Privacy Policy
Last updated: 17 August 2026
This policy describes how JeevanOS actually works today. It is written to be read, not to be survived — plain words, and nothing in it that the app does not do. Questions about any of it: message us — a real person reads it, and it does not depend on email working. You can also write to hello@khakta.com.
1. Who we are
JeevanOS is operated by Mehak Khakta, operating as a sole proprietor, based in India, at an address available on request through khakta.com/contact. For anything privacy-related, write to hello@khakta.com.
2. The short version
- There are two apps here, and they store things differently. The try-it demo keeps everything in your own browser. The account app keeps it on our server so it follows you between your phone and your laptop. Section 3 says exactly which is which.
- We do not run advertising networks or third-party trackers on this site.
- We do not sell, rent or share your personal data with advertisers. Ever.
- Nothing you write privately is reachable through any screen we have. There is no admin page that can open your diary — see section 4.
- You can export everything and delete everything, yourself, at any time.
3. What we actually collect
3.1 The try-it demo (khakta.com/app.html)
The demo needs no account and asks for nothing. Everything you create in it —
memories, diary entries, plans, mood logs, photos — is stored only in your own browser
using localStorage. Nothing you write in the demo ever leaves your device,
and we cannot see any of it. If you clear your browser data, or open the demo on a
different device or browser, that data will not be there, and we cannot recover it for
you. Use the Export button to keep your own copy.
The demo is a separate app. What you write in it does not move to an account by itself — export it and bring it with you if you want to keep it.
3.2 The account app (khakta.com/os/)
This is the app you sign in to, and it is the honest opposite of the demo: your data is stored on our server, because that is the only way it can still be there when you pick up a different phone. It is held on Hostinger infrastructure in Mumbai, India and sent over an encrypted connection (HTTPS).
What is stored for an account:
- Your account row — email address, a one-way hash of your password (never the password itself), when you joined, and your plan.
- Your life blob — everything you create in the app, held as one private record tied to your user id: diary, memories, plans, money, habits, your Memory Brain, your settings.
- Photos and files you attach — stored separately, compressed, under an id only your account uses.
- Things you deliberately share — a marketplace request, a bid, a social post, a provider profile. These are shared by design and other members can see them. The app says so at the moment you post.
- A count of AI actions per day, to apply your plan's limit.
We keep a daily backup of the database — compressed, stored outside the public web folder so it cannot be fetched from the internet, and only the newest 14 are kept. It is a compressed copy, not an encrypted one; we would rather say so than let the word "encrypted" do work it has not earned. Backups exist so a failure does not lose your life's writing; they are not browsed.
Being straight with you about one thing: your account data is stored as ordinary rows in our database, not encrypted field-by-field at rest. Encryption at rest would not protect you from us — only from someone who steals the disk — and we would rather tell you what is actually true than imply a protection we have not built.
3.3 The waitlist form
There is no waitlist form on the site at present. If one returns, this is all it would store:
- Name — so we can address you properly.
- Email address — to tell you when Pro opens.
- City (optional) — to decide which areas to launch in first.
- What you're interested in — Pro, listing a service, or the marketplace pilot.
- A one-way hash of your IP address and the page you arrived from, kept purely to block spam. The raw IP is not stored alongside your record.
Legal basis: your consent, given by submitting the form. We use this to contact you about JeevanOS only — not for unrelated marketing, and never sold on.
3.4 Server logs
Our hosting provider (Hostinger, servers located in Mumbai, India) keeps standard web server logs including IP addresses, for security and abuse prevention, under their own retention policy.
3.5 What we do not collect
No advertising cookies. No Google Analytics, Facebook Pixel, or similar third-party trackers. No location tracking. No contact-list access. No microphone or camera access unless you deliberately use a feature that asks for it — attaching a photo, or speaking to the app instead of typing. In the try-it demo a photo you attach never leaves your device. In the account app it is uploaded, because it has to travel with the note it belongs to; it is stored under an id only your account uses.
4. The diary promise, and exactly how far it goes
Every private read the server will answer is scoped to the account that asked for it. The database query that fetches your private data matches on your own user id and takes no account of who is asking beyond that — being the owner grants nothing. There is no administrative screen anywhere in this product that can open a member's diary, because there is no request that would return one. That is enforced in the server's code and held by an automated test that runs on every single release: if someone changed it, the release would fail rather than ship.
What that promise does not cover, said plainly. The founder runs the server, and anyone who runs a server can read its database directly. No product can promise otherwise without end-to-end encryption, which this app does not yet have. What we can promise, and do, is that no tool for doing it exists, no part of the product offers it, and the code is written so that adding one would break the build. If we ever build end-to-end encryption, this page will say so on the day it ships and not before.
We may still be legally required to disclose data in response to a valid, lawful order from an Indian authority. Where we are permitted to notify you, we will.
5. AI processing
The try-it demo makes no network calls at all. Its "Just Write" sorting runs on simple rules inside your browser. Nothing is sent anywhere.
In the account app, AI runs only when you press an AI button. Nothing is sent for reading, browsing or typing. When you do press one, we send that request to an AI provider — Anthropic, or another provider connected by the operator — together with your Memory Brain: the short set of facts about you that the app has gathered and that you can read, edit and delete yourself at any time in ⚙ Settings.
Your diary is never uploaded wholesale. Under our API terms your content is not used to train the provider's models. Each division of the app — you, your work, your business — sends only its own memory, so a question asked at work is never answered out of your personal life.
If you would rather it never learned anything about you, ⚙ Settings has a switch to stop the AI keeping its own notes, and every note it has ever kept can be deleted individually.
6. Payments
When paid plans launch, payments will be handled by an Indian payment gateway (Razorpay or Cashfree). Your card or UPI details are entered on their systems and are never seen or stored by us. We keep only the transaction reference, amount and status.
7. How long we keep things
- Waitlist entries: until you ask us to remove them, or until 24 months after launch, whichever comes first.
- Account data: for as long as your account exists. When you delete your account the rows are removed immediately, not queued for later — your life blob, your attachments, your usage counts and your login. The only copies that remain are in the daily backups, which age out within 14 days, after which nothing of it is left anywhere. Invoice records are kept where tax law requires it.
- Try-it demo data: entirely under your control — it lives on your device and we never receive it, so there is nothing for us to delete.
8. Your rights
Under India's Digital Personal Data Protection Act, 2023 — and equivalently under GDPR if you are in the EU/UK — you have the right to access, correct, export and delete your personal data, and to withdraw consent at any time.
In the app, 🧠 Brain → 🔒 Privacy holds ⬇ Download everything (your copy, a real file), 🔥 Erase my personal data (a fresh start, login kept) and 🗑 Delete my account entirely — these rights work directly, with no request needed. For waitlist data, email hello@khakta.com and we will action it within 30 days. If you're unhappy with how we handle it, you may complain to the Data Protection Board of India.
9. Children
JeevanOS is not intended for children under 18. We do not knowingly collect data from children. If you believe a child has provided us data, contact us and we will delete it.
10. Security
The site is served over HTTPS. Server-side data is access-controlled, and passwords — once accounts exist — will be stored hashed, never in plain text. No system is perfectly secure; if a breach ever affects your data, we will notify you and the Data Protection Board as required by law.
11. Changes
If we change this policy materially, we will update the date above and, where we have your email, tell you before the change takes effect.
Questions? hello@khakta.com · Terms · Refunds