Privacy Policy
Last updated: 20 July 2026
AakrutiAI is a product operated by Shreenath TechCons, the data controller for the purposes of India's Digital Personal Data Protection Act, 2023 ("DPDP Act"). In this policy "we", "us", and "our" refer to Shreenath TechCons. We respect your privacy. This Privacy Policy describes how we collect, use, disclose, and safeguard your information when you use the AakrutiAI website and services (the "Service"). By using AakrutiAI, you agree to the practices described here.
1. Information We Collect
a. Information you provide
- Account data: name, email address, password (hashed), profile picture.
- Content: images you upload (including face reference photos), hook text, video details, and thumbnails you generate.
- Payment data: billing information processed by our payment provider (Easebuzz). We do not store full card numbers, CVV, or UPI PINs.
- Communications: messages you send to support.
b. Information collected automatically
- Device, browser, operating system, IP address.
- Usage data: pages visited, features used, generation history.
- Cookies and similar technologies (see our Cookie Policy).
c. Information from third parties
- Profile info from Google when you sign in with Google.
2. How We Use Your Information
- To provide, maintain, and improve the Service.
- To generate AI thumbnails on your behalf using third-party models (Google Gemini, Replicate).
- To process payments and manage subscriptions.
- To send transactional emails (confirmation, password reset).
- To detect fraud, abuse, and enforce our Terms.
- To comply with legal obligations.
3. How We Share Your Information
We share data only with:
- Service providers that process data on our behalf under strict contractual obligations: Supabase (auth, database), Google Gemini (AI generation), Replicate (AI generation), Resend (email delivery), Easebuzz (payments), Vercel (hosting), PostHog (product analytics), Sentry (crash reporting).
- Legal and safety: to comply with law, court orders, or to protect rights and safety.
- Business transfers: in the event of a merger, acquisition, or asset sale.
We do not sell your personal data to advertisers or data brokers.
4. AI Model Training
Your uploaded images and prompts are sent to third-party AI providers (Google Gemini, Replicate) solely to generate the thumbnails you request. We do not use your content to train our own models. Third-party providers' handling of your data is governed by their own privacy policies.
5. Analytics and Advertising
We use third-party analytics and advertising tools to understand how the product is used and to measure our advertising campaigns:
- PostHog — product analytics (page views, feature usage, errors).
- Meta Pixel (Facebook / Instagram) — measures the effectiveness of our ads and helps us show relevant ads to people similar to our users. The pixel records events such as page views, sign-ups, and subscription purchases. No sensitive personal data (passwords, uploaded photos, payment numbers) is sent to Meta. You can opt out of Meta personalised advertising in your Facebook ad preferences.
6. Data Retention
- Account data: retained while your account is active and up to 12 months after deletion for legal/financial records.
- Generated thumbnails and uploaded images: retained until you delete them, or until account deletion plus 30 days.
- Payment records: retained for 8 years per Indian tax law.
7. Your Rights (DPDP Act 2023)
If you are a Data Principal in India you have the right to:
- Access a summary of your personal data we process.
- Correct or erase inaccurate or unnecessary data.
- Nominate another person to exercise rights in case of incapacity.
- Grievance redressal (see Contact below).
- Withdraw consent at any time.
To exercise any right, email support@aakrutiai.com. We will respond within 30 days.
8. Security
We use industry-standard measures: TLS in transit, encryption at rest where supported, hashed passwords, role-based access, and audit logs. No method of transmission is 100% secure; we cannot guarantee absolute security.
9. International Transfers
Your data may be processed in countries outside India (e.g. United States, EU) by our service providers. We rely on provider contractual safeguards for such transfers.
10. Children
AakrutiAI is not intended for users under 18. We do not knowingly collect personal data from children. If you believe a child has provided data, contact us to delete it.
11. Mobile App (iOS & Android)
The AakrutiAI mobile app is a thin client over the same backend the web app uses. The data practices in Sections 1–10 apply to mobile too. The points below are mobile-specific.
a. What the mobile app collects
- Account data: email + Supabase user ID, identical to the web sign-in.
- Face reference photos (1–3): the photos you take or pick are uploaded to our private Supabase Storage bucket (
face-refs) and the URLs are saved on your user row for re-use across generations. The image bytes are passed inline to Google Gemini for the duration of each generation request only; Google does not retain them (see Section 3). - Uploaded videos (Upload source): picked videos are uploaded directly to a private Supabase Storage bucket (
videos) via a short-lived signed URL — the bytes do not pass through our application servers. Whisper (via Replicate) transcribes the audio for analysis; Replicate's policy is to not train on customer data. - Free-form instructions (Freeform source): the text you type — including any text you ask us to render in your regional language — is sent to Google Gemini (Nano Banana Pro) alongside any reference image you attached. Stored on your thumbnail row as
source_contextfor your own generation history. - Generated thumbnails: stored under your account in the
thumbnailsSupabase Storage bucket; visible only to you. - Product analytics (PostHog): the mobile app sends anonymous-by-default usage events (screens viewed, features used — e.g. a generation started or completed) to PostHog, tied to your user ID so we can understand and improve the product. No IDFA / GAID or cross-app identifier is collected, and analytics data is never sold or used for advertising.
- Crash reporting (Sentry): if the app crashes or hits an error, a diagnostic report (device model, OS version, app version, stack trace) is sent to Sentry so we can fix the problem. Crash reports do not include your photos, videos, or generated thumbnails.
- Device permissions requested: Photos (NSPhotoLibraryUsageDescription) and Camera (NSCameraUsageDescription) — used solely to pick or capture face reference photos and pick source videos. Saving a generated thumbnail uses the Photos / Photos Add permission. The app does not request audio recording permission and does not access contacts, calendar, location, microphone, or any identifier-for-advertisers (IDFA / GAID).
b. What the mobile app does NOT collect
- Advertising identifiers or cross-app tracking:no IDFA / GAID access and no ad-attribution SDK. No App Tracking Transparency prompt is shown because we do not track you across other companies' apps or websites. Analytics (PostHog) and crash reporting (Sentry) are first-party product telemetry — see Section 11a — not advertising trackers.
- Push tokens: push notifications are not currently enabled; we do not collect APNs or FCM tokens.
- Background location, motion, or biometrics.
c. Payments on mobile
The mobile app is read-only with respect to subscriptions: there is no in-app purchase. To upgrade your plan you visit aakrutiai.com/pricing in a browser, where billing is handled by Easebuzz under the same terms described in Section 1. We do not collect or store any payment instrument on the mobile app.
d. Account deletion from the mobile app
Settings → Delete account permanently erases your AakrutiAI account from inside the app. The deletion is identical to the web flow: it removes auth.users, cascades to every public.users child row (thumbnails, generations, subscriptions, referrals, processed payments), and best-effort deletes your storage objects. Stragglers are picked up by the 90-day storage-cleanup cron. Deletion is irreversible.
12. YouTube API Services
AakrutiAI lets you connect your own YouTube channel to publish videos you created and to view your own channel statistics. This feature uses YouTube API Services. By connecting a YouTube channel or using any YouTube feature in AakrutiAI you also agree to the YouTube Terms of Service. Google's handling of your data is described in the Google Privacy Policy.
a. What we access and store
- OAuth tokens:when you connect your channel via Google sign-in, we store the OAuth access and refresh tokens (encrypted at rest) so we can act on your explicit requests — uploading a video you publish, reading your channel's statistics and recent uploads, and applying title/description changes you approve. We only act on your own channel, only when you initiate the action.
- Channel metadata: your channel ID and channel name, stored so we can show which channel is connected.
- Video metadata snapshots:before applying a title/description change you approve, we snapshot the video's existing metadata so you can revert the change with one click.
b. What we do NOT do
- We do not access any other user's or channel's non-public data, and we do not read your YouTube watch history, comments, or subscriptions.
- We do not publish, modify, or delete anything on your channel without an explicit action from you.
- We do not sell or share your YouTube data with third parties.
c. Revoking access and deleting stored data
You can disconnect your YouTube channel at any time from Settings → Connected channelsin AakrutiAI, which deletes our stored tokens for that channel. You can also revoke AakrutiAI's access directly from your Google security settings. Deleting your AakrutiAI account (Settings → Delete account) removes all stored tokens, channel metadata, and snapshots. Stored YouTube data follows the retention rules in Section 6 and is never retained longer than needed to provide the features described above.
13. Changes to This Policy
We may update this policy. Material changes will be notified by email or in-app notice at least 7 days before they take effect.
14. Grievance Officer
Per the DPDP Act 2023 and IT Rules 2011:
Name: Grievance Officer, AakrutiAI
Email: support@aakrutiai.com
15. Contact
Questions about this Privacy Policy? Email support@aakrutiai.com.