Privacy Policy
At Karada, we are committed to transparent and secure data practices. This Privacy Policy outlines how we collect, use, and protect your information when you use the Karada platform, deploy Go MCP servers, and access our developer tools.
Privacy Commitment & AI Transparency
At Karada, we believe privacy and developer trust are fundamental. As a platform that powers Model Context Protocol (MCP) servers connecting software APIs to AI assistants, we enforce strict data hygiene and isolation:
- Zero AI Model Training: We do NOT use your OpenAPI specs, source code, tool arguments, or agent execution traces to train public or proprietary machine learning models.
- No Data Brokering: We will never sell, rent, or monetize your personal data, API specifications, or telemetry to third-party data brokers or advertising networks.
- Encrypted by Default: All data in transit is protected by TLS 1.3, and all stored credentials and API secrets in our vaults are encrypted at rest using AES-256.
Information We Collect
We collect only the minimum personal and technical information necessary to provide, maintain, and protect the Service:
2.1 Account Information: When you register for Karada, we collect your email address, name, organization name, and authentication tokens provided via OAuth providers (such as GitHub or Google).
2.2 Payment and Billing Data: When paid subscriptions, metered tiers, or credits are activated, transactions are processed directly by authorized PCI-DSS compliant payment providers (such as Stripe or Paddle). Karada does not directly store, process, or transmit raw credit card numbers on its servers.
2.3 Server Operational Telemetry: To guarantee high availability and monitor cold starts, our platform records infrastructure telemetry, including request timestamps, execution duration (latency in milliseconds), HTTP status codes, and container memory consumption.
How We Handle MCP Payloads & Tool Calls
When an AI assistant (such as Cursor or Claude Desktop) or your client application executes a tool call through a Karada MCP server:
- Ephemeral In-Memory Routing: The request is decrypted in-memory within an isolated container runtime, routed to the target microservice or third-party API, and the response is returned immediately to the caller.
- No Payload Logging: Karada does not persist the raw body, parameters, or responses of tool calls in permanent databases unless you explicitly enable customer-managed debug tracing.
- Ephemeral Container Lifecycle: Containers are automatically scaled down when idle, discarding local volatile container state.
Secret Vaults & API Key Security
Karada provides an integrated Secret Vault for storing environment variables, bearer tokens, and upstream API keys needed by your MCP servers:
4.1 Encryption at Rest: All stored secrets are encrypted at rest using AES-256-GCM encryption with per-tenant encryption keys managed via Google Cloud Key Management Service (Cloud KMS).
4.2 Injection into Secure Containers: Secrets are injected as environment variables exclusively into the isolated container instance at spin-up time over mutual TLS (mTLS). They are never written to system log files or exposed via client-side bundles.
Third-Party Sub-Processors
We partner with specialized enterprise vendors to operate our platform infrastructure. Each vendor undergoes security assessment and is bound by Data Processing Addenda (DPAs):
| Vendor | Purpose | Location |
|---|---|---|
| Google Cloud Platform | Container hosting (Cloud Run), databases, and KMS | United States & Global Regions |
| Payment Processors (e.g., Stripe, Paddle) | Billing, checkout, and PCI-DSS compliance (when paid tiers are enabled) | United States & EU |
| PostHog | Product analytics and feature usage (anonymized) | United States & EU |
| Sanity AS | Content management for marketing and changelog | Norway / EU |
Your Privacy Rights (GDPR & CCPA)
Regardless of your physical jurisdiction, Karada provides you with comprehensive control over your data:
- Right of Access & Portability: You can export your team definitions, OpenAPI configurations, and generated Go MCP server projects at any time from the dashboard.
- Right to Rectification: You can update your name, email, and team information directly in your account profile settings.
- Right to Erasure (“Right to Be Forgotten”): You can request the permanent deletion of your account and all associated MCP deployments by emailing privacy@karada.ai.
- Non-Discrimination: We will never deny services, charge different rates, or provide a different quality of service because you exercised your privacy rights.
Data Retention & Account Deletion
We retain your information only as long as necessary to provide the Karada platform and satisfy legal, accounting, or reporting obligations.
Upon account deletion, all active Cloud Run instances, secret vault entries, and server configurations are immediately de-provisioned and permanently purged from production databases within thirty (30) days. Ephemeral server logs and backups are cycled and overwritten within our standard sixty (60) day backup rotation.
International Data Transfers
Karada utilizes cloud infrastructure hosted in the United States and other globally distributed regions. When transferring personal data from the European Economic Area (EEA), the United Kingdom, or Switzerland to countries without an adequacy decision, we rely on European Commission approved Standard Contractual Clauses (SCCs) and equivalent UK data transfer mechanisms to protect your information.
Security Measures & Incident Response
We implement industry-standard physical, administrative, and technical safeguards, including:
- End-to-end encryption in transit via TLS 1.3 and at rest via AES-256;
- Principle of least privilege (PoLP) and multi-factor authentication (MFA) for internal administrative systems;
- Automated dependency auditing and container image vulnerability scans;
- Continuous monitoring and rapid incident response protocols with mandatory notification of affected users in the event of a verified security incident.
Children's Privacy
Our Service is designed for developers, professionals, and organizations. It is not intended for or directed to individuals under the age of 16. If we become aware that we have inadvertently collected personal data from a child under 16 without parental consent, we will take prompt steps to delete such data from our systems.
Updates to this Privacy Policy
We may update this Privacy Policy from time to time to reflect modifications in our technology, legal obligations, or service offerings. When material updates are made, we will notify you by updating the “Last Updated” date at the top of this page, and, where appropriate, through an email notification or prominent dashboard banner.
Contact & Data Protection Inquiries
If you have questions, feedback, or requests regarding this Privacy Policy or our data practices, please contact our Data Protection and Security team:
- Email: privacy@karada.ai (Privacy & Compliance)
- General Support: support@karada.ai
- Platform: Karada (karada.ai)