---
title: "Privacy Policy"
description: "How Kalpana collects, uses, shares, protects, retains and deletes account, workspace, content, billing and integration data."
url: https://kalpana.one/privacy
---

# Privacy Policy

Effective 22 September 2026. Last updated 6 October 2026.

## 1. Scope and who we are

This Privacy Policy explains how Shreekaram Technologies ("Kalpana", "we", "us", or "our") collects, uses, shares, and protects personal data when you visit kalpana.one or use Kalpana's web app, Figma plugin, REST API, MCP server, browser extension, integrations, rendering systems, and related services (together, the "Service").

For account, website, security, and billing data, Kalpana decides why and how the data is processed. When a business customer puts personal data into its templates, product data, assets, or other workspace content, that customer decides the purpose, and Kalpana processes the data on its behalf. In that case, please contact the relevant organisation first; we will help as the law and our agreement with them require.

---

## 2. Summary

- We use your data to run the Service: import designs, connect your data sources, render creatives, bill you, and keep things secure.
- When you use AI image editing, the image and your prompt are sent to our AI image provider, BRIA, to produce the result.
- Integrations read only what a feature needs. Kalpana does not change your store, spreadsheets, or ad accounts.
- We do not sell personal data, and we do not use your content to train AI models.
- You can ask us to access, export, correct, or delete your data at any time.

---

## 3. Information we collect

### 3.1 Account and profile information

Name, email address, profile image, sign-in method, email-verification status, and preferences. If you sign in with Google, we receive the account details you approve, such as your Google account ID, name, email, and profile image. If you use email and password, we store a password hash, never the password itself.

### 3.2 Organisation and workspace information

Organisation and workspace names, members, invitations, roles (such as Owner, Admin, Billing, Manager, Designer, Reviewer, and Viewer), permissions, allowed import domains, and related settings. Other members of a shared organisation or workspace can see your name, email, profile image, role, and activity in it.

### 3.3 Customer Content

Content that you or your teammates upload, import, create, or generate, including:

- templates and layer data exported from Figma, template variables, and campaign feeds;
- product and catalog data, spreadsheet rows, and batch inputs;
- images, fonts, and other assets, including images you edit with AI tools;
- prompts, masks, and reference images used for AI image editing;
- previews and rendered outputs (images, GIFs, and videos), with their file names, sizes, formats, and job status.

### 3.4 Connected-service information

When you connect an integration, we store the provider, connection name, granted permissions, connection status, the provider account identifier, and basic profile details. Access tokens and other credentials are encrypted before they are stored. Section 6 explains what each integration accesses.

### 3.5 Billing information

Billing contacts, plan and credit purchases, credit balances and usage, subscription status and dates, currency, amounts, and payment-provider identifiers. Our payment provider, Dodo Payments, collects and processes card details, billing addresses, and tax information. Kalpana never receives your full card number.

### 3.6 Usage, device, and security information

IP address, browser and device type, operating system, session records, pages and features used, request and job identifiers, API and MCP activity, render performance, errors, and security signals.

### 3.7 Communications

Messages and contact details you send us for support, sales, billing, feedback, or legal matters.

---

## 4. How we use information

We use personal data to:

- create and secure accounts and sessions;
- run organisations, workspaces, roles, and invitations;
- import designs, connect data sources, render previews and creatives, edit images, and deliver outputs;
- operate the REST API, MCP server, Figma plugin, and browser extension;
- process purchases, subscriptions, credits, taxes, and refunds;
- send service, security, and billing messages, and, where allowed, product news you can opt out of;
- monitor reliability, fix errors, prevent fraud and abuse, and enforce limits;
- improve the Service using operational data, or aggregated or de-identified information; and
- comply with law and enforce our agreements.

Depending on where you are, our legal bases are performing our contract with you, your consent, our legal obligations, and our legitimate interests in running, securing, and improving the Service. Where we rely on consent, you can withdraw it at any time.

**No AI training.** We do not use Customer Content to train, or to help train, AI or machine-learning models, unless you agree to it separately in writing.

---

## 5. AI image editing

When you use AI image editing (for example, prompt-based edits or generative expand to a new size), Kalpana sends the following to **BRIA**, our AI image provider:

- the image you are editing, plus any reference images or masks;
- your prompt and any negative prompt; and
- technical settings, such as the output size and a request identifier.

BRIA processes the request and returns the result, which we store in your workspace's asset library. BRIA processes this data to provide the service to us, under its own terms and privacy policy. We do not send your account details to BRIA.

Please make sure you have the right to edit the images you upload, and do not include other people's personal data in images or prompts unless you have the right to do so.

---

## 6. Integrations and connected services

You choose which services to connect. Each connection reads only what the feature needs. **Kalpana does not change or delete existing data in your connected accounts.** It only adds new files when you choose to save outputs to your cloud storage.

| Service | What Kalpana accesses | How it is used |
|---|---|---|
| Figma (plugin) | Frames you choose to send, with their layers, fonts, and images | Creates templates in your workspace |
| Shopify | Products and collections (read-only) | Rows for batches and campaign feeds |
| WooCommerce | Products and categories, using a key you provide (read-only) | Rows for batches and campaign feeds |
| Google Sheets | Spreadsheets you select (read-only) | Rows for batches and campaign feeds |
| Airtable | Bases, tables, and records you select (read-only) | Rows for batches and campaign feeds |
| Google Drive | Files and folders, so you can browse and pick images | Selected images are copied into your asset library; outputs you choose to save |
| Dropbox, OneDrive | Files and folders, so you can browse and pick images | Selected images are copied into your asset library; outputs you choose to save |
| Google Merchant Center, Google Ads, Meta Ads | Account authorisation only, where available | Reserved for upcoming features; no data is read or written today |

Data you import (such as product rows or images) is copied into your workspace so batches can run. Disconnecting an integration stops future access but does not delete data already imported; you can delete that separately. You can also revoke Kalpana's access from each provider's account settings.

### 6.1 Google user data

Kalpana's use and transfer of information received from Google APIs follows the <a href="https://developers.google.com/terms/api-services-user-data-policy" target="_blank" rel="noopener">Google API Services User Data Policy</a>, including the Limited Use requirements.

- We use Google data only to provide the feature you asked for, such as importing sheet rows or Drive images.
- We do not sell Google data, use it for advertising, use it to decide creditworthiness, or use it to train AI or machine-learning models.
- We do not transfer Google data except to provide the feature, for security, to comply with law, or as otherwise allowed by Limited Use.
- Our staff do not read Google data unless you give specific permission for support, it is needed for security or legal reasons, or it has been aggregated and de-identified.

---

## 7. API keys, the MCP server, and extensions

- **REST API.** API keys act as you. Treat them like passwords, and revoke any key you no longer need.
- **MCP server.** When you connect an AI assistant (such as Claude or ChatGPT) to Kalpana, it signs in with OAuth. Access and refresh tokens are stored only as secure hashes. The assistant can reach only the workspaces you select when connecting, within your role, and you can disconnect it at any time under Settings > Connected assistants. Anything you share with the assistant itself is handled by that assistant's provider under its own terms.
- **Figma plugin.** The plugin stores your API key in Figma's local plugin storage on your device and uploads the frames you choose to send.
- **Browser extension.** If you use the Kalpana image-capture extension, it reads images on pages only when you use it, keeps captured images and your sign-in session in your browser's local storage, and uploads only the images you choose to sync.

---

## 8. How we share information

We do not sell or rent personal data. We share it only as follows:

- **Within your organisation**, according to members' roles and permissions.
- **Service providers** that run the Service for us, under contracts that limit their use of the data:

| Provider | Purpose |
|---|---|
| Cloudflare | Object storage, content delivery, and edge services (including the MCP server) |
| Amazon Web Services | Render job queues and compute |
| Upstash | Job scheduling and caching |
| BRIA | AI image editing |
| Dodo Payments | Payments, subscriptions, invoices, and tax |
| Resend | Account emails such as password resets |
| Sentry | Error monitoring for rendering services |
| Google | Sign-in, Google Fonts, website analytics (Google Analytics), and the Google integrations you connect |

- **Connected services you choose**, as described in section 6.
- **Legal and safety**, to advisers, auditors, or authorities when reasonably needed to comply with law, enforce agreements, or protect rights and safety.
- **Business transfers**, as part of a merger, financing, acquisition, or sale of assets, subject to confidentiality and any required consent.

---

## 9. Cookies and local storage

The Kalpana app uses essential cookies to keep you signed in (for example, `kalpana-token`), to authorise access to your files on our content delivery network, and to remember your workspace. Our website uses local storage for preferences, such as your chosen pricing region, theme and cookie choice.

Our website also uses Google Analytics to count visits and see which pages and links are used. When you first visit, we ask whether you accept analytics cookies. Until you accept, Google Analytics runs in consent mode without setting analytics cookies, and advertising cookies are always off. You can change your choice by clearing this site's storage in your browser, which shows the prompt again. The Kalpana app does not use Google Analytics.

Blocking essential cookies may stop the app from working.

---

## 10. Retention and deletion

We keep information only as long as needed for the purposes in this policy:

- account, organisation, and workspace records, while the account is active;
- Customer Content and outputs, until you or your workspace delete them. Deleting an asset or creative removes the file from storage. Deleted templates and batches may be kept for a short recovery period before permanent removal;
- integration credentials, until you delete the connection;
- billing and tax records, for the periods required by law;
- security and diagnostic logs, for a limited period; and
- backups, until they are overwritten in normal cycles.

To close your account or delete an organisation or workspace and its content, email us (see section 15). We will confirm the request and complete it within the time the law requires.

---

## 11. Security

We protect data with access controls and workspace permissions, encryption in transit, encryption of stored integration credentials, hashing of passwords and OAuth tokens, signed and expiring download links, request limits, and signature checks on incoming webhooks. No system is perfectly secure. Please protect your password and API keys and tell us promptly if you suspect misuse. We will notify affected users and authorities of a personal-data breach as the law requires.

---

## 12. International processing

Kalpana is based in India. We and our service providers may process data in India, the United States, the European Union, and other countries where our providers operate. Where required, we use contractual or other lawful safeguards for international transfers.

---

## 13. Your rights and choices

Depending on where you live, you may have the right to access, correct, export, or delete your personal data, withdraw consent, object to or restrict certain processing, nominate someone to act for you, and complain to a data-protection authority.

- Update your profile and workspace details in the app.
- Ask your organisation's administrator about data your organisation controls.
- Disconnect integrations in Kalpana, and revoke access in each provider's settings.
- Revoke API keys and connected AI assistants at any time.
- Unsubscribe from marketing emails using the link in each message.
- Email us to access, export, correct, or delete your data.

We may need to verify your identity. We will not treat you differently for exercising your rights.

---

## 14. Children

The Service is for businesses and is not directed to anyone under 18. We do not knowingly collect personal data from children. If you believe a child has given us personal data, contact us and we will remove it.

---

## 15. Changes and contact

We may update this policy as the Service or the law changes. We will post the new version here and update the date above, and for material changes we will give additional notice by email or in the app.

Shreekaram Technologies is based in Bengaluru, Karnataka, India. For privacy requests, questions, or grievances, email our grievance officer at [support@kalpana.one](mailto:support@kalpana.one) with the subject "Privacy request" or "Grievance". Include your account email and organisation, but never send passwords, API keys, OAuth tokens, or card details. We will respond within the time required by applicable law.
