Privacy Policy

Last updated: September 30, 2026

This Privacy Policy explains how [Legal entity name], doing business as Karya ("Karya," "we," "us," or "our"), collects, uses and shares information when you use the Karya platform, our website and related services (together, the "Service"). By using the Service you accept the practices described here. If your organization has signed a separate written agreement with us, such as a master services agreement or a data processing agreement, that agreement takes priority wherever it conflicts with this Policy.

Karya is a business-to-business service built for software teams. It is not intended for anyone under 16 years of age.

"Personal Data" means information that identifies an individual or can reasonably be linked to one.

1. Information we collect

Account information

When you create an account we collect the details you give us, including your name, work email address and company. If you sign in through a third-party provider such as GitHub, we receive the profile information and access tokens from that provider that we need to run the Service.

Demo requests and correspondence

When you book a demo or contact us, we collect what you submit, such as your name, email address, company, number of engineers and how you heard about us.

Customer Content

"Customer Content" has the meaning given in our Terms of Service. It includes the repositories, source code, configuration, telemetry, fixtures and test definitions you connect or submit to the Service, and the results of verification runs on your software.

Usage and log data

We automatically record information about how the Service is used, including IP addresses, browser type, device identifiers, pages visited, features used, timestamps and error logs. We use it to operate, secure and improve the Service.

Integration data

If you connect third-party services, such as source control, CI systems, observability and APM tools, coding agents or AI model providers, we collect the credentials and tokens needed to make those connections work. We also receive information from those services as needed to provide the Service, for example repository metadata from your source control provider or traces from your APM tool.

Cookies and similar technologies

We use cookies and similar technologies to keep you signed in, remember preferences and measure usage. We do not use third-party advertising cookies. You can turn cookies off in your browser, but parts of the Service may then stop working properly.

2. How we use information

We use the information we collect to:

3. AI features and model training

Karya is used by coding agents and works with third-party AI providers such as Anthropic, OpenAI and Google.

Karya follows a bring-your-own-tokens model. Your coding agents run on the model provider accounts, API keys or subscriptions you already hold, and your agreement with that provider governs how it handles your data. Where Karya itself calls a third-party AI provider to deliver a feature, for example to draft or update tests, the Customer Content needed for that feature is sent to the provider.

We do not use Customer Content to train generative AI models or machine learning models unless you explicitly opt in.

For more on our model training practices and the obligations of third-party AI providers, see Sections 2(b) and 3 of our Terms of Service.

4. How we share information

We do not sell your personal information. We may share information in these situations:

5. Your privacy rights

You may ask us for access to, correction of or deletion of your personal information using the contact details below. We respond to verified requests within 30 days. You can opt out of marketing email through the unsubscribe link in any message we send.

We do not sell or "share" your personal information as those terms are defined in the California Consumer Privacy Act (CCPA).

6. Data security

We use industry-standard measures to protect your information, including:

No system is completely secure. We work to protect your information but cannot guarantee absolute security.

Security incident notification

Our obligations to notify you of a security incident are set out in Section 10(b) of our Terms of Service.

7. Data retention and deletion

We keep personal information and Customer Content for as long as reasonably necessary to provide the Service, comply with legal obligations and resolve disputes. Some information may remain in backups or logs for a limited time after it is deleted from production systems.

You or your authorized representative may ask us to delete personal information and Customer Content using the contact details below. We process deletion requests within approximately 30 days, subject to legal holds and technical constraints such as backup retention cycles. We also respond to verified access and deletion requests as applicable law requires.

8. International data transfers

The Service is designed for users in the United States. We do not market it to residents of the United Kingdom, the European Economic Area or other jurisdictions with data protection laws similar to the GDPR, we do not intentionally collect data from users there, and we have not adopted GDPR-specific data handling practices. If you use the Service from outside the United States, you do so at your own risk and are responsible for complying with your local laws.

9. Sensitive and regulated data

The Service is not designed to process protected health information subject to HIPAA, payment card data subject to PCI-DSS or other highly regulated categories of personal data. You agree not to submit that data to the Service. Test environments should be seeded with synthetic or test data, not production personal data.

10. Children's privacy

The Service is intended for business use by people aged 16 or older. We do not knowingly collect personal information from anyone under 16. If we learn that we have, we will delete it promptly.

11. Changes to this Policy

We may update this Policy from time to time. If we make material changes, we will post the updated Policy on our website and change the "Last updated" date. Continuing to use the Service after the changes take effect means you accept the revised Policy.

12. Contact us

If you have questions about this Policy or want to exercise your rights, contact us at:

[Legal entity name]
[Registered address]
Email: legal@karya.sh