Privacy Policy
Last updated: 26 September 2026
This policy explains what personal data SARVA ("Sarva", "we", "us") collects when you use the Sarva website and tools (the "Service"), why, who else handles it, how long we keep it, and the rights you have. It is our notice under India's Digital Personal Data Protection Act, 2023 ("DPDP Act") and, where they apply to you, the EU/UK GDPR and US state privacy laws such as the CCPA.
1. Who is responsible for your data
SARVA, based in Delhi, India, decides how and why your personal data is processed. We are the "Data Fiduciary" under the DPDP Act and the "controller" under the GDPR. Contact us about anything in this policy at support.sarvaeditor@gmail.com.
2. What we collect and why
We collect only what the Service needs. The table shows each kind of data, why we use it, the legal basis for doing so, and how long we keep it.
| Data | Why we use it | Legal basis | Kept for |
|---|---|---|---|
| Files you upload to server-side tools (PDF, Word, Excel, CSV and similar), their name, size and type | To perform the operation you asked for and let you download the result | Performing our contract with you; your consent | 24 hours if you are not signed in; 30 days in your history if you are, then deleted automatically |
| AI inputs: text you submit, documents you ask us to summarise, and YouTube links | To generate the summary or transcript you asked for | Performing our contract; your consent | Not stored with your account. Results for a public YouTube video are cached by video, not by user |
| Account details: email address, name, and (if you use a password) a one-way hash of it (never the password itself) | To create and secure your account and sign you in | Performing our contract | Until you delete your account |
| Sign-in provider details (Google, Apple, GitHub or Microsoft): your verified email and name | To sign you in without a Sarva password | Performing our contract; your consent | Until you delete your account |
| Email verification codes (stored only as a hash), session tokens, and your last-active time. Password-reset links are signed, so nothing about them is stored | To verify your email, keep you signed in, reset passwords, and sign you out after inactivity | Performing our contract; security | Codes: 10 minutes. Reset links: 24 hours. Sessions: at most 3 hours, or 40 minutes idle |
| Plan and billing records: plan, subscription status, renewal dates, and Razorpay subscription and invoice references | To provide Premium, show your payment history, and handle renewals and cancellations | Performing our contract; legal obligation (tax and accounting) | While your account exists; Razorpay keeps its own records as the law requires |
| IP address and approximate country | To apply rate limits, block abuse, keep the Service secure, and show prices in your currency | Legitimate interest in security; performing our contract | Rate-limit counters: up to one day. Hosting logs: a limited period set by our hosting providers |
| Usage and performance data: pages visited, device and browser type, page speed | To understand aggregate usage and keep the site fast | Legitimate interest | Aggregated by our analytics provider; not linked to your account |
Payment details. Payments happen on Razorpay's own hosted page. We never see or store your card number, UPI ID, bank details or CVV.
Browser-only tools. Some tools, including the text, JSON, Markdown, Base64 and image utilities, and small CSV files, run entirely in your browser. Those files are never uploaded to us and we never receive their contents.
We do not collect sensitive categories of data on purpose. Please do not upload documents containing other people's personal data unless you are entitled to.
3. What we do not do
- We do not sell your personal data, and we do not "share" it for cross-context behavioural advertising.
- We do not show ads, and we do not use your files or AI inputs to build profiles or for advertising.
- We do not train AI models on your content.
- We do not make decisions about you that have legal or similarly significant effects by automated means alone.
4. Who else handles your data
We use a small number of service providers ("processors") to run the Service. Each receives only what it needs for its function and may use it only to provide that function to us.
| Provider | What it does | Data it receives |
|---|---|---|
| Razorpay | Payments and subscriptions | Your email, plan, and the payment details you enter on its page |
| Supabase | Database hosting | Account, plan and file records |
| Render | Application hosting | Uploaded files while they are processed and stored; IP address in logs |
| Vercel | Website hosting, cookieless analytics and speed measurement | IP address, pages visited, device and browser type |
| Our email provider (SMTP), through a relay hosted on Vercel | Sending verification codes, password resets and account notices | Your email address and the message |
| Google, Apple, GitHub, Microsoft | Sign-in, only if you choose one of them | Confirmation of your identity |
| AI providers (currently Google Gemini and Groq) | Generating summaries and transcripts | The text, document text or video link you submit |
| Supadata and YouTube | Fetching captions for a YouTube link you submit | The video link only, nothing about you |
We choose AI providers whose terms for API use do not allow training on submitted content, but their handling is governed by their own terms. Do not submit highly sensitive material to AI features. We may also disclose data where the law requires it (for example to comply with a valid court or government order) or to protect the rights, safety or property of our users or the Service.
6. How we protect your data
- All traffic uses HTTPS (TLS).
- Passwords and email verification codes are stored only as one-way hashes; password-reset links are signed and expire.
- Your session lives in an httpOnly cookie and expires after inactivity.
- Links to your files are signed and expire after a few hours, and only your account can reach a signed-in user's files.
- Our database provider encrypts the database at rest.
- Rate limits, upload checks and size limits protect the Service from abuse.
What this does not mean. The Service is not end-to-end encrypted. To convert, edit or summarise your file, our servers (and, for AI features, the providers above) must read it. Uploaded files are stored on our hosting provider's disks until they are deleted automatically. No system is perfectly secure; keep your own copy of anything important.
If something goes wrong. If a personal data breach affects you, we will tell you and the relevant authorities without undue delay, as the DPDP Act, the GDPR and other applicable laws require.
7. Your rights
Wherever you live, you can ask us to:
- Access: get a summary of the personal data we hold about you and how we use it.
- Correct or update data that is inaccurate or incomplete.
- Erase your data. You can do this yourself at any time from your account page: it cancels any subscription, then permanently deletes your profile, sign-in details and every file in your history.
- Withdraw consent, as easily as you gave it. This does not affect processing already done.
- Get a copy of data you gave us in a portable format (GDPR).
- Object to or restrict processing based on legitimate interest (GDPR).
- Nominate someone to exercise your rights if you die or become incapable (DPDP Act).
- Opt out of sale or sharing: we do neither (CCPA).
Email support.sarvaeditor@gmail.com from the address on your account. We may need to confirm it is you before acting. We reply within 15 days, or within one month where the GDPR applies. We will not treat you differently for exercising any right.
If you are not satisfied, contact our Grievance Officer (section 8). In India you may then complain to the Data Protection Board of India; in the EU or UK, to your local data protection authority.
8. Grievance Officer
In line with the Information Technology Act, 2000, the rules made under it, and the DPDP Act, our Grievance Officer is:
We acknowledge complaints within 24 hours and resolve them within 15 days of receipt. See also our Contact page.
9. International transfers
We and our providers may process your data outside your country, including outside India, for example in the United States, the European Union or Singapore. We transfer data only as the DPDP Act permits and, for data from the EU or UK, rely on appropriate safeguards such as the European Commission's standard contractual clauses.
10. Children
The Service is for people aged 18 or older. We do not knowingly collect personal data from anyone younger, and we do not track or target advertising at children. If you believe a child has given us personal data, contact us and we will delete it.
11. Changes to this policy
We will update the date at the top of this page whenever this policy changes. If a change materially affects how we use your personal data, we will tell you by email or with a notice on the Service before it takes effect.
12. Contact
Questions or requests: support.sarvaeditor@gmail.com. Read this alongside our Terms of Service and Refund, Cancellation & Delivery Policy.