What we collect, exactly why, how long we keep it, and the rights the DPDP Act 2023 gives you. The short version: we collect the minimum for the step you are on, every consent expires, and we sell nothing.
Vriksha AI Technologies Private Limited is the data fiduciary for personal data processed on Rupyam, under the Digital Personal Data Protection Act 2023 and the Information Technology rules that apply to us. The rule we hold ourselves to is stricter than the law's minimum: every collection states its purpose, every consent expires, and nothing is pre-ticked, anywhere, ever.
| Data | Why | When |
|---|---|---|
| Mobile number and OTP verification | Your account identity. It is the only thing an account needs to exist. | At signup |
| Documents you upload or import (loan letters, policies, statements) | To run the check you asked for. Each imported document takes its own tick. | When you run a check |
| Consent records (the Ticks) | The verbatim text you agreed to, where and in which language — our proof and yours. | At every grant, decline and revocation |
| Call recordings | Quality and dispute resolution, only where you granted the recording tick. Declining recording never blocks the call. | Only with a live recording grant |
| De-identified product analytics | To understand the journey and improve completion. Events use random device/session identifiers and exclude names, contact details, PAN, income, bureau data, document contents, balances, messages, audio and transcripts. Off by default. | Only after you allow analytics cookies |
| Live voice-advisor audio and transcript | To answer the financial question you actively ask in the Advisor section. The session begins after a separate microphone consent and uses a short-lived connection credential. | Only while you actively run the voice advisor |
| Policy document and extracted policy brief | To explain the policy you deliberately upload and ground the text or voice questions you ask about it. | Only after a separate one-time policy-analysis consent |
Consent on Rupyam is a stored record, not a checkbox: each grant names its channel, its purpose in one plain sentence, its frequency cap and its expiry date, and stores the exact wording you saw, the page you were on and the language it was in. You can read every live grant at any time, and revoke any of them — revocation works even when you are logged out, takes effect immediately, and generates its own dated record.
Withdrawal is as easy as the grant. Nothing in the product is withheld because you declined or revoked a contact permission.
Your data page at /account/data shows what we hold about you, per purpose. Signed-in members delete their account from the app itself: once a one-time code is confirmed the erase runs immediately — call forwarding to Rupyam must be switched off on every screened line first — and it issues a deletion receipt whose status anyone can check at /account/data?receipt=… without logging in. Consent records are kept for 7 years with identifiers removed. Requests made while logged out go by email to the grievance inbox and are answered within 30 days.
| Data class | Retention |
|---|---|
| Uploaded and imported documents | For as long as needed to provide the check you requested, or until you delete them or close your account, subject to records we must retain by law |
| Consent records | 7 years past account closure — they are your proof as much as ours |
| Call and chat logs | 2 years; transcripts are PII-redacted after that |
| Analytics events | Pseudonymous by design and retained only under the published analytics-retention schedule; never joined to documents, voice, transcripts, PAN, income or bureau information |
| Live interpreter media | Processed during the session; Rupyam does not add the audio or transcript to journey analytics or save it as an advisor record unless you separately choose to do so |
| One-time policy analysis | The original file is sent inline for analysis and is not retained by Rupyam in this browser flow; the extracted brief and chat remain only in the open page and are cleared when you remove them or leave/reload the page |
Rupyam does not send your information to a bank, NBFC, lender, insurer or credit bureau to obtain an offer, start an application or make an eligibility decision. Data is shared only with processors that run Rupyam under contract and on our instructions, when you expressly choose to export or send information yourself, or with authorities where the law compels it. Personal data is stored in India.
If you connect a Google account, Rupyam reads only what you granted: Gmail to find financial documents you asked us to fetch, and Calendar free/busy so a call lands when you are free. We can see that you are busy. We cannot see why — no event titles, no attendees, no locations.
Rupyam's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Concretely: Google user data is used only to provide and improve the features you connected it for; it is never sold; it is never used for advertising; it is not transferred to others except as needed to provide those features, to comply with law, or as part of a merger with prior notice; and no human reads it except with your explicit consent, to resolve a support issue you raised, or where the law requires.
Documents fetched from Gmail are processed and deleted; nothing is retained without a tick on that specific document. Disconnect either connection at any time from your Ticks, and the access token is revoked.
When you deliberately upload a policy in the Advisor section, the original PDF or image is sent inline over an encrypted connection to Google Gemini for one-time extraction. Rupyam receives a bounded brief of policy facts, findings and page/clause references. In this browser flow, Rupyam does not persist the original file, extracted brief or policy chat. The brief may be sent with the text or live-voice questions you deliberately ask, so the answer can stay grounded in your policy. AI extraction can be wrong; the policy wording remains authoritative.
When you deliberately start the voice advisor, audio and the policy brief shown on screen (if one is attached) are sent over an encrypted live connection to Google Gemini to return spoken audio and captions. Rupyam's server issues a short-lived, feature-limited credential; the Gemini API key is never placed in the app. You can stop the session at any time, which closes the microphone and connection. Rupyam AI explains a user-supplied document; it does not recommend, sell or renew insurance and cannot place a transaction.
Our parent company publishes group-level policies at vriksha.ai. For anything that happens on Rupyam surfaces, this policy governs; where this policy is silent, the group privacy policy applies.
Material changes to this policy are announced on this page with a new effective date. Questions about personal data go to privacy@rupyam.com; grievances to grievance@rupyam.com. The registered office is at Flat C1-123, Gottigere Main Road, Chikka Kammanahalli, Bannerghatta, Bangalore South, Karnataka 560083.
Vriksha AI Technologies Private Limited · Registered office: Flat C1-123, Gottigere Main Road, Chikka Kammanahalli, Bannerghatta, Bangalore South, Karnataka 560083 · Business address: Building No. 46, 1st Floor, 12th Main Road, behind HSR BDA Complex, Sector 6, HSR Layout, Bengaluru, Karnataka 560102 · Questions to support@rupyam.com · Grievances to grievance@rupyam.com · See all policies at rupyam.com/legal