CoreLayerEngine is operated by Ektasi Technology (OPC) Private Limited, an Indian company (CIN U72900UP2020OPC128958, GSTIN 09AAFCE9082J1Z4), registered office Chiraigaon, Varanasi, Uttar Pradesh 221112, India. This policy explains exactly what we process, why, where it lives, how long we keep it, and how you make us stop.
We have written it to be checkable rather than reassuring. Where a limit exists — and there are several — it is stated here rather than left out.
1. Who is responsible for what
For your own account — the people on your team, your billing records, our security logs — we are the controller (under India's DPDP Act, the Data Fiduciary).
For the data you put into the product — your contacts, your broadcast recipients, the people who comment on your posts, the mentions you collect — you are the controller and we are your processor. Our obligations to you in that role are set out in our Data Processing Agreement.
2. What we process
| Category | What it is |
|---|---|
| Account & identity | Name, email address, organisation, role. Your password is stored only as a scrypt hash with a per-user salt — never in plain text. |
| Authentication | Session identifiers; if you enable two-factor authentication, your TOTP secret (encrypted at rest) and scrypt-hashed single-use recovery codes. |
| Brand inputs | Your offerings, voice, goals, logos, reference assets and briefs. |
| Connection credentials | OAuth access and refresh tokens for the channels you connect, plus the account identifiers needed to publish. Encrypted at rest with AES-256-GCM, bound to their own record so a copied ciphertext cannot be reused elsewhere. |
| Content | Generated copy and creative, uploaded images and video, edit history, publication records. |
| Contacts you upload | Names, phone numbers, email addresses, tags, and a per-channel consent ledger. Consent is opt-in and never assumed — a bulk import cannot silently mark rows as consenting. |
| Third-party public content | Comments on your posts (author handle and text) and, if you switch on social listening, public mentions of your brand. |
| Likeness | None by default. Presenter video uses a curated library of synthetic faces. A photograph of a real person is processed only if your operator has deliberately enabled that path, which is switched off on a standard deployment. |
| Technical & usage | IP address, user-agent, request metadata, event and audit log entries — for security, abuse prevention and reliability. |
| Billing | Billing email, plan, subscription and transaction identifiers. We never receive or store card numbers — checkout runs on the payment provider's own page. |
The Service is not directed to people under 18 and we do not knowingly collect their data. Please do not upload special-category data (health, biometric, political or similar) — the product is not designed for it.
3. How we use it
To run your workspace, generate the content you ask for, publish it to the channels you have connected within the approval rules you set, retrieve metrics for your own posts, deliver the messages you initiate to contacts who have consented, secure the Service against abuse, bill you, and support you.
We do not sell personal data. We do not show third-party advertising. We do not build profiles across customers. Our outcome learning — the part that works out which tones and timings perform — operates only inside a single workspace, on that workspace's own results, and adjusts scoring weights, not model weights. Nothing learned in your workspace is applied to anyone else's.
4. Connected platforms
We contact a platform only after you complete an OAuth grant for it, and only with the permissions you approve. Until then we hold no token for it and send it nothing about you.
| Platform | What we send and receive |
|---|---|
| Meta — Facebook Pages, Instagram, Threads | Post and media content you approve; your page/profile identifiers; comments on your own posts and the replies you approve; for WhatsApp, recipient numbers and message bodies for broadcasts you send. |
| Post content and media; organisation and member identifiers; metrics for your own posts. | |
| TikTok | Video content; account identifiers; metrics for your own posts. |
| Pin content and media; board and account identifiers; metrics. | |
| X | Post and thread content; account identifiers; metrics. |
| Google — YouTube, Google Business Profile | Video and local-post content; channel and location identifiers; metrics. |
Once content reaches a platform, that platform processes it under its own terms with you. You can disconnect any channel at any time; where the platform exposes a revoke endpoint — Meta, Instagram, Threads, Google, YouTube, TikTok, X and LinkedIn all do — we revoke the grant at the platform, not just delete our copy of the token. Where a platform has no revoke API, the console says so rather than implying we revoked something.
If you connected us through Facebook, Instagram or Threads and want your data removed, follow the data deletion instructions.
5. Google user data
This section is specific to data CoreLayerEngine receives from Google APIs when you connect a Google Business Profile, because Google requires us to state it plainly and in one place.
What we receive. With the single scope
https://www.googleapis.com/auth/business.manage we receive an OAuth access token and
refresh token for the Google account you connect, the list of Business Profile accounts and
locations that account manages (we read the location name and identifier only), and the result of
each local post we publish on your instruction. Google exposes no narrower scope for posting.
What we do with it. We show you your locations so you can choose which one a post goes to, and we publish the local posts you have approved to that location. Nothing else.
Who we share, transfer or disclose it to. We do not sell it, we do not use it for advertising, and we do not use it to train any AI model — ours or anyone else’s. Google user data is not sent to the AI providers listed under Sub‑processors: those receive the brief and the copy you ask us to write, never your Google tokens, account list or location list. It is disclosed only to:
- Our own infrastructure — the self‑managed PostgreSQL database and application containers that run CoreLayerEngine, and the encrypted database backups held in the same region. Tokens are encrypted at rest.
- Cloudflare, Inc. — as the TLS and CDN layer in front of the product; it carries request metadata in transit and stores no Google user data.
- A competent authority, where we are legally required to disclose it.
How long we keep it. Tokens live until you disconnect the channel or revoke access at Google, whichever happens first. Disconnecting from Settings revokes the grant at Google and deletes our copy in the same action.
Limited Use. CoreLayerEngine’s use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
6. AI providers
To generate content we send prompts — built from your brand profile and briefs, plus anything you type into one — to a single configured AI provider: OpenRouter, Anthropic or OpenAI. Audio you submit for transcription goes to OpenAI's Whisper. Images you upload go to a separate provider: Groq is the default endpoint for image understanding (OCR and captioning), and an uploaded image may contain identifiable faces. Groq processes in the US. Optional features send data to HeyGen or D-ID (presenter video: your script and a photograph) and remove.bg (background removal: the image).
We do not train any model on your data. There is no training, fine-tuning or embedding pipeline in the product. Where the Anthropic or OpenAI API is used directly, those providers' API terms state that inputs are not used to train their models. Where OpenRouter is used, requests are brokered onward to a downstream provider, and we cannot give a single no-training guarantee across every model reachable that way. If you need that guarantee contractually, ask us and we will pin your workspace to a direct provider.
Content generated by the engine can carry signed Content Credentials recording that it was AI-generated, and sponsored posts are stamped with #ad / paid-partnership disclosure automatically.
7. Sub-processors
The complete, current list of every third party that can receive data — with the purpose, the data categories and the region for each — is published at corelayerengine.com/subprocessors. We give 30 days' notice before adding or replacing one that processes customer personal data, and you may object.
Inside the product we use no third-party product analytics, no error-tracking service, no advertising pixels and no session replay. On this marketing website we use Google Analytics 4, loaded through Google Tag Manager, to count visits and see which pages get read. That is the only third-party analytics anywhere in what we run: there is no advertising, remarketing or conversion tag beside it, and none of it is present in the product at app.corelayerengine.com.
8. Cookies and similar storage
This marketing website sets one first-party analytics cookie — _ga, plus a per-property _ga_<id> — so Google Analytics can tell a returning visit from a new one. It is never read for advertising, and no advertising signal is sent at all: every Google advertising consent category is set to denied before the tag loads. For visitors in the EEA, the UK and Switzerland analytics storage is denied as well, so no cookie is written there and Analytics receives only a cookieless ping. The site also stores a theme preference in your browser's local storage. Everything else this page needs — the React runtime, the icon set, the fonts — is served from our own domain, so no third-party CDN sees your IP address for this website.
The product at app.corelayerengine.com sets strictly necessary cookies only: cl_session (sign-in, HttpOnly, SameSite=Lax, 7 days), cl_csrf (anti-forgery), and a short-lived cl_ostate during an OAuth connection. If you make a choice in the cookie banner, that choice is stored in cle_consent for 180 days. Analytics and marketing categories are off by default and no scripts are currently wired to them. Our CDN, Cloudflare, may serve a cookieless analytics beacon that sets no browser storage and uses no cross-site identifiers. Full detail: Cookie Policy.
9. Where your data lives, and transfers
Every workspace is pinned to a region when it is created, and the region decides which database holds its rows — it is not a label on a settings page. Data is stored in India. That is the only region we operate — there is no European Union, Singapore or United States shard, and no way to move a workspace to one. A request for data from any other region is refused outright rather than served from somewhere else.
Backups are stored in the same region as the data they came from.
Where personal data moves out of the EEA or UK to us in India, we rely on the EU Standard Contractual Clauses (and the UK International Data Transfer Addendum where relevant), available through our DPA. Being straight about the limits: choosing EU hosting reduces transfers but does not remove them entirely, because support access and the configured AI provider may still sit outside the EEA, and publishing to a channel you have connected is a transfer you instruct.
10. How long we keep things
| Category | Default retention |
|---|---|
| Raw mentions from social listening | 180 days — except anything retrieved from the YouTube API (video metadata and comments), which is deleted after 30 days, the maximum YouTube's API Services Terms allow us to store it. A workspace can shorten either window; neither can be lengthened past 30 days for YouTube. |
| Comment replies | 180 days |
| Notifications | 90 days |
| Undeliverable webhook events | 30 days |
| Publications and event log | Kept while the workspace exists — this is the history the engine learns from |
| Governance audit trail | Per workspace setting; pruning re-seals the tamper-evidence chain so it stays verifiable |
| Deletion tombstones (proof an erasure happened — no name, email or content) | 730 days |
| Billing and tax records | As required by Indian law |
A workspace can tighten these windows; ask us and we will set them. If an account is placed under legal hold, all automated deletion stops for it.
The honest limit on deletion. Data you erase disappears from the live system straight away, but it persists in encrypted backups until those rotate out under our 7 daily / 4 weekly / 12 monthly schedule — up to roughly twelve months for the oldest monthly copy. Those backups are encrypted, are not restored into production, and if one ever is restored we re-run the purge so deleted records do not return.
11. Your rights, and exactly how to use them
If you are a CoreLayerEngine customer
- Access and portability — your account and profile data are visible and editable in Profile; the governance audit trail exports as CSV or PDF from Governance, with its tamper-evidence chain head printed on the export.
- Correction — edit in Profile and Settings.
- Erasure — Profile → Delete workspace, confirmed by typing the workspace name. This deletes the account from every region we can reach, not only the one that served your request, and leaves only a tombstone containing no personal data.
- Objection and complaints — email us (below). You may also complain to your supervisory authority, or to the Data Protection Board of India.
If you are a person whose data one of our customers holds
Our customer is the controller of that data, so please contact them first. They can, from Profile → Privacy & data in their console, look you up by email or phone, export everything held about you, erase it, or record a withdrawal of consent that removes you from future messages. If you cannot reach them, write to us and we will pass the request on and tell you we have done so.
If you used Facebook, Instagram or Threads to connect
See the data deletion instructions, which include the public request URL and how to check the status of a request.
We answer rights requests within 30 days, and a grievance to our Grievance Officer within 72 hours. Restriction of processing (GDPR Art. 18) is now built in: Profile → Privacy & data → Restrict processing keeps the person’s record but stops every broadcast, review request and automation reaching them, and records who restricted it and when it was lifted. It is deliberately not erasure — the record is kept, which is what Art. 18 asks for.
12. Security
TLS with HSTS in transit. OAuth tokens, two-factor secrets and webhook secrets are sealed with AES-256-GCM before they are written, under keys that can be rotated without downtime; production will not start without one. Passwords and recovery codes are scrypt-hashed. Sessions are signed and HttpOnly with CSRF protection on every state-changing request. Two-factor authentication is available and can be enforced organisation-wide. Governance actions are recorded in a hash-chained, tamper-evident trail. Backups are encrypted, stored in the same region as the data, and a job restores the newest one into a scratch database to prove it works — if that check fails or goes stale, it wakes someone up.
We do not claim certifications we do not hold. Our security posture is described on the Trust & Security page, and we will answer specific questions in writing for any contract that needs them. To report a vulnerability, see security.txt.
13. Changes and contact
We update this policy as the product changes; material changes are reflected in the date at the top and notified to workspace owners. Privacy, data-protection and DPA questions: legal@ektasi.io. Anything else: innovations@ektasi.io. Post: Ektasi Technology (OPC) Private Limited, Sandaha, Varanasi, Uttar Pradesh 221112, India. Legal contact line: +91 11 6965 6628.
Under India’s DPDP Act our Grievance Officer is Rajan Singh — rajan@ektasi.io, Ektasi Technology (OPC) Private Limited, Sandaha, Varanasi, Uttar Pradesh 221112, India. We respond within 72 hours. If our response does not satisfy you, you may complain to the Data Protection Board of India; in the EEA or UK you may also complain to your own supervisory authority.