SARATHI by KatalAiser

Privacy notice

Pilot notice · Updated 23 September 2026 · Pending legal review

Who operates Sarathi

Sarathi is provided by KatalAiser, a division of Careerconnects. Contact hello@katalaiser.com with privacy questions or requests. Your organisation determines which business information it submits and who should have workspace access.

Information processed

We process account details such as email and name; organisation membership and access settings; strategies, business-model inputs and assumptions; uploaded files and extracted text; pasted conversations, transcripts and contributor answers; imported connector content; Ask conversations; and generated findings, recommendations and validation history. These records may contain personal or confidential business information.

We also process sign-in and session information, connector authorisation tokens, sync status, and technical or audit records needed to operate and protect the service. Only submit information you are authorised to share, and remove unnecessary personal details and secrets.

Purpose and access

This information supports authentication, workspace access, source import, strategy analysis, evidence assessment, answers, recommendations and progress checks. Workspace information can be available to other authorised members of your organisation according to the implemented access controls. Do not assume a submitted business record is private to you personally.

Support emails are handled separately. Recognised product-help questions in Ask use fixed guidance and are not saved as strategy evidence. Unrecognised questions may follow the normal Ask conversation path.

Providers and AI processing

Sarathi uses Supabase for authentication, database and file storage, Vercel for application hosting, and OpenAI for AI analysis and responses. Relevant strategy text, source excerpts, business context and questions may be sent to OpenAI. Sign-in emails are delivered through the configured email provider. These providers process information needed for their services under their applicable terms and configurations.

We do not promise that all processing occurs in India. Database hosting location alone does not determine where hosting, AI, email or other provider processing occurs. This notice does not assert provider-specific zero retention or model-training exclusions; obtain confirmation of the applicable arrangements before submitting information with such requirements.

Connected sources

  • Google authorisation requests Gmail read access, Drive read access, account email and offline access. The current manual sync imports recent Gmail subjects, sender details and snippets; Drive import is not currently implemented.
  • Microsoft authorisation requests Mail.Read, User.Read and offline access. The current manual sync imports recent Outlook subjects, sender details and body previews.
  • Slack authorisation requests public/private channel listing and history permissions. The current manual sync imports recent message text from channels accessible to the installed app, with channel names and timestamps.

Authorisation tokens are stored to support connection and sync. Review the provider consent screen and obtain your organisation's permission before connecting. Revoke access through the provider's app-permission settings when needed; revocation does not delete information already imported into Sarathi. Contact us to request removal of stored credentials or imported content.

Cookies and optional voice features

Cookies support sign-in sessions and workspace selection; connector flows also use temporary authorisation state. Microphone input uses your browser's speech-recognition service, which may process audio through the browser vendor. Read-aloud uses the browser or operating system's speech services. Their processing depends on your browser, device and settings; use typed input if those services are unsuitable for your information.

Retention and privacy requests

The pilot does not currently provide an automatic retention schedule for workspace content. Records and uploaded files can remain stored until removed or reset. Closing a browser, signing out or revoking a connector does not delete stored content. Backup, security-log and third-party retention can differ from active application records; immediate deletion from every system is not promised.

Request access, correction, deletion or clarification through hello@katalaiser.com. Include your account email, organisation and the nature of your request, but not passwords, magic links or confidential documents. We may need to verify identity and authority, especially for shared organisation content, before acting.

Pilot status

This notice describes the current pilot and is pending legal review. It is not a claim of DPDP compliance, ISO 27001 certification or any other certification. Specific contractual, residency or regulatory requirements should be confirmed with Careerconnects before use.