Privacy Policy
Effective date: June 30, 2026. Last updated: July 27, 2026.
This policy explains how CoreDhristi ("we", "us", "our") collects, uses, and protects your information when you use coredhristi.com and related services.
1. Who We Are
CoreDhristi is an AI workforce marketplace operated from Indore, Madhya Pradesh, India. Our platform connects developers who build AI agents with businesses that hire them. For data protection purposes, CoreDhristi is the data controller for information collected through this website.
Contact for privacy matters: security@coredhristi.com
2. Information We Collect
2.1 Information you provide directly
- Account registration: full name, email address, phone number (required for OTP verification), password (stored as a bcrypt hash, never in plaintext).
- Profile data: professional bio, GitHub URL, skills tags, profile photo URL.
- Company data: company name, company size, industry, GST number (optional).
- Payment data: billing address, GST details (if provided). We do not store card numbers or UPI credentials. Payment processing is handled by Razorpay (India) and Stripe (international).
- Support communications: messages sent to our support and security email addresses.
- Listing review answers (creators): the security scope questionnaire you complete when you submit a listing, covering what your agent can access, what it could affect if it misbehaved, and whether it asks for human approval before an irreversible action. It is stored with your listing and shown to our review process.
- Promotion records (creators): if you pay to promote a listing, we store which listing, the amount and currency, and the period it runs for.
2.2 Information collected automatically
- Usage data: pages visited, features used, session duration, click events (via Vercel Analytics and Speed Insights).
- Device and browser information: IP address, browser type, operating system, screen resolution.
- Approximate location (country): we derive your country from your IP address at signup and at checkout. We use it to show prices in your local currency, to route your payment to the correct processor, and, in aggregate, to show sellers and our team which countries their agents are used in. We store only the two-letter country code, never a precise location.
- Cookies and local storage: session tokens (HTTP-only cookies), a consent record when you accept our Terms and this Policy at signup, and 30-day cookies for the Skills copy feature.
- Transaction records: for every payment we store the amount charged, the amount that went to the creator, our commission, and the service fee, along with the payment processor's own reference. We keep these as our accounting record and as the evidence behind your receipt.
2.3 Information from third parties
- Google OAuth: if you choose to sign in with Google, we receive your name, email address, and profile photo from Google.
- Payment processors: Razorpay and Stripe provide us with transaction identifiers, payment status, and payer country. Neither shares card data with us.
3. How We Use Your Information
- To create and manage your account and authenticate you on login.
- To display your profile in the marketplace (creators and agent builders only, based on your role selection).
- To process payments, issue invoices, and calculate the 80/20 revenue split for creators.
- To send transactional emails: account creation, OTP codes, payout notifications, subscription confirmations (via Resend).
- To operate the CoreDhristi AI assistant: your chat messages are sent to our third-party AI infrastructure provider and processed by a language model. Raw messages are kept briefly (30-90 days) for quality purposes, and a running summary of your business needs is kept for as long as your account is active so the assistant does not re-ask what you already told it - see Section 6 for the exact retention periods.
- If you explicitly ask the assistant to look at your business's own public website, we fetch that one page, extract structured business facts from it (never a person's name, email, or phone number), and store those facts - never the raw page - to inform your conversation. This only ever happens after you agree to it in chat; see Section 6 for retention and how to have it forgotten immediately.
- To detect fraud, enforce rate limits, and maintain platform security (using Upstash Redis for session and rate-limit state).
- To improve the platform through aggregated, anonymised analytics.
- To send product updates if you opted in during signup (you can unsubscribe at any time).
We do not use your information to train AI models. We do not sell your data to third parties.
3.1 Shared data access within company teams
If your company account uses team seats, members you invite and who accept access can see shared data belonging to that company account: hired agent deployments, license keys, invoice and payment history, and usage or logging history. This sharing happens only within your own company's team, not across different companies. The company account owner (Admin, or Owner for an AI agent development company) and any member with the Finance role can manage who has access; a Hiring or Product member sees only what their role needs.
3.2 Access by the CoreDhristi team
Members of the CoreDhristi team can access your data only through named permissions granted to them individually, not because of a job title. Permissions are granted by a Super Admin, are limited to what that person needs (for example, a finance role can see payments but not your private conversations), and every grant, change and removal is written to an audit log with the exact permissions involved.
Two-factor authentication is mandatory for every member of the CoreDhristi team, and for the Owner, Admin and Finance roles on company accounts, before they can open a dashboard at all. Sensitive actions, including refunds, account suspensions, reading a conversation for a dispute, and any change to platform-wide settings, are recorded in our audit log with who did it and when.
4. Legal Basis for Processing (GDPR)
For users in the European Economic Area (EEA) and United Kingdom, we process your data under the following lawful bases:
- Contract performance: processing necessary to provide the service you signed up for (account management, payments, marketplace access).
- Legitimate interests: fraud prevention, platform security, aggregate analytics.
- Consent: optional product update emails (withdrawable at any time).
- Legal obligation: compliance with applicable Indian tax and regulatory requirements.
5. Third-Party Services
We use the following third-party services that may process your data:
- Razorpay: payment processing for INR transactions. Privacy policy.
- Stripe: payment processing for USD/international transactions. Privacy policy.
- Supabase: cloud file storage for assets and images. Data is stored in AWS infrastructure.
- Upstash Redis: in-memory state for rate limiting, OTP lockout, and session management. Upstash does not store personally identifiable data beyond session keys.
- Hosting partners (affiliate links): the "Host Your Agent" page links to third-party hosting providers CoreDhristi has an affiliate relationship with. Clicking one of these links takes you to that provider's own website, where their own privacy policy applies - CoreDhristi does not share your account data with a hosting partner merely by you clicking the link, and only knows that a click occurred, not who made it (see Section 9 on Cookies for how anonymous click analytics work). The related liability disclaimer (CoreDhristi is not responsible for a hosting partner's own service) is in Section 13.2 of our Terms and Conditions.
- AI infrastructure provider: powers the CoreDhristi AI assistant. Chat messages are transmitted to that provider's servers for processing. As of 2026-08-23, we technically restrict this routing to a small allow-list of approved infrastructure providers, and explicitly exclude China-based AI infrastructure providers from serving this traffic. We do not currently guarantee a single specific country of processing, since our approved providers operate multi-region infrastructure. We name our current provider on request: write to privacy@coredhristi.com and we will tell you who it is and, to the best of our knowledge, where it processes data. The business information this assistant is designed to collect (industry, pain points, tools you use, and similar operational detail) is not, in our assessment, "Sensitive Personal Data or Information" as defined under Rule 3 of the IT (Reasonable Security Practices and Sensitive Personal Data or Information) Rules, 2011 - that definition covers specific categories such as passwords, financial/payment instrument details, health records, and biometric data, not ordinary business context. Regardless, please do not send sensitive personal information (passwords, card or bank details, health information, or similar) in the chat - it is not requested and not needed to help you.
- Message Central: OTP delivery via SMS to your registered phone number.
- Resend: transactional email delivery (receipts, OTPs, notifications).
- Vercel: hosting and edge infrastructure. Vercel Analytics and Speed Insights collect anonymised performance data.
- Google Fonts: font files are loaded from Google servers, which may log your IP address.
5.1 GitHub App access
If you connect GitHub from the creator dashboard, you install the CoreDhristi GitHub App on the repositories you choose. This grants CoreDhristi scoped, read-only access to the contents of those repositories only. That access is used exclusively to run the automated layers of the 7-layer review (secret scanning, static analysis, dependency and supply-chain scanning, QA/functionality checks, automated attack-simulation, workflow/MCP verification, and data-claim cross-check with SBOM generation) before a listing is approved. We do not request write access, do not access repositories you have not explicitly selected, and never share your GitHub URL or repository contents with companies who hire your agent.
5.2 Scan-only certification, and code protection at install
Added, 2026-08-06: if you submit an agent, automation, or MCP server for a stand-alone certification without listing it on the marketplace, we collect the same information a listing submission would (agent name, version, and repository access via the GitHub App above, under the identical read-only, scoped-to-your-selected-repos consent described in 5.1 - certification does not request or use any additional GitHub access). The scan result, verdict, and certificate are used only to issue and publicly verify that certificate; we do not share the underlying repository contents with anyone.
Separately, every code delivery to a company that hires your agent embeds a disclosed, per-license identifier (a “license fingerprint”) unique to that company and subscription, so that a leaked copy of your code can be traced back to the account that leaked it. This identifier contains only internal reference IDs, never personal data about the company's own staff. If we detect a suspected leak, we may email the licensed company a warning using the contact details on their account. See coredhristi.com/trust for the full, non-technical explanation of what this does and does not protect.
6. Data Retention
- Account data is retained for as long as your account is active, plus 3 years after deletion (for legal and tax compliance).
- Transaction records are retained for 7 years in accordance with Indian tax law.
- Support communications are retained for 2 years.
- Update, 2026-07-29: the line previously here ("messages to the CoreDhristi AI assistant are not stored beyond the current session") predated a product change and was inaccurate as of this update - corrected below rather than left to quietly drift from what the product actually does.
- Your individual messages to the CoreDhristi AI assistant are encrypted at rest and kept for 30 to 90 days (60 by default) for quality and debugging purposes, then deleted automatically. A running summary of what the conversation established about your business (industry, pain points, and similar) is kept, separately from your raw messages, for as long as your account is active so the assistant does not ask you the same things again on a later visit; it is deleted when your account is deleted.
- If you explicitly agree, in chat, to let the assistant look at your business's own public website, we fetch and store facts extracted from that one page only (never the full page content), each one labelled as a confirmed fact or an inference, for 30 days by default, and only after your consent - we never fetch a page you have not agreed to. We do not extract or store an individual's personal name, email, or phone number from that page even if it is publicly listed there. You can ask the assistant to forget a site at any time, which deletes it immediately rather than waiting for the 30-day window.
- In-platform chat messages between a Company and a Developer are encrypted at rest and retained for up to two years. We rely on legitimate interest and, where applicable, the establishment or defence of legal claims as the basis for this retention: a written record is necessary to resolve disputes fairly without contacting each party individually. Messages are automatically purged after the retention period.
- Lead details you provide to the CoreDhristi AI assistant (name, email, phone, role) are retained to follow up on your enquiry; marketing follow-ups are sent only if you gave the separate, optional marketing consent, which you may withdraw at any time.
- Security scan results, including your listing's scope questionnaire answers, are retained for as long as the listing exists and for 3 years afterwards, so we can show why a listing was approved if it is ever questioned.
- Promotion records are retained with the transaction they belong to, for the same 7 years as other financial records.
- Added, 2026-08-06: certificate records (both the free certificate issued with an approved listing and a paid stand-alone certification) are retained for as long as the certificate remains publicly verifiable, and for 3 years afterwards - the same period as other security scan results above, since a certificate is itself a scan-result artifact. Paid certification purchases are retained with other transaction records, for the same 7 years.
- Audit-log entries recording actions by the CoreDhristi team are retained alongside the financial records they relate to, for the same 7 years. We rely on legitimate interest and on our legal recordkeeping obligations: without a durable record of who did what, we cannot investigate a security incident or answer a regulator honestly. If you ask us to erase your account, these entries are kept but your personal details in them are anonymised, which is the exemption Article 17(3)(b) of the GDPR provides for.
- Session cookies expire when you close your browser. Remember-me tokens expire after 30 days.
- Phone OTP verification records (used for signup and login) are deleted 30 days after they expire.
7. Your Rights
The rights below are common across jurisdictions. Regional specifics follow.
- Access: request a copy of the personal data we hold about you.
- Rectification / correction: correct inaccurate or incomplete data.
- Erasure / deletion: request deletion of your account and associated data, subject to legal retention requirements.
- Portability: receive your data in a structured, machine-readable format. You can do this yourself at any time from Dashboard, Settings, Your data: “Download my data” produces a JSON file of everything we hold about your account. Credentials (passwords, two-factor secrets, licence keys, integration tokens) are deliberately excluded, because putting them in a downloadable file would create a security risk rather than remove one.
- Objection: object to processing based on legitimate interests.
- Withdraw consent: unsubscribe from marketing emails at any time using the link in any email.
To exercise any of these rights, email security@coredhristi.com. We will respond within 30 days.
7.1 India: Digital Personal Data Protection Act, 2023 (DPDPA)
As a matter of good practice, and in line with the Digital Personal Data Protection Act, 2023 (DPDPA) as its provisions come into force in phases, we already extend you the right to nominate another individual to exercise your rights on your behalf in the event of your death or incapacity, and the right to file a complaint with our Grievance Officer (Section 16 of our Terms and Conditions). Once the Data Protection Board of India is constituted and this Chapter of the DPDPA is in force, you will additionally be able to escalate a complaint to the Board; until then, our Grievance Officer (see the notice at the bottom of this page, which reflects our current obligation under the Information Technology Act, 2000) is the authority who handles these requests today.
For reference, the DPDPA's phased commencement is currently scheduled as: the Consent Manager framework (Section 6(9), Section 27(1)(d), and the related Rules) twelve months after the Rules' notification, i.e. on or around 13 November 2026; and the Data Principal rights and Data Protection Board escalation mechanism described above eighteen months after that notification, i.e. on or around 13 May 2027. These dates come from the Government of India's own notified schedule as of the last time we checked and could still be moved by a further notification - they are not a guarantee, and we recommend independently confirming them if this date matters to you.
Data breach notification: if a personal data breach occurs that is likely to cause you harm, we will notify affected individuals without undue delay, and will notify the Data Protection Board of India once it is constituted and this requirement is in force. We treat this as our practice today, ahead of the DPDPA’s full commencement, not as a claim that the Board-notification duty is already legally binding on us as of the date above.
7.2 European Economic Area, UK, and Switzerland: GDPR / UK GDPR
In addition to the rights above, you have the right to lodge a complaint with your local data protection supervisory authority at any time. Our lawful bases for processing are set out in Section 4. Where we act as an online marketplace facilitating listings between Creators and Companies, our fraud-reporting mechanism (a "Report this agent" link on every listing, reviewed by our trust and safety team) serves as our notice-and-action process for illegal or harmful content, consistent with the transparency expectations of EU digital services regulation.
Data breach notification: in the event of a personal data breach affecting EU/UK residents, we will notify the competent supervisory authority within 72 hours of becoming aware of it, and will notify affected individuals directly without undue delay where the breach is likely to result in a high risk to their rights and freedoms, as required under GDPR Articles 33 and 34.
EU/UK representative (GDPR Article 27): a business based outside the EU/UK that offers services to EU or UK residents on an ongoing basis is generally required to appoint a local representative, unless its processing of EU/UK residents' data is genuinely occasional, low-risk, and does not involve special-category data at scale. We are reviewing whether CoreDhristi's EU/UK user base takes us outside that narrow exemption. If you are an EU or UK resident and want to know our current position on this, contact us at the email above.
Data Protection Officer: GDPR requires a DPO only where an organisation's core activities involve regular, systematic, large-scale monitoring of individuals, or large-scale processing of special-category data. CoreDhristi does not currently meet either threshold; we keep this under review as the platform grows.
International transfers: see Section 11 for the mechanisms (adequacy decisions, standard contractual clauses) we rely on when your data leaves the EEA/UK.
7.3 United States: CCPA / CPRA (California) and similar state laws
CoreDhristi does not sell or share your personal information for cross-context behavioural advertising, and has not done so in the preceding 12 months. You still have the right to know what personal information we collect, to request deletion, to correct inaccurate information, and to not be discriminated against for exercising any of these rights.
7.4 United Arab Emirates: Personal Data Protection Law (PDPL)
For users in the UAE, we aim to align with the UAE Personal Data Protection Law (Federal Decree-Law No. 45 of 2021), extending the same access, correction, and erasure rights described above.
This section describes our good-faith alignment with the UAE PDPL and is not a certification of compliance. If you believe a specific requirement applies to you and is not reflected here, contact us at the email above.
7.5 Saudi Arabia: Personal Data Protection Law (PDPL)
Saudi Arabia's Personal Data Protection Law, enforced by the Saudi Data and Artificial Intelligence Authority (SDAIA), applies to any organisation - wherever based - that processes the personal data of individuals in Saudi Arabia. For users in Saudi Arabia, in addition to the rights described above, we recognise your right to know the purpose and legal basis for our processing of your data at the point of collection, and we do not make consent a condition of using the Platform beyond what a specific processing activity actually requires. Requests to access, correct, or delete your data, or to limit our processing of it, are handled within 30 days, consistent with the timeline in Section 7 above.
Cross-border transfers: where your data as a Saudi resident is transferred outside Saudi Arabia (for example, to the infrastructure providers listed in Section 5), we rely on the destination country's data-protection standards and contractual safeguards, consistent with Section 11.
Data breach notification: in the event of a personal data breach affecting Saudi residents that poses a risk to you, we will notify you promptly with the contact details of the person responsible for data protection matters at CoreDhristi.
This section describes our good-faith alignment with the PDPL and is not a certification of compliance. If you believe a specific PDPL requirement applies to you and is not reflected here, contact us at the email above.
8. Security
We implement technical and organisational measures to protect your data:
- Passwords are hashed using bcrypt before storage.
- TOTP secrets for two-factor authentication are encrypted at rest using AES-256.
- All data in transit is protected by TLS 1.2 or higher.
- Rate limiting and account lockout prevent credential brute-force attacks.
- Security headers (CSP, HSTS, X-Frame-Options) are applied on all responses.
- Dependency scanning and static analysis (Semgrep, Betterleaks) run on all code.
- Two-factor authentication is mandatory for roles that control money, team access, or account settings (internal CoreDhristi staff, and the Owner/Admin and Finance roles on company accounts), and available optionally to everyone else.
- Internal administrative actions, such as granting a staff role, freezing an account, or changing a payout or security setting, are recorded in an internal audit log (actor, action, timestamp, IP address) that only authorised CoreDhristi staff can access, for accountability and to investigate security incidents.
To report a security vulnerability, email security@coredhristi.com. We commit to a 48-hour initial response SLA.
9. Cookies
We use the following cookies:
- next-auth.session-token (HTTP-only, Secure): authentication session. Expires after 30 days or on logout.
- copied_skill_[id]: tracks which Skills you have copied, enabling the copy-once UI. Expires after 30 days.
We do not use advertising cookies or third-party tracking pixels. You can clear cookies through your browser settings at any time; this will log you out.
When you accept or decline the cookie banner, we record that choice on our servers (timestamp, IP address, and browser user-agent, alongside your account if you are signed in) in addition to storing it in your browser. This server-side record is how we can demonstrate, if asked, that consent was actually given.
10. Children
CoreDhristi is not directed at anyone under 18. We do not knowingly collect personal data from minors. If you believe a minor has created an account, contact us at hello@coredhristi.com and we will delete it.
11. International Data Transfers
Your data may be processed in countries outside India, including the United States (Vercel, Stripe) and the European Union (Upstash). Our AI infrastructure provider operates multi-region global infrastructure; we restrict which providers may process this traffic (see Section 5) and exclude China-based AI infrastructure providers, but do not currently guarantee a single specific processing country for AI chat traffic. Where we transfer data outside India or the EEA, we rely on standard contractual clauses or the third-party service's adequacy certification to protect your data.
12. Liability for Agent and Automation Performance
This Privacy Policy governs how we handle your personal data; it does not set out commercial liability terms. If an Agent or Automation you use through CoreDhristi malfunctions and causes your company a direct financial loss, responsibility for that loss rests with the independent Creator who built it, not with CoreDhristi. The full terms, including the compensation CoreDhristi provides as a goodwill measure in this situation, are set out in Section 13.1 of our Terms and Conditions, which apply to both Companies and Creators.
13. Changes to This Policy
We may update this policy as our service evolves or as legal requirements change. Material changes will be communicated by email to registered users and by updating the "Last updated" date above. Continued use of CoreDhristi after the effective date constitutes acceptance of the revised policy.
14. Contact Us
For any privacy-related questions or requests:
- Email: security@coredhristi.com
- General: hello@coredhristi.com
- Address: CoreDhristi, Indore, Madhya Pradesh, India
If you are in the EEA and believe we have not addressed your concern, you have the right to lodge a complaint with your local data protection authority.
This Privacy Policy is governed by the laws of India, including the Information Technology Act, 2000 and the Digital Personal Data Protection Act, 2023. Disputes are subject to the exclusive jurisdiction of courts in Indore, Madhya Pradesh, India.
Grievance Officer: in accordance with the Information Technology Act, 2000 and rules made thereunder, the Grievance Officer for CoreDhristi is Krishanu Kaundilya, reachable at krishanukaundilya778@gmail.com.