SAARTHI · Strategic AI Ally Ready To Help Intelligently
Privacy Policy

How SAARTHI handles connected account and communication data.

Last updated: 6 October 2026

1. Scope and operator

This Privacy Policy applies to SAARTHI at saarthi.karansoni.com.np and the private services behind it. SAARTHI is operated by Karan Soni for authorized private use. Questions about privacy or data handling can be sent to hello@karansoni.com.np.

2. Information SAARTHI processes

Depending on the services that are deliberately connected and the permissions granted, SAARTHI may process:

  • Account identity information such as name, email address, provider account identifiers and connected business or channel identifiers.
  • Communication content and metadata needed for inbox, reply, follow-up, relationship and reporting functions, including messages, threads, comments, timestamps and sender or recipient context.
  • Relationship and operational records created inside SAARTHI, including contacts, leads, stages, notes, summaries, follow-ups, approval requests, automation rules and audit records.
  • Approved knowledge and business context supplied to SAARTHI, such as policies, pricing, documents and instructions.
  • Connection credentials issued by providers, such as OAuth access and refresh tokens. Provider passwords are not requested or stored.
  • Security and technical information necessary to operate the service, including authentication sessions, connection health, errors and limited operational logs.

3. How information is used

SAARTHI uses data only for functions that support its private communication-operator purpose. This can include retrieving authorized communication, organizing conversations, resolving contact context, preparing or sending permitted replies, managing follow-ups and leads, applying approved knowledge and authority rules, requesting approval when required, maintaining connection health, producing operational reports and protecting the application against unauthorized access or abuse.

SAARTHI does not sell personal information, rent connected account data, build advertising profiles, or use connected data for targeted advertising.

4. Google user data

When a Google account is connected, SAARTHI may request only the Google OAuth scopes needed for enabled features. Depending on those scopes and the services available to the connected account, this can include Gmail communication data, YouTube channel and engagement data, Google Business Profile account, location and review information, and basic Google account identity used to establish the connection.

Google user data is used only to provide the corresponding SAARTHI features, such as communication retrieval and response workflows, context building, comment or review handling, account connection, relationship continuity and reporting. SAARTHI does not use Google user data for advertising, does not sell it, and does not use it to train generalized artificial-intelligence models.

SAARTHI handles information received from Google APIs in accordance with the Google API Services User Data Policy, including its Limited Use requirements.

5. AI-assisted processing

Some SAARTHI functions use an AI service to classify, summarize, draft, reason over, or otherwise assist with communication and approved knowledge. Only information relevant to the requested operation is sent for that processing. SAARTHI does not intentionally use connected Google user data to train a generalized model. AI-generated output remains subject to SAARTHI's authority rules and approval requirements before action where the configured operating mode requires it.

6. Storage and security

SAARTHI uses hosted infrastructure to operate the application, database, deployment, limited queue or rate-limit state, and configured AI processing. Current infrastructure can include Supabase, Vercel, Upstash and the configured AI API provider. These services process information only as necessary to provide their infrastructure or processing function and are subject to their respective terms and security controls.

Provider access and refresh tokens stored by SAARTHI are encrypted before database storage. Connections use HTTPS in transit. Access to the private workspace is authenticated, and server-side credentials are kept separate from browser-visible configuration.

No system can guarantee absolute security. SAARTHI is designed to minimize unnecessary access and to keep credentials and private application data behind authenticated, controlled services.

7. Sharing and disclosure

SAARTHI does not sell or rent connected account information. Data may be disclosed only when necessary to:

  • operate the application through contracted infrastructure or API providers;
  • communicate with a third-party service at the owner's direction, such as sending an authorized reply through a connected provider;
  • protect the security, integrity or legal rights of the application or its operator; or
  • comply with a lawful obligation.

8. Retention, disconnection and deletion

OAuth credentials are retained while a provider connection remains active and as needed to maintain that authorized connection. Using Disconnect in SAARTHI clears the stored access and refresh credentials for that channel account and stops SAARTHI from using that stored connection.

Provider authorization can also be revoked directly from the provider's account-security settings. For Google, revoking SAARTHI's access from the Google Account permissions page prevents future API access with that authorization.

Operational records such as conversation history, contact context, audit events, summaries or follow-up records can remain after a connection is disconnected when they are needed for continuity, security or recordkeeping. A request to remove retained derived or operational data can be sent to hello@karansoni.com.np. Requests will be handled subject to legitimate security, legal and operational retention needs.

9. Cookies and authentication

SAARTHI uses authentication and security cookies required to maintain signed-in sessions and protect private routes. These are functional security mechanisms, not advertising cookies.

10. International processing

Because SAARTHI uses cloud and API providers, information may be processed in jurisdictions outside Nepal. The application uses those providers only as needed to deliver its functions and applies the controls described in this policy to connected data.

11. Children

SAARTHI is a private professional application and is not directed to children or offered as a public consumer service.

12. Changes to this policy

This policy will be updated when SAARTHI's data practices, connected providers or material functionality change. The current version will remain publicly available at this URL with its latest revision date.

13. Contact

For privacy questions, access revocation concerns or data-deletion requests, contact hello@karansoni.com.np.

Read the Terms of Service