Privacy Policy
Last updated: April 23, 2026
This Privacy Policy explains what information TinkerLLM collects, how we use it, and the choices you have. TinkerLLM is operated by Kalvium Labs ("we", "us", or "our"), an AI product studio based in India. If you have questions, write to us at support@tinkerllm.com.
We are committed to collecting only what we need and being clear about what we do with it. This policy applies to tinkerllm.com, app.tinkerllm.com, and related services (the "Service").
1. The short version
- We use Google Sign-In. We receive your name, email, and profile photo — nothing else from Google.
- Your API key stays in your browser. We do not store it on our servers or log your prompt content.
- Payments are handled by Razorpay. We never see or store your full card details.
- We use cookies and basic analytics to understand how the Service is used and to keep it running.
- We do not sell your personal data. Ever.
2. Information we collect
2.1 Information you give us directly
- Account information. When you sign in with Google, we receive your name, email address, Google account ID, and profile picture.
- Purchase information. When you buy the course, our payment partner Razorpay collects payment details. We receive a transaction ID, order status, the amount, and limited metadata (such as the last four digits of your card or UPI handle). We never receive or store full card numbers, CVVs, or banking passwords.
- Communications. When you email us, subscribe to the newsletter, or fill out a form, we receive the information you provide (such as your email address and the contents of your message).
2.2 Information generated by your use of the Service
- Progress data. Which lessons you have opened, which exercises you have completed, and your completion certificate details.
- Playground activity. Metadata about playground sessions (such as timestamps, model parameters, and exercise IDs). Your prompt and completion text stays in your browser and is sent directly to the third-party model provider — it is not stored on our servers or visible to us.
- Device and log data. IP address, browser type, operating system, referring URL, and pages viewed. This is used for security, debugging, and aggregate analytics.
- Cookies and similar technologies. We use a small set of cookies to keep you signed in, remember preferences, and measure traffic. See section 7 below.
2.3 Information we do NOT collect
- We do not store your Google AI Studio API key on our servers. It lives in your browser's local storage and is sent directly to Google.
- We do not log or store the contents of your prompts and completions.
- We do not receive your full card number, CVV, UPI PIN, or net banking password.
3. How we use your information
We use the information we collect to:
- provide, operate, and maintain the Service (including signing you in, tracking your progress, and unlocking paid content after purchase);
- process payments, issue receipts, and handle refunds via Razorpay;
- generate and deliver your completion certificate;
- send transactional emails such as receipts, refund confirmations, and important service updates;
- send the optional newsletter if you have subscribed (you can unsubscribe at any time);
- understand how the Service is used so we can improve lessons, fix bugs, and build new features;
- detect, prevent, and respond to fraud, abuse, and security incidents;
- comply with our legal obligations.
4. Legal bases for processing
Where applicable law (such as the EU GDPR or India's Digital Personal Data Protection Act) requires a legal basis for processing personal data, we rely on one or more of the following: your consent (for example, for optional newsletters and non-essential cookies); performance of a contract (to deliver the Service you purchased); compliance with a legal obligation (for example, tax and accounting records); and our legitimate interests in operating, securing, and improving the Service, where these are not overridden by your rights.
5. Sharing your information
We share personal data only with the following categories of recipients:
- Service providers. Trusted vendors who help us operate the Service, such as Google (authentication and LLM APIs), Razorpay (payments), our hosting and email delivery providers, and analytics providers. These vendors process data on our behalf under contractual obligations.
- Legal and safety. We may disclose information if required by law, legal process, or government request, or where necessary to protect the rights, property, or safety of TinkerLLM, our users, or others.
- Business transfers. If Kalvium Labs or TinkerLLM is involved in a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction. We will notify you (for example, by email or notice on the site) if this happens.
We do not sell your personal data, and we do not share it with advertisers for profiling.
6. International transfers
We operate from India, and some of our service providers (including Google) may process data in other countries. Where your data is transferred outside your home country, we take reasonable steps to ensure appropriate safeguards are in place.
7. Cookies and analytics
We use a small number of cookies and similar technologies:
- Essential cookies to keep you signed in and to remember your preferences.
- Analytics cookies to measure aggregate usage (such as page views and feature adoption) and help us improve the Service. Where required by law, we ask for your consent before setting non-essential cookies.
You can control cookies through your browser settings. Blocking essential cookies may affect your ability to sign in or use parts of the Service.
8. Data retention
We keep your personal data only for as long as we need it to provide the Service and for legitimate business or legal purposes. For example, account and progress data is retained while your account is active; payment and tax records are retained for the period required by Indian tax and accounting law; server logs are retained for a short period for security and debugging.
When you delete your account or ask us to delete your data, we will delete or anonymise your personal data, except where we are required to keep it (for example, to comply with tax law or to resolve disputes).
9. Your rights and choices
Depending on your location, you may have rights to:
- access the personal data we hold about you;
- correct inaccurate or incomplete personal data;
- request deletion of your personal data;
- object to or restrict certain processing;
- withdraw consent where processing is based on consent;
- port your data to another service where technically feasible;
- lodge a complaint with a data protection authority.
To exercise any of these rights, email us at support@tinkerllm.com. We will respond within the timeframes required by applicable law.
10. Security
We use industry-standard technical and organisational measures to protect your personal data, including TLS encryption in transit, access controls, and regular reviews of our systems. No system is perfectly secure, but we work hard to keep your data safe and to notify you if an incident materially affects you, as required by law.
11. Children
The Service is not directed to children under 13, and we do not knowingly collect personal data from children under 13. If you are a parent or guardian and believe your child has provided us with personal data, please contact us and we will delete it.
12. Third-party links and services
The Service links to third-party websites and services (such as Google AI Studio, Kalvium Labs, and blog references). Their privacy practices are governed by their own policies, not this one. We encourage you to read them.
13. Changes to this policy
We may update this Privacy Policy from time to time. When we do, we will update the "Last updated" date at the top of this page and, for material changes, provide additional notice (for example, by email or an in-product notice). Continued use of the Service after the changes become effective means you accept the updated policy.
14. Contact us
If you have any questions about this Privacy Policy or how we handle your data, please email us at support@tinkerllm.com. We will do our best to resolve your concern.