Thali

Privacy Policy

Thali — a sole proprietorship based in India Last updated: 1 August 2026 · Draft pending legal review

This is a working draft for a private beta and is not yet legal advice. It is written for the Digital Personal Data Protection Act, 2023 (India) and should be reviewed by Indian counsel before public launch.

This policy explains how Thali ("Thali", "we") handles your personal data when you use Thali. Under the Digital Personal Data Protection Act, 2023 (the "DPDP Act"), you are the Data Principal and we are the Data Fiduciary.

1. What we collect

  • Account data you give us: name, email and/or phone number, and — when you add credit — payment and invoice details processed by our payment partner.
  • Usage metadata created as you use the Service: which model you called, token counts, timestamps, latency, cost, and API-key identifiers. This is what we meter and bill on.
  • Technical data received automatically: IP address, browser/device type, and server log data, used for security and to keep the Service running.

2. What we do NOT collect

  • We do not store the content of your prompts or the model's completions. They pass through to the model and are not written to our database or logs.
  • We do not use your prompts or outputs to train models.
  • We do not knowingly collect data from anyone under 18.

3. Why we process your data (purposes)

To create and secure your account; to route, meter and bill your usage; to issue invoices; to prevent fraud and abuse; to provide support; to comply with law; and to send you service and account communications. We process your data on the basis of your consent and, where applicable, for the performance of our contract with you and our legitimate uses permitted under the DPDP Act.

4. Who we share it with

  • Model providers (e.g. Novita) receive the request needed to serve your call, under their own terms. We do not sell your personal data.
  • Payment and invoicing partners process your payments.
  • Infrastructure/hosting providers that run the Service.
  • Authorities, where required by law.

5. Where it is processed

The Service and some model providers operate outside India; requests to those models are processed on global infrastructure. Models we mark hosted_in: "in" are served from infrastructure in India. You can filter the catalog for these. Any cross-border transfer is done consistently with the DPDP Act.

6. Retention

We keep account and billing records for as long as your account is active and thereafter as required for tax, accounting and legal purposes (generally up to 8 years for financial records under Indian law). Usage metadata is retained for operational and audit needs and then deleted or aggregated. Prompt/completion content is never retained.

7. Your rights as a Data Principal

Under the DPDP Act you may: access a summary of your personal data and how it is processed; correct or complete it; erase it (subject to legal retention); withdraw consent; nominate another person to exercise your rights; and raise a grievance. To exercise these rights, contact privacy@thaliai.in.

8. Grievance redressal

If you are not satisfied, you may contact our Grievance Officer, and you have the right to complain to the Data Protection Board of India.

Grievance Officer — Thali — grievance@thaliai.in

9. Security

We use reasonable technical and organisational measures — encryption in transit, hashed API keys and credentials, access controls, and a no-content-retention design — to protect your data. No system is perfectly secure; we will notify you and the Board of a personal-data breach as required by the DPDP Act.

10. Cookies

We use cookies as described in our Cookie Policy. You can manage optional cookies from the cookie settings link in the site footer.

11. Changes and contact

We may update this policy; material changes will be notified. Contact: privacy@thaliai.in.