Legal

Privacy Policy

Last updated: April 2026  ·  Applies to all Telurai web services and products


Telurai is an enterprise prompt intelligence platform operated by NTH MOMENT, a partnership business registered in India (GST registered, UDYAM certified), based in Bengaluru, India. This policy explains exactly how we collect, use, store, and protect your information — written to be read by real people, not just legal teams.

If you have a question about anything in this policy that isn't answered here, email [email protected] and we'll respond within 2 business days.

Section 01

Who can use Telurai

Telurai is available exclusively to invited employees of organisations that have a signed agreement with NTH MOMENT. Access is not open to the general public. All users must be invited by their organisation administrator before they can log in.

Section 02

What we collect

Account information — Your work email address and a securely hashed password, created when your administrator sets up your account.

Session data — A session token stored locally in your browser. This keeps you logged in and is never sent to third parties.

Usage metadata — Token counts per session (numbers only: input tokens, output tokens, total tokens, token delta). We record how many tokens were used — not what was written.

Prompt library content — Prompts that your organisation's administrator explicitly creates and saves to your organisation's prompt library. This is deliberate, administrator-directed storage. It is owned by your organisation and accessible only within your account.

Analytics — Basic page-visit and feature-usage data via our self-hosted Umami instance. No personal identifiers are attached to analytics data.

Section 03

What we do not collect or store

Telurai does not store the text of prompts submitted for improvement, validation, or document processing. Submitted content is processed in memory and discarded immediately after a response is returned. We store token counts — numbers — not prompt content — text.

Document content — Documents uploaded to Document Intelligence are processed in memory and discarded after the corrected document is returned. We do not retain uploaded document content.

AI responses — We do not store AI-generated responses beyond the duration of your session.

Sensitive browser data — We do not track keystrokes, clipboard content, or browser activity outside the Telurai interface.

Training data — We do not use your prompts, responses, or documents to train AI models — ours or anyone else's.

Third-party data sharing — We do not sell, rent, or share your personal or organisational data with third parties except as described in Section 06 of this policy.

Section 04

Your organisation's prompt library

The prompt library feature allows your organisation's administrator to create and store reusable prompt templates for your team. This is intentional, consensual storage — your administrator creates this content on purpose as an organisational resource.

This data is:

Owned by your organisation — not by Telurai.

Logically isolated — accessible only to users within your organisation's account. No prompt library content is ever shared across organisations.

Deletable on request — your administrator can delete any prompt library content at any time. All organisational data is deleted within 30 days of account termination.

No prompt content submitted through the Prompt Improver, Response Validator, or Document Intelligence features is stored. Only content your administrator explicitly saves to the prompt library is retained.

Section 05

How we use your information

To authenticate your access to Telurai.

To deliver prompt improvement, response validation, and document intelligence services.

To serve your organisation's prompt library to authorised users.

To track token usage for billing and reporting purposes — counts only, not content.

To improve the platform over time using anonymised, aggregated usage patterns.

Section 06

Subprocessors — third parties we use

We use the following third-party subprocessors to operate Telurai. Each is governed by its own privacy and data processing commitments. The full subprocessor list is maintained at telurai.com/subprocessors.

Subprocessor Purpose Data accessed Location
Anthropic, Inc. Claude API — AI model inference Prompt and document content — ephemeral only, not retained United States
Self-hosted VPS Application and database hosting Account data, usage metadata United States
Umami (self-hosted) Privacy-first analytics Anonymised page visit data United States
Section 07

AI processing — what "ephemeral" means

When you use any Telurai product, your prompt or document content is sent to Anthropic's Claude API over an encrypted connection for the sole purpose of generating a response. Here is exactly what happens:

Content is not written to disk or logged by NTH MOMENT at any point in this process.

Content is not retained by Anthropic beyond the duration of the API call, subject to Anthropic's privacy policy.

After the response is returned to you, the submitted content is discarded from memory.

We do not use your content for model training — ours or Anthropic's.

Section 08

Data storage and security

Hosting — Account data is stored in a PostgreSQL database on a privately hosted server located in the United States. Enterprise clients requiring India-hosted data residency may request this as part of their agreement with NTH MOMENT.

Passwords — Hashed using bcrypt. Never stored in plain text.

Transit encryption — All data transmitted over HTTPS with TLS 1.2 or higher.

Session tokens — Stored locally in your browser. Never transmitted to third parties.

Organisational isolation — Each organisation's data is logically isolated at the application and database level. No data crosses organisational boundaries.

Section 09

Data retention

Account data — Retained for the duration of your organisation's agreement with NTH MOMENT.

Usage metadata (token counts) — Retained for up to 24 months for billing and reporting purposes.

Prompt library content — Retained until deleted by your administrator or until account termination.

On termination — All organisational data is deleted within 30 days of account termination.

Section 10

Security incident notification

In the event of a security incident that affects your organisation's data, NTH MOMENT will notify your organisation's administrator within 72 hours of becoming aware of the incident. Notification will be sent to the registered administrator email address and will include the nature of the incident, the data affected, and the steps taken to contain and remediate it.

Section 11

Your rights

You may request access to, correction of, or deletion of your personal data at any time by contacting us at [email protected]. Account deletion requests will be processed within 30 days. Where your rights under applicable law — including India's Digital Personal Data Protection Act 2023 — extend beyond these commitments, we will honour those rights.

Section 12

Cookies and tracking

The Telurai browser extension does not use cookies.

The Telurai website does not use third-party tracking cookies.

Our analytics are handled by a self-hosted Umami instance that does not use cookies and does not share data with any third party.

Section 13

Changes to this policy

We may update this policy from time to time. The date at the top of this page reflects the most recent update. Where changes are material, we will notify organisation administrators by email before they take effect. Continued use of Telurai after changes constitutes acceptance of the updated policy.

Section 14

Contact

For privacy-related questions or data requests:

Ram Chandra  ·  Founder, NTH MOMENT
[email protected]  ·  telurai.com
Bengaluru, India