Legal
Privacy
How Sharan AI handles your data.
Identity is stored as a hash
Sign-in is through Google. The raw Google account id never leaves the server. It is converted to a salted, one-way hash, and only that hash is attached to your interactions. We do not store a raw personal identifier for correlation.
Where answers are produced
SAP-grounded questions and any screen you upload are answered on Sharan AI's own infrastructure, never sent to an outside model provider. General, non-SAP questions may be answered by an external model.
What is captured, and why
Interactions are recorded to improve the model through a reviewed training flywheel. SAP questions and answers are captured in full, because they carry the training value. General, non-SAP interactions are captured only in minimal form, with personal text stripped. Uploaded images are referenced internally and are not forwarded to an outside provider.
Feedback becomes training signal
When you rate an answer or submit a correction, that feedback is stored against the captured interaction. Only examples an expert has reviewed and approved can enter a versioned training or evaluation set — unreviewed feedback never trains the model automatically.
Retention and control
Captured interactions are retained on Sharan AI's infrastructure for model improvement for as long as your account is active. You can request the data held for your account, or its deletion, at any time — see "Your rights" below.
Sub-processors
The SAP-grounded path uses no third-party sub-processor; it runs on Sharan AI's own infrastructure. A general, non-SAP question may be routed to an external model, which then processes only that minimal request. Payment processing, when a paid plan is used, receives billing details only, never your SAP content.
Your rights, and how to request deletion
You can ask for the data held under your account, and you can have it erased. Both are self-service from your account settings and cover the rights individuals hold under laws such as the GDPR and India's Digital Personal Data Protection Act.
An access request returns the interactions, usage, plan, and key metadata stored for you. A deletion request removes your records across every store — captured interactions, usage history, plan and subscription, trust and session records, rate counters, and any developer keys you own — in a single operation. The deletion is recorded to a tamper-evident audit log that holds only counts and a one-way fingerprint, never the erased content or a raw identifier. Deletion is irreversible. The processing arrangement behind this is described in the Data Processing Agreement.