Legal

Privacy Policy

KROVA reads the conversations a business already has with its own customers and turns them into business intelligence. This policy explains exactly what we access, why, who processes it, and how to get it deleted.

Last updated 8 August 2026

Who we are

KROVA is operated by Aqirox Technology Private Limited ("KROVA", "we", "us"), registered in India. We provide a multi-tenant business intelligence platform to small and medium businesses ("Customers").

This policy covers the KROVA web application, mobile web app, and backend services operating at krova.space and app.krova.space.

Two kinds of people in this policy

Keeping these separate matters, because our obligations differ for each.

  • Customers — the business owners and team members who hold a KROVA account. We are the data controller for their account data.
  • End Customers — the people who message our Customers on WhatsApp, Instagram, or email. We process their data only as a data processor acting on our Customer’s instructions. We never contact End Customers on our own behalf, and we never sell or share their data.

What we collect

Account data. Name, email address, phone number, business name, business category, and team member roles. Authentication is handled by Supabase; we do not store passwords.

Connected channel data. When a Customer connects a channel, we access the conversations on that channel:

  • WhatsApp Business Platform — message content, sender and recipient phone numbers, timestamps, message status, and WhatsApp Business Account metadata including phone number registration status, quality rating, messaging limits, and message templates. Accessed under the whatsapp_business_messaging and whatsapp_business_management permissions the Customer authorises when connecting their own WhatsApp Business account.
  • Instagram — direct messages, comments, and mentions on the Customer’s connected Instagram Business account.
  • Gmail and Outlook — the content, sender, recipient, subject, and timestamp of business email in the connected mailbox. Messages our classifier identifies as newsletters, notifications, or other non-business mail are discarded and not stored.

Derived intelligence. From the above we generate and store structured records: customer profiles and status, relationship health and churn indicators, commitments and their due dates, revenue signals, competitor mentions, and suggested follow-up messages.

Technical data. IP address, browser and device type, and application logs, used for security, debugging, and abuse prevention.

What we do with it

  • Provide the service — surfacing which customers need attention, what was promised, and what revenue is at risk.
  • Generate analysis on a scheduled nightly cycle and on demand.
  • Draft suggested replies for the Customer to review. Messages are sent only when the Customer approves them, or under automation rules the Customer has explicitly configured.
  • Send the Customer operational notifications, such as their morning briefing.
  • Maintain security, prevent abuse, and meet legal obligations.

We do not sell personal data. We do not use conversation content for advertising, and we do not use one Customer’s conversation content to serve another Customer. Where we publish comparative benchmarks, they are derived from aggregated, anonymised statistics that cannot be traced to an individual business or person.

AI processing

KROVA uses large language models supplied by Anthropic to analyse conversations and generate intelligence. Conversation content is transmitted to Anthropic’s API for processing and returned as structured output.

Anthropic acts as a subprocessor under contract and does not use data submitted through its API to train its models. We do not train any model on Customer or End Customer data.

Who else processes your data

  • Anthropic — AI analysis of conversation content.
  • Supabase — authentication and PostgreSQL database hosting.
  • Railway — backend application and worker hosting.
  • Vercel — web application hosting.
  • Meta Platforms — WhatsApp and Instagram message delivery. Meta bills Customers directly for messaging usage; we take no margin on it.
  • Google and Microsoft — Gmail and Outlook mailbox access, where connected.

Some of these providers process data outside India. Where that happens, transfers are made under the provider’s standard contractual protections.

Google user data — limited use

KROVA’s use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

Specifically: we use Gmail data only to provide user-facing features within KROVA; we do not transfer it except as necessary to provide those features, for security purposes, or to comply with law; we do not use it for advertising; and no human reads it except with the Customer’s explicit permission, for security purposes, or where required by law.

How we protect it

  • OAuth tokens and third-party API keys are encrypted at rest using Fernet symmetric encryption.
  • Every database record is scoped to a business identifier, and every query is filtered by it at the database layer, so one Customer's data cannot be returned to another.
  • All traffic is served over TLS.
  • Access within a Customer's account follows their configured roles — team members see only what their role permits.

How long we keep it

Conversation and intelligence data is retained for as long as the Customer’s account is active. When an account is closed, data is deleted within 30 days, except where we are required to retain records to meet a legal or tax obligation.

Disconnecting a channel stops further collection from that channel immediately. Data already collected is removed on request, or with the account.

Your rights

Under India’s Digital Personal Data Protection Act, 2023, and equivalent laws where they apply, you may request access to your personal data, correction of inaccurate data, erasure, and withdrawal of consent. You may also raise a grievance with our Grievance Officer, named below.

To exercise any of these, see Data Deletion or write to the address below. We respond within 30 days.

If you are an End Customer and want your data removed, contact the business you were messaging — they control that data, and we act on their instruction. You may also write to us and we will route your request to them.

Children

KROVA is a business tool and is not directed at anyone under 18. We do not knowingly collect data from children.

Changes

We will post any change to this policy on this page and update the date above. Material changes will be notified to Customers by email before they take effect.

Contact

Aqirox Technology Private Limited
Shivje Nagar, Muhisudharpur, Shivpurinewcolony
Gorakhpur Sadar, Gorakhpur- 273016
Uttar Pradesh, India
Email: privacy@aqirox.com
Grievance Officer: Nikhil Srivastava — privacy@aqirox.com