Privacy Policy

Last updated: February 2026

1. Introduction

Sahayak ("we", "our", or "us") is committed to protecting the privacy of our users and their customers. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our AI customer support platform.

2. Information We Collect

Account Information

When you create an account, we collect your name, email address, and organization details. If you subscribe to a paid plan, we collect billing information through our payment processor (Razorpay).

Knowledge Base Data

We process and store the documents, URLs, and articles you upload to your Knowledge Vault. This data is used to generate AI responses for your customers.

Conversation Data

We store chat conversations between your widget visitors and the AI, including messages, visitor identifiers, and any information visitors voluntarily provide (such as email addresses).

Usage Data

We collect information about how you use the platform, including message counts, feature usage, and analytics data.

3. How We Use Your Information

  • To provide and maintain our AI customer support service
  • To generate relevant AI responses using your knowledge base
  • To detect and respond in the appropriate language (10+ Indian languages supported)
  • To process billing and manage your subscription
  • To provide analytics and insights about your support performance
  • To identify knowledge gaps and improve your AI's responses
  • To communicate with you about service updates and support

4. Third-Party Services

We use the following third-party services to operate our platform:

  • Supabase — Database, authentication, and file storage
  • OpenAI — AI chat responses and text embeddings (for English queries)
  • Sarvam AI — AI chat responses, translation, and language detection (for Indian languages)
  • Razorpay — Payment processing (INR billing)
  • Vercel — Application hosting

5. Data Storage and Security

Your data is stored securely using industry-standard practices. We use row-level security (RLS) policies to ensure complete data isolation between organizations. All data is encrypted in transit using TLS.

6. Data Retention

We retain your data for as long as your account is active. Upon account deletion, your organization data, knowledge base, and conversation history will be permanently deleted within 30 days.

7. DPDP Act Compliance

We comply with India's Digital Personal Data Protection Act, 2023 (DPDP Act). As a data fiduciary, we process personal data only for legitimate purposes with appropriate consent. You have the right to access, correct, and erase your personal data. To exercise these rights, contact us at privacy@sahayak.xyz.

8. Your Rights

  • Access and download your data
  • Correct inaccurate personal data
  • Request deletion of your data
  • Withdraw consent for data processing
  • Lodge a grievance with the Data Protection Board of India

9. Contact Us

If you have questions about this Privacy Policy, contact our Data Protection Officer at privacy@sahayak.xyz.