Privacy Policy
Last updated: 27 July 2026
This policy explains what Depra AI collects, why, who else sees it, and what you can ask us to do about it. It is written to be read, not to be survived.
Who we are
Depra AI (“Depra”, “we”, “us”) operates depra.ai, a service that tracks how AI answer engines describe brands. We are based in India and act as the Data Fiduciary for the personal data described below, as that term is used in India’s Digital Personal Data Protection Act, 2023 (“DPDP Act”).
For any privacy question or request, contact team@depra.ai.
What we collect
Account data. Your email address, a securely hashed password (we never store the password itself), your name if you provide one, and whether your email has been verified. If you sign in with Google, we receive your email address, name and profile basics from Google — never your Google password.
Workspace data. Your organisation name, your GSTIN if you enter one for invoicing, optional white-label branding (logo URL, accent colour, footer text), and the projects you create: brand names, competitor names, website domains, target countries and the prompts you choose to track.
Results data. The answers AI engines return for your prompts, the sources those answers cite, and the brand mentions we extract from them. This is data about publicly generated AI output, but we store it against your account.
Billing data. Your plan, subscription period, invoice records and GSTIN. We never see or store your card, UPI or bank details — those go directly to Razorpay, our payment processor.
Technical data. Server logs containing IP address, request paths and timestamps, kept for security and debugging.
Why we use it
- To run the service you signed up for — scheduling runs, computing your metrics, generating reports.
- To authenticate you and keep your account secure.
- To take payment, issue GST invoices, and manage your subscription.
- To send service email: verification codes, password resets, renewal reminders and security notices.
- To detect abuse, debug failures, and meet legal or tax obligations.
We do not sell your personal data, and we do not use your prompts or results to advertise to you.
Who else processes your data (sub-processors)
Running the service means sending some data to specialist providers. Notably, your prompt text, brand names and competitor names are transmitted to AI search providers in order to capture what those engines say. Our current sub-processors:
- Microsoft Azure — hosting, database and transactional email. Application and database servers are in Azure Central India.
- DataForSEO — captures answers from ChatGPT, Gemini and Google AI Overviews. Receives your prompt text.
- Perplexity — Perplexity answer capture. Receives your prompt text.
- Azure OpenAI (South India region) — reads captured answers to identify brand mentions and sentiment. Receives answer text and your brand/competitor names.
- OpenAI — used as a fallback for answer capture and mention extraction when our primary providers are unavailable. In that case it receives your prompt text, the captured answer, and your brand and competitor names.
- Google — three distinct uses: Google Sign-In if you choose it; Gemini as a fallback answer-capture provider (receives your prompt text); and Google’s public favicon service, which our dashboard uses to display website icons. That last one means Google receives the domain names shown on your dashboard — your tracked domain and the domains cited in your results — along with your IP address and browser details.
- Brandfetch — supplies company logos on our public marketing pages. Receives the IP address and browser details of visitors to those pages. It is not used inside the logged-in application.
- Razorpay — payment processing. Receives your billing details directly; they are a PCI-DSS compliant processor. Their checkout script loads on our billing page.
Some of these providers process data outside India. The DPDP Act permits such transfers except to countries the Government restricts; we will update this policy if that list affects us. We will also update this section before adding a new sub-processor.
How long we keep it
Account and workspace data is kept while your account is open. Tracking results are kept so your historical trends remain meaningful. Invoices and tax records are retained for as long as Indian tax law requires (currently eight financial years). Password-reset and email verification tokens expire within an hour and are deleted automatically.
Closing your account. There is no self-serve delete button yet — email team@depra.ai from your account address and we will action it manually. We aim to complete deletion within 30 days of the request and will confirm by email when it is done. Invoices and tax records are retained as described above even after deletion, because Indian tax law requires it.
Your rights
Under the DPDP Act you may ask us to:
- tell you what personal data of yours we hold and who we have shared it with;
- correct or complete anything inaccurate;
- erase your personal data when it is no longer needed for the purpose you gave it for;
- nominate someone to exercise these rights if you die or become incapacitated;
- withdraw consent — though this may mean we can no longer provide the service.
These requests are handled by a person, not a self-serve tool: email team@depra.ai from the address on your account and we will respond within 30 days. You can already correct your organisation name, GSTIN and branding yourself in project settings, and export your answer data as CSV at any time.
If you are not satisfied with how we handle a grievance, you may escalate to the Data Protection Board of India.
Security
Traffic is encrypted in transit with TLS. Passwords are stored using bcrypt hashing. Password-reset and verification tokens are stored only as SHA-256 hashes, so even we cannot read them. Access to production systems is restricted to authorised personnel. No system is perfectly secure, but if a breach affects your personal data we will notify you and the Data Protection Board as the DPDP Act requires.
Cookies and third-party requests
We keep you signed in using a token stored in your browser’s local storage, not a cookie. We run no advertising cookies, analytics or tracking pixels — no Google Analytics, no Meta pixel, no session recording.
For completeness, three third-party requests do happen from your browser: website icons on your dashboard load from Google’s favicon service, company logos on our marketing pages load from Brandfetch, and Razorpay’s checkout script loads on the billing page. These are functional, not analytical, but each provider can see your IP address and the page that made the request.
Children
Depra is a business tool and is not directed at children. We do not knowingly collect personal data of anyone under 18.
Changes
If we change this policy materially we will update the date above and, where the change affects how we use your data, email account holders. Continuing to use Depra after a change means you accept the updated policy.