LEGAL

Privacy Policy

EFFECTIVE DATE: JANUARY 1, 2026 · LAST UPDATED: MAY 15, 2026

1. INTRODUCTION

At Kami, privacy is not an afterthought — it is our architectural foundation. Kami is engineered as a local-first application: the AI model runs entirely on your device, conversations are stored in your browser's private file system, and no conversation data ever leaves your device during normal operation.

This Privacy Policy ("Policy") explains how Kami ("we," "us," or "our"), developed by Adarsh Dev ("Developer"), handles information when you use our Services at www.mykami.in, including the Kami Progressive Web Application.

This Policy is designed to be transparent and accessible. If you have questions, contact us at adarshjagannath777@gmail.com.

2. OUR FUNDAMENTAL PRIVACY PRINCIPLE

Kami is built on the principle that your AI companion should be private by design, not by policy. Our architecture ensures:

  • No Conversation Data Collection: We do not collect, transmit, store, or have access to your conversations, memories, or any content you input into Kami.
  • No Cloud Storage: Kami does not operate servers that store user data. All conversation data, memories, and preferences reside exclusively in your browser.
  • No AI Server Processing: The AI model runs entirely on your device's GPU via WebGPU. Your conversations are never sent to a remote AI service for processing.
  • No Data Monetization: We do not sell, rent, or share your personal data. We do not show advertisements. We do not build profiles on you.

This is not merely a promise — it is a technical guarantee enforced by Kami's architecture. We cannot access your data because it never reaches our infrastructure.

3. INFORMATION WE COLLECT

3.1 Information You Provide Directly to Us

Waitlist Email: If you submit your email address through our waitlist form on the landing page, we store that email address in a file on our server to notify you when we launch new features. This is entirely optional and separate from using Kami.

Account Information: When you create an account, our authentication provider (Clerk, Inc.) collects your email address and, optionally, your name. This information is stored by Clerk, not by Kami. You can review Clerk's privacy practices at clerk.com/legal/privacy.

3.2 Information Collected by Third-Party Service Providers

Payment Information: When you subscribe to a paid plan, Dodo Payments processes your payment. Dodo Payments collects your payment card details, billing address, and transaction information. Kami never sees or stores your payment card information. Dodo Payments's privacy practices are available at dodopayments.com/privacy.

Optional Voice-to-Text: If you enable cloud-based voice-to-text via Groq, Inc., audio chunks from your device are transmitted to Groq's servers for transcription. This feature is opt-in and can be disabled at any time. No written conversation data is sent to Groq — only audio for the purpose of transcription. Groq's privacy practices are available at groq.com/privacy-policy.

Model Downloads: When you first load Kami or switch AI models, model files are downloaded from Hugging Face CDN servers. This download request does not include any personal or conversation data — it is solely a request for public model files. Hugging Face's privacy practices are available at huggingface.co/privacy.

Font Files: Google Fonts serves typography files to your browser. Google may collect standard HTTP request data (IP address, user agent). You can review Google's privacy practices at policies.google.com/privacy.

3.3 Information Stored Locally on Your Device

The following data is stored exclusively in your browser and never transmitted to Kami or any third party:

  • All conversation messages (your inputs and AI responses)
  • Memories extracted from conversations (core memories, semantic facts, emotional states)
  • Session metadata (titles, dates, durations)
  • Your preferences (name, selected model, UI settings, voice preferences)
  • Local embeddings and vector indices for semantic search
  • Cached AI model files
  • Cached TTS/STT model files

You have complete control over this data. You can view your memory statistics, export all data as a JSON file, or completely wipe your data at any time from the Settings panel. Clearing your browser data for the Kami domain will also delete all locally stored information.

3.4 Automatically Collected Information

Our hosting provider (Vercel, Inc.) may collect standard server logs when you access the Website, including IP address, browser type, referring URL, access timestamp, and pages visited. This is inherent to web hosting and is subject to Vercel's privacy practices at vercel.com/legal/privacy-policy. Kami does not use any analytics, tracking, or telemetry services (no Google Analytics, no Mixpanel, no Sentry, no comparable services).

4. HOW WE USE YOUR INFORMATION

We use the limited information we collect only for essential service operations:

  • Authentication: Your email and Clerk account data are used solely to authenticate you and maintain your account identity;
  • Subscription Management: Your payment data (handled by Dodo Payments) and subscription metadata are used solely to manage your subscription tier and provide paid features;
  • Email Notifications: Waitlist email addresses are used solely for the purpose for which they were collected;
  • Service Improvement: We may analyze aggregated, anonymized usage patterns to improve the Services — this includes only publicly available data such as download counts from Hugging Face.

5. HOW WE SHARE YOUR INFORMATION

We do not sell your personal information under any circumstances. We do not share your personal information except in the following limited circumstances:

  • Service Providers: We share limited information with third-party service providers (Clerk, Dodo Payments, Groq, Hugging Face, Vercel, Google) solely as necessary to provide the Services. Each provider is contractually obligated to protect your data and use it only for the specific service they provide to us.
  • Legal Compliance: We may disclose information if required by law (such as a subpoena, court order, or other valid legal process), or if we believe in good faith that disclosure is necessary to: (a) comply with legal obligations; (b) protect our rights, property, or safety; (c) investigate fraud; or (d) respond to a government request.
  • Business Transfers: If Kami is involved in a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction. We will notify you before your information is transferred and becomes subject to a different privacy policy.

6. YOUR DATA RIGHTS

Depending on your jurisdiction, you may have the following rights regarding your personal information:

6.1 GDPR (European Economic Area and United Kingdom)

If you are a resident of the European Economic Area (EEA) or the United Kingdom, you have the following rights under the General Data Protection Regulation (GDPR) and the UK GDPR:

  • Right of Access: You may request a copy of the personal data we hold about you.
  • Right to Rectification: You may request correction of inaccurate personal data.
  • Right to Erasure: You may request deletion of your personal data ("right to be forgotten").
  • Right to Restriction: You may request restriction of processing of your personal data.
  • Right to Data Portability: You may request a machine-readable copy of your personal data.
  • Right to Object: You may object to processing of your personal data.

Importantly, for the conversation data and memories stored locally on your device, we are not the data controller — you are, because this data never reaches our servers. You can exercise your rights over this data directly through Kami's export, view, and delete features built into the application.

6.2 CCPA/CPRA (California, United States)

If you are a California resident, you have the following rights under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA):

  • Right to Know: You may request information about the categories and specific pieces of personal information we have collected about you, the sources, the purpose of collection, and the categories of third parties with whom we share information.
  • Right to Delete: You may request deletion of personal information we have collected from you.
  • Right to Correct: You may request correction of inaccurate personal information.
  • Right to Opt-Out: We do not sell or share personal information as defined under CCPA. No opt-out is necessary.
  • Non-Discrimination: We will not discriminate against you for exercising any of your CCPA rights.

6.3 DPDP Act (India)

If you are a resident of India, the Digital Personal Data Protection Act, 2023 (DPDP Act) provides you with rights including the right to access, correct, and erase your personal data processed with your consent. Since Kami processes minimal personal data (primarily via Clerk for authentication), and all conversation data remains on your device, most rights can be exercised directly through the application.

6.4 Exercising Your Rights

To exercise any of the above rights regarding data held by Kami (as opposed to data on your device), please contact us at adarshjagannath777@gmail.com. We will respond to your request within the timeframe required by applicable law. We may need to verify your identity before processing your request.

7. DATA RETENTION

Local Data: Conversation data and memories stored locally on your device are retained until you choose to delete them or clear your browser data. Kami does not impose automatic deletion of your local data.

Account Data: Authentication data held by Clerk is retained in accordance with Clerk's data retention policies. You may delete your account at any time through your account settings.

Waitlist Emails: Retained until you unsubscribe or until the waitlist program concludes.

8. DATA SECURITY

We implement appropriate technical and organizational security measures to protect the limited information we handle.

Local Data Security: Your browser's Origin Private File System (OPFS) provides filesystem-level isolation. Kami additionally encrypts sensitive local data using AES-256 encryption at rest within the OPFS environment. However, the security of your local data depends in part on the security of your device and browser. You are responsible for maintaining the security of your device.

Transmission Security: All communications between your browser and our servers (and third-party services) use TLS/HTTPS encryption.

No Perfect Security: No method of electronic storage or transmission is 100% secure. We cannot guarantee absolute security of information.

9. CHILDREN'S PRIVACY

Kami is not intended for use by children under the age of 18. We do not knowingly collect personal information from children under 18. If you are a parent or guardian and believe your child has provided us with personal information, please contact us immediately at adarshjagannath777@gmail.com and we will take steps to delete such information.

We do not knowingly process personal data of children under 13 in the United States (COPPA), under 16 in the EEA (GDPR), or under 18 in India (DPDP Act). If we become aware that we have collected such data without verifiable parental consent, we will take prompt steps to delete it.

10. INTERNATIONAL DATA TRANSFERS

The limited personal data we process (authentication data via Clerk and payment data via Dodo Payments) may be stored and processed in any country where our third-party service providers operate, including the United States, India, and other jurisdictions. By using the Services, you consent to the transfer of this limited information to countries outside your country of residence, which may have data protection rules different from those of your country.

For users in the EEA, UK, or Switzerland, when personal data is transferred to a jurisdiction without an adequacy decision, we rely on appropriate safeguards such as standard contractual clauses approved by the relevant authorities.

11. DO NOT TRACK SIGNALS

Kami does not track users for behavioral advertising or cross-site tracking purposes. Since we do not engage in the tracking practices that Do Not Track ("DNT") signals are designed to address, we do not change our behavior in response to DNT browser settings.

12. CHANGES TO THIS PRIVACY POLICY

We may update this Privacy Policy from time to time to reflect changes in our practices or for other operational, legal, or regulatory reasons. When we make material changes, we will provide notice through the Website or the App. Your continued use of the Services after the effective date constitutes acceptance of the revised Policy.

13. CONTACT US

For questions, concerns, or to exercise your data rights, please contact:

Email: adarshjagannath777@gmail.com
Website: https://www.mykami.in/legal/privacy
Developer: Adarsh Dev
Twitter/X: @mykami

If you are an EEA or UK resident, you have the right to lodge a complaint with your local data protection supervisory authority if you believe your data protection rights have been violated.

This Privacy Policy was drafted to accurately reflect Kami's local-first architecture. It should not be used as a template for cloud-based services without comprehensive legal review.