Last updated 6 August 2026
This describes what Khata AI stores, where it is stored, and which other companies see any of it. It is written to match what the software actually does.
| Data | Why |
|---|---|
| Name and email address | To identify your account and send you verification, password reset and filing reminder emails. |
| Password | Stored only as a bcrypt hash. We cannot read it or recover it for you. |
| Google or GitHub profile (name, email, profile picture URL) | Only if you choose to sign in with one of those. We do not receive your password and we ask for nothing beyond your basic profile and email. |
| Business name, GSTIN, state, phone number, address | These appear on the invoices you issue. The state decides whether an invoice gets CGST + SGST or IGST. |
| Invoices you create — customer name, state, GSTIN, address, line items, quantities, rates, tax and totals | This is the product. |
| Photographs of bills you upload | To read the line items off them. See below. |
| A session cookie | To keep you logged in. It holds a random identifier, nothing about you. |
There are no analytics scripts, advertising trackers or third-party cookies on this site.
We send only the image and the reading instructions — no name, email or account identifier travels with it. We do not keep a copy of the image after the response comes back; it is held in memory for the duration of the request and never written to disk. What OpenRouter and the model provider do with it is governed by their own terms, so please read them.
Everything the AI returns is a suggestion, including quantities, rates, HSN codes and GST slabs. It misreads figures. You are shown every value before an invoice is issued and you are responsible for checking them.
Your account and invoices are stored in a file on the server that runs this instance of Khata AI. They are not kept in any third-party database or cloud storage service, and they are not sold, rented or shared for marketing.
Your account and invoices are kept for as long as your account exists, because invoices are business records you may need later. Email verification links expire after 24 hours and password reset links after one hour; both are stored as hashes, never in readable form.
The site is served over HTTPS. Passwords are hashed with bcrypt. Sign-in attempts are rate limited. Session cookies are marked HttpOnly, Secure and SameSite=Lax, and requests that change data are rejected unless they come from this site.
No system is perfectly secure. If you find a problem, please tell us at the address below rather than disclosing it publicly, and we will fix it.
Khata AI is a business tool and is not intended for anyone under 18.
If this policy changes in a way that affects how your data is handled, we will update the date at the top and, for anything significant, email account holders.
Questions, data requests or security reports: cintan.mht@gmail.com