Sanchay ("we", "our", "us") is a personal record-keeping platform that helps Indian families and NRIs track health records, insurance policies, renewal dates, and family wealth (mutual fund SIP). Sanchay is operated by [Your Full Legal Name / Partnership Name], based in India.
For purposes of the Digital Personal Data Protection Act, 2023 ("DPDP Act"), we are the Data Fiduciary with respect to the personal data you provide.
When you create an account, we collect your email address and a hashed (encrypted) password. We do not store your password in plain text — ever.
| Category | Examples | Why collected |
|---|---|---|
| Person profiles | Name, date of birth, relationship, blood group, allergies, medical conditions, emergency contact | To display emergency info and personalise records |
| Insurance policies | Policy name, number, type, premium, renewal date, insurer | To track and remind you of renewals |
| Medical reports | Report name, date, lab/doctor, findings, uploaded files | To maintain a personal medical history |
| Financial data | Mutual fund names, invested amount, units held | To display portfolio value using live AMFI NAV |
| Documents | PDF scans, JPG/PNG images uploaded by you | To store and display your documents on demand |
We collect standard technical data: IP address, browser type, device type, pages visited, and time of access. This is used solely for security monitoring and improving the service.
Under the DPDP Act 2023, certain data is classified as Sensitive Personal Data and requires explicit consent before collection. The following data you may enter into Sanchay falls into this category:
We apply additional safeguards to sensitive data:
All data is stored on Supabase servers located in Singapore (ap-southeast-1) — the nearest region to India with enterprise-grade data centres. Supabase is SOC 2 Type II compliant.
In the event of a data breach that is likely to cause harm to you, we will notify you by email within 72 hours of becoming aware of it, as required under the DPDP Act 2023.
| Service | Purpose | Data shared | Their privacy policy |
|---|---|---|---|
| Supabase | Database, authentication, file storage | All app data (encrypted) | supabase.com/privacy |
| Vercel | Web hosting | IP address, request logs | vercel.com/legal/privacy-policy |
| Razorpay | Payment processing | Email, payment amount (no card numbers) | razorpay.com/privacy |
| Resend | Transactional email (reminders, OTP) | Email address only | resend.com/privacy |
| AMFI India API | Live mutual fund NAV data | No personal data sent — only scheme code queries | amfiindia.com |
We do not sell, rent, or trade your personal data to any third party for any purpose, including advertising.
As a Data Principal under the Digital Personal Data Protection Act, 2023, you have the following rights:
You can view all personal data Sanchay holds about you at any time by logging into your account. You may also request a full data export by emailing support@sanchay.app.
You can update or correct any of your personal data directly within the app at any time. If you need help correcting data you cannot access, contact us.
You may delete your entire account and all associated data from Settings → Delete Account. All data including uploaded documents will be permanently deleted within 30 days. This action is irreversible.
You may withdraw consent for processing sensitive data at any time by deleting your account. Note that withdrawal means we cannot continue providing the service.
If you believe your data rights have been violated, contact our Grievance Officer (see Section 13). If unresolved, you may escalate to the Data Protection Board of India once established.
You may nominate another individual to exercise your data rights in the event of your death or incapacity. Contact us to register a nominee.
Sanchay is not intended for use by children under the age of 18. We do not knowingly collect personal data from minors. If you are a parent or guardian and believe your child has created an account, contact us immediately at support@sanchay.app and we will delete the account promptly.
You may add children as "people" within a family member's account (e.g. tracking a child's medical records), but the account holder must be 18 or older.
Sanchay uses only strictly necessary cookies to maintain your login session. We do not use:
The session cookie is deleted when you sign out or close your browser.
If you access Sanchay from outside India (e.g. USA, UK, UAE, Singapore, Canada), your data is still stored on servers in Singapore and governed by Indian law (DPDP Act 2023). By using the service, you consent to this transfer and storage.
For users in the European Union: while we are primarily governed by Indian law, we endeavour to meet GDPR standards as a matter of good practice. Contact us for a GDPR data processing addendum if required.
We may update this Privacy Policy from time to time. If we make material changes — especially to how we handle sensitive data — we will:
Continued use of Sanchay after the effective date constitutes acceptance of the updated policy. If you disagree with any changes, you may delete your account before the effective date.
As required under the DPDP Act 2023, we have appointed a Grievance Officer to address data-related concerns.
For general queries: support@sanchay.app