AI processing

Kavi uses third-party AI model providers to draft content and to analyse marketing performance. Information you mark as internal or sensitive during onboarding is withheld from model prompts. We use providers under terms that prohibit training their public models on our customers' data. Kavi learns from your results within your own account only.

Platform data

Where we access data through a platform's API, we use it only to deliver the features you asked for, and we follow that platform's developer terms. Specifically, data obtained through Google APIs is handled in line with the Google API Services User Data Policy, including its Limited Use requirements. We do not transfer platform data to third parties except the infrastructure providers listed below, and we do not use it for advertising.

Who processes data for us

We rely on a small set of infrastructure providers, each bound by their own data protection terms: hosting and forms (Netlify), database and authentication (Supabase), email delivery and forwarding (Google Workspace, ForwardEmail), and AI model providers used for drafting and analysis. Payment processing, where applicable, is handled by the payment provider directly; we do not store card details.

How long we keep it

We keep your account data for as long as your engagement is active, and for up to 12 months afterwards so you can return without losing your history. Access tokens are deleted as soon as you disconnect a channel or end your engagement. Demo request details are kept for 24 months unless you ask us to remove them sooner.

Your rights

You can ask us for a copy of your data, ask us to correct it, ask us to delete it, or withdraw a permission you granted, at any time. Write to hello@panigrahana.com and we will respond within 30 days. See how to request deletion for the specific steps, including deleting data we obtained from a connected social account.

You can also revoke Kavi's access directly from the platform itself at any time, in the security or connected-apps settings of your Meta, Google, LinkedIn or Pinterest account. Revoking there stops publishing immediately.

Security

Access tokens and API keys are stored encrypted. Every customer's data is isolated at the database level with fail-closed access rules, so one customer's records cannot be read from another customer's session. Staff access is limited to the people who need it to operate the service.

Children

Kavi is a business tool and is not directed at anyone under 18. We do not knowingly collect data from children.

International transfers

We operate from India and use infrastructure providers who may process data in other countries, including the United States and the European Union. Where required, transfers rely on the standard protections offered by those providers.

Changes

If we make a material change to this policy we will update the date at the top and, where the change affects how we handle your data, tell you by email.

Questions about your data?

Write to us and a human replies. We will tell you exactly what we hold and remove it if you ask.

hello@panigrahana.com