This Privacy Policy explains how ELLOTH ("ELLOTH", "we", "our", "us") — the entity behind the KrishiScan platform, including its sub-products KrishiScan Diagnose, Profit AI, and YojanaAI (collectively, the "Services") — collects, uses and protects the personal information of the farmers, FPOs, consultants and other users ("you") who access the Services through our web application or progressive web app.
By using the Services you agree to the practices described here. If you disagree, please do not use the Services.
1. Who we are
The Services are operated by ELLOTH, an independent technology company founded and owned by Abir Majumder. All references to KrishiScan, Profit AI, YojanaAI and the KrishiScan brand assets in this document refer to products of ELLOTH.
2. What we collect
We collect only the minimum information required to run the Services:
- Account data: email, name (optional), password (stored as a bcrypt hash — we never store plaintext passwords), and the Indian state you choose during sign-up.
- Crop images: the photos you upload or capture using the AR Scanner (stored as base64 in your diagnosis history until you delete them).
- Diagnosis metadata: the crop name, disease/pest inferred, the language you selected, and any thumbs-up/thumbs-down feedback you provide.
- Profit AI inputs: district, state, land size, current crop, soil type and (optionally) investment budget.
- YojanaAI answers: the six short answers you provide during the scheme-eligibility interview (state/district, age & gender, occupation, land holding, income band, category).
- Chat transcripts: messages you send in the AI chat / Diagnose composer and Yojana conversation.
- Approximate location: when you tap "Use my location" or "Enable weather", the browser shares GPS coordinates with the map widget and Open-Meteo weather API. We do NOT store your coordinates server-side unless you explicitly save them to a prediction.
- Payments: when you subscribe, we receive from Razorpay a payment reference (razorpay_payment_id, order_id, status). We do NOT store your card number, CVV or UPI PIN — those live only inside Razorpay.
- Cookies: a single HTTP-only session cookie (JWT) to keep you logged in, and localStorage keys to remember your language, the "onboarding seen" flag and a randomly generated farmer_id for anonymous use.
- Feedback: anything you send via the "Give feedback" button — we treat this as public product-improvement input.
We do not knowingly collect Aadhaar numbers, PAN numbers, bank account numbers, biometric information or any special-category personal data.
3. How we use it
- To perform the AI diagnosis, price prediction or scheme match you requested.
- To show you your own history of diagnoses, profit predictions and YojanaAI chats — always filtered by your farmer_id or account id.
- To calculate your remaining free-tier quota (3 diagnoses/month on the ks_free plan) and prevent abuse.
- To send you state-targeted in-app notifications (e.g. "Maharashtra farmers: PM-Kisan installment released"). No email, SMS or WhatsApp marketing is sent.
- To improve KrishiScan — aggregated, non-identifying metrics such as "how many diagnoses were run this week" or "which state has the most Profit AI users".
We do not sell your data. We do not use your crop photos to train third-party foundation models beyond what is transiently required to produce your answer.
4. AI processing & third parties
The Services rely on the following processors:
- Google Gemini (via Emergent LLM Key) — analyses crop photos and generates the diagnosis, remedies, TTS audio, Profit AI recommendations and YojanaAI schemes. Photos and text are sent to Google for the duration of the request only.
- Razorpay — payment gateway for KrishiScan and YojanaAI subscriptions. Razorpay is a PCI-DSS Level-1 compliant provider based in India.
- Open-Meteo — free weather forecast API. We send only your coordinates (or none if permission is denied) to Open-Meteo.
- OpenStreetMap Nominatim — used by the Dealer Locator to find agri-input retailers. Only the search string and your coordinates are sent.
- Google Maps (public embed) — the "Nearby suppliers & FPOs" iframe uses google.com/maps' public search embed. No API key or personal data is passed; Google may set its own cookies inside that iframe.
- MongoDB (self-hosted) — our own database, hosted on infrastructure controlled by ELLOTH.
None of these processors receive your password. Only Google Gemini receives the actual content of your queries; the others receive only the minimum required parameters.
5. Cookies & local storage
- access_token (HTTP-only, Secure): JWT session cookie — required for login. Cleared on logout or after 7 days of inactivity.
- krishi_farmer_id (localStorage): a random UUID that lets anonymous users have their own history. Never shared with any third party.
- krishi_language (localStorage): your chosen UI language.
- ks_onboarding_seen_v1, ks_profit_tutorial_seen_v1, ks_yojana_tutorial_seen_v1 (localStorage): flags so we don't re-show the wordless 3-step tutorials.
- krishi_dismissed_broadcasts (localStorage): IDs of admin broadcasts you have already dismissed.
You can clear these at any time via your browser settings. We do not use third-party advertising cookies.
6. Payments (Razorpay)
Subscriptions to the paid KrishiScan tiers (Farmer ₹299/month, FPO/Cooperative ₹1,999/month) and YojanaAI tiers (Individual ₹99, Farmer & SMB ₹299, Consultant/Agent ₹999) are processed through Razorpay. Razorpay collects your card, UPI or netbanking details on its own PCI-DSS environment. We only receive a transaction reference, a status ("captured" / "failed") and the plan you paid for.
Refunds follow the refund policy in our Terms of Service. Chargebacks may be verified against Razorpay dispute records.
7. Data retention
- Diagnoses, profit predictions, Yojana sessions: retained until you delete them from the /history page. Deletion is immediate and irreversible.
- Chat transcripts: retained inside the corresponding session document; deleted when the session is deleted.
- Feedback: retained until you request removal (email us).
- Account data: retained while your account exists. You can request full deletion at contact@elloth.in — we act within 30 days.
- Payment records: retained for 7 years per Indian tax rules.
8. Your rights & choices
As a user in India you have the right to (a) access your data, (b) correct inaccurate data, (c) delete your data, (d) withdraw consent, and (e) receive an export of your data. To exercise any of these, email contact@elloth.in from the email tied to your account. We respond within 30 days.
You may also delete individual diagnoses, profit predictions and Yojana sessions yourself from the /history page.
9. Security
- Passwords are stored as bcrypt hashes (never plaintext).
- All API traffic runs over HTTPS/TLS. Session cookies are marked HTTP-only and Secure.
- Admin controls are gated by strict email + role checks on every request.
- No password recovery emails are sent yet — this feature is on the roadmap and will be added with a verified email provider.
- We follow least-privilege database access. Only the Owner (Abir Majumder) has direct database access.
No online system is fully secure. If we ever discover a personal-data breach, we will notify affected users within 72 hours by email and in-app notification.
10. Children
The Services are intended for adults (18+). If you believe a minor has provided personal information, contact us and we will remove it.
11. Changes
We may update this Privacy Policy from time to time. The "Last updated" date at the top always reflects the most recent version. Material changes will be announced via an in-app broadcast.
12. Contact
Questions, requests or concerns?
ELLOTH — Legal / Privacy · Founder & Owner: Abir Majumder
Email: contact@elloth.in
© 2026 ELLOTH · KrishiScan, Profit AI and YojanaAI are trademarks of ELLOTH. All rights reserved.