Atharv SecureTech Private Limited
1. Who We Are
Atharv SecureTech Private Limited ("we", "us", "our") is an Indian company incorporated in India. This Privacy Policy explains how we collect, use, disclose, retain, and protect personal information when you visit atharvsecuretech.com, contact us, or register for one of our products through the website.
2. Scope of This Policy
This is our company level Privacy Policy. It covers the atharvsecuretech.com website itself: our contact form, general enquiries, and account registration for our products where that registration happens on the website.
We currently offer Atharv Vault, and we intend to offer additional products in the future. Each individual product has its own Privacy Policy that describes exactly what that product collects, stores, and does with your information once you are using it (for example, our Atharv Vault Privacy Policy). Where a product has its own Privacy Policy, that product specific policy governs your use of that product. This general policy governs the website itself, and anything not already covered by a product specific policy.
3. Information We Collect
- Contact form submissions: if you use the contact form on our website, we collect your name, your email address, and the message you send us. We use this only to respond to your enquiry and to keep a record of business communications.
- Account registration for our products: our website allows you to register an account for one of our products, such as Atharv Vault, directly from the website. When you do this, we collect the account information described in that specific product's own Privacy Policy (for Atharv Vault, this currently means your full name, your email address, and your password after it has been securely hashed). We do not collect any additional information at the website level beyond what that product's own Privacy Policy describes.
- Automatically Collected Information (Analytics): We use industry-standard analytics tools, including Google Analytics, to understand how visitors interact with our website. These tools automatically collect non-personally identifiable information, such as your browser type, device operating system, IP address, and the pages you visit on our website. This data is used strictly in aggregate to improve our website's performance and user experience. We do not use this data to identify individual visitors. For more details on how we use cookies and tracking technologies, please refer to our Cookie Policy.
4. How We Use Information Collected on the Website
We use the information described above to respond to enquiries submitted through the contact form, to create and manage accounts for our products where registration happens on the website, to maintain records required for legal, tax, and accounting purposes, and to operate and secure the website itself. We do not use this information for advertising, and we do not sell it to third parties.
5. How This Policy Relates to Our Products
Atharv SecureTech operates on two levels. This document is our company level policy, describing the website itself. Each product we offer, starting with Atharv Vault, has its own dedicated Privacy Policy describing exactly what that product collects and how it works once you are using it, including any encryption keys, activity logs, or other product specific data. If you are looking for information about how a specific product handles your data once you are using it, please refer to that product's own Privacy Policy rather than this one.
6. Data Sharing and Disclosure
We share the information described in Section 3 only where necessary: with our hosting and email providers, to operate the website and respond to enquiries; with the relevant product's infrastructure, where you register for a product through our website; and where required by law, court order, or a valid request from a government authority. We do not sell personal data to third parties, and we do not share it for independent marketing purposes.
7. Data Retention
We keep contact form submissions for as long as reasonably necessary to respond to your enquiry and to maintain business records, after which we delete them. Account information collected during registration for a product is retained according to that product's own Privacy Policy and is deleted when you delete your account for that product.
8. Your Rights
Under India's Digital Personal Data Protection Act, 2023 and, where applicable, the General Data Protection Regulation of the European Union and the United Kingdom, you have the right to access the personal data we hold about you, request its correction, request its erasure, and object to certain processing. To exercise these rights regarding a contact form submission or general website enquiry, use the contact details in Section 11. To exercise these rights regarding a specific product account, such as Atharv Vault, please also refer to that product's own Privacy Policy, since some of these rights can be exercised directly within the product itself.
9. Children's Data
This general policy does not set a single age requirement for all of our products, since different products may have different age ratings and requirements described in their own Privacy Policy (for example, Atharv Vault is rated 3+ on Google Play). We do not knowingly collect personal data from children in a manner inconsistent with applicable law. If you are a parent or guardian with concerns about a child's use of our website or one of our products, contact us using the details in Section 11.
10. International Data Transfers
Our servers and service providers may be located outside your home country, including in India. Where we transfer personal data across borders, we rely on the service provider's own compliance obligations and, where applicable, standard contractual safeguards recognised under the General Data Protection Regulation.
11. Grievance Officer and Contact
In accordance with the Digital Personal Data Protection Act, 2023 and the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, grievances relating to personal data processing, security concerns about our website or products, or escalation under applicable Indian law may be directed to:
Designation: Director
Email: director@atharvsecuretech.com
Address for correspondence: TBI, BITS Pilani, Hyderabad Campus, Secunderabad, Telangana, 500078, India
For general questions about the website, a contact form submission, or anything not requiring the Grievance Officer specifically, you can also reach us at admin@atharvsecuretech.com.
We will acknowledge and endeavour to respond within 30 days of receipt, subject to the nature of the request and any statutory timelines.
For users in the European Union or United Kingdom: we have not yet appointed a representative under Article 27 of the General Data Protection Regulation. If you are an EU or UK user with a data protection query in the meantime, please use the contact details above.
12. Changes to This Policy
We may update this policy as our website and product offerings evolve, or as required by law. Material changes will be reflected by updating the "Last updated" date above. We encourage you to review this page periodically, particularly as we introduce new products alongside Atharv Vault.
Product Specific Policy
Atharv Vault: Privacy Policy
Atharv SecureTech Private Limited (CIN: U62091TS2025PTC204537) ("we", "us", "our") built Atharv Vault around a simple principle: we should never be able to see the contents of your files. This policy explains, in complete detail and without shorthand, exactly what information we collect, why we collect it, how long we keep it, who we share it with, and the rights you have over it under India's Digital Personal Data Protection Act, 2023 ("the Digital Personal Data Protection Act") and, where applicable, the General Data Protection Regulation of the European Union and the United Kingdom.
Questions about your data or this policy? Email us at admin@atharvsecuretech.com, or director@atharvsecuretech.com for a formal grievance.
1. Our Approach: Zero-Knowledge by Design
Your files are encrypted and decrypted locally, on your own device, using a password or key that never leaves that device. Atharv Vault offers several encryption levels for everyday use, and a more advanced encryption option, referred to in the App as Level 6 encryption, that uses post-quantum cryptography, meaning it is designed to remain secure even against future quantum computers. In every case, whichever level you choose, your files never touch our servers as part of the standard encrypt or decrypt workflow. There is nothing for us to collect, because the file never leaves your phone or computer.
For Secure Share, you encrypt the file on your device using the recipient's encryption key, and you digitally sign it using your own signature key, so the recipient can confirm the file genuinely came from you and has not been altered. Every Secure Share must be protected with a password that you set; this is not optional. You then send the encrypted file to the recipient yourself, through whatever channel you choose: email, a messaging application, a USB drive, or however you would normally send a file. The file itself never passes through our servers. Our server stores only the cryptographic information described in Section 2 that the recipient's device needs in order to unlock and verify the file. It never stores the file itself, never your encryption password, and never any private key capable of unlocking your file. If we were ever compelled to hand over what we hold, we would not be able to hand over your file contents, because we do not have them.
2. Information We Do Collect
Account information: your full name, your email address, and your password after it has been securely hashed using bcrypt, a well-established password-hashing algorithm. We never store your actual password, in any form. We also store whether your email address has been verified, the date and time your account was created, the date and time you last logged in, and the date and time you last changed your password (this last detail lets us invalidate older login sessions after a password change, for your security).
Encryption keys: your device generates two separate pairs of cryptographic keys, one pair for encryption and one pair for digital signatures, using a post-quantum cryptographic standard. We store only the public half of each pair on our servers. The corresponding private halves are generated and stored only on your own device, and are never transmitted to us or stored by us in any form. A public key, on its own or combined with anything else we hold, cannot be used to decrypt any file or to forge your digital signature.
Encryption and decryption usage counts: the number of times you have encrypted or decrypted a file at each of our standard encryption levels, the number of times you have used Level 6 post-quantum encryption specifically, the date these counts were last reset, and the number of Secure Share operations you have performed. We use these counts only to enforce the usage limits of your subscription plan (see Section 3), never to inspect what you actually encrypted.
Secure Share package information: when you create a Secure Share, we store the sender's and recipient's email addresses, the original filename, an expiry time, how many times the share is allowed to be accessed, how many times it has actually been accessed, and whether it has been used. Because a password is required to protect every Secure Share, we also store the cryptographic salt used to derive a key from that password; a salt cannot be used, on its own, to recover or guess your password. We also store the specific cryptographic material the recipient's device needs to unlock and verify the file: a cryptographic nonce (a one-time-use random value), post-quantum key encapsulation data (the mechanism that lets the recipient's device recover the encryption key using their own private key), your File Encryption Key in wrapped, meaning still encrypted, form, a digital signature of the file itself, a separate digital signature confirming that the sharing details have not been tampered with, and a cryptographic hash of the encrypted file used to confirm it has not been altered in transit. All of this material is generated on your device and is only usable together with the recipient's own private key and the password you set. We never store the file itself, the password itself, or either party's private key.
Secure Share access log: every time a Secure Share is accessed, we log the type of access event, the IP address the request came from, and the time it happened. This is a security log used to detect abuse; it does not give us access to the file.
Secure Share reissue requests: if a share needs to be regenerated, for example because it expired, we store the sender's and recipient's email addresses, the original filename, the request's status (Pending, Approved, or Rejected), and the date and time it was requested and resolved.
Activity log: a record of the actions you take (encrypting or decrypting a file), along with the filename and the time it happened, so you can review your own history in the Activity Log screen within the App. This log records that an action happened, not what was inside the file.
Notifications: in-app alerts about your own account and Secure Share activity.
Technical and audit data: for security purposes, we log the IP address associated with certain sensitive requests, along with a timestamp. This is kept separately from any cryptographic data and is used to detect abuse, not to profile you.
Payment data: if you subscribe to Pro, Premium, or Enterprise, your payment is handled entirely by Apple, Google, Razorpay, or Lemon Squeezy, depending on how and where you paid (see Section 4 of our Terms & Conditions). We receive confirmation that a purchase was made, which plan it unlocked, and when your subscription expires. We do not receive or store your card number, bank details, or other payment instrument details ourselves.
3. How We Use Your Information
We use the information above strictly to operate the App: authenticating you, verifying your email address, delivering Secure Share transfers, showing your own activity log and notifications back to you, enforcing your subscription plan's usage limits (for example, how many standard or Level 6 encryptions or Secure Shares you are entitled to perform), detecting and preventing abuse of the service, invalidating old login sessions after you change your password, and sending you important account or security notices. We do not use your data to build an advertising profile, we do not sell it, and we do not use it to train any third-party artificial intelligence or analytics model.
4. Legal Basis for Processing
Where the General Data Protection Regulation applies to you, we process your data on the following bases: performance of a contract (running the account and features you signed up for), legitimate interests (security logging and abuse prevention, kept narrow and proportionate), and legal obligation (for example, responding to a valid legal request). Under the Digital Personal Data Protection Act, our processing is based on your consent at account creation and the legitimate uses described in Section 3.
5. Data Retention
We keep your account information, activity log, and Secure Share information for as long as your account exists. If you delete your account, that information is removed immediately as described in Section 10. We do not keep a backup or archival copy afterward. Technical and audit logs (Section 2) are kept for a limited window for security purposes and are rotated out automatically. Payment processors retain their own transaction records independently of us, for the period required by their own legal and accounting obligations (see Section 10).
6. Data Sharing & Disclosure
We share data only where necessary to run the App:
- With our hosting and database provider, to store the account and metadata described in Section 2.
- With our email provider, to deliver verification, one-time password, and notification emails.
- With Apple, Google, Razorpay, or Lemon Squeezy, strictly for the purchase you make through them, and only to the extent needed to confirm and fulfil that purchase.
- If required by law, court order, or a valid request from a government authority.
We do not sell personal data to third parties, we do not share it for their independent marketing purposes, and we cannot share the content of your files with anyone, including law enforcement, because we never have access to it.
7. International Data Transfers
Our servers and service providers may be located outside your home country, including in India. Where we transfer personal data across borders, we rely on the service provider's own compliance obligations and, where applicable, standard contractual safeguards recognised under the General Data Protection Regulation. Because file contents never reach our servers, no file data is ever part of such a transfer, only the limited account and metadata described in Section 2.
8. Data Security
Account passwords are hashed using bcrypt, a well-established password-hashing algorithm, and are never stored in plaintext, in any form. Data in transit between your device and our servers is encrypted using Transport Layer Security. Every record in our database, including accounts, activity log entries, notifications, Secure Share packages, and reissue requests, uses a randomly generated, high-entropy identifier rather than a predictable sequential number, to make these records much harder to guess or enumerate. Access to production systems is restricted to authorised personnel on a need-to-know basis. No system is perfectly secure. You are required, not merely encouraged, to use a strong, unique account password and to keep your device itself secure; local device security is outside our control and remains your responsibility.
9. Your Rights
Under the Digital Personal Data Protection Act (and the General Data Protection Regulation where applicable), you have the right to access the personal data we hold about you, request its correction, request its erasure, and object to certain processing. You can exercise most of this yourself, at any time, from Settings within the App. See Section 10 for exactly what account deletion removes. For anything Settings doesn't cover, or to raise a grievance, use the contact details in Section 12.
10. Deleting Your Account & Data
How to delete: open the App, go to Settings, and choose Delete Account. You will be asked to confirm, since this action is immediate and cannot be undone. You do not need to contact support. It is available in-app, at any time, to any logged-in user.
What gets deleted immediately: your account itself (name, email address, hashed password, and both of your stored public keys); every Secure Share you sent or received, and their delivery and access records; your entire Activity Log; all notifications tied to your account; and any pending Secure Share reissue requests you were part of. This is a genuine deletion from our database, not a deactivation flag. The records are removed, immediately, with no waiting period.
What we never had, so there is nothing to delete: because encryption, decryption, and digital signing all happen locally on your device, we never stored your files, your encryption passwords, or either of your private keys. Account deletion does not touch any of that, and files already on your device stay exactly where they are.
What may be retained, and why: if you paid for Pro, Premium, or Enterprise, the payment processor you used (Apple, Google, Razorpay, or Lemon Squeezy) keeps its own transaction and billing records independently of us, for the period required by their own legal, tax, and accounting obligations. We do not control that retention, and you would need to contact them directly about their own copy. We do not otherwise keep a backup of your account data after deletion.
Effect on a Secure Share: deleting your account removes the shared package record entirely, including the other party's copy, since it is one record tied to both accounts. A pending, unclaimed share becomes unusable to the other person after you delete your account.
Effect on a subscription: if you delete your account and later create a new one, even using the same email address and password, the new account starts fresh on the Free plan. This is true even if the subscription tied to your deleted account was still active and paid for. Deleting your account forfeits the remainder of that subscription period; it does not carry over to a newly created account. See Section 10 of our Terms & Conditions for more on this.
Can't log in? Email admin@atharvsecuretech.com from the address on your account, and we will process the same deletion manually.
11. Children's Data
Atharv Vault is rated 3+ on Google Play. Anyone aged 3 or older may use the App; there is no other minimum age requirement. We do not collect any different or additional information from children than what is described in Section 2 for any other user: name, email address, and a hashed password. We do not use any user's data, child or otherwise, for advertising or profiling (see Section 3). If you are a parent or guardian with concerns about a child's account, contact us using the details in Section 12.
12. Grievance Officer & Contact
In accordance with the Digital Personal Data Protection Act, 2023 and the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, grievances relating to personal data processing, security concerns about our services, or escalation under applicable Indian law may be directed to:
Designation: Director
Email: director@atharvsecuretech.com
Address for correspondence: TBI, BITS Pilani, Hyderabad Campus, Secunderabad, Telangana, 500078, India
For general privacy questions, account help, or anything not requiring the Grievance Officer specifically, you can also reach us at admin@atharvsecuretech.com.
We will acknowledge and endeavour to respond within 30 days of receipt, subject to the nature of the request and any statutory timelines.
For users in the European Union or United Kingdom: we have not yet appointed a representative under Article 27 of the General Data Protection Regulation. If you are an EU/UK user with a data protection query in the meantime, please use the contact details above.
13. Changes to This Policy
We may update this policy as the App evolves or as required by law. Material changes will be reflected by updating the "Last updated" date above, and, where appropriate, an in-app notice. We encourage you to review this page periodically.