← Back to vedavinya.com
Legal · Data Protection

Privacy Policy

Effective: 20 May 2026Last updated: 20 May 2026Governing law: India

This Privacy Policy explains how Vedavinya Pvt. Ltd. ("Vedavinya", "we", "us") collects, uses, stores, shares and protects your personal data when you use Chaiverse (our social & messaging platform) and Vedavinya AI, together with vedavinya.com and chaiverse.in (the "Services"). It is published under the Digital Personal Data Protection Act, 2023 ("DPDP Act"), the Information Technology Act, 2000 and the IT (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 and the IT (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021.

For the purposes of the DPDP Act, Vedavinya is the Data Fiduciary and you are the Data Principal. This document is a working draft and must be reviewed and approved by the Company's legal counsel / Company Secretary before being relied upon; items shown as TO-BE-CONFIRMED must be finalised.

1. Personal data we collect

We practise data minimisation. We collect only what a feature needs:

  • Account & identity: a username, a device-bound passkey/public key, and (only if you choose) a display name and avatar. Chaiverse identity is passkey-first; phone-number lookup is off by default.
  • Content you create: posts, thoughts, moments, profile information. Private messages are end-to-end encrypted (see §5) — we cannot read them.
  • Technical & device data: app/version, device model, IP address and security/abuse-prevention signals, retained for the minimum period required for security and law (see §8).
  • Payment data: for paid plans, payments are processed by an RBI-authorised payment aggregator. We do not store full card numbers; we retain only a subscription status, invoice and GST records as required under tax law.
  • Support & grievances: information you provide when you contact us or raise a grievance.

We do not run advertising trackers, third-party ad-/marketing cookies, cross-site tracking, or sell personal data. See our Cookie & Tracking Policy.

2. How and why we use your data

  • To create and operate your account and provide the Services;
  • To deliver core features — your chronological feed, messaging, discover — without engagement-maximising profiling;
  • To keep the platform safe (abuse, fraud, spam, security);
  • To process subscriptions, issue GST invoices and prevent fraud;
  • To respond to your requests, grievances and legal obligations;
  • To send service/transactional communications.

We do not use your personal data for behavioural advertising, and we do not build advertising profiles.

3. Lawful basis & consent

We process personal data on the basis of your consent and for legitimate uses permitted under §7 of the DPDP Act (including provision of a service you have requested, compliance with law, and responding to an emergency). Before or at the time of collection we provide an itemised notice in clear English (and supported Indian languages) describing the data, purpose, your rights and how to complain. You may withdraw consent at any time from in-app Settings → Privacy, or by writing to [email protected]; withdrawal is as easy as giving consent and does not affect lawful processing before withdrawal.

4. Children & persons with a guardian

Where a user is a child (under 18) or a person with a disability who has a lawful guardian, we will process personal data only with verifiable consent of the parent/lawful guardian as required by §9 of the DPDP Act. We do not undertake tracking, behavioural monitoring or targeted advertising directed at children, and we do not knowingly process a child's data in a manner likely to cause harm. Age-assurance and parental-consent mechanisms are TO-BE-CONFIRMED and will follow the manner prescribed by the DPDP Rules.

5. Encryption & messaging

Chaiverse private messages use end-to-end encryption with on-device keys. The content of your conversations is not readable by Vedavinya, is not used for advertising or AI training, and is not disclosed because we do not hold the keys. We retain only the minimum routing/abuse metadata necessary to deliver the Service and to comply with law, and we do not build a social graph for advertising.

6. Vedavinya AI

  • Vedavinya AI is trained on a documented, auditable data charter. We do not train Vedavinya AI on your private Chaiverse conversations or private content.
  • If you use Vedavinya AI, your prompts are processed to generate a response and are handled per this Policy; we do not sell them and do not use them to build advertising profiles.
  • AI output may be inaccurate or incomplete and is not professional (legal, medical, financial) advice — see the Terms of Service.

7. Sharing & disclosure

We share personal data only:

  • with Data Processors (e.g. cloud hosting, payment aggregator) bound by contract to process data only on our instructions and to protect it;
  • where required by law or a lawful order by a competent authority following due process under the IT Act / CrPC / BNSS — we assess such requests and disclose the minimum necessary;
  • to protect rights, safety, and to prevent fraud or abuse;
  • on a merger/restructuring, subject to this Policy.

We do not sell, rent or trade personal data, and we do not share it for third-party advertising.

8. Storage, data localisation & retention

Personal data of Indian users is stored and processed on infrastructure located in India ("sovereign by design"). Cross-border transfer, if any, will be restricted to countries not barred by the Central Government and subject to DPDP Act requirements. We retain personal data only as long as necessary for the stated purpose or as required by law (e.g. tax/GST records, CERT-In log retention of 180 days, IT Rules retention of 180 days after cancellation/withdrawal), after which it is erased or anonymised.

9. Security

We implement reasonable security safeguards as required by §8(5) of the DPDP Act and the SPDI Rules, 2011, including encryption in transit and at rest, end-to-end encryption for messaging, passkey-based authentication, access controls, least-privilege, logging and periodic review. No method of transmission or storage is perfectly secure; we work continuously to protect your data.

10. Your rights as a Data Principal

Subject to the DPDP Act, you have the right to:

  • Access a summary of your personal data and processing;
  • Correction, completion and updating of your data;
  • Erasure of your data where no longer necessary or on withdrawal of consent ("right to disappear" — one-tap account deletion in-app);
  • Grievance redressal (see §12 and our Grievance Redressal Policy);
  • Nominate another individual to exercise your rights in the event of death or incapacity;
  • Withdraw consent at any time.

Exercise any right from Settings → Privacy or by writing to [email protected]. You also have corresponding duties under §15 of the DPDP Act (e.g. not to file false or frivolous grievances and not to impersonate another).

11. Personal data breach notification

In the event of a personal data breach, we will notify the Data Protection Board of India (constituted under the DPDP Act, 2023) and affected Data Principals in the manner and within the timelines prescribed under the DPDP Act and its Rules, and report cyber incidents to Indian Computer Emergency Response Team (CERT-In) — https://www.cert-in.org.in within the timelines under the CERT-In Directions, 2022 (including the 6-hour reporting requirement, where applicable).

12. Grievances & the Data Protection Board

Contact our Grievance Officer:

  • Rishav Singh (Interim — TO-BE-CONFIRMED), Grievance Officer
  • Email: [email protected]
  • Vedavinya Pvt. Ltd., [Registered Office Address, Kolkata, West Bengal — TO-BE-CONFIRMED]

We acknowledge grievances within 24 hours and resolve them within the timelines in our Grievance Redressal Policy (and in any case within 15 days under the IT Rules, 2021). If you are not satisfied, you may approach the Data Protection Board of India (constituted under the DPDP Act, 2023), or the relevant Grievance Appellate Committee(s) — https://gac.gov.in (IT Rules, 2021, Rule 3A).

13. Changes & contact

We may update this Policy; material changes will be notified in-app or by email and the "Last updated" date will change. Questions: [email protected]. Registered office: Vedavinya Pvt. Ltd., [Registered Office Address, Kolkata, West Bengal — TO-BE-CONFIRMED].