KripaXBack to home

Privacy Policy

Last updated: September 19, 2026

Inframiq Solutions Private Limited ("Inframiq", "we", "us", or "our") operates KripaX (the "Service"), an AI-assisted resume, job-description analysis, and interview preparation tool for individual job seekers. KripaX is a self-service tool: you use it to build and improve your own resume, and there is no employer-, recruiter-, or agency-facing product that screens, ranks, or scores you for a third party. This Privacy Policy explains what personal data we collect, why, how it is used, where it is stored, who we share it with, and the rights you have over it — wherever in the world you are using the Service from. It also serves as our Notice at Collection for California residents (see Section 10). By creating an account or otherwise using the Service, you acknowledge that you have read and understood this Policy.

1. Who we are and how to reach us

The Service is operated by Inframiq Solutions Private Limited, a company registered in India. For any question, request, or complaint about this Policy or your personal data, contact us at support@inframiq.com. We aim to acknowledge privacy requests within 7 days and to resolve them within the timeframe required by applicable law (see Section 9).

2. Information we collect

This is a complete inventory of the personal data the Service collects or generates about you:

  • Account data — your name, email address, profile picture, and a unique account identifier, obtained from Google when you sign in with Google OAuth. Google Sign-In is the only way to create or access an account on the Service; we do not collect or store passwords.
  • Resume and profile content — work history, education, skills, contact details, and any resume file or text you upload, type, or generate within the Service. Resumes commonly contain your address, phone number, and photo if you choose to include them — these are optional and provided entirely at your discretion; we do not require or request sensitive personal data (such as health, religious, or biometric information) and ask that you avoid including it in resume content unless it is something you specifically intend to share as part of your own document.
  • Job descriptions you paste in for analysis, ATS scoring, or tailoring.
  • AI prompts, outputs, and generation history — the text sent to an AI provider for a given feature and the content it returns (tailored resume text, cover letters, interview questions, ATS scores), which we store so you can view and reuse your past results within the Service.
  • Networking data — if you use the Networking feature: the networking profile you choose to create (name, headline, bio, location, skills, availability, and LinkedIn/GitHub links), your connection requests, and any contacts you add to your own list. A networking profile is visible to other signed-in users in Discover, and the form says so before you save it; you can remove it at any time. Contacts you add are visible only to you. These are fields you type in yourself, not data obtained from a third-party login or by us visiting those profiles on your behalf. If you add someone else's details as a contact, please add only what you need and have a legitimate reason to keep.
  • Plan and credit data — your subscription tier and remaining credit balance. If and when paid plans involve a card payment, the payment itself is collected and processed directly by a PCI-compliant third-party payment processor; we store a transaction reference and the plan/amount, not your full card number.
  • Support communications — anything you send us at support@inframiq.com or through an in-app feedback form, including your email address and the content of your message.
  • Usage and device data — IP address, browser type, device identifiers, pages visited, timestamps, and error/diagnostic logs, collected automatically to operate, secure, and troubleshoot the Service. Authentication events (sign-in and sign-out) are logged for security purposes for a limited period as described in Section 8.
  • Cookies and local storage — see Section 7.

Nearly all of this data comes directly from you or is generated by your use of the Service. The one exception is Account data, which we receive from Google when you sign in — we do not obtain personal data about you from any other third-party source, data broker, or public scraping.

3. How we use your information, and our legal basis for doing so

We use personal data only for the purposes below. For users in the EEA, UK, or Switzerland, each purpose is matched to the legal basis we rely on under GDPR/UK GDPR:

  • Providing the Service you asked for — creating and authenticating your account, generating and tailoring resume content, computing ATS scores, generating cover letters and interview questions, and storing your generation history so you can access it later. Legal basis: performance of a contract with you (our Terms of Service).
  • Payments and subscriptions — processing payments, managing your plan, and tracking credit usage. Legal basis: performance of a contract, and compliance with tax/accounting obligations.
  • Fraud prevention and security — detecting abuse (e.g. credential stuffing, credit-limit circumvention) and maintaining authentication logs. Legal basis: our legitimate interest in keeping the Service and its users safe from fraud and abuse. We have weighed this against your privacy interest by limiting this processing to security-relevant metadata (Section 8), not resume or job-description content, and you may object to this processing at any time (Section 9), though we may need to weigh an objection against our ability to keep the Service secure.
  • Essential account, billing, and security notices — messages you need to receive to use the Service (e.g. sign-in alerts, payment receipts, policy changes). Legal basis: performance of a contract — these are not optional and are not marketing, so there is no separate opt-out for them short of closing your account.
  • Optional product updates or marketing — sent only if you opt in. Legal basis: consent. You can withdraw consent at any time via the unsubscribe link in any such message or by emailing support@inframiq.com; withdrawing stops future messages but does not affect the lawfulness of anything already sent while consent was in effect.
  • Legal compliance and enforcement — retaining payment/tax records (Section 8), responding to lawful requests from courts or regulators, and enforcing our Terms of Service against violations such as abuse of credit limits or unlawful content. Legal basis: legal obligation for regulatory/tax retention specifically, and legitimate interest for Terms enforcement more broadly.

We do not use your resume content, job descriptions, or personal data to serve advertising, and we do not sell personal data to third parties, in any form, for any consideration.

4. Automated processing and AI-generated content

KripaX uses AI to generate suggestions — tailored resume text, cover letters, ATS compatibility scores, and interview questions. This processing is advisory only: it acts on your own resume, at your own request, and you decide whether to use, edit, or discard any output. No employer, recruiter, or other third party uses KripaX to screen, rank, or evaluate you — there is no feature through which anyone other than you receives or acts on this output. An ATS compatibility score is an estimate intended to help you improve your resume; it does not guarantee acceptance by any real applicant tracking system, which we do not control. We describe this so you can assess for yourself, or with your own advisor, how automated-decision-making rules under GDPR, the DPDP Act, or other applicable law apply to your specific situation — we do not make that determination for you in this Policy.

5. AI providers and third-party subprocessors

To generate resume content, tailoring suggestions, ATS scores, and interview questions, the resume and job-description text you submit for that specific action is sent to OpenAI, the single AI provider KripaX currently uses in production, solely to generate that response. Only the text relevant to the feature you triggered is sent (for example, a bullet-rewrite sends the bullet and job context, not your entire account); we do not send your Google account credentials, email, or payment data to OpenAI. We may add or switch to a different or additional AI provider (such as Google Gemini) in the future — if we do, we will update this section and our Terms of Service before the change takes effect, and, where it materially changes how your data is used, notify you as described in Section 14.

We access OpenAI through its standard commercial API, under OpenAI's published API terms, which state that API-submitted content is not used to train its general models by default. We have not independently negotiated a separate data-processing agreement with OpenAI beyond its standard API terms. We send every request with OpenAI's response storage turned off, so OpenAI does not keep prompts and outputs for later retrieval. It may still retain them for a limited period for abuse and safety monitoring under its own policies — we do not control that retention and encourage you to review OpenAI's own privacy and API data-usage terms directly.

Other subprocessors that handle personal data on our behalf, used solely to provide the Service: our cloud database and file storage provider (Supabase), a PCI-compliant payment processor (used only for paid-plan transactions), and our cloud hosting provider (Vercel), which also provides the cookieless page-view and performance measurement described in Section 7. We do not permit any subprocessor to use your data for its own purposes, and we take reasonable contractual steps with each of them to protect your data, consistent with their standard terms of service.

6. Our role: controller or processor

For the personal data described in this Policy — your account, resume, and usage data — we act as the data controller (or "data fiduciary" under Indian law): we decide why and how that data is processed. We are not acting as a processor on behalf of any employer, recruiter, or other organization, because no such organization uses the Service to process your data. Our AI and hosting subprocessors act as processors on our behalf, strictly for the purposes described in Section 5.

7. Cookies and local storage

We use cookies only to keep you signed in (Supabase Auth session cookies), and browser local storage only to remember choices you make in the app: whether the side menu is collapsed, whether you have seen the guided tour, and your in-progress target role on the Career Path page. None of these are used for advertising or cross-site tracking. Our Cookie Policy lists each one by name, with its purpose and duration.

We measure page views and page-load performance with Vercel Web Analytics and Speed Insights. These set no cookies and store nothing on your device. They work from the request itself and do not identify you or follow you across websites.

Because everything we store on your device is strictly necessary or remembers a setting you chose, it is exempt from consent requirements under the ePrivacy rules and similar laws, so we do not show a cookie banner. If we ever add non-essential cookies or storage (analytics that identify you, advertising), we will update the Cookie Policy and ask for your consent first, where required.

8. Where data is stored, retention periods, and security

Account and application data is stored with Supabase (PostgreSQL), in the cloud region configured for our project. Generated PDF exports and uploaded files are stored in Supabase Storage. Resume files and profile photos are kept in private storage and are only ever opened through short-lived links issued to your own account. Data may be processed and stored on servers located outside your country of residence; where required (for example, for transfers of personal data originating in the EEA, UK, or Switzerland), we rely on our subprocessors' Standard Contractual Clauses or equivalent transfer mechanism with their own downstream infrastructure. Data is encrypted in transit (TLS) and at rest. Access to production data is restricted to authorized personnel on a need-to-know basis, gated by account-level access controls; we do not currently operate a dedicated 24/7 security-monitoring team or hold a third-party security certification (e.g. SOC 2, ISO 27001) — if you require that level of assurance before use, contact us before relying on the Service for sensitive data.

Retention periods:

  • Account, resume, job-description, and AI generation history: retained while your account is active, and deleted on account deletion as described below.
  • Authentication/security logs: retained for up to 90 days for abuse investigation, then deleted or anonymized.
  • Payment/transaction records: retained for 8 years to meet Indian tax and accounting record- keeping obligations, even after account deletion.
  • Support communications: retained for up to 24 months after your last contact, then deleted or anonymized. Feedback sent through the in-app form is deleted with your account.
  • Encrypted database backups: rolled over on a cycle of no more than 90 days.
  • Deletion requests: a record of the request (the email address, what was asked, and what we did) for 3 years, to show it was handled. It never contains the data that was deleted.

When you delete your account, we remove your resumes, profile, job descriptions, generated content, and account identifiers from our active production database immediately, and this action cannot be undone from your side. "Immediately" means removal from the live database that powers the Service — it does not mean your data is instantaneously erased from every layer of infrastructure: residual copies may persist in encrypted backups until they age out (up to 90 days), and copies already sent to an AI provider before your deletion request are subject to that provider's own retention window (Section 5), which we do not control. Payment records are retained per the schedule above regardless of account deletion, as required by law.

9. Your rights

You can access, edit, or delete your resumes, profile, and job descriptions at any time from within the app, and delete your account from the Account page (see Section 8 for what that does and does not immediately erase). If you can't sign in, or you aren't a user but think a user entered your details, you can ask us to delete your data on our Delete your data page. Depending on where you live, you may also have the following rights, which you can exercise by contacting support@inframiq.com — please tell us which right you are exercising and the email address on your account; we will verify your identity via your authenticated Google account before acting on the request, and will let you know if we need more information or if an exception applies:

  • European Economic Area, UK, and Switzerland (GDPR/UK GDPR) — access, rectification, erasure, restriction, and objection to processing; data portability; withdrawal of consent at any time where processing is based on consent; and the right to lodge a complaint with your local data protection supervisory authority. We aim to respond within 30 days, extendable by a further 60 days for complex requests, as GDPR permits.
  • California and other U.S. states (CCPA/CPRA and similar state laws) — the right to know what personal information we collect and how it is used (see Section 2 for categories, Section 8 for retention); the right to request deletion; the right to correct inaccurate information; and the right to opt out of the "sale" or "sharing" of personal information. We do not sell or share personal information as those terms are defined under CCPA/CPRA, so no opt-out mechanism is required, and we will not discriminate against you for exercising any right under this Policy. We aim to respond within 45 days, extendable once by a further 45 days.
  • India (Digital Personal Data Protection Act, 2023) — the right to a summary of your personal data and processing activities, the right to correction, updating, and erasure, and the right to grievance redressal, including contacting our grievance contact (Section 13).
  • All other jurisdictions — we extend the same core rights (access, correction, deletion, and objection) to all users of the Service regardless of location, to the extent technically and legally feasible, and will aim to respond within 30 days.

10. Age requirement and children's privacy

The Service is intended solely for users who are at least 18 years old, worldwide — including in India, where the Digital Personal Data Protection Act, 2023 defines a "child" as anyone under 18. We do not offer a parental-consent mechanism, so if you are under 18 you are not permitted to create an account or use the Service. Account creation relies on your Google account's own age standing — we do not perform independent, separate age verification beyond that. If we learn that we have collected personal data from someone under 18, we will delete the associated account and data promptly. If you believe this has happened, contact us at support@inframiq.com.

11. Data breach notification

In the event of a security incident that results in unauthorized access to your personal data and creates a risk to your rights, we will assess the scope and severity of the incident, take reasonable steps to contain it, and notify affected users and, where legally required, the relevant supervisory authority (such as under GDPR's 72-hour rule where applicable, or as required under the DPDP Act and its rules), without undue delay.

12. EU/UK representative

We have not currently appointed a representative in the European Union or United Kingdom under GDPR Article 27 / UK GDPR. We will appoint one, and update this section with their contact details, before we actively market the Service to, or process data at scale from, users in the EU/UK on an ongoing basis. Until then, EU/UK users can reach us directly using the contact details in Section 1.

13. Grievance contact (India)

We have not yet formally designated a named Grievance Officer with the title and contact particulars that Indian law expects to be published. Until we do, grievances regarding this Policy or the handling of your personal data can be sent to support@inframiq.com, which is monitored by Inframiq Solutions Private Limited. We aim to acknowledge grievances within 24 hours and resolve them within 15 days, and we will update this section with a named officer's details as our operations formalize.

14. Changes to this Policy

We may update this Policy from time to time to reflect changes in our practices or for legal, operational, or regulatory reasons. We will post the updated Policy on this page with a revised "Last updated" date, and for material changes we will provide additional notice (such as an in-app notification or email) before the change takes effect. Where a change requires your consent under applicable law, we will ask for it rather than relying on continued use alone.

15. Contact and governing law

This Service is operated by Inframiq Solutions Private Limited. Questions, requests, or complaints about this Policy can be sent to support@inframiq.com. This Policy is governed by the laws of India, without prejudice to any mandatory data protection rights you may have under the law of your own country of residence, as described in Section 9. See our Terms of Service for the jurisdiction and dispute-resolution terms (Visakhapatnam, Andhra Pradesh, India) that apply to your use of the Service more broadly.