Privacy Policy — Vasavi Community

Effective: 15 September 2026 · Version: 2.2

Applies to: the Vasavi Community mobile application (com.vasavi.community) and the invitation and family-invite links we host.

1. Who we are

Vasavi Community is operated by Yealisetty Nikhil, as a sole proprietorship ("we", "us", "our").

For the purposes of the Digital Personal Data Protection Act, 2023 ("DPDP Act") we are the Data Fiduciary for the personal data described in this Policy. You are the Data Principal.

Grievance Officer: Yealisetty Nikhil
Email: yealisettynikhil@gmail.com

Write to that address for any privacy question, data request or complaint. We acknowledge within 48 hours and respond within 30 days.

2. Plain-language summary

We are a private community app, not a public social network. We collect what we need to run the community — who you are, where you belong, what you post, and what you pay for. We do not sell your personal data, and we do not use it for third-party advertising. Advertising inside the app is sold by us, to members' own businesses, and is targeted only by area and placement — never by building a profile of you for an outside advertiser.

Four things are worth knowing before you read further:

  1. Your sign-up code is delivered by SMS through Google Firebase, so Google processes your phone number at that moment (§3.1).
  2. Your profile, posts and business listing are converted into a mathematical index so the in-app assistants can search them. That index is held by a specialist provider outside India (§5.3, §5.4).
  3. Direct and group messages are not end-to-end encrypted (§3.4).
  4. Deleting your account removes most, but not every, record immediately — §8 lists exactly what goes at once and what needs a request.

The detailed sections below are the binding ones. This summary is not.

3. What we collect

We collect only the categories listed here. Each row states what it is, why we have it, and whether you can avoid giving it.

3.1 Account, phone number and the one-time password (OTP)

Your mobile number is your identity on Vasavi Community. There is no email or social sign-in.

DataWhyRequired?
Mobile numberYour login identifier, the destination for your OTP, and our only reliable way to reach youYes
One-time password (OTP)A 6-digit code we generate to prove the number is yours. Issued at sign-up and when you reset a forgotten PINYes
4-digit PINDay-to-day sign-in. Stored only as a BCrypt hash, never in readable form, and never returned by any APIYes
Full nameYour identity in the community directoryYes
Area / branchDetermines which community, businesses and events you seeYes
Email addressOptional alternative contact and login identifier; also passed to the payment gateway when you buy a planOptional

How the OTP is handled. The code is generated, sent and checked by Google Firebase Authentication. We never see it. When you enter it correctly, Firebase gives the app a signed confirmation, and that is the only thing sent to our server. Our server accepts each confirmation once, and only within 10 minutes of your verifying the code — after that it must be done again. The confirmation is never written to the database; the server keeps only a one-way fingerprint of it, in memory, for those 10 minutes, so that the same one cannot be used twice. Firebase applies its own limits on how often a number may be sent a code.

Who sees your number during this step. To deliver the SMS, your mobile number is transmitted to Google (Firebase Authentication), which processes it under its own terms and privacy policy and may share it with the mobile operator that carries the message. We do not send your name, profile or any other field to Google for this purpose. Google's SMS verification also runs an automated anti-abuse check on the device (Play Integrity) to confirm the request comes from a genuine installation of the app.

Session tokens. After sign-in we issue a signed session token valid for 30 days, plus a refresh token. Long sessions are a deliberate choice for our largely 45–65-year-old membership, who should not have to sign in repeatedly. A super administrator can invalidate every token issued to an account instantly. Tokens are stored on your device in the operating system's encrypted secure storage, not in ordinary app storage.

Failed sign-ins. We count consecutive failed PIN attempts and temporarily lock the account after repeated failures. The count and the lock expiry are stored on your account record and never returned to any client.

3.2 Profile information

DataWhyRequired?
Gotra, surname (intiperu), native cityThe gotra network and family-matching featuresOptional
Date of birthBirthday milestones and celebration remindersOptional
Marriage date and marital statusAnniversary milestones, and so family features can tell "unmarried" apart from "married but no date given"Optional
Profession, business nameThe business directoryOptional
Profile and cover photographsYour profile and member ID cardOptional
Instagram handleShown on your profile if you add itOptional
WhatsApp numberFor new accounts this is your login number by default. It is shown to other members unless you turn off Show phone number in Settings, and it can only be changed to a different number after that number is verified by SMSOptional
Preferred language (English/Telugu)So notifications arrive in your languageSet by your toggle
Community badge, subscription tier and plan expiryShowing your standing and unlocking what you have paid forDerived
Additional fields defined by the community administratorOccasionally a super administrator adds a custom profile field (for example a committee role). Any such field, and whether it is optional, is shown to you at the point you fill it inVaries

3.3 Sensitive and special-category data

DataWhyControls
Blood group The community blood-request feature Optional. Hidden by default. It appears in the directory and on your profile only if you explicitly switch on "show for emergencies". Server-side matching for an active blood request works whether or not it is visible, so that an emergency request can still reach you.
Family relationships (parent, spouse, sibling, child and other kinship links) The Family Universe and family-circle features Optional. A relationship is created only when both members declare it. Either side can withdraw it. Visibility is controlled by your Family Privacy settings.

We do not knowingly collect caste-, health-, biometric- or financial-account data beyond what is listed in this Policy.

3.4 Content you create

Feed posts, comments, reactions, community photographs, forum threads and replies, polls and votes, reviews of businesses, milestones, blessing cards, event RSVPs, business listings and visiting cards, promotions, direct messages, group and business chat messages, trip plans, expenses and settlements, invitation designs and their guest lists, and japa/parayanam participation records.

Direct messages and group messages are stored on our servers so that they persist across your devices. They are not end-to-end encrypted. A super administrator can access message content when required to investigate a report of abuse, or when compelled by law. Treat the app as you would a community WhatsApp group, not as a private channel.

3.5 Business information, and information about your customers

If you list a business, we hold the listing itself — name, category, address, contact numbers, description, photographs, opening hours, offers and the reviews members leave — and we show it in the directory.

If you use the AI voice receptionist or the customer-relationship (CRM) features, the app additionally stores records about people who may not be members of Vasavi Community at all: your customers and enquirers. For each we may hold their name, phone number (and alternate/WhatsApp number), email, business name, location, preferred language and contact method, your own notes and tags, a history of calls and follow-ups, and machine-generated commercial estimates such as a purchase-probability score, an estimated deal value, and the products, budget, timeline, objections and risks extracted from a conversation.

Who is responsible for that data. You are. For the personal data of your own customers, you are the Data Fiduciary and we act as your processor: we store and process it on your instructions so that we can provide the CRM and voice features to you. You must have a lawful basis for entering a customer's details, must tell your customers how you use this app to handle their information, and must not upload data you have no right to hold. We delete a business's customer records when you delete them or when you close the business listing, subject to §6. If a customer of yours contacts us directly, we will route their request to you and assist you in answering it.

3.6 Payments and subscriptions

We use Razorpay as our payment gateway, and Google Play Billing where a purchase is made through the Play Store. We receive and store: the payment or purchase identifier, the amount, the plan or product purchased, the status, the receipt or invoice number, the refund record, and the mandate identifier for auto-renewing plans. Your name, mobile number and email are passed to the gateway so it can raise the charge and issue a receipt.

We never receive or store your card number, CVV, UPI PIN, bank account number or net-banking credentials. Those are handled entirely by Razorpay or by Google, under their own privacy policies.

Where a subscription auto-renews, the mandate is held by the gateway, not by us. Cancellation and refund handling are described in our Refund & Cancellation Policy and Subscription & Billing Terms.

3.7 Device and technical data

DataWhy
Firebase push tokenTo deliver notifications. Treated as a device secret: it is write-only and is never returned by any API
Device type (android / ios) and app versionSupport, and knowing which builds are in the field
Last login and last-active timestampAccount security, and understanding whether an account is dormant
Session heartbeatShowing who is currently online. We keep one row per member, refreshed roughly every 30 seconds, and purge it weekly — only a last-active date survives
Security event logFailed sign-ins, lockouts, rate-limit trips and suspicious requests, for fraud prevention
Request correlation identifierA per-request id in our server logs so a support query can be traced to what actually happened

We do not operate a third-party crash-reporting SDK — no crash data is sent to Sentry, Crashlytics or any similar service. When the app hits an unexpected error, our own servers record the error's type, the screen it happened on, your app version, your phone model and Android/iOS version, and the error message and stack trace. We need those last two to actually fix the fault; a fingerprint alone tells us a screen broke and never why.

Because an error message can contain personal data that happened to be in memory at the moment of the fault, both the message and the stack trace pass through automated redaction before they are stored. Phone numbers, email addresses, authentication tokens and long digit sequences (such as card or Aadhaar numbers) are replaced with [redacted]. This runs on our servers, so it applies regardless of what the app sends.

These records are visible only to our super administrators, are kept for 90 days from the last time that error occurred, and are never sold or shared.

3.8 Analytics

Analytics run through two separate sinks, and they differ in what they can identify:

We also record advertisement impressions so we can count how often an ad was shown and report and bill accurately, and we derive an interest profile from what you engage with. It orders what you see inside the app and, while Offers from nearby shops is on, decides whether a SUPREME shop's offer notification is relevant to you (at most one a day). Shops never see your interest profile — only how many members an offer reached.

Turning off analytics collection entirely is not currently offered in-app. If you want your Firebase analytics identity cleared, sign out — that clears the identifier on your device — or write to the Grievance Officer.

3.9 Addresses and places you save

Several features are about a place, so they ask you for one: the address of a business you list, the address of your home when you invite the Parayanam Mandali to it, and the venue of an event or an invitation. You can type these, or use the map picker — search for a place, or drag the pin.

What we store is what you chose: the address text, the Google place identifier, the latitude and longitude of the pin, and for a home visit the optional flat or floor, landmark and access note you add so people can find the door. This is content you entered, not a reading of where your phone was. It is kept for as long as the listing, request, event or invitation it belongs to, is visible to exactly the people who can see that record, and is deleted when you delete it.

The address search and the pin-to-address lookup are provided by Google (Places API and Geocoding API). Those requests are made by our server, not by your phone: Google receives the text you typed, the place you picked and the coordinates of the pin, but not your name, your phone number, your account or your device's network address. Google's handling of that request is governed by its own terms. With no key configured every picker falls back to typing the address by hand, and nothing is sent to Google at all.

3.10 Permissions we request on your device

We ask for each of these at the moment you first use the feature, and the app works without them — you simply cannot use that feature.

PermissionUsed forNotes
Photos and mediaChoosing a profile photo, posting to the feed, uploading a reference photo for AI designs, saving a generated card to your galleryWe access only the items you select
CameraScanning a family member's Family Connect QR code, and taking a photo to post
MicrophoneAI voice calls and voice notesRecording happens only while a voice session is active
Location (approximate and precise) Four things, each one you choose: (a) centring the map picker on where you are when you tap “Use my location”, so you can fill in a business address, the address for a Parayanam at your home, or an event or invitation venue; (b) showing how far away an event venue is; (c) attaching your position to a Parayanam emergency alert; (d) live location sharing with the people on a trip you are part of Foreground only. Background location is explicitly disabled in the app's configuration on both Android and iOS. The map picker reads your position only on that tap — typing the address by hand always works instead — and what is saved is the address and pin you chose, not a reading of where you were. The event distance is worked out on your phone, is never sent to us, and that screen never asks for the permission; it uses it only if you had already granted it. An emergency alert carries your position only when you switch that on for that alert, and it is erased 7 days after the alert is closed. Trip sharing is off until you switch it on, applies only to that one trip, and each record is deleted 12 hours after it is written — exactly one current-position record per member per trip (latitude, longitude and the GPS accuracy your phone reported), so there is no location history to reconstruct, even inside the 12-hour window
NotificationsCommunity, celebration, business and subscription alerts, and offers from nearby shops you are interested inYou can turn off Smart Nudges and Offers from nearby shops separately in settings, and all notifications in your device settings

We do not collect your contact list, your call log, your SMS, your precise location in the background, or any data from other apps. The app does not request the "draw over other apps" permission; it is explicitly blocked.

3.11 AI features, and what is sent to AI providers

When you use an AI feature — the assistants, occasion planning, image and invitation generation, greeting text, translation, or the business AI team — the text of your request and the context needed to answer it are sent to a third-party AI provider, processed there, and the result returned to you. Where you attach a photograph (for example a shop photo used as a reference for a generated card), that image is sent too.

Search index. So that assistants can answer questions like "find a carpenter in my area", we convert community records into numerical representations ("embeddings") and store them in a specialist search database run by Qdrant Cloud. The collections indexed this way include member profiles, family records, business listings, posts, events, satrams, calendar entries, notifications, help articles and CRM records. The text sent for indexing is generated from records you or your community have already created. This index is hosted on servers in Australia (§5.4).

Voice calls. Two different technical paths exist, and they differ in who hears the audio:

In both cases, after the call ends we store a transcript, a summary (in English and Telugu), the detected intent and sentiment, the caller's number, the duration and cost in minutes, and any lead or follow-up record the call produced. We do not store the raw audio recording on our own servers.

3.12 What we do NOT collect

We do not collect data about you from data brokers, we do not track you across other apps or websites, we do not use advertising identifiers for cross-app tracking, and we do not build profiles for sale.

4. Why we process your data (purposes)

We process personal data only for these purposes, and only on the basis of the consent you give at registration and at each permission prompt, or where a legitimate use permitted by law applies (for example, responding to a medical emergency, or complying with a legal obligation):

  1. Running your account — registering you, verifying your number by OTP, signing you in, keeping your session valid, and letting you edit your profile.
  2. The community — the member directory, the gotra network, family circles, the member ID card, area feeds, events, festivals, parayanam and community campaigns.
  3. Businesses and commerce — listings, reviews, visiting cards, promotions, the CRM and voice receptionist, and telling a business owner (on eligible plans) that a member viewed their page.
  4. Celebrations and invitations — generating greetings, invitations and celebration experiences, and delivering per-guest invitation links.
  5. AI features — answering your questions, planning occasions, generating images and designs, searching community records, and voice assistance.
  6. Payments — taking payment, managing auto-renewal, issuing receipts, handling refunds, and preventing payment fraud.
  7. Notifications — celebration reminders, community announcements, business offers and subscription notices, in your chosen language.
  8. Safety and moderation — investigating reports, removing content that breaks our rules, and blocking abuse.
  9. Security and fraud prevention — rate limiting, OTP and sign-in lockouts, audit logging of administrator actions, and detecting misuse.
  10. Improving the app — aggregate usage counts, and error diagnostics.
  11. Legal compliance — tax, accounting, and responding to lawful requests from a court or authorised government agency.

We will not use your personal data for a new purpose that is materially different from these without asking you first.

5. Who can see your data

5.1 Other members

5.2 Administrators

Area administrators and super administrators can view and moderate member content in order to run the community. Sensitive administrative actions are recorded in an audit log. Business-wide administrative powers (approvals, pricing, taxonomy, commerce) are restricted to super administrators only.

5.3 Service providers (Data Processors)

We share the minimum necessary data with the following providers, each under a contract requiring them to protect it and to process it only on our instructions:

ProviderWhat they receivePurpose
MongoDB AtlasThe application databasePrimary data storage
Upstash (managed Redis)Live session state, voice-call session state, notification and webhook de-duplication keys, and game rooms — short-lived, mostly identifiersCaching and real-time state
Google Cloud (Cloud Run, region asia-south1 / Mumbai)Application hosting — every API request and the data in it passes through the serverRunning the backend
CloudinaryImages and media you uploadMedia storage and delivery
Google Firebase (Authentication)Your mobile number, at the moment a code is sent, plus an automated device-integrity checkDelivering and checking your sign-up / PIN-reset code by SMS
Google Firebase (Cloud Messaging, Analytics)Push token, device info, screen and product events, your member id, role and area idNotifications and usage analytics
RazorpayName, mobile number, email, payment detailsPayment processing, autopay mandates, refunds
Google Play BillingPurchase token, product identifierIn-app purchases on Android
Google (Gemini) and, where a super administrator configures them, OpenAI, Anthropic, OpenRouter, Groq and Hugging FaceThe text, and where applicable the image, needed to answer your request or generate your design; and the text used to build the search indexAI assistants, image and design generation, embeddings
ElevenLabsLive call audio, streamed directly from your device, and the call transcriptAI voice conversations
Qdrant CloudEmbeddings of member, family, business, post, event, satram, calendar, notification, help and CRM records, with the source text held alongside themThe search index behind the AI assistants

This is the complete list of processors as at the effective date. If we add or change a processor we update this table and, where the change is material, the Data Safety declaration on the Google Play store listing in the same release.

5.4 Transfers outside India

Several providers above process data on servers outside India — in particular the AI providers, and the Qdrant Cloud search index, which is hosted in Australia. Where that happens we rely on the provider's contractual commitments to protect the data and to process it only on our instructions, and we do not transfer data to any country to which such transfer is restricted by the Central Government.

5.5 We do not sell your data

We do not sell, rent or trade your personal data. We do not share it with third-party advertising networks or data brokers.

5.6 Legal disclosure

We may disclose personal data where we are required to by law, by a court order, or by a lawfully authorised government agency, and where necessary to protect the safety of a person or to enforce our Terms.

6. How long we keep it

DataRetention
OTP codes5 minutes, in server memory only — and destroyed sooner on use or after 5 wrong guesses. Never written to the database
Trip location pings12 hours, deleted automatically by the database itself, with no archive and no history
Parayanam emergency position7 days after the alert is closed, then erased from the alert record. A super administrator can set this between 1 and 90 days; the alert itself, without the position, is kept as a safety record
Addresses and map pins you saveAs long as the business listing, Parayanam request, event or invitation they belong to. Deleted with it
Live session heartbeatUp to 1 week, then reduced to a last-active date
Session and refresh tokens30 days, or until you sign out, or until a super administrator revokes them
Account, profile and contentWhile your account is active
After account deletionRemoved or irreversibly anonymised — see §8
Payment, invoice and tax records8 years from the end of the relevant financial year, as required by Indian tax and company law. Retained even after account deletion
Voice-call transcripts, summaries and lead recordsWhile the owning business account is active, then deleted with it
Business CRM customer recordsControlled by the business that entered them; deleted when they delete the record or close the listing
Moderation and abuse recordsUp to 3 years after the account closes, to stop a blocked user simply re-registering
Security and administrative audit logsUp to 2 years
Aggregate, non-identifying analyticsIndefinitely
Firebase Analytics eventsUnder Google's own retention settings for our Firebase project
Encrypted disaster-recovery backupsRotate out on their own cycle, the longest being 6 months. Backups are never used for ordinary operations. Deleted data may persist in a cold snapshot until it expires; if we restore from one, we re-apply completed deletions

7. Your rights

Under the DPDP Act you may, at any time:

We respond to rights requests within 30 days. To exercise a right, write to yealisettynikhil@gmail.com from the mobile number or email registered on your account, or use the in-app path described in §8.

8. Deleting your account and your data

You can delete your account yourself, from inside the app:

8.1 What happens immediately

Deletion is not queued for later. As soon as you confirm:

  1. Any active subscription is closed and auto-renewal is stopped at the gateway first, so that nothing can continue to charge a deleted account.
  2. Your account record is deleted, including your name, phone number, email, PIN hash, date of birth, gotra, blood group, photographs and push token.
  3. The following are deleted with it: your posts, comments, business listings, milestones, notifications, japa and parayanam records, AI creations, your interest profile, your event RSVPs and your session tokens.
  4. You are removed from event attendee lists, poll votes, trip participant lists and community groups.

An audit record that a deletion took place survives, because a compliance trail must outlive the account it refers to. It records the action, not your content.

8.2 What needs a request

A small set of records is not reached by the automatic cascade, because each of them belongs to a shared context rather than to your account alone:

Tell us at yealisettynikhil@gmail.com — or say so when you request deletion — and we will delete or irreversibly anonymise these within 30 days. We are working to bring all of them into the automatic path.

8.3 What we keep, and why

Payment, invoice, refund and tax records are retained for 8 years from the end of the relevant financial year, because Indian tax and company law requires it. They are kept for that purpose only. Moderation records may be retained for up to 3 years, so that an account blocked for abuse cannot simply re-register.

Deleted data may persist in an encrypted disaster-recovery backup until that backup expires (at most 6 months). Backups are never used for ordinary operations, and if we ever restore from one we re-apply completed deletions.

Cancel any active subscription before deleting, and note that a purchase made through Google Play must also be cancelled in your Play Store account if you want it to stop renewing there.

9. Your duties

The DPDP Act places duties on you too. You must not impersonate another person when providing personal data, must not suppress material information, and must not raise a false or frivolous grievance. Providing verifiably false information may result in your account being suspended.

10. Children

Accounts on Vasavi Community are for individuals aged 18 and above.

Our community features naturally involve families. If you enter information about a child — a child's name, date of birth, photograph, or their relationship to you — you may do so only if you are that child's parent or lawful guardian, and by doing so you consent on the child's behalf as required by the DPDP Act. We do not knowingly show a child's data to anyone outside the family circle in which it was declared, and we do not use a child's data for tracking, behavioural monitoring or targeted advertising.

If you believe a child has registered an account, or that a child's data has been entered without a parent's consent, write to yealisettynikhil@gmail.com and we will remove it.

11. Security

We protect your data with:

No system is completely secure. Keep your PIN private, never share an OTP with anyone — including someone claiming to be from our team, who will never ask for it — and tell us at once if you think your account has been misused.

If a personal data breach occurs, we will notify each affected Data Principal and the Data Protection Board of India without delay, in the manner and within the timelines the DPDP Rules require.

12. Changes to this Policy

We may update this Policy. The current version, with its effective date, is always available at this address and in the app. Where a change materially affects how we use your data, we will notify you in the app and, where the law requires it, ask you to consent again before the change applies to you.

13. Contact

OperatorYealisetty Nikhil (sole proprietorship), trading as Vasavi Community
Grievance OfficerYealisetty Nikhil
Emailyealisettynikhil@gmail.com
Applicationcom.vasavi.community (Android)
EscalationData Protection Board of India