Privacy Policy
This Privacy Policy explains how [Legal entity name], doing business as Karya ("Karya," "we," "us," or "our"), collects, uses and shares information when you use the Karya platform, our website and related services (together, the "Service"). By using the Service you accept the practices described here. If your organization has signed a separate written agreement with us, such as a master services agreement or a data processing agreement, that agreement takes priority wherever it conflicts with this Policy.
Karya is a business-to-business service built for software teams. It is not intended for anyone under 16 years of age.
"Personal Data" means information that identifies an individual or can reasonably be linked to one.
1. Information we collect
Account information
When you create an account we collect the details you give us, including your name, work email address and company. If you sign in through a third-party provider such as GitHub, we receive the profile information and access tokens from that provider that we need to run the Service.
Demo requests and correspondence
When you book a demo or contact us, we collect what you submit, such as your name, email address, company, number of engineers and how you heard about us.
Customer Content
"Customer Content" has the meaning given in our Terms of Service. It includes the repositories, source code, configuration, telemetry, fixtures and test definitions you connect or submit to the Service, and the results of verification runs on your software.
Usage and log data
We automatically record information about how the Service is used, including IP addresses, browser type, device identifiers, pages visited, features used, timestamps and error logs. We use it to operate, secure and improve the Service.
Integration data
If you connect third-party services, such as source control, CI systems, observability and APM tools, coding agents or AI model providers, we collect the credentials and tokens needed to make those connections work. We also receive information from those services as needed to provide the Service, for example repository metadata from your source control provider or traces from your APM tool.
Cookies and similar technologies
We use cookies and similar technologies to keep you signed in, remember preferences and measure usage. We do not use third-party advertising cookies. You can turn cookies off in your browser, but parts of the Service may then stop working properly.
2. How we use information
We use the information we collect to:
- Operate the Service. Scan repositories, build feature maps, provision isolated environments, run tests, return results to your coding agents and CI, and maintain your testing suite.
- Bill for the Service. Meter active test time and credits and process payment.
- Secure the Service. Detect and prevent fraud, abuse and security incidents, and enforce our Terms of Service.
- Provide support. Answer questions, troubleshoot problems and contact you about your account.
- Improve the Service. Analyze usage, diagnose technical issues and develop new features.
- Meet legal obligations. Respond to lawful requests from authorities and comply with applicable law.
3. AI features and model training
Karya is used by coding agents and works with third-party AI providers such as Anthropic, OpenAI and Google.
Karya follows a bring-your-own-tokens model. Your coding agents run on the model provider accounts, API keys or subscriptions you already hold, and your agreement with that provider governs how it handles your data. Where Karya itself calls a third-party AI provider to deliver a feature, for example to draft or update tests, the Customer Content needed for that feature is sent to the provider.
We do not use Customer Content to train generative AI models or machine learning models unless you explicitly opt in.
For more on our model training practices and the obligations of third-party AI providers, see Sections 2(b) and 3 of our Terms of Service.
4. How we share information
We do not sell your personal information. We may share information in these situations:
- Service providers. Vendors that help us run the Service, such as cloud infrastructure, analytics and monitoring providers. They are bound by contract to use the information only to provide services to us.
- AI providers. As described in Section 3, Customer Content is sent to AI providers to deliver AI features.
- Integrations. If you enable an integration, information is shared with that service as needed for the integration to work.
- Legal requirements. We may disclose information where law, regulation or legal process requires it, or where we believe disclosure is needed to protect our rights, your safety or the safety of others.
- Business transfers. If Karya is involved in a merger, acquisition or sale of assets, your information may pass to the successor.
5. Your privacy rights
You may ask us for access to, correction of or deletion of your personal information using the contact details below. We respond to verified requests within 30 days. You can opt out of marketing email through the unsubscribe link in any message we send.
We do not sell or "share" your personal information as those terms are defined in the California Consumer Privacy Act (CCPA).
6. Data security
We use industry-standard measures to protect your information, including:
- Encryption of data in transit and at rest.
- Isolated environments for each verification run, which are torn down when the run ends.
- Access controls that limit employee access to Customer Content to people with a legitimate need.
- Logging and monitoring of access to systems that hold Customer Content.
No system is completely secure. We work to protect your information but cannot guarantee absolute security.
Security incident notification
Our obligations to notify you of a security incident are set out in Section 10(b) of our Terms of Service.
7. Data retention and deletion
We keep personal information and Customer Content for as long as reasonably necessary to provide the Service, comply with legal obligations and resolve disputes. Some information may remain in backups or logs for a limited time after it is deleted from production systems.
You or your authorized representative may ask us to delete personal information and Customer Content using the contact details below. We process deletion requests within approximately 30 days, subject to legal holds and technical constraints such as backup retention cycles. We also respond to verified access and deletion requests as applicable law requires.
8. International data transfers
The Service is designed for users in the United States. We do not market it to residents of the United Kingdom, the European Economic Area or other jurisdictions with data protection laws similar to the GDPR, we do not intentionally collect data from users there, and we have not adopted GDPR-specific data handling practices. If you use the Service from outside the United States, you do so at your own risk and are responsible for complying with your local laws.
9. Sensitive and regulated data
The Service is not designed to process protected health information subject to HIPAA, payment card data subject to PCI-DSS or other highly regulated categories of personal data. You agree not to submit that data to the Service. Test environments should be seeded with synthetic or test data, not production personal data.
10. Children's privacy
The Service is intended for business use by people aged 16 or older. We do not knowingly collect personal information from anyone under 16. If we learn that we have, we will delete it promptly.
11. Changes to this Policy
We may update this Policy from time to time. If we make material changes, we will post the updated Policy on our website and change the "Last updated" date. Continuing to use the Service after the changes take effect means you accept the revised Policy.
12. Contact us
If you have questions about this Policy or want to exercise your rights, contact us at:
[Legal entity name]
[Registered address]
Email: legal@karya.sh