1. Information We Collect
We collect only the information required to provide, maintain, secure, and improve AryaSDR. The categories are:
Account information. Your name, work email address, company name, and role. This is collected when you sign up through Clerk (our authentication provider).
Campaign & lead data. Lead lists you upload or generate, prospect information, email templates, sequence configurations, and campaign performance metrics.
Outreach content. The emails, LinkedIn messages, and WhatsApp messages that Arya drafts and sends on your behalf, plus replies received in response.
Integration data. When you connect Gmail, Google Calendar, LinkedIn, WhatsApp Business, or your CRM, we store OAuth access tokens and the metadata needed to sync emails and calendar events.
Usage & device data. IP address, browser type, operating system, referrer URL, pages visited, and timestamps. Collected via standard server logs and privacy-respecting analytics.
Payment metadata. Plan tier, subscription status, transaction ids. Actual card numbers and UPI IDs are never seen or stored by us; they are handled directly by Razorpay (see Section 3).
2. How We Use Your Data
- To operate the platform: running your campaigns, sending outreach, syncing replies, generating analytics.
- To generate AI-drafted outreach content using models from Anthropic (Claude). Only the minimum context required for a given draft is sent to the model.
- To secure your account: detecting suspicious login activity, rate-limiting abuse, preventing fraud.
- To bill you and process payments through Razorpay.
- To communicate with you about product updates, billing events, and security notifications. You can opt out of non-essential emails at any time from Settings → Notifications.
- To comply with our legal obligations under Indian law and other applicable jurisdictions.
We do not sell your personal data. We do not share your data with advertisers, data brokers, or marketing networks.
3. Third-Party Services
AryaSDR is powered by a small number of trusted sub-processors. Each has been chosen for its security posture and DPA / GDPR compliance. The list may change; the current list is:
| Provider | Purpose | Data |
|---|---|---|
| Clerk | Authentication & session management | Name, email, sign-in metadata |
| Neon | Postgres database hosting | All application data (encrypted at rest) |
| Vercel | Application hosting & edge network | Request logs, IP addresses |
| Anthropic (Claude) | Generative AI for outreach drafting | Draft prompts (no training on your data) |
| Google (Gmail, Calendar) | Email sending & calendar sync (only if connected) | OAuth tokens, message metadata |
| Razorpay | Payment processing (PCI-DSS Level 1) | Card / netbanking details (never touch our servers) |
| Upstash | Redis rate limiting & caching | API request counters, ephemeral session keys |
4. Storage & Security
Application data is stored in a managed Postgres database (Neon), primarily in the AWS ap-south-1 region (Mumbai). Data is encrypted at rest (AES-256) and in transit (TLS 1.2+). OAuth tokens and any secrets are encrypted at the field level.
Access to production data is limited to authorized engineers, secured with SSO + hardware key MFA, and audit-logged.
We retain personal data only as long as your account is active, plus a short window (up to 90 days) after account deletion to satisfy accounting and legal obligations. Backups are retained for up to 30 days.
5. Your Rights
Under the Digital Personal Data Protection Act 2023 (India) and the GDPR (EU / UK), you have the following rights over your personal data:
- Access: request a copy of the data we hold about you.
- Correction: ask us to fix inaccurate or incomplete data.
- Deletion: request permanent deletion of your account and data.
- Portability: receive your data in a common, machine-readable format.
- Withdraw consent: for any processing that relies on consent (e.g. integrations).
- Complain: file a complaint with the Data Protection Board of India or your local supervisory authority.
To exercise any of these rights, email privacy@aryasdr.in. We respond within 30 days.
7. Children's Privacy
AryaSDR is a business-to-business product and is not intended for anyone under 18. We do not knowingly collect personal data from children. If you believe a child has provided us with information, contact us and we will delete it.
8. Changes to This Policy
We may update this Privacy Policy from time to time as our product evolves and as regulations change. Material changes will be notified in-app or by email at least 30 days before they take effect. The “Last updated” date at the top always reflects the current version.
9. Contact Us
Questions about this policy, or want to exercise your data rights? Email us at privacy@aryasdr.in or support@aryasdr.in for general support.
Grievance Officer (as required under Indian law): grievance@aryasdr.in.