Savdhaan.in
Legal

Privacy Policy

Effective: 24 February 2026

Compliant with the Digital Personal Data Protection (DPDP) Act, 2023 and the Information Technology Act, 2000

TL;DR — We respect your privacy

Minimal data collection. Scan content deleted within 1 hour. We never sell your data. Full rights under Indian law. Email support@savdhaan.in anytime.

🏛

Data Fiduciary

Under the DPDP Act 2023, we are the Data Fiduciary responsible for processing your personal data.

EntitySavdhaan AI
📋

Personal Data We Collect

We collect minimal data necessary to provide the Service:

Account Data

  • Email address
  • Display name (optional)
  • Google profile (name + email only)
  • Hashed password (never plain text)

Scan Data

  • Messages you submit for scanning
  • Screenshots for OCR analysis
  • Extracted URLs, phones, UPI IDs

WhatsApp Bot

  • Your WhatsApp phone number
  • Messages sent to the bot

Processed and discarded within 1 hour.

Automatic

  • IP address (anonymised in 24h)
  • Browser & device type
  • Pages visited & timestamps

Key point: Scan content is processed in real-time and automatically deleted within 1 hour. Only anonymised risk scores and categories are retained.

🎯

Purpose of Processing

PurposeData UsedLegal Basis
Scam detection analysisScan data, entitiesConsent (Sec 6)
Account managementEmail, name, hashConsent (Sec 6)
WhatsApp bot repliesPhone, messageConsent (Sec 6)
Analytics & improvementAnonymised metadataLegitimate use (Sec 7)
Abuse detectionIP, usage patternsLegitimate use (Sec 7)
Legal complianceAs requiredLegal obligation

Data Retention

Scan content (text/images)Deleted within 1 hour
Scan results (score, category)Up to 12 months
Account dataUntil you delete your account
WhatsApp phone numberNot stored beyond session
Analytics dataAnonymised, up to 24 months
Server logs (IPs)Anonymised in 24h, deleted in 30d
🛡

Your Rights Under DPDP Act 2023

As a Data Principal, you have these rights:

Right to Access

Section 11

Request a summary of your data and processing activities

Right to Correction & Erasure

Section 12

Correct inaccurate data or request deletion

Right to Grievance Redressal

Section 13

File a complaint — we respond within 30 days

Right to Nominate

Section 14

Nominate someone to exercise your rights

Right to Withdraw Consent

Delete your account or contact us anytime

To exercise any right, email support@savdhaan.in. We respond within 30 days.

🔗

Data Sharing & Third Parties

Threat Intel (Google Safe Browsing, PhishTank, URLhaus, WHOIS)

Only extracted URLs/domains/phones — never your identity or full message

AI Analysis (Anthropic Claude)

Message text for classification. Anthropic does not train on this data.

WhatsApp / Meta

Message delivery only, per WhatsApp's own Privacy Policy

Analytics (Vercel, Google Analytics)

Anonymised usage statistics. No personal data shared with advertisers.

Law Enforcement

Only if required by Indian law, court order, or government authority

We do not sell your personal data. We do not share data with advertisers or data brokers.

🔒

Data Security

We implement security safeguards per the IT (Reasonable Security Practices) Rules, 2011:

HTTPS/TLS encryption in transit
bcrypt password hashing
Encrypted environment variables
Restricted database access
Rate limiting & abuse detection
Regular security reviews
🍪

Cookies & Local Storage

Auth tokens

Keep you signed in (localStorage). Cleared on logout.

Essential

Theme preference

Remember light/dark mode choice.

Essential

Analytics cookies

Anonymised usage stats via Vercel & Google Analytics. Blockable via browser settings.

Analytics

We do not use advertising cookies or tracking pixels.

🧒

Children's Data

Per Section 9 of the DPDP Act 2023, we do not knowingly collect personal data from children under 18 without verifiable parental consent. If we discover such data was collected, we will delete it promptly.

🌍

Cross-Border Data Transfer

Some providers (Anthropic, Vercel, Google) may process data outside India. Under DPDP Act 2023, transfers are permitted to countries not restricted by the Central Government. We maintain equivalent protection standards through contractual safeguards.

📨

Grievance Redressal

Under the IT (Intermediary Guidelines) Rules, 2021 and DPDP Act 2023:

Grievance Officersupport@savdhaan.in
First ResponseWithin 72 hours
ResolutionWithin 30 days

If unsatisfied, you may file a complaint with the Data Protection Board of India.

Applicable Law

This policy is governed by Indian law, including:

  • Digital Personal Data Protection (DPDP) Act, 2023
  • Information Technology Act, 2000
  • IT (Reasonable Security Practices) Rules, 2011
  • IT (Intermediary Guidelines) Rules, 2021

Disputes are subject to the exclusive jurisdiction of courts in India.

🔄

Changes to This Policy

Material changes will be notified via email (if you have an account) or by a prominent notice on the website. Continued use after changes constitutes acceptance.

📞

Contact Us