Legal
Privacy Policy
Last updated: 26 August 2026
1. Who we are
Ail is an AI-powered writing platform operated by Lahon Technologies ("we", "us", "our"). Our platform is accessible at ai.lahon.in and related subdomains. For any privacy-related queries, contact us at tech@lahon.in.
2. What information we collect
Account information: When you register, we collect your phone number, hashed password, country, and account type (Pay-per-package or Bring Your Own Key).
Conversation data: The messages you send and the AI responses generated in your conversations are stored to provide continuity within your chat sessions. Message content is encrypted at rest using AES-256-GCM with a unique key generated for your account, so your conversations cannot be decrypted using another user's key.
Uploaded documents: Files you upload (PDFs, images, Word documents) are stored to enable the AI to read and work with them in your conversation.
Payment information: We do not store your card or UPI details. Payments are processed by Razorpay. We store transaction amounts, status, and Razorpay order references only.
API keys (BYO plan): If you use the Bring Your Own Key plan, your Anthropic API key is encrypted using AES-256-GCM before being stored in our database. It is decrypted only in memory at the moment it is needed to fulfil your request and is never logged or exposed.
Usage data: We collect information about how you use the platform (pages visited, features used, and error logs) to improve the product. This data is not linked to your identity in analytics tools.
3. How we use your information
We use the information we collect to:
- Provide and improve the Ail service
- Process payments and manage your account
- Send you transactional communications (receipts, OTPs)
- Detect and prevent fraud and abuse
- Comply with applicable Indian laws and regulations
We do not use your conversation data to train any AI model, and we do not sell your personal data to third parties. For API usage terms relating to the underlying Anthropic Claude model, refer to Anthropic's usage policies.
4. Data retention
Your account data and conversations are retained as long as your account is active. If you delete your account, we delete your personal data within 30 days, except where we are required to retain it for legal or financial compliance purposes (e.g., transaction records).
Uploaded documents are automatically deleted 24 hours after upload. To request deletion of a conversation or your account, contact us at tech@lahon.in.
5. Data sharing
We share your data only with the following service providers, strictly to deliver the service:
- Anthropic: Your conversation messages are sent to the Anthropic API to generate AI responses. Anthropic's own privacy policy governs this processing.
- Razorpay: Payment processing. Your payment details are governed by Razorpay's privacy policy.
- Neon (database hosting): Your data is stored on Neon's PostgreSQL infrastructure, hosted in the US. Neon is SOC 2 Type II certified.
We do not share your data with advertisers, data brokers, or any other third parties.
6. Internal access for support and safety
Our own staff do not browse accounts at will. An authorized team member may access your account — including decrypted conversation content — only while one of the following is true:
- You have an open support ticket (raised via the in-app chatbot's "Support" tab) that hasn't yet been resolved, or
- Content you submitted was flagged by our automated moderation system and no team member has yet recorded what action, if any, was taken on it.
Access requires a written reason and is only possible for the duration one of the above stays true — closing your ticket, or a team member recording the action taken on flagged content, immediately ends eligibility for further access. Every access is recorded: which team member, the reason given, and the exact start and end time. This is separate from, and does not weaken, the encryption described in Section 7 — it is a logged, purpose-limited exception to it, not a bypass available at will.
7. Security
We implement reasonable technical and organisational security measures including:
- HTTPS encryption for all data in transit
- AES-256-GCM encryption for chat message content at rest, with a unique key per user account
- AES-256-GCM encryption for API keys at rest
- Bcrypt hashing for passwords
- HTTP-only, secure session cookies with 30-day expiry
- Rate limiting to prevent abuse
No method of transmission over the internet is 100% secure. If you believe your account has been compromised, contact us immediately at tech@lahon.in.
8. Your rights
Under the Digital Personal Data Protection Act, 2023 (DPDP) and applicable Indian law, you have the right to:
- Access the personal data we hold about you
- Correct inaccurate personal data
- Request erasure of your personal data
- Withdraw consent for data processing
To exercise any of these rights, email us at tech@lahon.in. We will respond within 30 days.
9. Cookies
We use a single session cookie (ailahon_session) to keep you logged in. This is an HTTP-only, secure cookie and does not track you across other websites. We do not use advertising or analytics cookies.
10. Children's privacy
Ail is not intended for use by children under 13 years of age. If you believe a child has created an account, contact us at tech@lahon.in and we will delete the account promptly.
11. Changes to this policy
We may update this Privacy Policy from time to time. Material changes will be communicated via email or a notice within the platform at least 7 days before they take effect. Continued use of the platform after the effective date constitutes acceptance of the updated policy.
12. Contact
For any privacy-related questions or requests:
- Email: tech@lahon.in