Privacy Policy
Last updated: 10 October 2026
This policy explains what Kritiverse ("we") collects when you use Kritiverse, why, and the choices you have. We follow India's Digital Personal Data Protection Act, 2023 (DPDP Act).
What we collect
- Account details: name, email, password (stored only as a secure hash), profile photo if you add one, and your email preferences.
- Google sign-in: if you sign in with Google, we receive your name, email and profile photo from Google.
- What you create: saved prompts, characters, and images or videos you upload for Image to Prompt or as references. Uploads are used to make your prompt and are not kept longer than needed for that.
- Usage: which features you use, AI action counts against your plan limits, and basic technical data (browser, device type, a hashed form of your IP address) for security and rate limits.
- Payments: handled by Razorpay. We never see or store your full card or UPI details. We keep the payment id, amount, GST and invoice details.
- Messages: what you send through the contact form.
Without an account, your selections, drafts and history stay in your own browser (local storage) and are not sent to us, except when you use an AI feature.
Why we use it
To run the service and your account, process payments and issue invoices, keep plan limits fair, prevent abuse, answer support messages, send service emails (sign-in, receipts, plan changes) and, only if you agree, tips and offers. We do not sell your personal data.
Who processes it for us
- Razorpay: payments and subscriptions.
- Anthropic: AI processing. When you use an AI feature, your idea and choices (and an uploaded image, for Image to Prompt) are sent to Anthropic's Claude API to produce the result. Anthropic does not use this data to train its models.
- Hostinger: website hosting, database and email delivery.
- Google: Sign in with Google, reCAPTCHA (spam protection), Google Analytics (how the site is used) and, when switched on, Google AdSense ads.
Some of these providers may process data outside India, under their own privacy and security commitments.
Cookies
We use a few essential cookies for sign-in and security, and optional analytics and ads cookies. See the Cookie Policy.
How long we keep it
- Account data: while your account is open. When you delete your account, it is removed after a 7 day grace period.
- Invoices and payment records: as long as Indian tax law requires (usually 8 years).
- Security logs, usage records and support messages: only as long as needed for security, billing and support, then deleted.
Your rights
Under the DPDP Act you can:
- Access and export your data: Account, Privacy and data, Download my data.
- Correct your name or email: Account, Profile.
- Delete your account: Account, Privacy and data, Delete my account.
- Withdraw consent for marketing emails at any time with the unsubscribe link or in Account, Notifications.
- Complain: contact us first. You can also approach the Data Protection Board of India.
Children
The service is not meant for children under 18 without a parent's or guardian's permission. We do not knowingly collect children's data.
Security
Passwords are hashed, connections use HTTPS, admin access needs two-step sign-in, and only staff who need it can see account data.
Contact for privacy requests and grievances
Write to the email on our Contact page with the subject "Privacy request". We reply within 7 working days.
Grievance officer: The founder, Kritiverse, email the email on our Contact page. Complaints about how we handle your personal data are acknowledged within 48 hours and resolved within 30 days. Kritiverse