Last updated · 2026-09-01
Privacy policy
We collect the minimum data needed to run Karigar. This page explains what we collect, why, the applicable legal basis under GDPR and India's phased DPDP framework, how long we keep it, who else processes it on our behalf, and how to exercise your rights.
Who we are
Karigar is operated by photoGen. For privacy questions, data-subject requests, or concerns about how your data is handled, contact support@karigar.studio. This address is also our designated privacy and grievance contact.
What we collect & why
- Email — only if you sign in. Used to send magic-link sign-ins and pack-purchase receipts. Lawful basis: performance of contract (GDPR Art 6(1)(b)).
- Photos you upload — stored for generation processing. Auto-deleted from our servers after 24 hours. Lawful basis: performance of contract.
- Generated outputs — kept as long as your account exists so you can re-download them. Lawful basis: performance of contract.
- IP-derived country — used to show the right currency, payment methods and marketplaces for your region. Stored briefly in a cookie. We do not store your IP address itself; for abuse prevention we keep only a one-way salted hash, which cannot be reversed to your address and is not associated with your account. Lawful basis: legitimate interest (regional service delivery).
- Payment info — handled entirely by Razorpay. We never see or store card or UPI credentials; we receive only a payment ID and amount. Lawful basis: performance of contract.
- Usage analytics — privacy-friendly product analytics (PostHog) to understand which features get used. Off until you opt in through the consent banner; no analytics cookies are set before you accept, and you can withdraw anytime from Cookie settings in the footer. We never attach your account ID, name, photo bytes or payment data to analytics. Lawful basis: consent (GDPR Art 6(1)(a)); analytics cookies are set only after prior consent.
- Error monitoring — crash and error reports (Grafana Faro) so a failure during signup or a render can be diagnosed. This runs from page load because an error before the consent banner still needs to be fixed. It carries no photo bytes or payment data; text and inputs are masked, and your account ID is attached only if you opt in to identified analytics. Lawful basis: legitimate interest (keeping the service working).
How we use it
Only to run the service: generate photos, grant credits, process payments, prevent abuse, fix bugs, and improve product flows. We do not sell or share your data with advertisers. We do not send marketing emails unless you explicitly opt in.
Who else processes your data
We use third parties for website hosting, database and authentication, private photo storage, image generation, payments, abuse protection, optional Google sign-in, consented product analytics, and error monitoring. Their applicable contractual and data-protection terms govern this processing. Where personal data is transferred internationally, applicable transfer safeguards such as Standard Contractual Clauses (SCCs) or an adequacy mechanism apply.
The current named providers, purposes and processing regions are published on our sub-processors page. We notify signed-in users 14 days before adding a new provider.
Cookies
We use two categories of cookies. Essential cookies keep you signed in, remember your language choice, and carry your IP-derived country for payment and marketplace selection; these are always on because the site does not work without them. Analytics cookies (PostHog) are off by default and set only after you accept on the consent banner; you can change your choice anytime through Cookie settings in the footer. Error monitoring (Grafana Faro) runs from page load under legitimate interest so failures are diagnosable.
Retention
- Uploaded photos: 24 hours (auto-deleted)
- Generated outputs: stored as long as your account exists
- Server logs: 30 days
- Hashed IP counters (abuse prevention): kept while they serve that purpose, then cleared. They hold no address and no account link.
- Account data: deleted immediately when you delete your account. Payment and invoice records (payment ID and amount only — never photos, generated images or other content) are retained for as long as Indian tax law requires, up to 8 years, and then deleted.
- Anti-abuse record: after account deletion we keep a one-way salted hash of the signup email — never the address itself, and it cannot be reversed. It exists only to prevent repeated free-credit claims through account recreation. It is not linked to your identity, photos or activity. Lawful basis: legitimate interest (fraud prevention); retained only for this lawful purpose.
- Analytics events: 12 months rolling window
Your rights
We provide the following controls at no cost. GDPR rights apply where you are in the EU, EEA or UK. India's corresponding DPDP rights are subject to the Act's phased commencement, currently scheduled from May 2027; we provide the same practical request channels in advance:
- Right to access — see what data we hold on you. The “Export my data” button on /account downloads JSON containing your account, credit history, generations and purchases. If you want anything it does not cover, email us and we'll send the rest within a month.
- Right to rectification — correct anything inaccurate. Email us and we'll update it.
- Right to erasure — delete your account and associated data. The Delete account button on /account immediately deletes your account, uploaded photos, generated images and credit history from our systems. Our processors delete their copies on their schedules under their terms with us; email us if you need written confirmation. Two narrow exceptions are listed under Retention.
- Right to data portability — use the same machine-readable JSON export described above.
- Right to restrict or object to processing — turn analytics off from Cookie settings in the footer; for other processing, email us.
- Right to withdraw consent — revoke analytics consent anytime from Cookie settings in the footer; this affects only future tracking.
- Right to lodge a complaint — contact your local Data Protection Authority (EU or UK), or India's Data Protection Board where the DPDP framework permits. You do not need to contact us first where applicable law gives you that right.
We aim to respond to privacy and data-subject requests within 30 days and will meet any shorter deadline required by applicable law. For requests, email support@karigar.studio.
Age
Karigar is intended for users aged 18 or older. We do not knowingly collect data from anyone under 18. India's DPDP framework treats anyone under 18 as a child once the relevant provisions commence; GDPR Art 8 also sets child-consent requirements that vary by EU member state. If you believe we have data on a minor without proper consent, email support@karigar.studio and we will delete it.
Data breach notification
If a security incident exposes personal data, we will: (1) notify the relevant supervisory authority within 72 hours where GDPR requires it and notify India's Data Protection Board where applicable DPDP provisions require it, (2) notify affected users without undue delay where the law requires it, and (3) publish a post-incident summary on this page.
Grievance officer
photoGen operates Karigar. Aman Chirania, Grievance Officer, can be reached at support@karigar.studio. Consumer e-commerce complaints are acknowledged within 48 hours and resolved within one month. Privacy requests follow the response period stated under Your rights and any applicable statutory deadline.
Changes to this policy
If we make material changes — adding a new sub-processor, changing retention windows, or expanding the data we collect — we'll update the “Last updated” date and email signed-in users 14 days before the change takes effect. The latest version is always at /privacy.
Contact
Any privacy question, request or complaint: support@karigar.studio. We read every email.