Skip to content
Sarva

Privacy Policy

Last updated: 26 September 2026

This policy explains what personal data SARVA ("Sarva", "we", "us") collects when you use the Sarva website and tools (the "Service"), why, who else handles it, how long we keep it, and the rights you have. It is our notice under India's Digital Personal Data Protection Act, 2023 ("DPDP Act") and, where they apply to you, the EU/UK GDPR and US state privacy laws such as the CCPA.

1. Who is responsible for your data

SARVA, based in Delhi, India, decides how and why your personal data is processed. We are the "Data Fiduciary" under the DPDP Act and the "controller" under the GDPR. Contact us about anything in this policy at support.sarvaeditor@gmail.com.

2. What we collect and why

We collect only what the Service needs. The table shows each kind of data, why we use it, the legal basis for doing so, and how long we keep it.

DataWhy we use itLegal basisKept for
Files you upload to server-side tools (PDF, Word, Excel, CSV and similar), their name, size and typeTo perform the operation you asked for and let you download the resultPerforming our contract with you; your consent24 hours if you are not signed in; 30 days in your history if you are, then deleted automatically
AI inputs: text you submit, documents you ask us to summarise, and YouTube linksTo generate the summary or transcript you asked forPerforming our contract; your consentNot stored with your account. Results for a public YouTube video are cached by video, not by user
Account details: email address, name, and (if you use a password) a one-way hash of it (never the password itself)To create and secure your account and sign you inPerforming our contractUntil you delete your account
Sign-in provider details (Google, Apple, GitHub or Microsoft): your verified email and nameTo sign you in without a Sarva passwordPerforming our contract; your consentUntil you delete your account
Email verification codes (stored only as a hash), session tokens, and your last-active time. Password-reset links are signed, so nothing about them is storedTo verify your email, keep you signed in, reset passwords, and sign you out after inactivityPerforming our contract; securityCodes: 10 minutes. Reset links: 24 hours. Sessions: at most 3 hours, or 40 minutes idle
Plan and billing records: plan, subscription status, renewal dates, and Razorpay subscription and invoice referencesTo provide Premium, show your payment history, and handle renewals and cancellationsPerforming our contract; legal obligation (tax and accounting)While your account exists; Razorpay keeps its own records as the law requires
IP address and approximate countryTo apply rate limits, block abuse, keep the Service secure, and show prices in your currencyLegitimate interest in security; performing our contractRate-limit counters: up to one day. Hosting logs: a limited period set by our hosting providers
Usage and performance data: pages visited, device and browser type, page speedTo understand aggregate usage and keep the site fastLegitimate interestAggregated by our analytics provider; not linked to your account

Payment details. Payments happen on Razorpay's own hosted page. We never see or store your card number, UPI ID, bank details or CVV.

Browser-only tools. Some tools, including the text, JSON, Markdown, Base64 and image utilities, and small CSV files, run entirely in your browser. Those files are never uploaded to us and we never receive their contents.

We do not collect sensitive categories of data on purpose. Please do not upload documents containing other people's personal data unless you are entitled to.

3. What we do not do

  • We do not sell your personal data, and we do not "share" it for cross-context behavioural advertising.
  • We do not show ads, and we do not use your files or AI inputs to build profiles or for advertising.
  • We do not train AI models on your content.
  • We do not make decisions about you that have legal or similarly significant effects by automated means alone.

4. Who else handles your data

We use a small number of service providers ("processors") to run the Service. Each receives only what it needs for its function and may use it only to provide that function to us.

ProviderWhat it doesData it receives
RazorpayPayments and subscriptionsYour email, plan, and the payment details you enter on its page
SupabaseDatabase hostingAccount, plan and file records
RenderApplication hostingUploaded files while they are processed and stored; IP address in logs
VercelWebsite hosting, cookieless analytics and speed measurementIP address, pages visited, device and browser type
Our email provider (SMTP), through a relay hosted on VercelSending verification codes, password resets and account noticesYour email address and the message
Google, Apple, GitHub, MicrosoftSign-in, only if you choose one of themConfirmation of your identity
AI providers (currently Google Gemini and Groq)Generating summaries and transcriptsThe text, document text or video link you submit
Supadata and YouTubeFetching captions for a YouTube link you submitThe video link only, nothing about you

We choose AI providers whose terms for API use do not allow training on submitted content, but their handling is governed by their own terms. Do not submit highly sensitive material to AI features. We may also disclose data where the law requires it (for example to comply with a valid court or government order) or to protect the rights, safety or property of our users or the Service.

5. Cookies and browser storage

We use only what the Service needs to work. We do not use advertising or cross-site tracking cookies.

  • sarva_auth: keeps you signed in. httpOnly, so page scripts cannot read it. Expires after at most 3 hours.
  • csrftoken: protects your account from cross-site request forgery.
  • Session storage: a flag that a checkout is in progress, so we can take you to your account once the payment is confirmed. Cleared when you close the tab.

These are strictly necessary, so they do not need consent; blocking them will stop sign-in from working. Our analytics (Vercel) is cookieless, and we do not keep personal data in your browser's local storage.

6. How we protect your data

  • All traffic uses HTTPS (TLS).
  • Passwords and email verification codes are stored only as one-way hashes; password-reset links are signed and expire.
  • Your session lives in an httpOnly cookie and expires after inactivity.
  • Links to your files are signed and expire after a few hours, and only your account can reach a signed-in user's files.
  • Our database provider encrypts the database at rest.
  • Rate limits, upload checks and size limits protect the Service from abuse.

What this does not mean. The Service is not end-to-end encrypted. To convert, edit or summarise your file, our servers (and, for AI features, the providers above) must read it. Uploaded files are stored on our hosting provider's disks until they are deleted automatically. No system is perfectly secure; keep your own copy of anything important.

If something goes wrong. If a personal data breach affects you, we will tell you and the relevant authorities without undue delay, as the DPDP Act, the GDPR and other applicable laws require.

7. Your rights

Wherever you live, you can ask us to:

  • Access: get a summary of the personal data we hold about you and how we use it.
  • Correct or update data that is inaccurate or incomplete.
  • Erase your data. You can do this yourself at any time from your account page: it cancels any subscription, then permanently deletes your profile, sign-in details and every file in your history.
  • Withdraw consent, as easily as you gave it. This does not affect processing already done.
  • Get a copy of data you gave us in a portable format (GDPR).
  • Object to or restrict processing based on legitimate interest (GDPR).
  • Nominate someone to exercise your rights if you die or become incapable (DPDP Act).
  • Opt out of sale or sharing: we do neither (CCPA).

Email support.sarvaeditor@gmail.com from the address on your account. We may need to confirm it is you before acting. We reply within 15 days, or within one month where the GDPR applies. We will not treat you differently for exercising any right.

If you are not satisfied, contact our Grievance Officer (section 8). In India you may then complain to the Data Protection Board of India; in the EU or UK, to your local data protection authority.

8. Grievance Officer

In line with the Information Technology Act, 2000, the rules made under it, and the DPDP Act, our Grievance Officer is:

Anmol Rajput

SARVA, Delhi, India

Email: support.sarvaeditor@gmail.com

We acknowledge complaints within 24 hours and resolve them within 15 days of receipt. See also our Contact page.

9. International transfers

We and our providers may process your data outside your country, including outside India, for example in the United States, the European Union or Singapore. We transfer data only as the DPDP Act permits and, for data from the EU or UK, rely on appropriate safeguards such as the European Commission's standard contractual clauses.

10. Children

The Service is for people aged 18 or older. We do not knowingly collect personal data from anyone younger, and we do not track or target advertising at children. If you believe a child has given us personal data, contact us and we will delete it.

11. Changes to this policy

We will update the date at the top of this page whenever this policy changes. If a change materially affects how we use your personal data, we will tell you by email or with a notice on the Service before it takes effect.

12. Contact

Questions or requests: support.sarvaeditor@gmail.com. Read this alongside our Terms of Service and Refund, Cancellation & Delivery Policy.