Legal
Privacy policy
This policy explains what BHUMITAT TECHNOLOGIES (OPC) PRIVATE LIMITED collects when you use gavedu.ai, why, who else sees it, and how it is protected. It covers the website and the hosted service. We are the data fiduciary (under India's Digital Personal Data Protection Act, 2023) and the data controller (under the EU/UK GDPR) for that data.
1. Information we collect
You give us:
- Account details — name, email address, password hash or the identifier from your Google sign-in, and your chosen language.
- Conversation content — the prompts you send, files or images you upload, and the model output returned to you. Agents and instructions you save are stored the same way.
- Voice — only if you use a voice feature. Audio is transcribed and the transcript is treated as conversation content. Raw audio is not retained after transcription.
- Billing details — name, email, billing country and the GSTIN you enter for a tax invoice. We never receive or store card numbers, UPI IDs, CVVs or OTPs. Those are entered on Stripe's hosted checkout and stay with Stripe.
- Support correspondence — what you write to us and our replies.
We collect automatically: IP address, browser and device type, pages viewed, timestamps, and error diagnostics. We also keep usage counts — how many messages and how much compute your account used — because plan limits and billing depend on them. Those counts record volume and timing, never message content.
We do not buy personal data from data brokers, and we do not build profiles from sources outside the service.
2. How we use it
- To run the service — routing your prompt to a model, returning the answer, and storing the conversation so you can come back to it.
- To operate your account — signing you in, applying your plan's limits, taking payment, issuing invoices.
- To keep it working and safe — diagnosing faults, preventing abuse, fraud and automated scraping, and enforcing the acceptable-use rules in the terms.
- To improve the product — aggregate, non-identifying analytics about which features are used.
- To contact you — service notices, billing notices and security alerts, which you cannot opt out of while you hold an account. Marketing email is separate, opt-in, and unsubscribable in one click.
- To meet legal obligations — tax records, and responses to lawful demands.
We do not train models on your conversations. We do not sell your personal data, and we do not share it for cross-context behavioural advertising. Nobody at BHUMITAT TECHNOLOGIES (OPC) PRIVATE LIMITED reads your conversations except when you ask us to for support, or where we are legally compelled — and access is logged either way.
Our lawful basis. In India we rely on your consent, and on the legitimate uses the DPDP Act permits for a service you asked for. Under the GDPR we rely on performance of the contract (running the service), legitimate interests (security, abuse prevention, product analytics), legal obligation (tax), and consent where consent is what applies.
3. Who we disclose it to
We disclose personal data only to the processors below, each of which is bound by contract to use it solely to provide its service to us. We have no other recipients, and we do not sell or rent data to anyone.
| Recipient | Why they receive it | Processed in |
|---|---|---|
| Our own inference infrastructure | Runs the Gavedu models. Handles most chat requests, including all Indian-language ones. | India and the United States |
| Groq, OpenRouter, OpenAI | Model providers used as fallbacks when our own inference is unavailable or a request needs a capability we do not host. They receive the prompt and return the answer. | United States |
| Stripe | Payments. Receives your name, email, billing country and the amount. Card and UPI details go to Stripe directly and never reach us. | United States, Ireland |
| Clerk | Account authentication and session management. | United States |
| Google (Sign in with Google) | Only if you choose to sign in with Google. We receive your name, email address and profile picture; Google receives the fact that you signed in. | United States |
| Google Analytics 4, PostHog | Product analytics — which pages and features are used, and where people get stuck. Conversation content is never sent to either. | United States |
We also disclose data where the law requires it — to a court, regulator or law-enforcement agency acting under valid legal authority. We check that the demand is valid, disclose only what it covers, and tell you unless we are legally barred from doing so. If the business is ever sold or merged, data transfers with it and you will be told before it becomes subject to a different privacy policy.
4. How disclosure happens
Every disclosure listed above is a machine-to-machine transfer over a TLS-encrypted connection to that provider's API, made at the moment it is needed — your prompt goes to a model provider when that provider answers your request; your billing details go to Stripe when you check out. There is no bulk export, no scheduled data feed, no shared database and no file hand-off. Access is authenticated per request with credentials held only on our servers.
Cross-border transfer. Because we serve customers worldwide, some of these providers process data outside India, as the table shows. The DPDP Act permits transfer to any country the Government of India has not restricted, and we do not transfer to a restricted country. For personal data covered by the EU or UK GDPR, the transfer is made under the European Commission's Standard Contractual Clauses (with the UK Addendum where the UK GDPR applies).
5. How we protect it
- In transit — TLS 1.2 or better on every connection, with HTTP Strict Transport Security. Certificates renew automatically.
- At rest — passwords are stored only as salted hashes and cannot be recovered, only reset. Any third-party credential you save is encrypted with a key held separately from the database.
- Access control — least privilege. Production access is limited to the engineers who need it and is reachable only over a private network, not the public internet. Administrative actions are recorded in an audit log.
- Payments — out of scope by design. Card and UPI data never touch our servers, so it cannot leak from them.
- Secrets and dependencies — API keys live in a secret store, not in code. Changes are reviewed before deployment, and dependencies are scanned automatically for known vulnerabilities.
No system is perfectly secure, and we do not claim otherwise. If a breach is likely to affect you, we will notify you and the Data Protection Board of India without undue delay, and any other regulator the law requires — within 72 hours where the GDPR applies. To report a vulnerability, write to privacy@gavedu.ai; we will not pursue anyone who reports one in good faith and does not access other people's data.
6. How long we keep it
- Conversations, agents and files — until you delete them, or until you delete your account. Deleting a conversation removes it from live systems at once and from backups within 30 days.
- Account details — for as long as the account exists, then deleted within 30 days of an account-deletion request.
- Usage counts — 24 months, in a form that carries no message content, for billing history and capacity planning.
- Invoices and tax records — 8 years, because Indian tax law requires it. This is the one category we cannot delete on request.
- Server and security logs — 90 days.
7. Your rights
Whatever country you are in, you can ask us to do all of the following, and we will:
- Access — get a copy of the personal data we hold about you, and a summary of how it is processed and who it has been shared with.
- Correct — fix data that is wrong, incomplete or out of date.
- Erase — delete your data and your account, subject only to the tax records above.
- Withdraw consent — as easily as you gave it. Withdrawal is not retrospective, and some features stop working without the data they need.
- Port — receive your conversations in a machine- readable format.
- Object or restrict — to processing based on legitimate interests, including analytics.
- Nominate — under the DPDP Act, name someone to exercise these rights for you if you die or become incapacitated.
- Complain — to our grievance officer first (details on the contact page), and after that to the Data Protection Board of India, or your local supervisory authority if you are in the EU or UK.
Write to privacy@gavedu.ai from the address on your account. We acknowledge within 1 working day and complete the request within 30 days, free of charge. We may ask you to confirm your identity before acting — that check protects you, not us. We do not discriminate against anyone for exercising a right.
8. Cookies
We use strictly necessary cookies to keep you signed in and to protect against cross-site request forgery; the service cannot work without them. We also use analytics cookies for the products named in §3, which you can decline without losing any functionality. We do not use advertising cookies and we do not run third-party ad trackers. Your browser's Global Privacy Control signal is honoured as an objection to analytics.
9. Children
The service is not directed at children under 13, and we do not knowingly collect their personal data. Under India's DPDP Act, processing the data of anyone under 18 requires verifiable parental consent, and we do not undertake tracking, behavioural monitoring or targeted advertising towards children at all. If you believe a child has given us personal data, write to privacy@gavedu.ai and we will delete it.
10. Changes to this policy
If we change how we use personal data in a way that materially affects you — a new category collected, a new purpose, a new recipient — we will email the address on your account at least 14 days before the change takes effect. The date at the top of this page always shows the current version.
11. Contact and grievances
Data controller and fiduciary: BHUMITAT TECHNOLOGIES (OPC) PRIVATE LIMITED. Privacy contact: privacy@gavedu.ai.
Our grievance officer, appointed under Rule 3(2) of the IT (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, is named with full contact details on the contact page, together with our registered office address and Indian telephone number. Complaints are acknowledged within 24 hours and resolved within 15 days.