Legal

Privacy Policy

How Intellara Technologies handles personal data in troveGEN — and, because the same product is sold three different ways, exactly which of those handlings applies to you.

Last updated 13 August 2026 · Applies to trovegen.com, the troveGEN API, and the troveGEN software when supplied for self-hosting.

Read this first

Which deployment model you are on changes everything below.

troveGEN is one engine sold in three shapes. The privacy consequences are not marketing distinctions — they determine whether Intellara holds your content at all.

SOVEREIGN · SELF-HOSTED

We hold nothing

You run troveGEN on your own infrastructure. Your documents, vectors, embeddings and logs never reach us. Intellara is not a processor of that data — you are both controller and processor. We hold only the account and billing data of whoever bought the licence.

BYO VECTOR DATABASE

We hold your text, not your vectors

troveGEN runs as a hosted service and writes embeddings into your vector database. But the extracted document text is stored in our Postgres, because the keyword half of hybrid search runs against it. We are a processor for that text.

MANAGED · troveGEN-Z

We hold your corpus

We host the documents, the extracted text and the vectors, in a Postgres schema and vector namespace dedicated to your workspace. We are a processor for all of it.

1. Who we are

Intellara Technologies Private Limited (“Intellara”, “we”), a company incorporated in India with its registered office in Bengaluru, Karnataka, operates troveGEN. For questions about this policy, to exercise a right, or to raise a grievance, contact [email protected]. We aim to acknowledge within 72 hours and resolve within 30 days.

Under India’s Digital Personal Data Protection Act, 2023, that address also reaches our grievance officer. Under the GDPR, it reaches the person responsible for data protection. We have not appointed a statutory Data Protection Officer, and we say so rather than implying an office that does not exist.

2. Roles: controller and processor

The distinction decides who owes you what, so we set it out explicitly:

  • Account data — we are the controller. Names, email addresses, workspace names, billing details, authentication records, support correspondence and usage metering. We decide why and how these are processed.
  • Customer content — we are a processor (on the managed and BYO models only). Documents you ingest, the text extracted from them, embeddings, queries you run, and answers generated. You remain the controller; we act on your instructions, which are the API calls and settings you configure.
  • On the Sovereign model we are neither. We never receive that data. If you self-host, this policy governs only your relationship with us as a customer, not your handling of your own users’ data.

Where we act as a processor for customers subject to the GDPR, a Data Processing Addendum incorporating the Standard Contractual Clauses is available on request. That DPA, not this page, is the contractual instrument.

3. Personal data we collect as a controller

  • Account. Name, email address, hashed password, workspace name and slug, role, email-verification state, and the timestamp of the last password change. Passwords are stored as bcrypt hashes; we cannot read them.
  • Billing. Legal name, billing address, country and state, tax identifier, plan, billing cycle, and a record of each payment. We never receive or store your card number. Payments are processed by Razorpay; we retain only what the processor reports back for display and reconciliation — the method (card, UPI, netbanking), the card network with its last four digits, or the bank or VPA.
  • Service operation. Request logs with a correlation identifier, tenant identifier, endpoint, status and duration; API key metadata and last-used timestamp; error reports; and usage counters (pages processed, searches, storage) used for entitlement enforcement and billing.
  • Communications. What you send us by email, and one-time codes issued for email verification and password reset (stored hashed, valid for minutes).

We do not use advertising cookies, third-party analytics or tracking pixels on this website or in the console. The console keeps your session in browser local storage, not in a tracking cookie. There is no consent banner because there is nothing to consent to.

4. Customer content: exactly what we hold, per model

This is the section most likely to be glossed over elsewhere, so it is written literally. On the Sovereign model, none of the following reaches us at all.

DataBYO vector databaseManaged (troveGEN-Z)
Original uploaded fileNot retained after processingNot retained after processing
Extracted text and chunksStored by us — the keyword half of hybrid search runs on itStored by us
Embeddings (vectors)Written to your database; we hold no copyStored by us in a namespace dedicated to your workspace
Extracted figures and imagesStored by us when figure extraction is enabledStored by us when figure extraction is enabled
Queries and generated answersProcessed in memory; stored only if you enable conversationsSame
Credentials for your own stores and modelsEncrypted at rest with AES-256-GCM, never returned by any API

If your documents contain personal data, we process it. troveGEN is content-agnostic — it will ingest a personnel file as readily as a product manual. Deciding what is lawful to put into it is the controller’s responsibility, which on the managed and BYO models is yours.

Two product features exist specifically to reduce that exposure, and both are opt-in: PII redaction detects identifiers before embedding, replaces them with tokens, and keeps the mapping in a separately encrypted vault, so raw identifiers never reach the vector store; and ACL enforcement filters retrieval by the end user’s permissions before results are ranked, rather than filtering afterwards.

5. Why we process it, and on what legal basis

PurposeBasis (GDPR Art. 6)
Providing the service you signed up forContract
Billing, invoicing and tax recordsContract; legal obligation
Security, abuse prevention and rate limitingLegitimate interests
Diagnosing faults and improving reliabilityLegitimate interests
Service and security notificationsContract; legitimate interests
Marketing email, where sentConsent, withdrawable at any time
Processing customer contentYour instructions, under the DPA

We do not train models on your content. Not our own models, and we do not permit it for our sub-processors. Your corpus is used to answer your queries and for nothing else.

6. Sub-processors

The managed service uses a small number of third parties. Which apply depends on your configuration — several are used only if you choose a hosted model rather than bringing your own.

ProviderPurposeWhen
Cloud infrastructure providerHosting, databases, backupsManaged and BYO
Razorpay Software Private LimitedPayment processingPaid plans only
Email relay (SMTP)Verification codes, service emailWhen a relay is configured
Embedding / reranking / LLM providersGenerating embeddings and answersOnly where troveGEN supplies the model. Bring your own and no third party receives your text through us

Every sub-processor is bound by written terms no less protective than this policy. We will give notice of a new sub-processor before it starts processing customer content, and you may object.

7. International transfers

Intellara is established in India. Depending on the region you choose, data may be processed in India or in the region hosting your deployment. Where personal data protected by the GDPR or UK GDPR leaves the EEA or UK, we rely on the European Commission’s Standard Contractual Clauses (and the UK Addendum), with a transfer risk assessment available on request.

Data residency is a deployment choice, not a pricing tier. If your obligations require content to stay in a particular jurisdiction, self-hosting or a BYO vector database in that region achieves it absolutely, rather than contractually.

8. Retention

  • Account data — for as long as the workspace exists, then up to 90 days.
  • Customer content — until you delete it or close the workspace. Deleting a document removes its chunks, its vectors (including from your own store, where troveGEN wrote them) and any PII vault entries for it. A failed vector deletion aborts the whole operation rather than silently orphaning data, so a delete that reports success has actually propagated.
  • Billing and tax records — retained for the period Indian tax law requires (currently up to eight financial years). These survive account closure because we are legally required to keep them.
  • Operational logs — typically 30 days.
  • Backups — deleted data persists in encrypted backups for up to 35 days before rotating out.

9. Security

Measures actually implemented, not aspirations:

  • TLS in transit; encryption at rest for databases and backups.
  • Credentials for your vector stores and model providers encrypted with AES-256-GCM and never returned by any API — a leaked database read does not yield a usable key.
  • Workspace isolation: managed tenants get a dedicated Postgres schema and vector namespace, with routing enforced by a check that fails the build if a query could read the wrong tenant.
  • Passwords stored as bcrypt hashes. Password reset and email verification use short-lived, hashed, attempt-limited one-time codes, and a completed reset revokes sessions created before it.
  • Rate limiting per account and per IP; scoped API keys that can be revoked individually.
  • Prompt-injection sanitisation on ingested content, and egress filtering on generated answers.

What we do not claim: we hold no SOC 2, ISO 27001 or HIPAA attestation today. We would rather state that plainly than let an unqualified “enterprise-grade security” imply one. If certification is a procurement requirement, tell us where you are in your process and we will be straight about ours.

If a breach affects your personal data, we will notify you without undue delay and, where the law requires, within 72 hours of becoming aware — with what we know at the time rather than waiting for a complete picture.

10. Your rights

Depending on where you live, you may have rights to access, correct, delete, port, restrict or object to processing, and to withdraw consent. Indian residents additionally have rights under the DPDP Act, including nomination; residents of California and similar jurisdictions have rights of access and deletion and to opt out of “sale” or “sharing” — we do neither, and never have.

Exercise any of these at [email protected]. We do not charge for a first request and will not penalise you for making one. Most account data is also directly editable or exportable from the console.

If your request concerns data inside a customer’s troveGEN workspace — for example you are an employee of one of our customers — we are the processor, not the controller. We will forward your request to that customer and support them in answering it, but we cannot alter their corpus on your instruction. That is the correct outcome, not an evasion: acting unilaterally on someone else’s data is precisely what a processor must not do.

You also have the right to complain to a supervisory authority — the Data Protection Board of India, or your local authority in the EEA or UK.

11. Children

troveGEN is a business product and is not directed at children. We do not knowingly collect personal data from anyone under 18. If you believe a child has provided us data, contact us and we will delete it.

12. Changes

We will update this policy as the product changes. The date at the top always reflects the current version. For a material change affecting how we handle personal data, we will notify account owners by email before it takes effect rather than relying on you to notice a new date.

Questions

Intellara Technologies Private Limited, Bengaluru, Karnataka, India · [email protected]

For how sovereignty is enforced technically rather than contractually, see Sovereignty.