Privacy Notice
1. Operator and scope
KRNLA is operated by Britesh Gaire, Nepal. This Notice covers the approval-required free beta and its account, workspace, governance, messaging and support functions. Privacy questions and requests can be sent to privacy@krnla.com. The service is for adults aged 18 or older and has no customer payment collection.
2. Information processed
- Account email, identity-provider identifiers, verified identity information, sessions and access-approval state.
- Workspace membership, roles, invitations, agents, configured connections, policies and policy revisions.
- Agent credential hashes, encrypted provider credentials and encrypted inbox payloads needed for delivery.
- Governance and delivery metadata, structural discovery observations and security/operational records, including request identifiers, times, error classes and infrastructure IP/device information where processed.
- Support correspondence you choose to provide.
Governance processes submitted content. The application telemetry/discovery design excludes message bodies, API keys, matched sensitive text and arbitrary payload values. This does not mean content is never processed: encrypted inbox storage and allowed model-provider requests necessarily handle it. Avoid sending credentials or full sensitive payloads in support mail.
3. Purposes and responsibility
Information is used to provide accounts and workspaces, authenticate and authorize users/agents, enforce configured policies, deliver messages, call selected model providers, operate and secure the beta, respond to support and rights requests, and meet applicable legal duties.
The operator determines account, service-security and support processing. Workspace users determine the content and policies they submit and must have authority for that processing. This Notice does not itself establish a customer data-processing agreement or guarantee that every use of submitted data complies with every jurisdiction. Contact the operator before submitting data subject to special legal requirements.
4. Service providers and locations
- Neon: production PostgreSQL, documented in AWS Singapore, for account/workspace data, policies, encrypted credentials/inbox payloads and metadata.
- Cloudflare: application hosting, Gateway, queues, security infrastructure and encrypted R2 backups. Processing and backup storage are not guaranteed to remain in Singapore.
- WorkOS: authentication and identity services. Account-specific residency has not been verified.
- AWS KMS: configured key operations in Singapore.
- GitHub Actions: encrypted backup jobs; runner location is not guaranteed.
- Zoho Mail: support, privacy and security correspondence; the configured mailbox uses the US data center.
- OpenAI or Google Gemini: the selected provider receives governed input for an allowed call, after required redaction. Provider terms and processing, retention and training practices depend on your provider account and plan.
These services may process information outside Nepal or your country. No universal regional-residency, transfer-compliance or provider no-training guarantee is made. KRNLA does not sell personal information or use the reviewed application for advertising trackers. Disclosures to authorities occur where legally required.
5. Retention
- Inbox payloads: a 24-hour TTL, with earlier clearing after acknowledgement or terminal state where implemented. Expiry cleanup and older encrypted backups can outlast immediate live-message access.
- Ordinary operational detail: 7 days.
- Security detail: 90 days.
- Deduplication receipts: 91 days.
- Aggregate rollups: 90 days.
- Backups: newest 14 complete encrypted daily recovery points.
Account, workspace, membership, policy revision and support records do not yet have an approved fixed deletion deadline. Do not treat the short operational periods as applying to all records. Closure requests are reviewed after verifying identity and workspace authority. Retained security/legal records and older encrypted backups can limit immediate deletion. No self-service closure or fixed deletion deadline is promised. Restored backups must not silently undo valid deletion requests.
6. Security
Controls include TLS, tenant authorization and database isolation, credential hashing, protected provider-secret storage, encrypted inbox/backup content and restricted infrastructure access. Agents do not receive stored provider keys. No service is completely secure; report suspected compromise to security@krnla.com without sending secrets.
7. Cookies and choices
KRNLA uses essential sign-in and security cookies. Its reviewed source does not install Google Analytics, Microsoft Clarity or advertising trackers. See the Cookie Notice. Authentication providers may also use their own cookies. Provider-controlled cookie practices can change.
Depending on applicable law, you may have rights to access, correct, export, delete, restrict or object to processing. Contact privacy@krnla.com. Identity and authority will be verified, and requests assessed under applicable law. No universal response deadline or immediate deletion promise is made. Stopping use or clearing cookies does not delete server-side records.
8. Children, changes and contact
The beta is not intended for anyone under 18. Contact the privacy address if you believe an underage user has submitted personal information. Material changes will be communicated where required.
Support: support@krnla.com. Privacy: privacy@krnla.com. Security: security@krnla.com. These addresses reach the individual operator, not separate teams.