Effective Date: 20-08-2026
Kyven ("Kyven", "we", "us", "our") is committed to protecting the privacy of every person ("you", "User") who uses our reminder and personal-assistant application, including any associated website, mobile application, and connected services (collectively, the "Service"). This Privacy Policy explains what personal data we collect, why we collect it, how we use it, and the rights available to you under applicable law, including the Digital Personal Data Protection Act, 2023 ("DPDP Act"), the Information Technology Act, 2000 and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 ("SPDI Rules"), the General Data Protection Regulation ("GDPR"), and the California Consumer Privacy Act ("CCPA").
By using the Service, you agree to the collection and use of information in accordance with this Policy.
1. Information We Collect
We collect only the personal data reasonably necessary to operate the Service.
1.1 Information You Provide
- Conversations and voice recordings you share with Kyven for the purpose of setting reminders, tasks, or queries.
- Personal details, such as your name and stated preferences (optional).
- Reminders and task content, including any personal information embedded in it.
- Connected service data, where you elect to link Gmail or other third-party accounts — limited strictly to the access scope you authorise.
1.2 Information Collected Automatically
- Usage data, to diagnose and improve Service performance.
- Device information, such as device model and operating system version.
- Location data, collected only where you have separately and affirmatively enabled location-based features, and used solely for that stated purpose.
We do not collect Sensitive Personal Data (as defined under the SPDI Rules) or Sensitive Personal Data (as defined under the DPDP Act and its rules) unless you voluntarily provide it within a reminder or note, in which case Sections 4 and 5 below apply with equal force.
2. How We Use Your Information
We use personal data strictly for the following purposes, and no other:
- To provide, operate, and maintain the Service;
- To generate reminders, task predictions, and personalised suggestions ("Automated Processing" — see Section 3);
- To respond to support requests;
- To detect, prevent, and investigate fraud, abuse, or security incidents;
- To comply with a legal obligation under Section 6.
We do not use your personal data for any purpose incompatible with the purpose for which it was collected, in accordance with the purpose-limitation principle under Section 5 of the DPDP Act.
3. Automated Processing and AI Features
3.1 Third-party processor
To provide predictive reminders and conversational features, your conversation data is processed using Microsoft Azure OpenAI Service, acting as our data processor. Microsoft does not use your data to train or improve its underlying models, and processes it solely to return the output you requested.
3.2 Nature of processing — important clarification
Because this Automated Processing requires your conversation content to be readable by our systems and by Azure OpenAI Service at the point of processing, your conversations are not end-to-end encrypted. They are encrypted in transit and at rest (Section 7), and access is restricted to the systems necessary to deliver the Service, but Kyven and its processor are technically capable of accessing conversation content for the limited purpose of providing the Service and complying with law. If you require a mode of use where no party other than you can access your content, do not use the AI-assisted reminder and prediction features.
3.3 Profiling disclosure
"Learning your patterns for better predictions" constitutes automated decision-making based on your usage history. This is used only to improve reminder relevance and timing. It does not produce any legal or similarly significant effect concerning you, and you may disable predictive personalisation in Settings at any time.
4. Data Retention
- Active accounts: Personal data is retained for as long as your account remains active and is reasonably necessary for the purposes in Section 2.
- Deleted accounts: Upon account deletion, we permanently erase your personal data within 30 days, save where retention is independently required by law (e.g., under the Prevention of Money Laundering Act, tax law, or in connection with a pending legal proceeding), in which case retention is limited to the minimum period and purpose required.
5. Disclosure of Information
We do not sell or trade your personal data. We disclose personal data only in the following circumstances:
- At your direction — where you connect a third-party service (e.g., Gmail), limited to the scope you authorise, and revocable at any time.
- To processors — trusted service providers (including Microsoft Azure) engaged strictly under written data processing agreements imposing confidentiality, purpose-limitation, and security obligations no less protective than this Policy.
- Where compelled by law — only pursuant to a valid court order, statutory summons, or a lawful request from an authority empowered under Indian law (e.g., Section 91 CrPC/BNSS, or a request under the IT Act) to compel such disclosure. We will, where legally permitted, notify the affected User before disclosure.
6. Cross-Border Data Transfer
Your data may be processed on servers located outside India. Such transfers are made in accordance with Section 16 of the DPDP Act (which permits transfer to countries other than those restricted by Central Government notification) and, for EU Users, pursuant to the European Commission's Standard Contractual Clauses or an equivalent adequacy mechanism under the GDPR.
7. Security
- In transit: TLS 1.3 encryption for all data transmitted between your device and our servers.
- At rest: Industry-standard encryption for all stored personal data.
- Access control: Access to personal data is restricted on a need-to-know basis to personnel and processors bound by confidentiality obligations.
No system is completely secure. In the event of a personal data breach likely to cause harm, we will notify the Data Protection Board of India and affected Users without undue delay, in accordance with Section 8(6) of the DPDP Act, and will notify EU Users within 72 hours where the GDPR applies.
8. Children's Privacy
Under the DPDP Act, any individual under the age of 18 years is a "child," and processing a child's personal data requires verifiable consent of a parent or lawful guardian. Kyven does not knowingly permit use of the Service by anyone under 18 without such verified parental consent, and we do not knowingly undertake tracking, behavioural monitoring, or targeted advertising directed at children. If we become aware that a child's data has been collected without verified parental consent, we will delete it without delay. Parents or guardians who believe their child has provided personal data to Kyven may contact our Grievance Officer (Section 11) for immediate deletion.
9. Your Rights
Subject to applicable law, you have the right to:
- Access — obtain a copy of the personal data we hold about you;
- Correction — correct inaccurate or misleading personal data;
- Erasure — request deletion of your personal data, except where retention is legally required;
- Withdraw consent — withdraw consent for any processing at any time, without affecting the lawfulness of processing before withdrawal;
- Grievance redressal — lodge a complaint with our Grievance Officer, and thereafter with the Data Protection Board of India (DPDP Act) or, for EU Users, your local supervisory authority (GDPR); for California residents, the rights to know, delete, correct, and opt out of sale/sharing under the CCPA, which we honour notwithstanding that we do not sell personal data.
Requests may be exercised through Settings or by writing to us at the addresses in Section 12.
10. Changes to This Policy
We may revise this Policy from time to time. Material changes will be notified to you through the app or by email at least 15 days before taking effect. The "Effective Date" above reflects the date of the last revision.
11. Grievance Officer
In accordance with the IT Rules and the DPDP Act, the following Grievance Officer is designated to address your concerns:
- Name: Manish Kumar Tailor
- Designation: Grievance Officer, Kyven
- Email: privacy@hellokyven.com
- Response timeline: Acknowledgement within 24 hours; resolution within 15 days.
12. Contact Us
- General privacy queries: privacy@hellokyven.com
- Support: support@hellokyven.com
- Data Protection Officer: dpo@hellokyven.com
Governing Law
This Policy is governed by the laws of India. Any dispute arising in connection with this Policy shall be subject to the exclusive jurisdiction of the courts at Jaipur.