Privacy Policy
Last updated July 2026
How Narada handles your information. In short: your data is yours, we only read it, we never sell it, we don't track you, and every connection is read-only and encrypted.
1. Who we are
Narada (“Narada”, “we”, “us”) is an early-stage product, currently operated by its founding team. Narada is not yet incorporated as a registered company; once a formal operating entity is established, it will be named here. The marketing site is naradaos.com and the application is app.getnarada.io. For any privacy question, contact privacy@naradaos.com.
2. The two kinds of data we handle
- Account data — the information needed to run your workspace: name, work email, role, and your workspace/company name. Provided by you or your administrator.
- Client Data — the operational data you connect (ERP exports by file upload, email, or a read-only ERP connection). This is your business data, which we process on your behalf to run diagnostics and produce findings, briefings and reports. We act as a processor of Client Data; you remain the controller. See our Security & Data Processing page.
- Payment data — handled entirely by our merchant of record, Dodo Payments (PCI DSS Level 1). Your full card details go straight to Dodo Payments and never touch Narada’s servers; we receive only what we need to manage your subscription (e.g. plan, billing status, and a masked card reference).
3. Cookies & tracking
The marketing site (naradaos.com) sets no cookies and uses no advertising or cross-site trackers. For basic traffic measurement we use Cloudflare Web Analytics, which is privacy-first: it sets no cookies, does not fingerprint your device, and collects no personal data — only aggregate page views and performance metrics, with no profile of you built. The application (app.getnarada.io) uses only the strictly-necessary cookies required to keep you signed in and your session secure; it does not track you across other sites, and we never sell activity data.
4. How connections work
- Every connection is read-only — Narada never writes back to your ERP or systems.
- ERP credentials and data are encrypted in transit (TLS/HTTPS) and at rest; integration connections are SSRF-guarded.
- Each customer’s data is isolated per tenant.
5. How we use data
We use data only to provide and improve the service for you:
- Run the nightly diagnostics and generate findings, briefings, the Impact Ledger, and recommended actions.
- Send the product emails you’ve enabled (briefings, collections drafts you choose to send, account notices).
- Operate, secure, debug and support the service.
Where data-protection law (such as the GDPR) requires a legal basis, we rely on: performance of our contract with you (to provide the Service and process payments); our legitimate interests in operating, securing, debugging and improving the Service; your consent where we ask for it (e.g. optional product emails, which you can withdraw at any time); and compliance with legal obligations (e.g. tax and accounting records). For Client Data we act only on the documented instructions of the customer who is the controller.
We do not sell your data, and we do not use Client Data to train shared or third-party models.
6. AI processing
Narada uses machine-learning models that run on your own data, plus a language model to write plain-English explanations of findings. AI enrichment is computed in our pipeline (not at page-load), is grounded strictly in your own findings and figures, and never invents numbers. The language model is Anthropic’s Claude, accessed through its API as a sub-processor under contract: prompts are not used to train its models and are not retained for model improvement.
7. Sub-processors
We use a small number of vetted providers to deliver the service — currently Railway (cloud hosting, United States), Anthropic (the Claude language model), Dodo Payments (our PCI DSS Level 1 merchant of record, which processes card payments and handles global sales tax), plus an email-delivery provider for the product emails you enable. Each is bound by data-protection terms, and the model provider is contractually barred from training on your data. A current list is available on request at privacy@naradaos.com.
8. Retention & deletion
We retain Account and Client Data for as long as your subscription is active and for up to 90 days afterwards to allow reactivation, then delete or anonymise it. You can request immediate deletion instead — on a verified request we will erase your Client Data without waiting out the 90 days. You can request export or deletion of your data at any time by emailing privacy@naradaos.com; we action verified requests within 30 days (and promptly for immediate-deletion requests). Some records may be kept longer only where the law requires (e.g. tax and billing records held by our merchant of record).
9. Your rights
Depending on your jurisdiction, you may have rights to access, correct, export, or delete your personal data, and to object to or restrict certain processing. Contact us to exercise them. For Client Data, we act on the instructions of the customer who is the controller.
10. Security
We apply encryption, tenant isolation, least-privilege access, and a supervised activation review before any figure is shown. Full detail is on the Security & Data Processing page. If we ever become aware of a breach affecting your data, we will notify affected customers without undue delay — and, where feasible, within 72 hours of becoming aware.
11. International transfers & governing law
Data is processed in the United States, our current hosting region. Where required, we use appropriate transfer safeguards. Until Narada is incorporated, this policy is governed by the laws of India, where Narada’s operator is currently based; a specific governing-law jurisdiction will be confirmed on incorporation.
12. Changes
We may update this policy; we’ll change the “last updated” date above and, for material changes, notify account administrators. Questions: privacy@naradaos.com.