Privacy Policy
Last updated 15 August 2026
1. What we collect
| Data | Why | Kept |
|---|---|---|
| Email address | To identify your account and send verification codes | Until you delete your account |
| Password (hashed) | To sign you in. Stored as a bcrypt hash — we cannot read it | Until you delete your account |
| Name and avatar | Only if you sign in with Google, and only to show who's signed in | Until you delete your account |
| Your chats | So you can come back to them | Until you delete the chat or the account |
| Files you upload | So the model can read them | Until you delete your account |
| Generated images | So they stay visible in your chat | Until you delete your account |
| Usage records | Token counts and cost per request, to meter credits and prevent abuse | Retained for accounting |
| IP address | Rate limiting and abuse prevention only | Login attempts cleared after 24 hours |
If you are not signed in
Anonymous chats are never written to our database. While you're trying Kryera, your conversation is held only in your server session and is discarded when that session ends or when you create an account. We store a random identifier in a cookie and a count of how many trial messages have been used, so the trial can't be reset by reloading the page. That's all.
2. Who we share it with
Running an AI product means sending your request to whoever operates the model. When you send a message, its text — plus any files attached to that message and the recent history of that conversation — is transmitted to the provider of the model you selected:
- Anthropic — for Claude models
- OpenAI — for GPT models and image generation
- Google — for Gemini models
The model shown in your picker tells you where a given message will go. Each provider handles that data under its own terms and privacy policy. We also use:
- PayPal — to take payment. They receive what they need to process it; we never receive your card details.
- Brave Search — when the agent runs a web search, the search query is sent to them. Your wider conversation is not.
- Our email provider — to deliver verification codes.
We do not sell your personal data, and we do not share it for advertising.
3. Training
We do not use your conversations, files or images to train any model. We have no model of our own to train. Whether a provider may use API traffic for training is governed by that provider's terms; the major providers listed above state that they do not train on API data by default.
4. Cookies
Kryera uses cookies only to make the product work. There is no advertising or analytics tracking, and no third-party trackers.
kryera_sess— keeps you signed inkryera_csrf— protects against cross-site request forgerykryera_gid— identifies an anonymous trial so it can't be reset by reloading
Your theme and model preferences are stored in your browser's local storage and never sent to us.
5. Security
- Passwords are hashed with bcrypt; we can never read them.
- Sign-in is rate limited per IP address and per account.
- Uploaded files are stored under randomised names and served only after we check that the account requesting them owns them.
- Traffic is served over HTTPS.
No system is perfectly secure. If you find a vulnerability, please report it to support@kryera.com rather than disclosing it publicly.
6. Your rights
You can, at any time:
- See your data — your chats, files and credit balance are all visible in the product.
- Delete a chat — removing it removes its messages.
- Delete your account — from Settings. This erases your chats, messages, uploaded files and generated images. Records of credit purchases are kept where we're required to retain them for accounting.
- Export or correct your data — email support@kryera.com and we'll help.
Depending on where you live, you may have additional rights under laws such as the GDPR, including the right to object to processing and to complain to your local data protection authority.
7. Children
Kryera is not intended for children under 13, and we don't knowingly collect their data. If you believe a child has created an account, contact us and we will remove it.
8. International transfers
The AI providers and payment processor we rely on operate servers outside Jordan, including in the United States. Using Kryera means your requests are processed in those countries.
9. Changes
If we change what we collect or who we share it with, we'll update this page and change the date at the top. Material changes will be notified in the product or by email.
10. Contact
Questions about privacy: support@kryera.com.
LEGAL_ENTITY, LEGAL_JURISDICTION and
LEGAL_CONTACT in config.php, confirm the provider list matches the
models you actually offer, and have this reviewed by a lawyer. Keep this page in sync with
the schema whenever you change what is stored.