Sutraya

Privacy Policy

Last updated 28 July 2026

What we collect, why we collect it, who else sees it, and how to get a copy or have it erased.

Controller

The data controller is [legal entity name], [registered address]. Privacy questions: [privacy@yourdomain].

What we collect

  • Account — name, email address, hashed password, sign-up date. Lawful basis: performance of a contract.
  • Your content — saved items, reading history, translations and drafts, Ask conversations, OCR uploads. Contract.
  • AI usage records — which feature you used, when, which model, and token counts. We do not store the text of your prompts in these records. Lawful basis: legitimate interest in enforcing usage limits and understanding cost.
  • Anonymous usage — for signed-out visitors we store a salted hash of your IP address plus a random cookie value, solely to apply the free-tier limit. It is not linked to an identity.
  • Billing — handled by Stripe. We store a customer reference and subscription status; we never see your card number. Contract and legal obligation.
  • Server logs — IP address, request path, timestamp, retained briefly for security and debugging. Legitimate interest.

What we do not do

We do not sell your data, we do not serve advertising, and we do not use your reading history or conversations to build advertising profiles. We do not train models on your content.

Sub-processors

Providers who process data on our behalf, each under a data-processing agreement:

  • Hetzner Online GmbH (Germany) — hosting and database storage
  • Stripe — payment processing and subscription billing
  • Brevo — transactional email (verification, password reset, billing notices)
  • [your model providers, e.g. OpenAI, Anthropic] — process the text you send to Ask, Translate, and OCR
  • Dharmamitra — OCR, when you use that provider

Some providers are outside the EEA. Transfers rely on Standard Contractual Clauses or an adequacy decision.

AI features specifically

When you use Ask, Translate, or OCR, the text you submit — along with relevant passages from the corpus — is sent to a model provider to generate a response. Providers may retain it briefly for abuse monitoring under their own terms. Do not paste anything into these features that you would not want processed by a third party.

How long we keep things

Account data and your content: until you delete them or close your account. AI usage records: 24 months. Server logs: 30 days. Billing records: as long as tax law requires, typically 7–10 years.

Your rights

You can access, correct, export, erase, restrict, or object to processing of your data, and lodge a complaint with your supervisory authority.

Two of these are self-service from your account page: Download a copy gives you everything as JSON, and Delete this account erases it. For anything else, write to us and we will respond within 30 days.

Cookies

We use a session cookie to keep you signed in, and — for signed-out visitors only — a random identifier used with your IP address to apply the free usage limit. Both are strictly necessary, so no consent banner is required. We do not use advertising or analytics cookies.

Security

Traffic is encrypted in transit. Passwords are hashed. Database access is restricted to the application. Backups are encrypted and stored separately. No system is perfectly secure; if a breach affects your data we will notify you and the relevant authority as the law requires.

Changes

We will post material changes here and, where they affect you meaningfully, notify you by email.