Klype AI Privacy Policy
Last updated: 1 June 2025
Introduction
KLYPE AI ("KLYPE AI," "we," "us," or "our") is an AI-powered content curation and generation platform committed to protecting your privacy. This Privacy Policy explains how we collect, use, share, and safeguard your personal information when you use KLYPE AI (the "Service"). It also outlines your rights and choices regarding your information. By using KLYPE AI, you agree to the collection and use of information as described in this policy. If you do not agree, please discontinue the use of the Service.
Compliance with Indian and International Privacy Laws
KLYPE AI complies with India's Digital Personal Data Protection Act (DPDP Act), 2023, IT Rules, 2011, and other applicable Indian laws, as well as global standards such as GDPR (EU) and CCPA (California, USA).
How We Ensure Compliance
- Data Minimization: We only collect the necessary data required to provide and improve our services, ensuring compliance with GDPR's purpose limitation principle and DPDP's data minimization requirement.
- User Consent & Transparency: Users are informed of data collection practices through clear disclosures, with explicit consent obtained where required. Granular consent mechanisms allow users to control data sharing preferences.
- Data Localization: In compliance with RBI and DPDP Act mandates, payment and financial data are stored within Indian servers.
- Security & Encryption: We use AES-256 encryption for stored data, TLS 1.2+ encryption for transit, and conduct regular cybersecurity audits to prevent unauthorized access.
- Data Processing Agreements (DPAs): Third-party integrations (LinkedIn API, OpenAI, Meta) adhere to strict Data Processing Agreements (DPAs) that align with GDPR, DPDP Act, and CCPA.
- User Rights Implementation: Users can access, correct, delete, or withdraw consent regarding their data, in line with GDPR's right to be forgotten and DPDP Act provisions.
- Incident Response & Reporting: We have a structured data breach response policy to notify affected users and relevant authorities in case of security incidents.
- Grievance Redressal Mechanism: Indian users can report concerns via admin@klype.io, and disputes will be handled in accordance with Indian consumer protection and IT laws.
Data Collection & Processing
We collect and process the following types of data:
1. Personal Data Collected
- Account Information: Name, email address, phone number (if provided), and login credentials.
- Content & User Inputs: Any text, files, or prompts submitted for AI-generated content.
- Usage Data: IP address, device details, browser type, and usage analytics.
- Payment Data: If subscribing to paid plans, we collect billing details via third-party payment providers (RBI-compliant).
2. How We Use Your Data
- To provide and maintain the Service.
- To generate AI-based content based on user prompts.
- To improve and personalize your experience.
- To communicate with you regarding updates and support.
- To comply with legal and regulatory obligations.
Third-Party Services & Data Sharing
We do not sell user data. However, we may share data with third-party service providers that assist in operating our platform, with strict security and contractual safeguards in place:
- LinkedIn API: If connected, we fetch profile data (with consent) for content personalization. Data transmission is encrypted, and access is governed by LinkedIn's security policies.
- OpenAI API: AI-generated content is processed via OpenAI, subject to their privacy safeguards. Data sent to OpenAI is encrypted in transit using TLS 1.2+ and is not stored for model training.
- Meta (WhatsApp) API: If opted-in, WhatsApp integration allows AI-generated content delivery. Message data is encrypted via WhatsApp's end-to-end encryption, ensuring privacy.
- Payment Processors: Stripe, Razorpay, or other RBI-compliant payment gateways handle transactions securely. Payment data is encrypted and stored per PCI-DSS standards.
All third-party integrations are bound by Data Processing Agreements (DPAs) to ensure compliance with GDPR, DPDP Act, and other relevant laws. We review these agreements regularly to ensure continued protection of user data.
User Rights & Choices (India-Specific Inclusions)
Under the DPDP Act, 2023, users in India have the right to:
- Access & Portability: Request a copy of their data.
- Correction: Modify inaccurate information.
- Deletion: Request account closure and data deletion (except where legally required).
- Withdraw Consent: Opt out of non-essential data processing.
- Lodge Complaints: Users can escalate privacy concerns via admin@klype.io or appropriate data protection authorities.
Security Measures
We implement strong encryption, access controls, and cybersecurity audits to protect your data. All stored data is encrypted using AES-256 encryption, and data in transit is protected via TLS 1.2+ encryption. We conduct regular penetration testing, security audits, and vulnerability assessments to ensure compliance with industry standards.
Payment data is handled under RBI guidelines and PCI-DSS compliance, ensuring secure transactions. Additionally, our infrastructure is monitored for threats in real-time, and access is strictly limited to authorized personnel through multi-factor authentication (MFA) protocols.
AI Usage Transparency
- AI-generated content may not always be accurate, and users should verify important outputs.
- AI does not store or use user inputs for future training beyond session-based responses.
- Users are responsible for avoiding sensitive data submission in prompts.
Data Retention & Localization
- Account Information: Retained as long as the account remains active. If a user requests deletion, data will be permanently erased within 30 days, except where legally required for tax, fraud prevention, or compliance purposes.
- Payment Records: Retained for 7 years as per financial regulations and RBI data localization requirements. Stored securely within Indian servers.
- AI-Generated Content: Not stored beyond session-based responses. Any temporary logs for debugging are deleted within 24 hours.
- Usage Data: Retained for 12 months to improve service functionality, after which it is anonymized or deleted.
- Legal Retention Requirements: In cases of regulatory obligations, data may be retained for longer durations as required by Indian and international laws.
- User-Requested Deletion: Users can delete their accounts, and all associated data will be removed within 30 days, except for necessary financial or compliance records.
Business Model & Billing Policies
- Free & Paid Plans: KLYPE AI offers both, with monthly billing.
- Refund & Cancellation: Users can cancel subscriptions anytime, and refunds (if applicable) follow our Terms of Service and Cancellation and Refund Policy.
Updates to Privacy Policy
We may update this policy periodically. Users will be notified of significant changes via email, in-app notifications, or a notice on our website before the changes take effect.
Contact Information
For privacy-related inquiries: Email: admin@klype.io
By using KLYPE AI, you acknowledge and consent to this Privacy Policy and our data handling practices.