Privacy Policy — Asym
Privacy Policy — Asym
Effective date: [EFFECTIVE DATE — fill before publishing] Last updated: [LAST UPDATED — fill before publishing]
This Privacy Policy describes how Asym AI Labs Pvt Ltd (“Company”, “we”, “us”), registered office at [REGISTERED OFFICE ADDRESS — fill before publishing], processes your personal data when you use the Asym mobile application (iOS and Android), the associated website and web services at asymmetriclabs.ai, and related services (together, the “Service”).
We are the Data Fiduciary for this processing under the Digital Personal Data Protection Act, 2023 (“DPDP Act”). This Policy also serves as the privacy policy required under the Information Technology Act, 2000 and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011.
By creating an account or using the Service, and by giving consent where we ask for it, you agree to the processing described in this Policy. This Policy is incorporated into our Terms & Conditions.
1. Data We Collect
1.1 Data you provide
| Category | Data | When |
|---|---|---|
| Identity & contact | Name, email address, phone number, username | Account registration and profile |
| Profile (optional unless stated) | Educational/professional background, exam attempt number and year, date of birth, gender, bio, postal address, profile photo, social-media links | Onboarding and profile editing |
| User content | Comments and replies, content ratings, issue/content reports, custom tests you create, bookmarks | When you use those features |
| Payment information | Selected plan, order details, coupon codes, billing state (for GST), payment status | When you purchase a Subscription |
| Support & grievances | The contents of your messages to us | When you contact us |
We do not collect or store your card numbers, UPI PINs, or bank credentials — these go directly to our payment processor (Razorpay).
1.2 Data collected automatically
| Category | Data | Notes |
|---|---|---|
| Device information | Device identifier (Android ID on Android; identifier-for-vendor on iOS), device model, operating system and version, app version, platform | Used to operate sessions and enforce device limits (up to 2 devices per platform) |
| IP address & approximate location | Your IP address and location estimated from it (country, region, city, postal code, approximate coordinates, timezone, internet service provider) | Derived through the third-party service ip-api.com at sign-in; stored with login records for security and fraud prevention |
| Login & security records | Sign-in events, sign-in method, device ID, IP address, hashed one-time passwords | Security auditing |
| Usage & study data | Questions attempted, answers (correct/incorrect/skipped), test results, progress, streaks, feature usage, content interactions | Powers your progress tracking and personalised study experience |
| AI feature logs | Your queries to AI-assisted features and the responses generated | See Section 4 |
| Diagnostics | Crash logs and performance data (Firebase Crashlytics on the apps; Sentry on our servers) | Crash reports are not tied to your marketing profile |
| Notifications | Push-notification tokens/topics (Firebase Cloud Messaging / Apple Push Notification service) | You can disable notifications at any time |
We do not collect your precise GPS location, contacts, photos (other than a profile photo you choose to upload), microphone, or camera data. We do not use advertising identifiers for tracking and we do not serve third-party advertising.
1.3 Data from third parties
If you sign in with Google or Apple, we receive your name, email address, a unique sign-in identifier, and (for Google) your profile picture, as permitted by your settings with that provider.
2. Why We Process Your Data (Purposes and Legal Basis)
Under the DPDP Act we process personal data with your consent (Section 6) or for legitimate uses (Section 7), as follows:
| Purpose | Data used | Basis |
|---|---|---|
| Creating and operating your account; providing the Service you signed up for | Identity, contact, profile, device, usage | Consent / voluntary provision for the specified purpose |
| Authentication (OTP delivery, SSO), session management, device limits | Contact, device identifiers | Consent / specified purpose |
| Progress tracking, statistics, personalised study features | Usage & study data | Consent / specified purpose |
| Processing payments, invoicing, GST compliance, refunds | Payment information, billing state | Specified purpose; legal obligation (tax law) |
| Security, fraud prevention, abuse prevention, enforcing device limits | Login records, IP address, approximate location, device ID, hashed identifiers of deleted accounts | Legitimate use (security) |
| AI-assisted features | Your queries and relevant study context | Consent / specified purpose |
| Service communications (OTPs, receipts, service notices) | Contact data | Specified purpose |
| Responding to support requests and grievances | Support data | Specified purpose; legal obligation |
| Diagnosing crashes and improving stability | Diagnostics | Specified purpose |
| Complying with law and lawful orders | As required | Legal obligation |
We do not use your personal data for third-party advertising, and we do not sell personal data.
3. Who We Share Data With (Data Processors and Recipients)
We share personal data only with service providers who process it on our behalf under contract, and with authorities where legally required:
| Recipient | Role | Data involved |
|---|---|---|
| Amazon Web Services (AWS) | Cloud hosting, file storage, content delivery, transactional email, SMS | Most Service data, incl. profile photos and content |
| Razorpay Software Pvt Ltd | Payment processing | Order and payment data; your payment credentials are collected by Razorpay directly |
| MSG91 / Twilio / AWS SNS | OTP and SMS delivery | Phone number, OTP message |
| Google (Firebase) | Push notifications, crash reporting; on Android, Firebase Analytics for aggregate app-usage statistics | Device data, crash data, notification tokens |
| Google / Apple | Sign-in (if you choose SSO); push delivery on iOS | Sign-in identity data; notification tokens |
| ip-api.com | IP-based location lookup at sign-in | Your IP address |
| Sentry | Server-side error monitoring | Technical error context (configured not to send personal data by default) |
| AI providers: OpenAI, Anthropic, Google (Gemini), ElevenLabs, Sarvam AI | Generating AI answers, explanations, and audio for AI-assisted features | Your queries and relevant study content |
| Professional advisers, auditors, and government/judicial authorities | Compliance, when required by law or lawful order | As required |
If the Company is involved in a merger, acquisition, or asset sale, personal data may be transferred as part of that transaction, subject to this Policy and notice to you.
4. AI Processing
When you use AI-assisted features (such as AI search or AI-generated explanations and audio), your query and relevant study context are sent to one or more of the AI providers listed in Section 3 to generate the response, and your queries and the responses are logged on our systems to operate and improve the feature and prevent abuse. AI providers process this data as our processors and are not permitted to use it to train their general-purpose models under our applicable agreements. Do not enter sensitive personal information into AI features.
5. Cross-Border Transfers
Some of our service providers (including AWS, Google, Apple, Sentry, Twilio, ip-api.com, and the AI providers) may process data on servers located outside India. Where personal data is transferred outside India, we do so in accordance with Section 16 of the DPDP Act and any countries or conditions notified by the Central Government, and we require our processors to protect it to the standards described in this Policy.
6. How Long We Keep Data (Retention)
| Data | Retention |
|---|---|
| Account and profile data | For as long as your account is active |
| Study/usage data | For as long as your account is active |
| Login and security records (incl. IP and approximate location) | 90 days, unless needed longer for an ongoing security investigation or legal obligation |
| Payment and order records | 8 years after the transaction, as required by Indian tax and company-law record-keeping obligations |
| AI feature logs | Up to 12 months, then deleted or anonymised |
| Support and grievance correspondence | 3 years after closure |
| Hashed identifiers of deleted accounts (Section 7) | Retained in one-way hashed form to prevent abuse (e.g., repeat fraudulent sign-ups) |
When data is no longer required for its purpose, we delete or anonymise it.
7. Account Deletion
You can delete your account at any time:
- In the app: Profile → Account → Delete Account; or
- By email: write to support@asymmetriclabs.ai from your registered email.
On deletion, your personal identifiers are removed or anonymised: your email and phone number are replaced with random values in our live systems, your profile is deactivated, and content that must remain for the integrity of the Service (e.g., comments visible to other users) is de-identified. We retain only: (a) one-way SHA-256 hashes of your email and phone number, to prevent abuse; and (b) records we must keep by law (e.g., payment records, per Section 6). Backups are purged on their normal rotation cycle.
8. Your Rights (DPDP Act, Sections 11–14)
As a Data Principal you have the right to:
- Access — obtain a summary of the personal data we process about you, the processing activities, and the recipients it has been shared with;
- Correction and erasure — have inaccurate or incomplete data corrected, and data erased when it is no longer necessary for the purpose (subject to legal retention duties);
- Grievance redressal — a readily available means of registering a grievance (Section 10 below);
- Nomination — nominate a person to exercise your rights in the event of your death or incapacity;
- Withdraw consent — at any time, with effect for the future, as easily as you gave it; we will stop the consent-based processing (some features, or the Service as a whole, may become unavailable as a result).
To exercise any right, use the in-app options where available or email legal@asymmetriclabs.ai from your registered email. We will respond within the timelines prescribed by law. If you are not satisfied with our response, you may complain to the Data Protection Board of India.
9. Children
The Service is intended for users aged 16 and above. Under the DPDP Act, persons under 18 are children: if you are 16–17, your parent or legal guardian must provide verifiable consent before you use the Service, and they accept our Terms on your behalf. We do not undertake behavioural monitoring of, or targeted advertising directed at, children. We do not knowingly process data of anyone under 16; if you believe we have done so, contact legal@asymmetriclabs.ai and we will delete it.
10. Grievance Officer and Data Protection Contact
Grievance Officer: Dr. Amirth Prasad Email: legal@asymmetriclabs.ai Address: Asym AI Labs Pvt Ltd, [REGISTERED OFFICE ADDRESS]
We will acknowledge grievances within 24 hours and resolve them within 15 days. This contact also serves for all data-protection questions, consent withdrawal, and rights requests under the DPDP Act.
11. Security
We use reasonable security safeguards appropriate to the data we process, as required under Section 8(5) of the DPDP Act and the SPDI Rules, including:
- encryption in transit (TLS/HTTPS) for the Service’s own APIs;
- encryption at rest for stored files (server-side encryption on cloud storage) and encrypted delivery of premium audio content via signed URLs;
- passwordless authentication — we never store passwords; one-time passwords are stored only as one-way hashes;
- access controls and audit logging for administrative access to personal data (including logging of any access to unmasked personal data);
- device-limit and session controls, and monitoring of login activity.
No system is completely secure. In the event of a personal-data breach, we will notify the Data Protection Board of India and affected users as required by the DPDP Act.
12. Cookies, Local Storage, and Notifications
- Apps: we store your session tokens, preferences, and downloaded study content on your device (in secure storage where available) so the app works offline and keeps you signed in. Clearing app data or uninstalling removes it.
- Website: our web service uses cookies/local storage strictly necessary for sign-in and preferences. We do not use third-party advertising cookies.
- Push notifications: sent via Firebase Cloud Messaging / Apple Push Notification service. You can turn them off in the app settings or your device settings at any time.
- Transactional SMS/email: OTPs and service messages are necessary to operate the Service and cannot be opted out of while you hold an account.
13. Changes to This Policy
We may update this Policy from time to time. Material changes will be notified through the Service (in-app notice or email) before they take effect, and the “Last updated” date above will change. Where a change requires fresh consent under the DPDP Act, we will seek it.
14. Contact
Asym AI Labs Pvt Ltd [REGISTERED OFFICE ADDRESS] Data protection & grievances: legal@asymmetriclabs.ai (Grievance Officer: Dr. Amirth Prasad) Support: support@asymmetriclabs.ai Website: https://asymmetriclabs.ai