🔒 PRIVACY POLICY

We Built This to Protect Your Data.
We Won't Misuse It Either.

Saaph.in is a privacy product. Our entire purpose is to remove your data from the internet — so we hold ourselves to a higher standard than most companies. This policy explains exactly what we do and don't do with information you share with us.

📅 Effective: January 2025 📍 Governing law: India (DPDP Act 2023) 📧 Contact: data@saaph.in
🛡️
Our core commitments — in plain language

Free scan data (your name, phone, email, city) is processed entirely in your browser and never transmitted to our servers. We do not sell, rent, or share your personal data with third parties. We do not show you ads. We do not use tracking pixels or ad networks.

In this policy
  1. Who We Are
  2. Free Scan — What We Collect and Where It Goes
  3. Account Data (Pro & Family Plans)
  4. What We Explicitly Don't Do
  5. Cookies and Analytics
  6. Your Rights Under DPDP Act 2023
  7. Data Retention
  8. Security
  9. Changes to This Policy
  10. Contact Us
01

Who We Are

Saaph.in ("we", "us", "our") is an Indian personal data removal service operating at saaph.in. We help individuals discover where their personal data is exposed on Indian and global platforms, and file DPDP Act 2023-compliant removal requests on their behalf.

For the purpose of India's Digital Personal Data Protection Act 2023, Saaph.in is the Data Fiduciary for data you provide when creating an account. For free scan users, no data fiduciary relationship exists because no data reaches our servers.

02

Free Scan — What We Collect and Where It Goes

When you use the free scan on our homepage, you enter your name, phone number, email address, and city. Here is exactly what happens to that information:

Data Point Where It Goes Sent to Our Servers?
Full Name Stored in your browser's localStorage only. Used to simulate scan results on your screen. No
Phone Number Stored in your browser's localStorage only. Used to display what would be found on platforms like TrueCaller. No
Email Address Stored in your browser's localStorage only. Used to show data broker exposure simulation. No
City Stored in your browser's localStorage only. Used to customise scan results by geography. No
Scan Results Generated locally in your browser based on statistical patterns. Stored in localStorage for the results page. No
💡
What "localStorage" means

LocalStorage is a browser feature that stores data on your device — like a cookie, but not transmitted with web requests. Your free scan data lives only on your phone or computer. When you clear your browser data, it's gone. We cannot access it.

The free scan results are illustrative and simulated, based on statistical patterns of data exposure common to Indian users. They are not the result of real-time queries to external platforms. Actual data discovery and verified removal requires creating a Pro account.

03

Account Data (Pro & Family Plans)

When you create an account to use our Pro or Family plan, we collect and securely store:

  • Name — to address removal requests correctly
  • Email address — for account access and removal request confirmations
  • Mobile number — for account verification and removal requests
  • City — to prioritise platform coverage relevant to your location
  • Payment details — processed entirely by Razorpay. We never see or store your card or UPI details.
  • Platform scan results and removal history — so we can track progress and re-scan automatically every 90 days

This data is used only to deliver the service you've paid for: finding your data, filing erasure requests on your behalf, and monitoring re-appearance. We do not use it for any other purpose.

04

What We Explicitly Don't Do

Given that we're a privacy company, we think it's important to be explicit:

  • ❌ We do not sell, rent, or trade your personal data to any third party
  • ❌ We do not share your data with advertisers or marketing platforms
  • ❌ We do not use Google Analytics, Facebook Pixel, or any ad network tracking
  • ❌ We do not send your data to data brokers (that would defeat our purpose entirely)
  • ❌ We do not display targeted ads anywhere on our platform
  • ❌ We do not use your data to train AI models
  • ❌ We do not retain free scan data on our servers — we never receive it
  • ❌ We do not keep your data after account closure beyond what is legally required
05

Cookies and Analytics

We use a minimal set of cookies, all strictly necessary for the service to function:

  • Session cookie — keeps you logged into your account. Expires when you close your browser unless you select "Remember me".
  • CSRF token — a security measure that prevents cross-site request forgery attacks.

We do not use advertising cookies, third-party analytics cookies, or any cookie that tracks your activity across other websites. We do not use Google Analytics. Our internal analytics (page views, feature usage) use privacy-preserving, aggregated counts with no personal identifiers.

06

Your Rights Under DPDP Act 2023

As an account holder, you have the following rights over data we hold about you:

  • Access — request a copy of all personal data we hold about you
  • Correction — request correction of any inaccurate information
  • Erasure — request permanent deletion of your account and all associated data
  • Portability — receive your scan history and removal records in a machine-readable format
  • Withdrawal of consent — close your account and stop all processing at any time

To exercise any of these rights, email data@saaph.in with the subject "DPDP Rights Request". We will respond within 7 business days and complete any action within 30 days.

07

Data Retention

We retain your account data for as long as your subscription is active. When you close your account:

  • Your personal profile, scan history, and removal records are deleted within 30 days
  • Anonymised, aggregated statistics (e.g. "X removal requests sent to TrueCaller this month") may be retained for service improvement — these contain no personal identifiers
  • Payment records are retained for 7 years as required by Indian financial regulations (GST Act), but stored by our payment processor Razorpay, not by us

Free scan users: since we never receive your data, there is nothing to delete.

08

Security

We implement industry-standard security measures to protect account data:

  • All data transmitted between your browser and our servers is encrypted using TLS 1.3
  • Account passwords are hashed using bcrypt and never stored in plain text
  • Database access is restricted to authorised personnel only, with audit logging
  • We conduct regular security reviews and vulnerability assessments

If you believe your account has been compromised, contact us immediately at data@saaph.in.

⚠️
In the event of a data breach

We will notify affected users and the Data Protection Board of India within the timeframe required by DPDP Act 2023 regulations. We will be transparent about what data was affected and what steps we're taking.

09

Changes to This Policy

We may update this Privacy Policy when our practices change or when required by law. If we make material changes, we will notify account holders by email at least 14 days before the change takes effect. Continued use of the service after notification constitutes acceptance of the updated policy.

The effective date at the top of this page shows when this version was last updated. Previous versions are available on request.

10

Contact Us

If you have any questions about this Privacy Policy or how we handle your data, please reach out:

Data Protection Officer — Saaph.in
📧 data@saaph.in
🌐 saaph.in
⏱ Response time: within 7 business days
📍 India (Governing law: DPDP Act 2023 & IT Act 2000)