Skip to content
kaniyan.ai

Legal

Privacy

Two different things are described here, and the difference matters: this website, and the platform we operate for institutions. The website collects almost nothing. The platform processes what a customer instructs it to, under that customer's control.

Effective
27 August 2026
Version
1.0

Draft pending legal review. This document describes our actual practice accurately, but it has not yet been reviewed by counsel and is not a final contractual instrument. It will be replaced with a reviewed version before we take on any customer data.

1 · This website

This site has no login, no accounts, no advertising, no analytics pixels, and no third-party trackers. Fonts are served from our own origin, not from a font CDN, so loading a page contacts no other company.

We process only:

  • Request logs. Our load balancer records the request path, timestamp, response code, user-agent and truncated IP address. These exist for security and reliability and are retained for 30 days.
  • A theme cookie. If you switch between light and dark, we store your choice in a cookie named kaniyan_theme. It contains the single word light or dark, expires after one year, and is not used for anything else. It is a preference, not an identifier, and it is the only cookie this site sets.
  • Email you send us. If you write to hello@kaniyan.ai, we keep the correspondence for as long as needed to answer it and to maintain a record of business contact.

We do not sell or share any of it. We do not build a profile of you. We set no cookie that requires consent, which is why you are not looking at a consent banner.

2 · The platform

When an institution deploys the kaniyan AI Platform, that institution is the controller of the data it processes and we act as its processor, on documented instructions, under a written agreement.

Our standing commitments to those customers:

  • Purpose limitation is enforced, not promised. An agent can only reach data scopes granted to its charter, and a scope without a recorded purpose is removed before the agent runs.
  • We do not train models on customer data. Not our own models, not a vendor’s.
  • Tenant isolation is enforced by the database engine (row-level security with forced policies), not only by application code.
  • Every consequential action is recorded with the identity of the officer who approved it. That record is the customer’s, and they can export it.
  • Sub-processors are named. Today the platform runs on Google Cloud. Model inference runs on Google Cloud Vertex AI; where a model is served through Vertex AI Model Garden by another provider, that provider is named in the customer’s agreement and in the decision record for each run.

3 · Where data lives

The platform’s primary region is asia-south1 (Mumbai, India). Application data, the database and the object store are in that region. Some model endpoints are served from other regions; which model answered and from where is recorded per run, and a customer can restrict the allowed set to in-region models only.

4 · Your rights

For this website, there is very little to exercise a right over — but if you have corresponded with us and want that correspondence deleted, write to hello@kaniyan.ai and we will do it and confirm.

If you believe an institution has made an automated decision about you using our platform, your rights are against that institution as the controller, and they have the record. We will support them in producing it — that is what the platform is for.

5 · Changes

We version this document and show its effective date at the top. Material changes to the platform sections will be notified to customers under their agreement.

6 · Contact

Privacy questions: hello@kaniyan.ai. Security reports: security@kaniyan.ai.