Privacy Policy
Last updated: 28 July 2026
NiryatBooks ("NiryatBooks", "we", "us") is an accounting and operations product for Indian exporters and businesses, operated by Rajdhani Telecom, a sole proprietorship based in India. You can use it on the web, on the NiryatBooks mobile app (iOS and Android), and on the desktop app. This policy explains, in plain terms, what data we handle, why, where it lives, who else touches it, and the rights you have under India's Digital Personal Data Protection Act, 2023 (DPDP Act). Questions or requests: support@niryatbooks.com.
1. Two roles — your data, and your customers' data
NiryatBooks holds two kinds of personal data, and our responsibility is different for each. It matters, so we state it up front.
For your own account (your name, email, login), NiryatBooks is the data fiduciary — we decide how that data is handled and we are accountable to you for it under the DPDP Act.
For the personal data you enter about other people — your buyers, suppliers and contacts (their names, addresses, phone numbers, emails, GSTINs, PANs) — you are the data fiduciary and NiryatBooks processes that data on your behalf to provide the service. You are responsible for having a lawful basis to collect and keep it, for giving those individuals any notice and obtaining any consent the DPDP Act requires, for honouring their rights, and for answering any request they make about their data (we will help you do so).
2. What we collect
- Account data: your name, email and password. Passwords are hashed and stored by our authentication provider (Supabase); NiryatBooks does not store or log raw passwords.
- Business data you enter: everything you create in NiryatBooks — contacts, items, invoices, proforma invoices, payments, purchase orders, bills, shipments, journal entries, and uploaded files (your logo, signature images, payment-QR images, item photos, quality-check inspection photos, payment receipts and attachments). This is your data; you own and control it.
- Content you send to AI features: the bill and scheme-letter images you scan, and the text and any images you enter into the Help assistant, the AI Workspace, the mobile AI dock, and the RFQ parser. See section 7.
- Technical and diagnostic data: request logs, IP address, and browser/app information needed to run, secure and troubleshoot the service. Each request carries a short correlation id in its headers for our own logging — it is not a tracking cookie and does not follow you across sessions.
- The apps do not access your device's location or address book, and do not collect advertising IDs or device identifiers. The mobile app can read your photo library, but only the pictures you yourself pick in the gallery picker — it never browses or scans your library on its own. (Business contact details, including phone numbers you enter for your customers and suppliers, are stored as part of your accounting records — see section 1.)
3. Why we use it, and our lawful basis
We use your data only for clear, stated purposes: to provide and run NiryatBooks, sign you in, keep each organisation's data isolated and secure, process the documents and AI results you ask for, send you service and security notices, back up your data, provide support, meet our legal and tax obligations, and fix and improve the product.
We process your account data on the basis of your consent, given when you sign up, and to provide the service you have asked for. Where we process data to meet a legal or tax obligation (for example, retaining accounting records), that legal obligation is our basis instead.
We do not sell your data, and we do not use it for advertising.
4. Where your data lives
Your primary business data — the database and your uploaded files — is hosted in India, in the Mumbai (ap-south-1) region of our database provider, Supabase. For an Indian exporter, that means your books stay in India by default.
Some processing does happen outside India, and we want to be straight about it: the application itself (the web servers and functions that respond to your requests) runs on Netlify, outside India; AI features send content to Google (Gemini) and, as a fallback, Anthropic — both in the United States; transactional email goes through Resend; and, if error monitoring is switched on, error reports go to Sentry. These providers handle data only to deliver their service to us. Section 6 lists them.
We do not transfer your data to any country or territory that the Government of India has restricted for such transfers under the DPDP Act.
5. Your files and how they are stored
Files are handled two ways, and one of them is public, so it is worth knowing:
Logos, signature images and payment-QR images are stored in a public storage bucket and served over public URLs — anyone who has the exact URL can view the image, and these images also appear on the documents you send to buyers. Do not upload a signature or logo you would not want visible to someone with the link.
Item photos, quality-check inspection photos and payment receipts/attachments are stored in an organisation-scoped bucket protected by row-level access controls and served only through short-lived signed URLs, so only your organisation can reach them.
Our own server-side backups of your data are kept in a separate private bucket that tenants cannot access.
6. Who else processes your data (subprocessors)
We use a small set of trusted providers to run NiryatBooks. Each receives only the data needed for its job. The list below is current. Sentry and Cloudflare Turnstile are only active when enabled; when they are off, they receive nothing.
We do not use Google Analytics, Facebook Pixel, Mixpanel, PostHog, or any other advertising or product-analytics tracker — there are none in the product. (Sentry, listed below, is for error diagnostics only; it sets no cookies and is off unless a monitoring key is configured.)
| Provider | Purpose | Data it receives | Location |
|---|---|---|---|
| Supabase | Database, authentication and file storage — the core of the product | Account credentials and emails; all business records; uploaded files | India (Mumbai, ap-south-1) |
| Netlify | Application hosting — runs the web app, server functions and scheduled jobs | Any data contained in a request, as it is processed | Outside India |
| Google (Gemini) | Primary AI provider — bill/scheme scanning, Help, RFQ parsing, and the mobile AI dock | The content you submit to AI features (text and images). Used under Google's paid commercial API terms, under which Google does not use it to train its models. | United States |
| Anthropic (Claude) | Fallback AI provider — used only when the primary (Gemini) is unavailable | The same AI content, and — for the agentic assistants — your organisation's accounting data via tools. Not used to train Anthropic's models. | United States |
| Resend | Transactional email — buyer documents, payment reminders, digests and notifications (account and email-verification messages are sent by Supabase Auth, not Resend) | Recipient email addresses and message content, including PDFs that may contain buyer names, addresses and amounts | United States |
| Sentry (only if enabled) | Error and crash diagnostics — off unless configured | Exception traces and limited diagnostic fields; user PII is minimised | Outside India (region set by configuration) |
| Cloudflare Turnstile (only if enabled) | Bot / CAPTCHA protection at login and signup | The visitor's IP address and browser/device signals during the challenge | Outside India (global edge) |
| GitHub | Desktop app update check against the public releases repository | The update request's IP address and platform only — no business or personal records | United States |
7. AI features
Several features use AI. They work by sending your content to an AI provider to produce a result. Our primary AI provider is Google, through the Gemini API; Anthropic (Claude) is used as an automatic fallback when the primary is unavailable. We use these providers under their paid, commercial API terms — under which Google and Anthropic do not use the content we send to train their models. We will not move these features to a consumer or free tier that permits such training without updating this policy first.
The AI features, and what each sends:
- Scan a bill (web and mobile): the bill or receipt images you upload or photograph are sent for extraction. These images are processed in memory to read them and are not saved to our storage.
- Scan a scheme letter: the letter text you paste and/or the letter images you upload.
- Help assistant: your typed questions, a hint about the page you are on, and your organisation's basic business profile. It does not read your financial records.
- AI Workspace (web) and the mobile AI dock: your chat messages and any images you attach. These are action-capable assistants — to answer and act, they read and write your organisation's own accounting data (invoices, payments, contacts, reports and so on) through secure, organisation-scoped tools. They only ever touch your organisation's data.
- RFQ parser: the buyer enquiry text you paste in.
- Voice input (web only): when you use the microphone button, your browser's own speech recognition converts your speech to text, and only the resulting text is sent to us. In some browsers (for example Chrome and Edge) that transcription is performed by the browser's vendor — a step that happens in your browser and is outside our control. The mobile app has no voice or audio capture.
- The active AI provider is a configurable setting. If we change it, we will update this policy first, because each provider's data-handling and training terms differ.
8. The mobile and desktop apps
Mobile app (iOS and Android): the app asks for two device permissions. The camera — to photograph bills for the Scan a bill feature, to scan product barcodes and serial / IMEI numbers during quality checks, and to capture quality-check inspection photos. And your photo library — so you can pick an existing bill or scheme-letter picture from the gallery instead of photographing it. The gallery permission is only requested at the moment you tap to choose a picture, and the app receives only the pictures you select; it never reads or scans the rest of your library. Barcode and serial scanning is performed on your device inside the app: the camera preview is read locally to decode the number, and the video itself is never uploaded — only the decoded number (or a photo you choose to attach) is sent to our servers. The Android microphone permission (RECORD_AUDIO) is declared in the app manifest because the camera library lists it, but the app never records or captures any audio — there is no voice or sound recording anywhere in the app. The app does not request notifications, location, or contacts access, and it contains no analytics or crash-reporting SDK. Your login session (a token) is stored in the app's private storage on your device. When you scan a bill or chat with the AI dock, those images and messages are sent to our servers for processing as described in section 7. App updates are delivered over the air via Expo's update service.
Desktop app (Windows and macOS): this is a thin wrapper that loads the NiryatBooks website in a secure window; it collects no analytics or telemetry of its own. It does check for its own updates automatically — on launch and periodically — against our public releases repository on GitHub, which exposes the request's IP address and platform to GitHub as part of that check. It stores a small local preference on your device (for example, an update version you chose to skip).
9. Security
We design for tenant isolation. Every organisation's data is separated at the database level by Row-Level Security — access policies that scope each row to the members of the organisation that owns it. Traffic is encrypted in transit (HTTPS), enforced with a long-lived HSTS policy and baseline protections against clickjacking and content-type sniffing. Passwords are hashed by our authentication provider; we do not handle them in the clear beyond passing them to that provider at sign-in.
No system is perfectly secure, and we do not promise absolute security. Encryption of stored data at rest, where it applies, is provided by our platform providers; we do not make a separate at-rest-encryption claim of our own.
NiryatBooks depends on the third-party providers listed in section 6 to operate, and we rely on those same services ourselves. We choose reputable providers and share only the data each one needs, but we do not control their systems and are not responsible for outages, failures, or security incidents that occur within their infrastructure and are beyond our reasonable control. We have never intentionally sold, misused, or disclosed your data, and we design the product to keep each organisation's data isolated. Our overall liability is limited as set out in our Terms of Service.
If a personal data breach affecting your information occurs, we will comply with our notification obligations under the DPDP Act, including notifying the Data Protection Board of India and affected users where required.
10. How long we keep your data
We keep your data while your account is active, and for a reasonable period afterwards, subject to legal retention rules — accounting, tax and GST records often must be retained for several years under Indian law, so some records may be kept for that long even after closure.
Deletion on request is handled by our team (see section 11); there is not yet a one-click self-delete button in the app. Some records are first soft-deleted and then removed, and our backups are cleared as part of deletion within a reasonable period.
11. Your rights, and how to use them
Under the DPDP Act you (as a Data Principal) have rights over your personal data. Here is what you have, and how to use it today:
- Access and export: download a full copy of your data anytime from Settings → Backup — a ZIP containing your business records plus your uploaded files. You can also export individual lists (contacts, items, invoices, payments and more) as CSV from within the app. There is no lock-in.
- Correct: edit your records directly in the app at any time.
- Erase / close your account: email support@niryatbooks.com and we will delete your data within a reasonable period, subject to the legal retention rules in section 10. This is currently a request-based process, not a self-serve button.
- Nominate: the Act lets you nominate another person to exercise your rights if you die or become incapacitated. To record a nominee, contact us.
- Withdraw consent: where we rely on your consent, you can withdraw it by contacting us; this does not undo processing already carried out. Because we need your account data to run the service, withdrawing consent for it generally means we can no longer keep your account open.
- Complain: raise a grievance with us (section 16) and, if we do not resolve it, escalate to the Data Protection Board of India.
- If a request concerns a person whose data one of our users entered (a buyer or supplier), that user is the fiduciary — we will route the request to them and assist.
12. Payments
NiryatBooks does not currently collect payment or card details — there is no payment processor wired into the product today. If we introduce paid plans, payment will be handled by a reputable third-party processor, we will not store full card numbers, and we will update this policy to name the processor before that goes live.
13. Cookies and tracking
We use only essential cookies — the session cookies from our authentication provider that keep you signed in and refresh your session. We set no advertising cookies and no analytics cookies, and we do not track you across other websites.
14. Children
NiryatBooks is a business tool intended for use by adults (18 and over). We do not knowingly create accounts for, or collect personal data from, children.
15. Changes to this policy
We may update this policy as the product and the law evolve. We will change the "Last updated" date above and, for material changes, notify you in the app or by email.
16. Contact and grievances
For any privacy question, data request, or grievance, contact our Grievance Officer for Rajdhani Telecom at support@niryatbooks.com. We aim to acknowledge your request within 3 working days and to resolve it within 30 days.
If we do not resolve your grievance to your satisfaction, you may escalate to the Data Protection Board of India.
Data fiduciary: Rajdhani Telecom (operating NiryatBooks), India. This policy is governed by the law of India.