Legal
Privacy policy
Last updated July 18, 2026
Plain English, not legal advice
This is a plain-English description of how khavion.com handles personal data — written to be read, not buried. It isn't legal advice, and it covers the website; a signed statement of work governs an engagement.
Who we are
Khavion is a founder-led AI consultancy based in Houston, Texas, working remotely with English-language teams worldwide. This policy covers khavion.com and the small amount of personal data the site handles.
What we collect, and why
- Contact form: your name, work email, and message — used to reply to you and stored as a lead record in our CRM (Zoho CRM). No enrichment, no purchased lists.
- AI readiness assessment: the four answers you pick are scored in your browser and the verdict shows on screen with no email required. If you opt in to receive your result, your email (and name, if you give it) plus your answers and score are stored as a lead in Zoho CRM and Zohaib follows up personally — no automated email is sent today.
- Booking: if you book a fit call, scheduling runs on Zoho Bookings, which collects the details you enter there under Zoho's own terms.
- Newsletter: if you subscribe, your email is stored as a lead in Zoho CRM so we can send occasional field notes. Unsubscribe any time.
- Tool accounts: if you create an account for the Architecture Diagram Reviewer, we store your work email and a scrypt hash of your password (never the password itself) in our database (Neon Postgres), plus any reports you choose to save. Your uploaded diagrams are processed in your browser and never reach our servers.
- Billing: if you subscribe to a paid plan, checkout happens on Stripe's pages and your card details go to Stripe, not us. We store only the subscription state Stripe reports back (customer id, plan, renewal date).
- Transactional email: account verification, password-reset, and report-delivery emails are sent through Resend to the address you gave us.
- Analytics: Vercel Web Analytics, which is cookieless and aggregates page-level statistics. It doesn't identify you and sets no tracking cookies.
- Abuse prevention and security records: our API briefly derives a request fingerprint (from your IP or user agent) to rate-limit submissions, and security events (sign-ins, resets) are recorded with your email and IP stored only as salted hashes — useful in an incident, useless as a directory.
- Embedded video: the About page loads a YouTube clip only after you click, via youtube-nocookie; nothing loads from YouTube until you ask.
Cookies
We set no advertising or analytics cookies. The only thing the site keeps in your browser is a single theme preference (a khavion-theme value in localStorage) so it remembers light or dark — and it never leaves your device.
What we don't do
We don't sell or share your personal data with third parties for their marketing. We don't run advertising trackers or Google Analytics. We don't add you to a newsletter you didn't ask for.
Where your data goes
- Hosting: Vercel. Accounts and saved reports: Neon (Postgres). Transactional email: Resend. Payments: Stripe.
- Lead records, assessment results, and newsletter signups: Zoho CRM. Booking details: Zoho Bookings.
- Encrypted database backups: stored with GitHub for 90 days, then deleted automatically.
- Embedded video: YouTube (privacy-enhanced youtube-nocookie), only after you click.
- The full subprocessor list — who, what, and where — is published on the Security page and changes only with a change to that page.
Retention and your rights
Lead records are kept while there's a plausible working relationship and deleted on request. Tool accounts are self-serve: deleting your account from its account page permanently removes the account, every saved report, and usage history immediately, and encrypted backups age out within 90 days. For anything else, email zkhawaja@khavion.com to access, correct, or delete what we hold about you — we respond within 30 days, wherever you're based.
Data ownership and regulated work
In an engagement, your data stays in your cloud accounts and everything we build is yours at handover. For work touching protected health information we sign a Business Associate Agreement and configure Security Rule safeguards. The Trust page has the specifics.
Changes
If the site starts collecting anything new, we'll describe it here and update the date above before the change takes effect.