Legal
Privacy policy
Last updated: 5 July 2026
What we collect
To run Kramo for a business, we collect a small set of things. Account and business information: your name, phone number, the business you register, and who on your team has access. Voice audio: the spoken entries you record while using the app, captured so a sale or stock movement can be turned into a ledger entry and, if a customer ever disputes what was said, replayed to settle it. Ledger entries: the sales, purchases, stock movements, and customer records that Kramo's voice, tap, and camera flows produce.
We do not ask for information we don't need to run the product. If a screen doesn't need a field to work, we don't collect it.
Your data is yours
Everything you record in Kramo belongs to you. Records you choose to keep private are end-to-end encrypted on your device before they ever reach us. What arrives at our servers is ciphertext: data scrambled with a key we never hold. We cannot read it, our staff cannot read it, and nobody who compels us to hand over data would get anything more than unreadable bytes.
Records you use to generate GST invoices and reports are processed on our servers so we can help you produce those documents.
At setup, you choose how your recovery key is kept. Under solo custody, you hold the only copy and Kramo holds nothing, so if you lose it, the private records tied to it are unrecoverable by design, not by accident, because there is no backdoor for us to use. Under witnessed custody, which you opt into and which we recommend for first-time smartphone users, a Kramo field agent safeguards a sealed, tamper-evident paper copy of your key under a logged chain of custody, so a documented, in-person recovery is possible if your own copy is lost. Either way, the server only ever holds ciphertext, and we cannot read your private records. See “Data and your recovery key” in our Terms for what that means for you.
Voice audio and retention
Voice is how Kramo works, so recording it requires your explicit, informed consent. You see and accept a plain-language consent screen before voice entry is turned on, and you can decline it and still use the tap and camera flows.
Audio for records processed on our servers is retained only long enough to be useful for correcting a parse or resolving a dispute with a customer, on a default retention window that you can shorten to immediate deletion or extend for a specific entry, at any time, from that entry's detail screen. Once the retention window passes, the clip is deleted automatically. We don't keep audio “just in case.” Audio tied to private records is encrypted on your device the same way those records are; we store an opaque blob and cannot listen to it under any circumstances.
You can delete any individual voice clip immediately from within the app, or request deletion of all your data at any time. See “Your rights” below.
How data is used, and not sold
We use the data you give us to run the product you asked for: turning speech into ledger entries and bills, keeping your stock counts accurate, generating GST-ready invoices, and sending reminders to your customers when you ask us to. We use aggregate, de-identified usage patterns to improve voice recognition accuracy and fix bugs.
We do not sell your data. We do not share it with advertisers. We do not use your business data to build products for anyone outside your own account.
Sharing with processors
A small number of specialist processors handle specific parts of the pipeline on our behalf, under contract, and only for the purpose of providing that part of the service:
- A speech-to-text provider: converts your recorded speech into text, so a spoken entry can become a ledger line.
- Google Gemini: reads photos of bills, delivery challans, and stock (vision / OCR), so a photo can become an inventory update.
Private, end-to-end encrypted records are never sent to these processors in a form they, or we, can read.
Your rights under the DPDP Act
India's Digital Personal Data Protection Act, 2023 gives you rights over your personal data, and Kramo is built to honour them:
- Access: you can ask what personal data we hold about you and your business.
- Correction: you can ask us to fix inaccurate account or business information.
- Erasure:you can delete individual voice clips immediately, or request deletion of your account and associated data. Transaction records processed on our servers may be retained beyond an erasure request where India's tax law requires it; we disclose that at the point of consent, not after the fact.
- Grievance redress: if you have a complaint about how we handle your data, you can raise it with the grievance officer at hello@kramo.in.
Security
Private records are protected by end-to-end encryption, the strongest guarantee we can make, because it means there is nothing on our servers to breach in a readable form. Records processed on our servers are encrypted in transit and at rest, access is scoped to what a given role actually needs, and every access to voice audio for dispute investigation is logged with a reason, visible to you in your own account.
No system is invulnerable, and we'd rather say that plainly than claim more than we can stand behind.
Contact
Questions about this policy, or about your data, can go to hello@kramo.in.