Privacy Policy

Tharas runs on your machine. This policy sets out the narrow set of things that do leave it, who receives them, and what you can require us to do about it.

This notice is not yet complete. The following statutory details are still to be published: registered office address, corporate identity number (CIN), grievance officer, grievance officer email. Until then, contact us at tech@tharastech.com and we will respond on the same timelines set out below.

The short version

The engine that reads and writes your code runs locally. We do not upload your repository, and no feature of the product does. Three things do cross the network, and they are the whole of what this policy is about:

Stays on your machine

  • Your repositories, working trees and git history
  • Plans, task graphs and the memory index built from your code
  • Credentials and tokens you configure locally
  • Everything the dashboard shows you, which it serves locally

Leaves your machine

  • An entitlement check — who you are and what you have paid for
  • Model calls, which contain the excerpts of your code the task needs, forwarded to the model provider
  • Anonymous product telemetry with no free-form text field, and any feedback you choose to send

Who we are

Tharas Tech India Private Limited (“Tharas”, “we”, “us”) is the data fiduciary for the personal data described here, within the meaning of India’s Digital Personal Data Protection Act, 2023. Where the General Data Protection Regulation applies to you, we are the controller for account and billing data, and a processor for the content of the model calls you cause us to make.

What we collect

Account data
Your email address, your name if you give one, a password hash (never the password), your organisation and your role in it. You give us this when you create an account.
Subscription and billing data
Your plan, invoices, payment references from our payment provider, and the pre-debit notices we are required to send before a recurring charge. Card details are handled by the payment provider and never reach our servers.
Metering records
One row per model call: your organisation and user, the goal and task it belonged to, the capability tier, token counts and cost. This is what produces your invoice. It does not include the text of the prompt or the response.
Model call content
The prompts our engine sends on your behalf, which include the excerpts of your source, file paths and error output that the task requires. These pass through our proxy to the model provider. See model providers below.
Product telemetry
Anonymous, keyed on a random installation identifier and never on you. Every field is checked against a closed list twice — once on your machine and again on receipt — and anything not on that list is discarded before it is written. The list admits numbers, booleans and named values only, so a file path, a prompt or a snippet of your code cannot be carried by it even by accident.
Support and feedback
If you send feedback it is identified and free-form, because prose is the point. It may be linked to the goal it is about so we can diagnose what happened. This is a separate stream from telemetry and is never merged into it.
Platform audit trail
Sign-ins, organisation changes, imports and goal submissions made through our infrastructure, with the originating IP address. This is a security record.

Why we process it, and on what basis

PurposeDataBasis
Providing the productAccount, entitlement, model call contentPerformance of our contract with you
Billing and taxSubscription, metering records, invoicesContract, and legal obligation under Indian tax law
Keeping the service secureAudit trail, IP address, rate-limit countersLegitimate interest in preventing abuse
Improving the productAnonymous telemetryLegitimate interest; the data is not linked to an identified person
SupportFeedback you send usYour consent, given by sending it

Model providers, stated plainly

Tharas is useless without a language model, and running one on your laptop is not on offer. When a task needs a model, our proxy forwards the request to the provider selected by routing and streams the response back. That request contains whatever the task needed to see: source excerpts, file paths, test output, error messages.

This is the one place your code content is disclosed to a third party, and it happens on every run. We hold the provider accounts, so the provider does not know who you are — but the content of the call is the content of your work, and we will not describe that as though it were anonymous.

We use providers who contractually undertake not to train their models on data submitted through business API accounts. We do not use your prompts, your code or your completions to train any model, and we do not sell any of it.

If your code may not be sent to a third-party model provider at all, the managed subscription is not the right product for you. Talk to us at tech@tharastech.com before you buy, rather than after.

Who else receives data

Model providers
Prompt and completion content, as described above.
Payment provider
Your billing details and payment instrument, handled directly by them. We receive a reference and a status, not a card number.
Infrastructure providers
Hosting and database services that run our control plane and store account, billing and metering data.
Email delivery
Your email address, to send sign-in, billing and the pre-debit notices we are required to send.
Product analytics (Mixpanel)
The usage events described below, forwarded by our own servers after they have been filtered. Mixpanel never receives your source code, file paths, project names, prompts, model output or search queries — the events cannot carry free-form text at all. It processes this on our instructions under a data processing agreement, and no Mixpanel code runs in Tharas, on this website or in our app.
Authorities
Where we are legally required to, and no further than the requirement.

We do not sell personal data, and we do not share it with advertisers.

Where it is processed

Our control plane and the model providers we route to operate outside India, so account, billing, metering and model-call data is transferred internationally. Where the GDPR applies, those transfers rely on the European Commission’s standard contractual clauses.

How long we keep it

Account data
For as long as your account exists, and then for as long as we need it to settle what is outstanding.
Invoices and metering records
Eight years, because Indian tax law requires books of account to be retained for that period. These cannot be deleted on request while that obligation runs.
Model call content
Not stored by us. The proxy streams it through and records only the metering row. Your model provider’s own retention applies to their copy.
Anonymous telemetry
Retained in aggregate. It is not linked to you and cannot be retrieved by reference to you.
Audit trail
Twelve months, then deleted.

Your rights

Under the Digital Personal Data Protection Act, 2023 you may ask us for a summary of the personal data we hold about you and how we process it, ask us to correct or complete it, ask us to erase it where we no longer need it, nominate someone to exercise these rights if you die or become incapacitated, and complain to the Data Protection Board of India. Where the GDPR applies you additionally have rights of access, portability, restriction and objection.

Write to tech@tharastech.com. We will acknowledge within 72 hours and respond substantively within 30 days. There is no charge. We will ask you to verify that the account is yours before we act, which is a protection for you rather than an obstacle.

Security

Passwords are stored as salted PBKDF2 hashes and never in a recoverable form. Session cookies are HTTP-only. Our public endpoints — the price list, the release manifest — accept no credentials at all, so a browser will not attach your session to them whatever a page asks. Release artifacts are signed, and the client verifies the signature before it installs anything.

No system is perfectly secure. If you believe you have found a vulnerability, write to tech@tharastech.com and give us a reasonable period to fix it before disclosing it.

Children

Tharas is not offered to anyone under 18. We do not knowingly process a child’s personal data, and we will delete it if we learn we have.

Cookies, and what the pages measure

The public pages set no cookies and carry no analytics or advertising scripts.Everything you can read without signing in — this page, pricing, the guides, the docs — measures nothing and stores nothing on your device. There is no banner to dismiss because there is nothing to consent to. If you are not signed in, these pages make no request to us at all beyond fetching the page itself and, on two of them, the current price list and release version.

The account area is different, and we would rather say so than bury it. Once you sign in:

  • One session cookie keeps you signed in. It is strictly necessary; without it you would be signing in on every page.
  • The pages record which part of your account you opened — overview, billing, keys, projects, profile — and how long the session lasted, against your account. Not the URL, not what you typed: a label from a fixed published list.
  • A session identifier is kept in your browser tab’s own storage so several page views read as one visit. It is not a cookie: it is never attached to a request, no other site can read it, and it is destroyed when you close the tab. It cannot follow you between visits.
  • A single yes/no flag is kept in your browser’s storage saying that you are signed in, so the header knows to show your account rather than asking us on every page you open. It holds nothing else — no name, no token, no identifier — it is never sent anywhere, and signing out removes it.
  • The download page tells your own account that you reached it, and that you started a download, so the setup progress on your account page moves while an install is still in flight. It is a fact about your account, like having a key, and it is recorded only when you are signed in.

Our mobile app hosts these same pages and behaves the same way. Your browser and the app never tell us who you are — the account is filled in by our own servers from the session you already authenticated with.

None of this is joined to the anonymous usage data the Tharas software on your machine sends. Those are stored separately, and an event that carries your account never carries the installation identifier that would connect the two. You can turn the machine side off entirely with tharas settings share_usage_data off; the account side stops when you sign out.

Changes

If we change this policy we will move the effective date at the top and, where the change materially affects you, tell you by email before it takes effect.

See exactly what stays local

The local-first design is a feature page, not a promise in a policy — it names the modules that enforce it.

How local-first works