Privacy Policy
Effective date: May 2, 2026 · Last updated: July 18, 2026
This Privacy Policy explains what personal data Enhanciar ("we", "us") collects when you use our service, how we use it, who we share it with, and your rights over it. We've tried to keep it straightforward — read it carefully and email support@enhanciar.in with any questions.
1. Who is responsible for your data
Enhanciar is operated by Enhanciar, Bengaluru, Karnataka, India. We are the data controller for the personal information described in this policy. For data-protection enquiries, contact support@enhanciar.in.
2. What we collect
From you directly
- Identity: name, email, and profile picture. You sign in with Google, or with an email and password — if you use email/password we store your email and a Firebase-managed credential (we never see your password in plain text).
- Two-factor authentication (optional): if you enable 2FA, we store a time-based one-time-password (TOTP) secret so your authenticator app can be verified.
- Profile (optional): role, team size, and use case if you provide them during onboarding.
- Content you upload or type: anything you enter into chat, files and documents you upload (PDF, DOCX, Markdown, transcripts, pasted text), images and video you submit for analysis, and support emails.
- Waitlist: if you join the waitlist, we store your email address and your position in the queue, and send you a confirmation email.
From the sources you connect
Enhanciar is a knowledge-base builder: you connect sources and we turn them into a searchable wiki and knowledge graph. We only read the sources you explicitly connect, and only with the scopes you grant. Depending on which connectors you enable, this can include:
- GitHub: repository contents (we clone and parse your code), plus issues, pull requests, and review threads. Code is mirrored to our storage to build the wiki.
- Websites you point us at: pages we crawl and convert to text, for URLs you supply.
- Slack: messages and threads in the channels the Enhanciar bot is added to, plus channel/user metadata.
- Google Gmail: email subjects, bodies, and participants in the inboxes you connect (read-only).
- Google Drive: the documents, sheets, and files you grant access to (read-only).
- Google Calendar: events, attendees, and RSVPs — both for ingestion and, for scheduling questions, queried live at the moment you ask.
- Notion, Jira, Confluence, Linear, Zendesk: the pages, issues, tickets, and comments in the projects/spaces you connect.
- WhatsApp: messages in the specific chats and groups you select, via a QR-linked session you authorize.
- Databases (PostgreSQL / MySQL): schema (tables, columns, relationships) and, on the paths you enable, query results.
- The wiki, knowledge graph, embeddings, and audit trail we generate from the above, the queries you run, and the AI responses.
You provide the credentials/API keys for each connector in Settings → Integrations. We store them encrypted (see Security) and use them only to read the data you asked us to ingest.
Through using the service
- Usage data: which features you use, token counts, query and ingest history, IP address, browser/device type, and request timestamps.
- First-party analytics: we run our own lightweight page/event analytics that stores an anonymous visitor id and session id in your browser and records page paths, referrers, and campaign (UTM) parameters. This is our primary source of product analytics.
- Third-party analytics: Google Analytics, loaded only after you accept analytics cookies (see "Cookies & tracking" below).
From third parties
- Razorpay (payments): payment-method type, card last-4, and billing details you provide. We do not see or store your full card number — Razorpay handles that.
3. AI processing — server-side and bring-your-own-key
Answering your questions and enriching your wiki requires sending content to a large-language-model provider. There are two paths, and you should understand both:
- Bring-your-own-key (BYOK): for the main experience you supply your own API key, and the relevant content from your connected sources plus your queries are sent to the provider whose key you configured to generate the answer. Supported providers are Google (Gemini), OpenAI, Anthropic, Groq, Ollama Cloud, or any OpenAI-compatible endpoint you configure. That data is handled under that provider's terms and your account with them — not ours. We recommend API-tier keys (which, for OpenAI and Anthropic, are not used for training by default) over consumer keys.
- Server-side default (Google Gemini): some lightweight tasks — such as generating chat titles, detecting intent, and the no-signup demo — may run on Enhanciar's own server-side Google Gemini key when you have not configured a BYOK key. In those cases the relevant content is sent to Google to process the request.
We never use your code, messages, or queries to train any AI model ourselves, and we do not sell your data.
4. Features that move your data outside Enhanciar
- AI Code Review: when enabled, our GitHub App reads the diff of a pull request together with related repository and wiki context, generates a review using your BYOK key, and posts the review (a summary and inline comments) back to that pull request on GitHub.
- MCP server & REST API: you can issue Enhanciar API keys (
dh_…) that let external clients — e.g. an IDE or an MCP-compatible assistant — search and query your knowledge base. A query made this way runs through your configured AI provider just like an in-app query. You control these keys and can revoke them at any time in Settings; access is filtered to what the key's owner is permitted to see.
5. How we use your data
- To provide the core service — ingest your sources, build and maintain your wiki and graph, and answer your queries.
- To operate the connectors and features you enable, and to keep an audit log of who queried or ingested what.
- To bill you, prevent fraud and abuse, and enforce usage limits.
- To send essential account and security emails (e.g. email verification, password reset, waitlist confirmation). Payment receipts and invoices are available in-app under Settings → Billing.
- To secure the service — including reCAPTCHA / Firebase App Check to block automated abuse.
- To understand and improve the product using aggregate usage statistics.
- To comply with legal obligations (tax, fraud prevention).
6. Where your data lives
Your account data, wiki content, and uploads are stored on Google Cloud Platform in Mumbai, India (asia-south1) — both Firestore and our Cloud Storage bucket. Application compute runs on Google Cloud Run in Singapore (asia-southeast1), so your data transits Singapore while it is being processed. Subprocessors and any BYOK AI provider you select may process data in their own regions; they are listed below.
7. Cookies & tracking
We use a small number of browser storage items. On your first visit we ask for your cookie/analytics preference and remember it.
- Essential (always on): your Firebase authentication session, your cookie-consent choice, active-workspace selection, and minor interface state (e.g. which tab you last used). The service can't function without these.
- Analytics (only after you consent): our first-party analytics (an anonymous visitor id and session id) and Google Analytics. Google Analytics is not initialised until you accept analytics cookies, and you can decline.
We do not use advertising or cross-site tracking cookies. You can clear these at any time in your browser, and change your choice via the cookie banner.
8. How long we keep it
- Active account: for as long as your account exists.
- Wiki content & ingested data: until you delete it or your account.
- Audit logs: up to 12 months.
- Payment records: 8 years (mandatory under Indian tax law).
- After account deletion: personal data and Customer Content are removed within 30 days, except where law requires retention.
9. Your rights (DPDP Act 2023, GDPR, CCPA)
- Access & portability — download everything we hold as a zip via Settings → Export (wiki, profile, and payment history).
- Correction — fix your details in Settings or by emailing us.
- Deletion — Settings → Delete account purges your encrypted keys and wiki; honored within 30 days. You can also disconnect an individual connector or delete a single API key at any time.
- Objection / opt-out — decline analytics cookies, and opt out of any non-essential email.
10. Subprocessors
We share data with these companies, who act on our behalf or process data when you connect the relevant source:
- Google Cloud Platform — hosting, Cloud Run compute, Firestore, Cloud Storage.
- Firebase (Google) — authentication, App Check, and Google Analytics.
- Google reCAPTCHA — bot/abuse protection.
- Razorpay — payment processing.
- Sentry — error and performance monitoring (error stacks may incidentally contain identifiers).
- Email delivery (SMTP) — sending transactional email (verification, receipts, waitlist).
- Connected sources — GitHub, Slack, Google Workspace (Gmail/Drive/Calendar), Notion, Jira, Confluence, Linear, Zendesk, WhatsApp, and your own databases — accessed only when you connect them.
- AI model providers — your selected BYOK provider (Google Gemini, OpenAI, Anthropic, Groq, Ollama Cloud, or a custom endpoint), plus Google Gemini for the server-side default tasks described in section 3.
11. Security
Data in transit uses TLS 1.2+. Data at rest is encrypted by Google Cloud's default at-rest encryption. Your BYOK API keys and connector credentials are additionally encrypted at the application layer (Fernet) before storage. Authentication tokens are short-lived (about 1 hour) and rotated automatically, and we support TOTP two-factor authentication. Customer data is isolated per tenant by Firebase UID, and access via API keys is scope- and ACL-filtered.
12. Minimum age
Enhanciar requires users to be at least 18 (see the Terms of Service) and is not directed at minors. If we learn we've collected data from anyone under 18, we'll delete it.
13. Changes to this policy
We'll notify you about material changes at least 30 days before they take effect. The current version always lives at this URL.
14. Contact us
Questions, requests, or complaints: support@enhanciar.in.