Privacy Policy
Last updated: January 2026 · Applies to NyayaVeda AI web and mobile interfaces
Privacy at a Glance
- ✓We never store the raw text of your legal queries on permanent logs — only an MD5 hash
- ✓We never sell your data to third parties
- ✓We never store your IP address — only a SHA-256 hash for security audit
- ✓You can delete your account and all associated data at any time
- ✓Authentication is handled by Google Firebase — we never see your password
1. Who We Are
NyayaVeda AI is an Indian legal research platform operated by its development team. For privacy inquiries, contact: bhargavabhay182@gmail.com
2. Information We Collect
From Firebase Authentication:
- Email address (from Google account)
- Display name
- Profile photo URL
- Firebase UID (anonymous identifier)
From your use of the Service:
- Legal research query text (stored for your history feature)
- AI-generated response (stored for your history feature)
- Query metadata: confidence score, citation score, timestamps
- Performance metrics: latency, token count (no query content)
Security audit logs (hashed only):
- MD5 hash of query text (not reversible — we cannot recover your query from this)
- SHA-256 hash of IP address (GDPR-compliant — not reversible)
- Event type (login, query, blocked, payment)
3. How We Use Your Information
- To provide the legal research service you requested
- To maintain your query history and bookmarks
- To enforce rate limits and plan quotas
- To process subscription payments via Razorpay
- To detect and prevent abuse, injection attacks, and fraud
- To improve the AI model and retrieval quality (aggregate stats only)
We do NOT use your queries to train AI models without explicit consent.
4. Data Storage and Security
Your data is stored in a PostgreSQL database hosted on servers in India or within AWS/GCP regions with GDPR-equivalent protections. We apply:
- TLS 1.3 encryption in transit
- AES-256 encryption at rest
- Row-level security — each user can only access their own queries
- Firebase Authentication for identity — we never store passwords
- All Razorpay payments processed on Razorpay's PCI-DSS compliant infrastructure
5. Third-Party Services
| Service | Purpose | Data shared |
|---|---|---|
| Google Firebase | Authentication | Email, name, UID |
| Groq (LPU inference) | LLM generation | Your query text (not stored by Groq per their policy) |
| Razorpay | Payment processing | Name, email, payment details (PCI-DSS scope) |
We do not share your data with any other third parties, advertisers, or data brokers.
6. Your Rights
You have the right to:
- Access: Request a copy of all data we hold about you
- Deletion: Delete your account and all associated data from Settings → Delete Account, or by emailing us
- Correction: Update your profile information at any time
- Portability: Export your query history as JSON from the History page
- Opt-out: Stop using the Service at any time
To exercise any of these rights, email bhargavabhay182@gmail.com. We will respond within 30 days.
7. Data Retention
- Query history: retained until you delete it or close your account
- Security audit logs (hashed): 90 days
- Payment records: 7 years (required by Indian accounting law)
- Account data: deleted within 30 days of account deletion request
8. Cookies
We use only essential cookies: a session token cookie to maintain your authentication state. We do not use advertising or tracking cookies. You may disable cookies in your browser, but this will prevent you from staying logged in.
9. Children's Privacy
The Service is not intended for users under 18. If you believe a minor has registered, contact us immediately at bhargavabhay182@gmail.com and we will delete the account.
10. Changes to This Policy
We will notify registered users by email of material changes to this Privacy Policy. Your continued use after the effective date constitutes acceptance.
11. Contact and Grievance Officer
For privacy concerns, data requests, or grievances under the Information Technology Act, 2000 and rules thereunder:
Email: bhargavabhay182@gmail.com
Response time: within 30 days as required by IT Act Rules.