Skip to content

Privacy policy

Last updated 2 October 2026.

Who we are

Triagic is operated by Sayan Bhattacharya, trading as Triagic, an individual based in Kolkata, India ("Triagic", "we", "us"). This policy covers triagic.com, the customer portal, hosted forms, and the Triagic desktop app. Questions, requests and complaints go to hello@triagic.com. That address also reaches our grievance officer under India's Digital Personal Data Protection Act, 2023 (the "DPDP Act").

Triagic is built for businesses. Two kinds of personal data pass through it, and our role differs for each:

  • Account data about the people who sign up and use Triagic. We decide how it is used, so we are the data fiduciary (controller) for it. Most of this policy is about account data.
  • Customer content: what our customers put into Triagic, such as form submissions from their own customers, email threads, knowledge base documents, and playbooks. We process it only on the customer's instructions, as their data processor. The customer's own privacy policy governs it, and our Data Processing Addendum sets out our obligations. If you submitted a form run by a company that uses Triagic, contact that company first.

How the product is built, and why it matters here

Most of Triagic's work happens on your own computer. The desktop app keeps tickets, investigations, chat history, checkups and its logs in a local database on that machine. We do not receive them. When the app calls an AI model, it connects directly from your computer to the provider you configured (OpenAI, Azure OpenAI, Anthropic, Google, OpenRouter, or a model you host yourself) using your own API key. Before a prompt is built, the app strips email addresses, phone numbers, card numbers, national ID numbers and IP addresses from ticket text by default. Your agreement with that AI provider governs what it does with the request. We never see the prompt or the response.

The desktop app sends no crash reports and no error logs. It does send usage analytics, described under “Usage analytics” below, which you can turn off inside the app.

What we collect

When you create an account or are invited

  • Email address, password (stored only as an argon2id hash), and the time your email was verified.
  • For organization members: username, role, team membership, and whether the account is enabled.
  • Passkeys, if you add one: the public key, a device label and when it was last used. The private key never leaves your device.

When you use the desktop app while signed in

  • A machine identifier (a one-way hash of your operating system's hardware ID), the app version, your computer's hostname, and when the machine last checked in. We use these to count seats, check your license and show admins which machines are connected.
  • Integration health reports: which of your organization's integrations are running on which machine, and error messages.
  • Daily AI usage totals per member, machine and model: token counts and estimated cost. Not prompts or responses.

Organization configuration you choose to store with us

  • Integration settings and credentials, AI provider API keys, and email provider credentials. These are encrypted with AES-256-GCM before they are stored. They are decrypted only to deliver them to your organization's signed-in desktop apps, which need them to connect.
  • Playbooks, knowledge base documents (for uploaded files we keep the extracted text, not the file), dashboard definitions (the prompt, saved queries and chart settings, never their results), teams and forms.
  • An audit log of administrative actions: who did what, and when.

When you pay

Payments are handled by Razorpay. We send it your plan, seat count, account ID and email address. Your card or bank details go straight to Razorpay and never reach our servers. We keep your plan, seat count, subscription status and Razorpay subscription ID.

Usage analytics

We use PostHog to see which parts of Triagic get used, so we know what to improve. It runs in three places, and in all of them it stores nothing in your browser or on your machine: no cookies, no local storage, no session recording, no heatmaps, no profile built about you. If your browser sends a Global Privacy Control or Do Not Track signal, the analytics script does not load at all.

  • Marketing pages and docs. Anonymous. We record page views and three kinds of clicks (starting a signup, downloading an installer, and a call to action on an integration page). PostHog groups visits using a daily identifier that it derives on its side and cannot link across days.
  • The web portal.Page views, labelled with your organization's ID, your role, and an internal account or member ID. That ID is a database key, not your name or email, and it means nothing outside our own systems. We use it to count how many people use a page, not to look at what one person did.
  • The desktop app.Which screens are opened (the screen name only, never a ticket ID or its contents), how often tickets are triaged, the app version, the operating system, and whether the install is on a trial or a licence. Events carry the same machine identifier that licensing already uses, plus your organization's ID. They do not carry your name, your email, or your computer's hostname.

Analytics never carry ticket contents, messages, attachments, file names, AI prompts or replies, customer details, credentials, or anything you type into the app. The desktop app caps how many events one machine can send in a day, and drops the rest.

Desktop analytics are on when you install the app. To turn them off, open the app, go to Cloud connection from the sidebar, and clear “Share anonymous usage data from this machine”. The setting is stored on that machine and takes effect at once.

Hosted forms and email threads (customer content)

When someone submits a Triagic-hosted form, we store what they entered, their name and email if the form asks for them, any attachments, and later email replies in the same thread. Public forms use Cloudflare Turnstile to block bots. Turnstile receives the submitter's IP address for that check.

Cookies and browser storage

We set only the cookies needed to keep you signed in. No advertising or analytics cookies.

NamePurposeLifetime
triagic_portalPortal session12 hours
triagic_accountAccount owner session12 hours
triagic_webauthnPasskey sign-in challengeMinutes

The site also keeps your sign-in token and dismissed notices in your browser's local storage. Signing out or clearing site data removes them.

How we use it

  • To run the service: sign-in, licensing, seat counts, syncing your organization's configuration, forms and email.
  • To send service email: verification links, invitations, usage warnings, and alerts when an email connection fails.
  • To bill you and keep records the law requires.
  • To keep the service secure: rate limiting, abuse prevention and audit logs.
  • To understand, in aggregate, which pages and integrations people look at.

We do not sell personal data, share it for advertising, or use customer content to train AI models or improve the product. Customer content is used only to provide the service to the customer who owns it.

Legal basis under the DPDP Act: you give consent when you create an account. Some processing is also a legitimate use the Act permits, such as meeting legal obligations. You can withdraw consent at any time by asking us to delete your account.

Who we share it with

We use a small number of service providers, listed with their purpose and location on our subprocessors page. Each receives only what it needs to do its job. We also disclose data if the law requires it, and to a successor if Triagic is sold or merged. In that case this policy continues to apply to data collected under it.

Where it is stored

Our database and file storage run in the United States, with Neon (on AWS us-east-2) and Vercel. If you are in India, your data is transferred to and stored in the United States. The DPDP Act permits this unless the Indian government restricts transfers to that country.

How long we keep it

  • Account and organization data: while the account exists. Cancelling a subscription does not delete anything, so you can resubscribe without losing your setup.
  • Form submissions, email threads and attachments: until the organization deletes them or its retention setting (90, 180 or 365 days) removes them. If no retention setting is chosen, they are kept until the account is deleted.
  • Integration health reports: 30 days.
  • Email verification and invitation links: until used, or 24 hours and 7 days respectively.
  • Audit logs and billing records: as long as needed for security and as Indian tax and accounting law requires (currently up to 8 years).

Deleting your data

Email hello@triagic.comfrom the address on the account and ask us to delete your account or organization. We will confirm the request is yours and delete the data within 30 days, except billing records we must keep by law. Deleted data leaves our database's restore history within 7 days. Data on your own computers is yours to delete: uninstalling the desktop app and removing its data folder removes it.

Your rights

Wherever you live, you can ask us to:

  • tell you what personal data we hold about you and give you a copy;
  • correct data that is wrong or incomplete;
  • delete your data;
  • nominate someone to exercise these rights for you if you die or become incapacitated (a DPDP Act right).

We answer within 30 days. If you are not satisfied with our answer and you are in India, you can complain to the Data Protection Board of India.

California residents

In the last 12 months we collected identifiers (email, account ID, IP address during bot checks), commercial information (plan and subscription), and internet activity (page views on our site), for the purposes above. We do not sell or share personal information as the CCPA defines those terms, and we do not use sensitive personal information to infer characteristics about you. You have the rights to know, delete, correct, and not be discriminated against for using them. We honor Global Privacy Control signals. To make a request, email hello@triagic.com; an authorized agent may make one for you with your written permission.

Security

Passwords are hashed with argon2id. Credentials and API keys are encrypted with AES-256-GCM before storage. Attachments are kept in private storage and served only to signed-in members of the organization that owns them. All traffic uses TLS. No system is perfectly secure. If a breach affects your personal data, we will notify you and, where required, the Data Protection Board of India.

Children

Triagic is for business use by people aged 18 or over. We do not knowingly collect data from anyone younger.

Changes

We will post changes here and update the date at the top. If a change materially affects how we use your data, we will email account owners before it takes effect.