Privacy Policy

Effective date: May 2, 2026 · Last updated: July 18, 2026

This Privacy Policy explains what personal data Enhanciar ("we", "us") collects when you use our service, how we use it, who we share it with, and your rights over it. We've tried to keep it straightforward — read it carefully and email support@enhanciar.in with any questions.

1. Who is responsible for your data

Enhanciar is operated by Enhanciar, Bengaluru, Karnataka, India. We are the data controller for the personal information described in this policy. For data-protection enquiries, contact support@enhanciar.in.

2. What we collect

From you directly

From the sources you connect

Enhanciar is a knowledge-base builder: you connect sources and we turn them into a searchable wiki and knowledge graph. We only read the sources you explicitly connect, and only with the scopes you grant. Depending on which connectors you enable, this can include:

You provide the credentials/API keys for each connector in Settings → Integrations. We store them encrypted (see Security) and use them only to read the data you asked us to ingest.

Through using the service

From third parties

3. AI processing — server-side and bring-your-own-key

Answering your questions and enriching your wiki requires sending content to a large-language-model provider. There are two paths, and you should understand both:

We never use your code, messages, or queries to train any AI model ourselves, and we do not sell your data.

4. Features that move your data outside Enhanciar

5. How we use your data

6. Where your data lives

Your account data, wiki content, and uploads are stored on Google Cloud Platform in Mumbai, India (asia-south1) — both Firestore and our Cloud Storage bucket. Application compute runs on Google Cloud Run in Singapore (asia-southeast1), so your data transits Singapore while it is being processed. Subprocessors and any BYOK AI provider you select may process data in their own regions; they are listed below.

7. Cookies & tracking

We use a small number of browser storage items. On your first visit we ask for your cookie/analytics preference and remember it.

We do not use advertising or cross-site tracking cookies. You can clear these at any time in your browser, and change your choice via the cookie banner.

8. How long we keep it

9. Your rights (DPDP Act 2023, GDPR, CCPA)

10. Subprocessors

We share data with these companies, who act on our behalf or process data when you connect the relevant source:

11. Security

Data in transit uses TLS 1.2+. Data at rest is encrypted by Google Cloud's default at-rest encryption. Your BYOK API keys and connector credentials are additionally encrypted at the application layer (Fernet) before storage. Authentication tokens are short-lived (about 1 hour) and rotated automatically, and we support TOTP two-factor authentication. Customer data is isolated per tenant by Firebase UID, and access via API keys is scope- and ACL-filtered.

12. Minimum age

Enhanciar requires users to be at least 18 (see the Terms of Service) and is not directed at minors. If we learn we've collected data from anyone under 18, we'll delete it.

13. Changes to this policy

We'll notify you about material changes at least 30 days before they take effect. The current version always lives at this URL.

14. Contact us

Questions, requests, or complaints: support@enhanciar.in.