Privacy Policy
Version 1 · effective 7 Sept 2026
This policy is still in draft
Drafted for Indian law during the prototype phase. Contains placeholders for legal entity, registered address, grievance officer and support email. Not yet reviewed by a qualified Indian lawyer. We are showing it anyway rather than showing nothing, so you can see how we intend to handle your data while the final version is prepared.
Privacy Policy
Effective date: [EFFECTIVE DATE] Last updated: [EFFECTIVE DATE]
This policy explains what Saayou collects, why, and what you can do about it. It is written to be read, not to be survived.
Saayou is operated by [LEGAL ENTITY NAME], [REGISTERED ADDRESS], India ("Saayou", "we", "us"). For the purposes of the Digital Personal Data Protection Act, 2023 ("DPDP Act"), we are the Data Fiduciary for the personal data described here, and you are the Data Principal.
Saayou is currently a beta product. Features are incomplete and may change. Please read the section "Beta status and what it means for your data" before you sign up.
1. Who can use Saayou
Saayou is for adults. You must be 18 or older to create an account. We do not knowingly create accounts for children, and we do not process children's personal data. If we learn that an account belongs to someone under 18, we will delete it and the data attached to it.
2. What we collect
You give us:
- Account details: your email address and password (stored only as a cryptographic hash, never in readable form).
- Your name, if you choose to give it.
- Health and lifestyle information you enter into the quiz and profile: age band, sex, health goals, diet, sleep, activity, symptoms you report, medications or supplements you tell us about, and your answers to safety screening questions.
- Your supplement stack: which products you save, and which days you mark as taken.
- Anything you send us by email or through a support form.
We collect automatically:
- Basic device and log data: IP address, browser type, pages viewed, timestamps, and error logs. We use this to keep the service running and secure.
- Cookie and session data, described in our Cookie Policy.
We do not collect:
- Payment card details. Saayou does not take payments today.
- Location beyond the coarse country or region implied by your IP address.
- Data from wearables or health apps. If we add this later, it will be optional and we will ask you separately.
3. Health information
The information you enter into the quiz and profile is health information. Under the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, it is treated as sensitive personal data.
We ask for your explicit consent before we store it. That consent is a separate, unticked checkbox at signup. You can withdraw it at any time from your account settings, and withdrawing it deletes the health information we hold about you.
Health information is used for one thing: generating and improving your personal protocol and safety flags. We do not sell it. We do not share it with supplement brands. We do not use it to let brands target you.
4. Why we process your data, and on what basis
| What we do | Why | Legal basis under the DPDP Act | |---|---|---| | Create and secure your account | So you can sign in and your data stays yours | Consent | | Generate your protocol and safety flags | The core service you asked for | Consent | | Save your stack and streaks | So your progress persists between visits | Consent | | Send service emails (verification, password reset, security notices) | To operate the account | Consent, and legitimate uses under the Act | | Keep logs, prevent abuse, fix bugs | To keep the service working and safe | Legitimate uses under the Act | | Aggregate, de-identified analysis of how the product is used | To improve Saayou | Consent |
We do not use your personal data for advertising, and we do not profile you for advertisers.
5. Trust Scores and product links are not personalised advertising
Saayou scores products against a published rubric. A brand cannot pay to change its Trust Score, to appear in your protocol, or to be recommended to you. Scores and recommendations are derived from the rubric and from your stated goals, not from commercial arrangements.
Saayou earns affiliate commission when you buy through some product links. This never affects a Trust Score or a recommendation. See the Terms of Service for the full affiliate disclosure.
6. Who we share data with
We share personal data only with service providers who help us run Saayou, and only as much as they need:
- Cloud hosting and database providers
- Email delivery provider, for verification and password reset messages
- Error monitoring and analytics providers
[LIST NAMED PROCESSORS HERE ONCE FINALISED]
Each is bound by contract to process data only on our instructions.
We will also disclose data if we are legally required to, for example under a valid court order or a lawful request from a government agency.
If Saayou is ever acquired or merged, personal data may transfer as part of that transaction. We will tell you before it happens and you will be able to delete your account first.
7. Where your data is stored
Your data is stored on servers operated by our cloud providers. Some of these may be located outside India. Where that is the case, the transfer is made in line with the DPDP Act and any restrictions the Central Government notifies on specific countries.
8. How long we keep it
- Account and health data: for as long as your account is open.
- After you delete your account: we delete or irreversibly anonymise your personal data within 30 days, except where we must keep something to comply with law.
- Logs: up to 180 days.
- Withdrawn consent: if you withdraw consent for health data, we delete that data promptly and your protocol stops being available.
9. Your rights
Under the DPDP Act you can:
- Access a summary of the personal data we hold about you and what we do with it.
- Correct data that is wrong, and complete data that is incomplete.
- Erase your data, unless we are legally required to keep it.
- Nominate another person to exercise these rights if you die or become incapacitated.
- Withdraw consent at any time. Withdrawing is as easy as giving it, and it does not affect anything we lawfully did before you withdrew.
- Complain to us, and then to the Data Protection Board of India if we do not resolve it.
You can do most of this yourself in account settings, including deleting your account. For anything else, contact our Grievance Officer below.
10. Grievance Officer
In line with the DPDP Act and the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021:
Grievance Officer: [GRIEVANCE OFFICER NAME] Email: [GRIEVANCE EMAIL] Address: [REGISTERED ADDRESS]
We acknowledge complaints within 48 hours and aim to resolve them within 30 days.
If you are not satisfied with our response, you may complain to the Data Protection Board of India.
11. Security
We protect your data with encryption in transit, hashed passwords, access controls limiting staff access to what is needed, and monitoring for unusual activity.
No system is perfectly secure. If a personal data breach occurs, we will notify affected users and the Data Protection Board of India as required by the DPDP Act and its Rules.
12. Beta status and what it means for your data
Saayou is in beta. In plain terms:
- Features are unfinished and may change or be removed.
- Data loss is unlikely but possible. Do not treat Saayou as the only record of anything that matters to you.
- We may contact you for feedback. You can decline.
- We may reset or migrate data structures as the product develops. If that would delete anything you entered, we will tell you first.
13. Changes to this policy
If we change this policy in a way that materially affects you, we will notify you by email and in the app before it takes effect. The "last updated" date at the top always reflects the current version.
14. Contact
[SUPPORT EMAIL] [LEGAL ENTITY NAME], [REGISTERED ADDRESS], India