Legal
Privacy Policy
Last updated: 2 September 2026
This Privacy Policy explains how Habilesoft Pvt. Ltd. (“nabh.cloud”, “we”, “us”) collects, uses, and protects your personal data when you use the Service. We process personal data in accordance with the Digital Personal Data Protection Act, 2023 (“DPDP Act”) and other applicable Indian law.
1. Data we collect
- Account data — name, email address, company name (optional), and password (stored only as a secure hash).
- Billing data — wallet balance, transactions, GSTIN (optional), and invoices. Payments are handled by Razorpay; we do not store your full card or bank account numbers.
- API usage metadata — per-request records containing the model used, token counts, cost, latency, status code, and timestamp.
- Technical data — IP address, browser type, and cookies necessary to operate the dashboard.
- Persistent memory (optional, on by default) — if enabled, durable facts our AI extracts from your conversations (e.g. stated preferences or context) so it can use them in later, unrelated chats. This is a distilled set of facts, not a transcript. You can view, delete individual entries, clear them all, or turn this off at any time from Settings → Manage Memories.
2. Usage logs vs. persistent memory
Our usage logs record only metadata (tokens, cost, latency, model, and timestamp) — never the text you send or receive, and never used to train models. Prompt content is transmitted to the upstream model provider purely to generate a response and is not retained in usage logs.
Separately, if Persistent Memory is on (the default), we extract and durably store facts from your conversations to personalize future, unrelated chats — see the “Persistent memory” item above. This storage is distinct from usage logs and is fully under your control: view, delete, or disable it anytime in Settings → Manage Memories.
3. How we use your data
- To provide, operate, meter, and bill the Service.
- To authenticate requests and enforce rate limits and security controls.
- To provide usage analytics and invoices in your dashboard.
- To send service, security, and billing communications.
- To comply with legal obligations and prevent fraud or abuse.
4. Legal basis
We process personal data on the basis of your consent (given when you create an account) and for the legitimate uses permitted under the DPDP Act, including providing a service you have requested and complying with law.
5. Sharing and sub-processors
We share data only with service providers who help us operate the Service:
- OVHcloud — performs model inference. Your prompts are sent here to generate responses. Inference occurs in the European Union (OVHcloud, GRA region).
- Razorpay — processes payments.
- Supabase — database, authentication, and storage infrastructure.
- Email and monitoring providers — transactional email and operational monitoring.
We do not sell your personal data or share it for third-party advertising.
6. International transfer
Because model inference is performed by OVHcloud in the European Union, the contents of your API requests are transferred outside India for processing. We rely on the provider’s contractual and technical safeguards for this transfer.
7. Data retention
Your dashboard defaults to showing the last 7 days (Free), 30 days (Developer), or 365 days (Pro/Enterprise) of usage analytics, but nothing is deleted on that schedule — full usage history is retained and exportable regardless of plan. Account, billing, and invoice records are retained as long as your account is active and thereafter as required for legal, tax, and accounting purposes. Persistent memory entries are kept until you delete them individually, clear them, turn the feature off, or delete your account.
8. Security
We apply industry-standard safeguards, including encryption in transit, SHA-256 hashing of API keys (we never store the raw key), row-level access controls, and the principle of least privilege. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
9. Your rights
Under the DPDP Act, you may:
- Access and obtain a copy of your personal data (your dashboard provides a data export).
- Request correction or completion of inaccurate data.
- Request erasure of your data and account.
- View, delete, or disable stored persistent-memory entries at any time (Settings → Manage Memories).
- Withdraw consent and raise a grievance with our Grievance Officer.
You can export your data, manage stored memories, or delete your account directly from your account settings, or contact us using the details below.
10. Grievance Officer
In accordance with the DPDP Act and the Information Technology Act, 2000, you may contact our Grievance Officer at info@habilesoft.com for any privacy concern or complaint. We will respond within the timelines prescribed by law.
11. Children
The Service is not directed to individuals under 18, and we do not knowingly collect their data.
12. Changes to this policy
We may update this Privacy Policy from time to time. We will update the “Last updated” date and, for material changes, provide reasonable notice.
13. Contact
Habilesoft Pvt. Ltd. — info@habilesoft.com.