← Back to Home
Privacy Policy
Last updated: March 2025 · DPDP Act 2023 Compliant
DPDP Act 2023 Compliant. We take your privacy seriously. Your data is encrypted, never sold, and you have full control.
1. Data We Collect
| Data | Purpose | Storage |
|---|
| Name, Email, Phone | Account & communication | Encrypted MySQL |
| Session notes | Clinical records | Encrypted, therapist-only |
| Mood/journal data | Self-help tracking | Your device ONLY |
| Payment info | Processing payments | Razorpay (PCI-DSS) |
| AI conversations | Support | Not stored |
2. Your Rights (DPDP Act 2023)
✓ Right to Access your data · ✓ Right to Correction · ✓ Right to Erasure (delete account) · ✓ Right to Withdraw Consent · ✓ Right to Grievance Redressal
3. Security
TLS 1.3 encryption in transit. AES-256 at rest. Payment via Razorpay PCI-DSS Level 1. We NEVER sell your data.
4. EAP/Corporate Users
Your employer can NEVER see your name, sessions, diagnosis, or personal info. Only anonymised aggregate data.
5. Cookies & Retention
Essential cookies only (login, language). Account data: until deleted. Session notes: 3 years. Payment records: 8 years. Mood/journal: your device only.
DPO: privacy@mannasukh.in · Response within 72 hours