Privacy Notice

How SHODH collects, uses, and protects your personal data.

This notice is published under the Digital Personal Data Protection Act, 2023 (DPDP Act) and explains what personal data SHODH AI ("SHODH", "we", "us") collects from you as a Data Principal, why, how long we keep it, who we share it with, and how you can exercise your rights.

Last updated: 25 August 2026 (draft, pending legal review).

1. What personal data we collect

We collect the following categories of personal data, only at the points where you actively provide them:

We do not currently run any analytics, advertising, or session-recording trackers. If that changes, non-essential trackers will be gated behind the consent banner described in Section 6, and this notice will be updated first.

2. Why we collect it (purpose of processing)

DataPurposeLegal basis (DPDP)
Name, email, passwordCreate and secure your accountConsent / performance of contract
Role, industry, goalsPersonalize agent behavior and report focusConsent / legitimate use for service delivery
WhatsApp numberSend report/update notifications, if you opt inConsent
Investigation briefs & reportsProvide the core investigation servicePerformance of contract
Billing dataProcess subscription paymentsPerformance of contract
Server logs / cookiesSecurity, fraud prevention, keeping you signed inLegitimate use (strictly necessary)

3. Retention periods

LEGAL REVIEW REQUIRED — the periods below are engineering defaults, not confirmed retention policy. Unless a shorter period is requested via the data-rights process (Section 7) or a longer period is required by law (e.g. billing records under tax law):

4. Who we share data with

We share personal data only with the service providers (data processors) necessary to run SHODH, under contract to use it solely on our behalf:

We do not sell personal data, and we do not share it with advertisers. Some of the providers above may process data outside India; where that is the case, the cross-border transfer basis is pending legal review (LEGAL REVIEW REQUIRED) under the DPDP Act's rules on transfers outside India.

If your research brief names a specific individual, that individual's personal data is processed as part of delivering your report to you. The basis for processing a non-account-holder's personal data this way is flagged for legal review (LEGAL REVIEW REQUIRED) — see also DPDP_PROGRESS.md Section 1.1.

5. Your rights as a Data Principal

Under the DPDP Act, you have the right to:

You can exercise any of these rights using our Data Rights Request form.

6. Consent and cookies

Where we ask for consent (for example, at signup), we ask separately for each purpose — never as a single bundled checkbox — and consent is opt-in (unticked by default). We keep a record of what you consented to, and when, in our consent_records table (see lib/supabase/consent_records.sql in the repository for the schema).

We use strictly-necessary cookies to keep you signed in. We do not currently use any non-essential (analytics/advertising) cookies or trackers. If that changes, a consent banner will ask for your permission before any non-essential tracker loads — the scaffold for that banner already exists in components/public/ConsentBanner.tsx, ready to be wired up if/when such a tracker is added.

7. How to exercise your rights

Submit a request through our Data Rights Request form or contact us directly (see Section 8). We aim to acknowledge every request within 7 days and resolve it within 30 days, per the timelines that will be confirmed on legal review (LEGAL REVIEW REQUIRED).

8. Contact

To raise a concern about how your personal data is processed, or to exercise any of the rights in Section 5, use our Data Rights Request form or our Contact page.

LEGAL REVIEW REQUIRED — the DPDP Act requires a named Grievance Officer and registered address to be published here before this page goes live.