BhaiFinder is a product of BharatAI Solutions Private Limited ("Company", "we", "us", or "our"). We are registered in India and operate BhaiFinder (the "App") and the website at bhaifinder.com (the "Website"), collectively referred to as the "Service."
This Privacy Policy explains what information we collect, how we use it, with whom we share it, and the choices you have. Please read it carefully. By using the Service, you agree to the terms of this Privacy Policy.
For any questions about this policy, contact us at: hello@bhaifinder.com
1. Information We Collect
1.1 Information You Provide Directly
- Account information: When you create an account, we collect your name, email address, and password (stored as a one-way hash โ we never store your plain-text password). If you sign in with Google or Apple, we receive your name and email from those providers.
- Content you save: Any link, photo, text, PDF, visiting card, screenshot, or other content you share with BhaiFinder through the share sheet or within the app. This content is stored on our servers to power the Service.
- Profile information: Any updates you make to your profile, such as display name or notification preferences.
- Payment information: When you subscribe to Bhai Pro or Bhai Pro Max, your payment is processed by Razorpay. We do not store your card number, UPI ID, or bank account details. We receive a subscription ID and payment confirmation from Razorpay. If you provide a GSTIN for GST invoicing, we store that.
- Support communications: If you contact us at hello@bhaifinder.com, we store that correspondence.
- Support tickets: If you raise a support ticket inside the app (You โ Help & FAQ โ Support), we store the description you write, every message exchanged with our support team on that ticket, its status, and your name and email address so we can identify and reply to you. Support tickets are deleted along with your account.
1.2 Information Collected Automatically
- Device information: Device type, operating system version, and app version. We do not collect advertising identifiers โ we do not read your Android Advertising ID or iOS IDFA, and we do not use them for tracking or profiling.
- Usage data: Features used, screens viewed, saves created, searches performed, reminders set and completed.
- Log data: IP address, timestamps, app version, crash reports, error logs.
- Push notification token: Your Firebase Cloud Messaging (FCM) token, used solely to send you reminders and app notifications.
1.3 Information from Third Parties
- Google Sign-In / Apple Sign-In: If you use social login, we receive your name and email from those providers under their respective privacy terms.
- Razorpay: Payment status, subscription status, and transaction metadata.
2. How We Use Your Information
We use the information we collect to:
- Provide the Service: Store your saved content, run AI categorization, execute reminders, and return search results.
- AI processing: Content you save is processed by the OpenAI API (GPT-4o mini model) to extract category, context, and tags. This processing happens server-side. We send only the content of what you saved โ we do not send your name, email, or account details to OpenAI for this purpose.
- OCR processing: Photos and visiting cards are first processed using Google ML Kit on your device. That OCR step never leaves your phone; only the extracted text is sent to our servers.
- Image understanding (fallback): If on-device OCR finds no usable text in a photo โ for example a picture of a product or a place rather than a document โ the image itself is sent once to the OpenAI API so it can be described for categorisation. This happens only for that fallback case. The image is used for that single request and is not stored by us, and is not used to train any model. The original photo otherwise stays on your device.
- Send reminders: Deliver push notifications for reminders you set, using Firebase Cloud Messaging.
- Account management: Authenticate you, manage your subscription, and process payments.
- Improve the Service: Analyse anonymised usage patterns to fix bugs and improve features. We do not use your saved content to train AI models.
- Communicate with you: Send transactional emails (receipts, OTP codes, password resets). We do not send marketing emails without your explicit consent.
- Legal compliance: Comply with applicable laws, respond to lawful requests, and enforce our Terms of Service.
3. How We Share Your Information
We do not sell your personal information. Ever.
We share information only in the following limited circumstances:
| Recipient | What we share | Why |
| OpenAI | Content of what you saved (text, URLs); and, only when on-device OCR finds no usable text, the photo itself | AI categorisation, context extraction, and image description. Not stored by OpenAI for training. |
| Google (Firebase) | FCM push tokens | Reminder and notification delivery |
| Google (ML Kit) | Nothing โ runs entirely on your device | On-device OCR text extraction |
| Razorpay | Subscription/payment transactions | Payment processing |
| MongoDB Atlas | All user and content data | Cloud database hosting |
All third-party processors we use are bound by data processing agreements. We select providers that offer adequate data protection.
We may disclose your information if required by:
- A court order, subpoena, or other legal process
- A government authority in India or internationally, where required by applicable law
- Protection of the rights, property, or safety of BharatAI Solutions, our users, or others
4. Data Storage and Security
- Your data is stored on MongoDB Atlas servers, preferably in the Asia Pacific (Mumbai) region.
- Photos and PDFs you attach stay on your own device. We do not upload or store the original files on our servers โ only the text extracted from them, and the AI context derived from that text, are saved to your account. If you uninstall the app or clear its data, those local files are gone.
- We use industry-standard security measures: HTTPS/TLS for all data in transit, encryption at rest, JWT-based authentication, and bcrypt password hashing.
- Access to production systems is restricted to authorised personnel only.
- We conduct periodic security reviews.
No system is 100% secure. If we discover a breach that affects your personal data, we will notify you as required under applicable law.
5. Data Retention
- Active accounts: We retain your data for as long as your account is active.
- Deleted accounts: Deletion is immediate and irreversible โ there is no grace period and no way to restore your account. Your login is revoked at once, and a background job then permanently erases your saved items, reminders, categories, in-app notifications, and subscription records held in our database. Payment and subscription records required for tax purposes are retained for 7 years for accounting compliance (see our Data Deletion Policy for the full breakdown).
- Audit logs: Retained for 90 days, then automatically deleted.
- Referral abuse-prevention record: To stop the same person from repeatedly deleting and re-creating an account to farm referral bonuses, we keep a minimal, permanent record that an identity has already used a referral. This record stores only a one-way hash of your email address and/or sign-in provider ID โ never your email in readable form, and no other personal data. Because its sole purpose is fraud prevention, this hashed record is retained even after your account is deleted.
- Cancelled subscriptions: Your saved content remains accessible until your paid period ends. After that, it remains on a Free plan.
6. Your Rights
Depending on where you are located, you may have the following rights regarding your personal data:
For all users (India โ IT Act 2000 and DPDP Act 2023)
- Access: Request a copy of the personal data we hold about you.
- Correction: Request correction of inaccurate data.
- Deletion: Request deletion of your account and personal data (subject to legal retention obligations).
- Grievance redressal: Contact our Grievance Officer (see Section 10).
For EU/EEA users (GDPR)
In addition to the above:
- Portability: Receive your personal data in a structured, machine-readable format.
- Restriction: Request that we restrict processing of your data.
- Objection: Object to processing based on legitimate interests.
- Withdraw consent: Where processing is based on consent, withdraw it at any time without affecting prior processing.
For California users (CCPA)
- Know: What personal information we collect, use, disclose, and sell (we do not sell personal information).
- Delete: Request deletion of your personal information, subject to exceptions.
- Non-discrimination: We will not discriminate against you for exercising your rights.
To exercise any of these rights, email hello@bhaifinder.com with the subject line "Privacy Request." We will respond within 30 days.
7. Cookies and Tracking
The BhaiFinder website (bhaifinder.com) uses:
- Essential cookies: Required for the website to function (session management).
- No analytics or advertising cookies. We do not run Google Analytics or any comparable third-party tracker on the Website. If that changes, we will update this policy and ask for your consent first.
The BhaiFinder mobile app does not use browser cookies. It includes the Firebase Analytics SDK, used to understand which features are used and where people get stuck so we can improve the app. Analytics collection is switched off by default and no analytics data is collected unless it is enabled. When enabled, Firebase Analytics records anonymised in-app usage events (for example: screens viewed, an item saved, a plan viewed) together with an app-instance identifier, device model, app version and approximate region derived from your IP address. It is never used for advertising, and the app does not read your Android Advertising ID or iOS IDFA. The other Google service the app uses at runtime is Firebase Cloud Messaging, for delivering notifications.
For full details, see our Cookie Policy.
8. Children's Privacy
BhaiFinder is not directed at children under the age of 13 (or 16 in the EU). We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, contact us at hello@bhaifinder.com and we will delete it promptly.
9. Third-Party Links
Content you save may include links to third-party websites. Our Privacy Policy does not apply to those websites. We are not responsible for the privacy practices of third parties.
10. Grievance Officer (India โ DPDP Act 2023)
As required under Indian law, we have designated a Grievance Officer:
Name: Grievance Officer, BharatAI Solutions Private Limited
Email: hello@bhaifinder.com
Response time: We aim to acknowledge grievances within 48 hours and resolve them within 30 days.
11. Changes to This Policy
We may update this Privacy Policy from time to time. When we make material changes, we will:
- Update the "Last updated" date at the top of this page
- Post a notice in the app on your next login
- Send an email notification for significant changes
Continued use of the Service after changes constitute acceptance of the updated policy.
12. Contact Us
BharatAI Solutions Private Limited
Product: BhaiFinder
Email: hello@bhaifinder.com
Website: bhaifinder.com
BhaiFinder is a product of BharatAI Solutions Private Limited, incorporated in India.