Dhanur AI
Docs menu· Data and privacy

Data and privacy

Live

Where your data is stored, who processes it, how long we keep it and how to use your rights.

This page is a short guide. The Privacy Policy is the full, binding version, and our Security page explains how we protect the service.

The short version

  • Servers and databases in India. Our app servers are in Mumbai, and our engine and databases are in Bengaluru. Photos and PDFs sent in chats are stored with DigitalOcean in New York, United States.
  • Not used for training. We don't use your content to train AI models.
  • No advertising cookies, and none at all on your customers. We use one cookie to keep you signed in. Google Analytics and Microsoft Clarity measure our own website and app, never a share page or the website chat window, so the people who write to your agents are not recorded. Inside the app every word is masked in a session replay, and page addresses lose their identifiers before they reach Google.
  • Not sold. We don't sell personal data.
  • Your workspace, your data. For content your business puts into a workspace, your business is in charge (the Data Fiduciary). We process that content only on your instructions.

What we hold about you today

  • Account: your name, email address, the workspaces you belong to and your role in each, plus what you told us at sign-up (workspace name, use case, team size, and — during early access — the optional invite code or who sent you). Phone numbers and email addresses are removed from that last answer before it is stored.
  • Google sign-in, if you use it: your name, email address, whether Google verified it, your profile picture and your Google account ID. Never your Google password.
  • Invitations: the invited email address, the role and who sent the invite.
  • Agents and their work: each agent's settings, instructions, knowledge and published versions; tasks with their conversations, steps, costs and approval decisions; and the leads agents save.
  • Knowledge files: the title, file name, type and size of each file or note, and the text we read from it. We don't keep the uploaded file itself.
  • Photos and PDFs sent in chats: the file itself, its name, type, size and a fingerprint (hash), and who sent it: a teammate, a website visitor or your own software. They are stored with DigitalOcean in New York, United States, and deleted after 90 days, or after a day if they were never sent.
  • Connected apps, if your workspace uses the pilot: the name and status of each connected account, and the app actions added to agents. Not your app passwords or sign-in tokens.
  • Google, Slack and HubSpot connections, if you make them: a masked account name (such as o***@yourshop.in), the account's status, and the permission the app gave us, stored encrypted. For a Google account we keep a scrambled (hashed) ID, not the ID itself. Gmail can only send; we never read your mailbox. Google Calendar can see only free and busy times, not what your events are.
  • Outreach contacts, if you run a campaign: the email, name, company, website and notes from your CSV, stored encrypted, and each contact's progress.
  • Opt-outs: when someone replies STOP to a follow-up or outreach email, a scrambled (hashed) form of their address, so no agent in your workspace emails it again.
  • Security records: scrambled (hashed) sign-in codes, session records, which version of the Terms and Privacy Policy you accepted, and an audit log of security-related actions. IP addresses are stored only in hashed form.

Cookies and local storage

  • dh_session is the only cookie. It keeps you signed in, scripts on the page can't read it, and it lasts until you sign out or for up to 30 days.
  • The app remembers a few display choices on your device, such as whether the sidebar is collapsed. These never leave your device.

How AI processing works

When an agent works on a task, we send the content it needs, such as its instructions, relevant knowledge, the message text and any photos or PDFs sent with it, to an AI model provider, Anthropic, which returns the result. We record which model ran each step, the tokens it used and what it cost, so you can see the cost of every task. Test chats work the same way, but replies, emails and changes in connected apps are simulated.

When an agent uses a connected app, the details the action needs are sent to that app through Pipedream, and the result comes back to the agent.

What the AI never sees

Customers sometimes type things they shouldn't into a chat. With Hide ID and card numbers from the AI on (it is, unless you switch it off in an agent's Advanced settings), these are replaced before the AI model receives the message:

What Replaced with
Aadhaar numbers (checked with Aadhaar's own check digit) [Aadhaar ending 1234]
Card numbers (checked with the card check digit) [card ending 1111]
PAN [PAN hidden]
Bank account numbers written after "account", "a/c" or "khata" [account ending 6789]
OTPs, CVVs and UPI or ATM PINs [OTP hidden], [CVV hidden], [PIN hidden]

The same applies to follow-up emails and daily quality checks. You still see the message as the customer sent it. Phone numbers, postal PIN codes, order numbers and amounts are left alone. Numbers inside photos and PDFs aren't covered.

Who processes data for us

Provider What for
DigitalOcean Servers and databases in Bengaluru; storage for photos and PDFs sent in chats in New York
Vercel Hosting and delivering the website and app
Cloudflare DNS and network security
Postmark Emails such as sign-in codes and invitations
Google Optional sign-in with Google
Razorpay Payments
AI model providers, such as Anthropic Doing the work in a task
Brave Web search, for agents you let search the web. It receives only the search words
Voyage AI Finding knowledge by meaning, with Voyage's option that stops it keeping or training on what we send
fal.ai Making images for agents that may create them, with fal's option that keeps no copy
Recall.ai The meeting notetaker: records a meeting your team sends it to and transcribes it, in the United States. The recording is deleted once transcribed
Pipedream Connected apps (pilot): signing in to your apps and running app actions, only if your workspace connects an app
Google, Slack, HubSpot Your own accounts in these apps, only if you connect them: booking on your calendar, sending from your Gmail, answering in your Slack, copying leads into your HubSpot
Messaging channels, such as WhatsApp (pilot) Delivering your agents' messages, for workspaces whose WhatsApp number our team has connected

Some of these providers process data outside India, as the law allows. The Privacy Policy explains this.

How long we keep it

Data How long
Sign-in codes Valid for 10 minutes, deleted about a week after they expire
Sessions End when you sign out or after 30 days; records are deleted soon after they expire
Account data While your account is active, and up to 90 days after it closes
Workspace content As the workspace's business decides; after a workspace closes, it can be exported for 30 days and is deleted within 90 days
Photos and PDFs sent in chats 90 days after they are sent (a day if never sent), or sooner if the agent is deleted
Removed Google, HubSpot and Slack connections 90 days after you disconnect, unless an agent's settings still point at one (then 90 days or more, until none does)
Invoices and payment records As long as tax and accounting law requires

What we keep after you disconnect

You disconnect an app under Integrations. Its sign-in key (the token that lets us act in the app) goes at once, and we ask the app to cancel it where the app lets us. We check the app's answer. If the app doesn't confirm, the message after you disconnect says so, and where to remove our app in the app itself. What your agents already did with the app stays in your workspace, because it is the record of what they did and what it cost, and it doesn't need the connection.

App Deleted at once What stays
Google Calendar Our copy of the key, and we ask Google to cancel it. Google gives Calendar and Gmail one permission, so while the same Google account is still connected for Gmail, Google keeps it until you disconnect that too. A record that the account was connected, marked removed: its masked name, a scrambled (hashed) account ID and the permissions it gave. Agents' appointment settings point at it, and reconnecting the same account brings it back. It is deleted 90 days after you disconnect, unless an agent's settings still point at it. Appointments already booked stay on your calendar and in Leads and Tasks.
Gmail The same as Google Calendar. The same removed record, deleted after 90 days in the same way (an outreach campaign that isn't finished also keeps it). Emails already sent stay in Leads and Tasks, outreach campaigns keep their contacts (encrypted) and progress, and opt-outs stay (hashed) so nobody who replied STOP is emailed again. Gmail could only send, so we hold nothing from your mailbox.
LinkedIn The whole connection: the key, the profile's name and its hashed member ID. We ask LinkedIn to cancel the key. Posts you approved stay in Tasks with their text and link. Posts scheduled for later go back to waiting for approval. Published posts stay on LinkedIn: delete them there.
Instagram The whole connection: the key, the username and the hashed account IDs. Instagram has no way for us to cancel a key, so we delete our only copy. To take our app off your account on Instagram's side too, remove Dhanur AI-IG in Instagram's settings under Apps and websites. The same as LinkedIn.
HubSpot Our copy of the key, and we ask HubSpot to cancel it. A removed record with the account's masked name and HubSpot account ID, deleted 90 days after you disconnect unless an agent's settings still point at it. Leads already copied stay in HubSpot and in Leads. HubSpot events kept for triggers are deleted after 30 days, as they always are.
Slack Our copy of the key. We also uninstall our app from your Slack workspace, which cancels its keys. A removed record with the Slack workspace's masked name and ID, deleted 90 days after you disconnect. Conversations with your agents stay in Tasks, with the Slack channel and thread they came from, and answers already posted stay in Slack.

How long the rest stays: a task, with its conversation and decisions, stays until you delete the agent that did it. Leads stay until the workspace is deleted. To have any of it deleted sooner, see Delete your data: write to us and we will do it. Deleting it yourself from the app is planned.

Your rights

Under India's Digital Personal Data Protection Act, you can ask to access, correct, update or erase your personal data. You can also withdraw consent, nominate someone to act for you, and have your complaints addressed.

To use these rights, write to outreach@prodigalai.com from your registered email address, or call +91 96548 13810. We may ask you to confirm who you are, and we respond within 30 days. Our Grievance Officer can be reached at the same email address and phone number.

If an agent run by one of our customers contacted you, send your request to that business first. If you write to us instead, we will pass it on and help them respond.

Planned. Exporting and deleting your data yourself, from the app. Until then, email us and we will do it for you.

Last updated 24 September 2026

Something unclear or wrong? Tell us