Legal

Privacy Policy

Last updated: 13 September 2026

This page explains what information Svarg collects, why, and how it's protected — including when you connect a third-party knowledge source like Confluence to ground your AI transformation blueprints in your organisation's own documentation.

What we collect

  • Account information — your name, email address, organisation name, and role, provided when you sign up or complete profile setup.
  • Blueprint content — the project objectives you describe and the AI transformation blueprints generated from them.
  • Connected knowledge source data — see the dedicated section below.
  • Visit information — see the dedicated section below.
  • Voice recordings, only if you choose to dictate — see below.

Voice input

Voice input is not currently enabled. No microphone is offered anywhere on this site, nothing is recorded, and nothing is sent to any transcription service. This section describes how it works if we switch it back on, and we will update the date at the top of this page when we do.

When it is enabled, you can describe your objective out loud instead of typing it. It only ever happens when you press the microphone button; nothing is recorded at any other time, and your browser asks your permission before the first recording.

  • The recording is sent to ElevenLabs, which converts it to text and returns it to us.
  • We do not store the recording. It exists on our server for the few seconds it takes to transcribe and is never written to disk or to our database.
  • The resulting text goes into the box on your screen, where you can edit or delete it. If you then generate a blueprint, that text is saved exactly as if you had typed it — and nothing more.

Visit information

When you open this website we record one entry per browsing session, whether or not you sign up or use the product. We do this to understand whether people are finding Svarg and what brings them here.

  • A partial IP address. We remove the last part of your address before storing it, so 203.0.113.45 is kept as 203.0.113.0. That is enough to tell one organisation apart from another and to work out the country; it is not enough to identify your device.
  • Country, derived from that partial address.
  • The page you opened and the site you came from — for example, that you arrived from a search engine or from LinkedIn.
  • Your browser's user-agent string, which describes the browser and operating system, not you.
  • A random identifier stored by your browser, so that returning counts as the same visit rather than a new one. It is not linked to your name or email unless you choose to sign up. Clearing your browser storage removes it permanently.
  • A campaign code, if you followed a link we sent you directly. This tells us that our message reached you.

We delete visit information automatically after 90 days.

To determine the country we send the partial address — never your full address — to ipapi.co. We do not use advertising trackers, we do not sell this information, and we do not build profiles that follow you across other websites.

If you would like your visit information removed sooner, email praneshbabykannan@svargai.com and we will delete it.

Connecting Confluence (and future sources: GitHub, SharePoint)

Svarg can connect to a customer's Confluence Cloud site via OAuth 2.0, either as an organisation-wide connection managed by a CTO or admin, or as an individual user's personal connection scoped to their own account. In both cases:

  • We request read-only access — Svarg never creates, edits, or deletes anything in your Confluence site.
  • We store your Confluence site identifier and OAuth access/refresh tokens, encrypted at rest using AES-256-GCM. Tokens are never logged or exposed in any API response.
  • We store the text content of pages you or your organisation explicitly choose to connect — titles, an AI-generated summary, and extracted text — used only to ground blueprint generation in your actual documentation. Diagrams, images, and spreadsheet attachments are not read.
  • This content may include personal data if your source pages contain it (e.g. author names) — we don't filter or redact this, so we recommend connecting spaces you're comfortable using for this purpose.
  • Disconnecting immediately and permanently deletes the stored connection and tokens. For an organisation-wide connection, all extracted documents for that organisation are deleted as well. For a personal connection, documents already linked to a specific blueprint remain as part of that blueprint's history, since they're already baked into content that's been generated — disconnecting stops any *new* linking, it doesn't retroactively unwind past generations.

The application Svarg builds for you

When Svarg builds and hosts an application for you, your operational records never come to Svarg. The application is built from the shape of your data — column names and a few invented example rows — and the records themselves go into the application, into a database that is yours, through its own Data page:

  • Files and exports (CSV, Excel, a WhatsApp chat export) are read in your browser and sent to your application's own server, never to Svarg.
  • Connected sources (Jira, Confluence, GitHub) keep their credentials encrypted in your application's database, with a key that exists only in your application's environment. Svarg holds neither the credentials nor the key.
  • Conversations inside your application — every question and answer — are kept in your application's database and are not sent to Svarg.
  • The Data page is unlocked by an owner key shown to you once at go-live; Svarg keeps only a hash of it. The public chat session cannot reach it.
  • Signing in to your application is with Google, or with a code sent by email, through Svarg — Google will only answer an address registered in advance, and your application has no mail transport of its own. Svarg passes the account's email address (and, from Google, the name and picture) to your application, signed, and keeps none of it; a code is kept only as a hash until it is used or expires. Your application holds its own record of its users, in its own database. Svarg does not know who uses your application.

What your application does tell Svarg is a short, fixed list of signals, so that Svarg can notice what you need next. The list is the whole of it, and your application shows the same list on its Data page:

  • question_asked — one question was answered: which capability answered, and when. Not the question.
  • feedback — a thumbs up or down on an answer: the vote, the capability, and when. Not the answer.
  • correction — what you said the answer should have been, in your words, when you chose to write it.
  • import — rows arrived on a dataset: the dataset name, the kind of source, and the count. Not a row.

Model calls your application makes pass through Svarg's gateway to the model provider so that usage can be metered; the gateway records token counts and cost and does not store the prompt or the reply. If you host the application yourself, you can point it at your own model keys and switch reporting off, and it runs in full.

How your data is protected

  • Third-party access tokens are encrypted at rest and never stored in plaintext.
  • Access to an organisation's connected knowledge is scoped to that organisation only — no cross-organisation data sharing.
  • Managing an organisation-wide connection (connecting, disconnecting, selecting spaces) is restricted to CTO and admin users for that organisation.
  • A personal connection and the documents linked through it belong to the connecting user; linking documents to a blueprint requires verified ownership of that blueprint.

Your choices

You can disconnect a Confluence connection at any time from the Knowledge Sources page, which immediately deletes the stored tokens. You can request deletion of your account and associated data by contacting us using the details below.

Contact

Questions about this policy or your data can be sent to praneshbabykannan@svargai.com.