Taralipi Fill the survey

Privacy Policy

Effective Date: August 21, 2026  ·  Last Updated: August 21, 2026

The short version. Taralipi is a writing tool that runs on your computer. Your manuscripts live on your own machine — we have no copy of your book. When you use an AI feature, the text that feature needs is sent to us, and we pass it to an AI provider to get you an answer. We do not keep it; the two exceptions are written plainly below, and both are short-lived. We never train AI models on your writing. We measure whether features worked — did you accept the suggestion, did the citation resolve — and improve from those measurements.

1. Who we are

Taralipi is operated by Taralipi Private Limited, an Indian company. Full registration details are in §16.

For anything in this policy, including exercising your rights or making a complaint:

Gummireddy Sai Lohith Reddy, Grievance Officer

[email protected]

We answer within 30 days.

Under India's Digital Personal Data Protection Act, 2023, we are the Data Fiduciary for the personal data described here — meaning we decide why and how it is processed, and we are answerable for it.


2. Who can use Taralipi

Taralipi is for people aged 18 and over. We do not knowingly collect personal data from anyone under 18. If you believe a child has created an account, contact the Grievance Officer and we will delete it.


3. What stays on your device

This is the most important thing to understand about Taralipi, so it comes first.

Stored only on your computer, never sent to us:

If you never use an AI feature, no content of yours ever reaches our servers. You could use Taralipi offline indefinitely and we would hold nothing but your account record.

We are not being modest here — we genuinely do not have your manuscript, and could not produce it if asked.


4. What we collect

4.1 Your account

When you create an account: your email address, and a display name if you provide one. If you sign in with Google, we receive your email address and name from Google — never your Google password.

4.2 Your credit balance and usage

AI features consume credits. To run that fairly we record, for each AI request: which feature you used, which AI model handled it, how many tokens it consumed, what it cost, how long it took, and whether it succeeded.

This record does not include the text of your request. It is an accounting entry, not a copy of your writing.

4.3 What we do *not* keep

We do not store the text of successful AI requests. When an AI feature works, the content passes through our servers, goes to the AI provider, returns to you, and is not retained.

Two narrow exceptions, both below.

4.4 Exception one — when an AI request fails

If an AI request errors or returns something we cannot use, we keep that request and its response for 30 days so we can find out why and fix it. After 30 days it is deleted automatically.

This applies only to failures — typically a small fraction of requests. A request that worked is not kept.

4.5 Exception two — when you report a problem

If you tell us an AI result was wrong, we ask whether you want to send us the details. Nothing is sent unless you choose to send it.

Before it sends, we show you exactly what the report contains — including the passages from your manuscript it would include. You can see the actual text, and you can decline to include your writing and send only the result you are disputing.

Reports are deleted within 30 days.

4.6 Diagnostic data

If Taralipi crashes, we receive a technical error report — what failed and where in the code. These do not contain your documents.


5. What happens when you use an AI feature

Concretely, using a research or editing feature:

1. Taralipi selects the text the feature needs — a paragraph, a section, a search query.

2. That text is sent to our service over an encrypted connection.

3. Our service passes it to an AI provider (§7) to produce a result.

4. The result comes back to you and is stored on your machine.

5. We record the accounting entry from §4.2. The text is not retained — unless the request failed (§4.4).


6. Why we process your data

WhatWhyOur basis
Email, display nameYour account exists and you can sign inNecessary to provide the service
Credit balance, usage recordsCharge fairly, answer billing questionsNecessary to provide the service
Payment and purchase recordsStatutory accounting obligationsLegal obligation
Failed-request content (30 days)Diagnose and fix faultsNecessary to provide the service
Problem reportsInvestigate the issue you reportedYour consent, given per report
Crash diagnosticsKeep the app workingNecessary to provide the service
Outcome signals (accepted / dismissed)Improve feature qualityNecessary to provide the service

Where we rely on your consent, you may withdraw it at any time and we will stop. The only thing we ask consent for is a problem report (§4.5): you give it per report, so you withdraw it simply by not sending the next one, and you can have a report you already sent deleted by asking the Grievance Officer. Withdrawing is as easy as giving. Withdrawing does not undo processing already carried out lawfully.


7. Who else touches your data

AI providers — these receive your text when you use an AI feature

ProviderWhat it receives
OpenAIText sent to AI features
AnthropicText sent to AI features
Google (Gemini)Text sent to AI features
Mistral AIText sent to AI features, including document text for OCR
NVIDIAText sent to AI features
Voyage AI (Voyage AI Innovations Inc., a MongoDB company)Text for search and ranking

We use these providers under terms that do not permit them to train their models on our customers' content.

Research services — these receive search terms, never your documents

ServiceWhat it receives
OpenAlexBibliographic search queries
Semantic ScholarBibliographic search queries
UnpaywallPublication identifiers (DOIs)

Infrastructure

ProviderRole
SupabaseAuthentication — email, sign-in credentials
NeonDatabase — account records and credit ledger
Cloudflare (R2)Storage for the short-lived records in §4.4 and §4.5
RedisTransient job state while a request is running
Google CloudServers that run our service
SentryCrash and error reporting
DopplerConfiguration secrets (no customer data)

A current list is at taralipi.com/legal/sub-processors. We update it when it changes.


8. Where your data goes

We store and process your data in India and elsewhere in the Asia-Pacific region. Our servers run in Mumbai; some services we rely on operate from other Asia-Pacific locations.

The AI providers in §7 operate in the United States and the European Union, so when you use an AI feature your text is processed outside India.

Because infrastructure locations change as we grow, we keep the current list on a separate page rather than in this policy: taralipi.com/legal/data-regions. We update it whenever a location changes.

We only use providers that commit contractually to protecting the data we send them.

9. Your choices

AI features are optional. Taralipi's writing, organisation and export features work with no AI and send us nothing.

Problem reports are always your choice. Nothing is sent unless you send it, and you see the contents first.

You can delete your account at any time, from Settings or by contacting us. See §11 for exactly what that deletes.


10. How long we keep things

WhatHow long
Account recordUntil you delete your account
Credit balance and usage records90 days, then aggregated without identifying you
Failed-request content30 days, deleted automatically
Problem reports30 days
Crash diagnostics90 days
Payment and purchase records8 years — required by Indian company law
Anonymous aggregate statisticsIndefinitely (these cannot identify you)

11. Your rights

You may:

If you are in the EU or UK, you also have the right to complain to your national supervisory authority as well as to us, and to receive a copy of the personal data you gave us in a portable, machine-readable form — ask the Grievance Officer and we will send it.

Languages. This policy is published in English. If you would prefer it in any language listed in the Eighth Schedule to the Constitution of India, ask the Grievance Officer and we will provide it.

Contact the Grievance Officer in §1. We reply within 30 days.

What deleting your account actually does

Deleted immediately: your account and sign-in credentials; usage records; any failed-request content; any problem reports; anything running at the time.

Kept, with your identity removed: payment and purchase records. Indian company law requires us to retain accounting records for eight years. We remove your name, email and account identifier and keep only the financial entry. It can no longer be connected to you.

We will confirm in writing what was deleted and what was retained.

Your documents are on your own computer, so deleting your account does not touch them. That is yours to do — or not.


12. How we protect your data

Encrypted connections everywhere. Data we store is encrypted at rest. Access limited to staff who need it. Automatic deletion on the schedules in §10, so short-lived data cannot quietly become permanent.

If a breach affects your personal data, we will tell you and the Data Protection Board of India, as the law requires.

No system is perfectly secure. The strongest protection here is architectural: most of what you write never reaches us at all.


13. Automated decisions

AI features generate suggestions — edits, citations, observations about your manuscript. They are suggestions. Nothing is applied to your work without you choosing it, and no decision with legal or similarly significant effect is made about you automatically.


14. Changes to this policy

If we change how we handle your data, we will update this page and change the date at the top. For anything that materially affects you, we will tell you in the app or by email before it takes effect.

Previous versions are available on request.


15. Governing law

This policy is governed by the laws of India. Courts at Hyderabad have exclusive jurisdiction.


16. Contact

Gummireddy Sai Lohith Reddy, Grievance Officer

[email protected]

Taralipi Private Limited
CIN: U62011TS2026PTC219300
Flat No 301, 3rd Floor, Dega Silpabanyan, Ameenpur, Ramachandrapuram, Medak – 502032, Telangana, India

If we have not resolved your concern, you may complain to the Data Protection Board of India.