Legal
Privacy Policy
How Kartik Bhat, trading as Unviewable handles your data when you use Unviewable.
1. Who we are
Kartik Bhat, trading as Unviewable (Sole Proprietorship), Sector 34, Noida, Uttar Pradesh, India, is the data controller. Contact us at join.invisibleai@gmail.com.
2. What we collect
Account data
Your email address and authentication credentials, handled by Supabase Auth. If you sign in with Google, we receive your email address and basic profile information from Google. We never see your Google password.
Payment data
Razorpay processes your payment and we never receive or store your card number, CVV, UPI PIN, or bank credentials. We store the Razorpay order and payment identifiers, the amount, the tax component, the status, the IP address recorded at the time of purchase, and your browser user agent — the records we need for accounting, support, and dispute handling.
Device and session data
When you sign the desktop app into your account we store a random device identifier it generates, session timestamps, the IP address at sign-in, and the user agent. Sign-in tokens are stored only as SHA-256 hashes, so a person reading our database cannot use them to sign in as you.
Your AI provider key
If you add a Groq API key, we encrypt it with AES-256-GCM before storing it. The encryption key is held in our server environment and never in the database, so database access alone does not reveal your key. We display only its last four characters. We never return the key to any client and never log it.
Usage data
We record which AI endpoint you called, the model, token counts, response latency, and status codes, so we can operate the service and enforce limits. The desktop app also reports coarse events such as sign-in, sign-out, launch, quit, and errors. We record downloads — the build, when, the IP address, and the user agent — to detect licence sharing.
What we do NOT store
We do not store your meeting audio, transcripts, screenshots, or AI conversations. When you use an AI feature, the audio or image is relayed through our server to Groq and discarded once the response is returned. Transcripts exist only in the memory of the application on your own machine.
3. Why we process it
- To provide your account, licence, and downloads (contract).
- To take payment and meet tax and accounting obligations (legal).
- To secure the service, prevent fraud, and detect licence sharing (legitimate interests).
- To provide support when you contact us (contract).
4. Who we share it with
We use these processors, and no others:
- Supabase — authentication, database, and private file storage for installers.
- Vercel — application hosting and request logs.
- Razorpay — payment processing. Governed by their own privacy policy.
- Groq — AI inference. Your prompts, audio, and images are sent to Groq to generate responses, under your own API key and their terms.
- Google — only if you choose Google sign-in.
We do not sell your data, and we do not share it for advertising. We may disclose data where legally required.
5. International transfers
Our processors may store or process data outside India, including in the United States and the European Union. We rely on their contractual data protection commitments for those transfers.
6. How long we keep it
- Account, licence, and payment records: while your account is open, and afterwards for as long as tax and accounting law requires.
- Sign-in sessions: until they expire or are revoked.
- Usage, activity, and download logs: up to 24 months.
- Your Groq key: until you remove it, or you delete your account.
7. Your choices
You can remove your Groq API key at any time from your account page, and sign out every device from there too. To request a copy of your data, a correction, or deletion of your account, email join.invisibleai@gmail.com; we respond within 3 working days.
Deleting your account removes your profile, sessions, stored key, and activity. We retain the minimum payment records that tax law requires, and deletion ends your licence and download access.
8. Security
Secrets live in server-side environment variables, never in client code. Your AI key is encrypted at rest. Sign-in tokens are stored as hashes only. Installers sit in a private bucket and are served through short-lived links tied to your entitlement. Logging is filtered to strip credentials before anything is written. No system is perfectly secure, and we will notify you and the relevant authority of a breach affecting you as required by law.
9. Children
Unviewable is not intended for anyone under 18, and we do not knowingly collect their data. Contact us if you believe a child has provided us data and we will delete it.
10. Cookies
We set cookies that are strictly necessary to keep you signed in and to remember your theme preference. We do not use advertising or third-party analytics cookies.
11. Changes
We will update this page when our practices change and revise the “Last updated” date. Material changes affecting your rights will be notified by email.
Last updated: 17 August 2026