Legal

Privacy Policy

Last updated 23 August 2026

Couple Sathi is a private space for two people. Most of what you put into it — letters, chat, photos, how your day went — is the kind of thing you would only share with your partner. This policy explains exactly what we hold, who can see it, who processes it on our behalf, and what you can make us do about it.

It is written to align with India’s Digital Personal Data Protection Act, 2023 (DPDPA) and the Information Technology Act, 2000 and its rules. In DPDPA language we are the Data Fiduciary and you are the Data Principal.

Who we are

Couple Sathi is a service of SathiVerse, a firm registered in Delhi, India. In this policy, SathiVerse is the Data Fiduciary responsible for your data. The service is provided through couplesathi.app and the installable app of the same name.

For anything in this policy, write to support@couplesathi.app.

The most important thing to understand first

Couple Sathi is built for two people, so almost everything you create in it is visible to the partner you link with. That is the product working as intended, not a leak — but it is the fact most worth being clear about before you start using it.

Once you and your partner are linked, they can see:

  • every chat message and voice note you send them;
  • letters you send them, including scheduled ones, once the unlock time passes;
  • photos and captions you add to your shared memory wall;
  • your daily mood check-in, and your mood history on the shared chart;
  • your answer to the daily question, once you have both answered;
  • your shared streak, medals, health score, occasions, and the merged timeline of all of it;
  • your display name, profile photo, and relationship stage.

Two things do not become visible to your partner: your password (we never see it either — see below), and your saved card decks, which stay private to you.

What happens if you unlink

Unlinking stops future sharing. It does not retroactively withdraw what was already shared: letters your partner has already received, messages they have already read, and photos added to the shared wall remain with them, in the same way an email you have already sent cannot be recalled. If you need shared content removed after a separation, write to us and we will help as far as we reasonably can.

The leaderboard

Couples appear on a public-within-the-app streak leaderboard under their first names. You can turn this off for both of you at any time in Settings → Leaderboard; opting out removes your couple from everyone else’s view entirely, not just from the top of the list.

What we collect

Information you give us

  • Account: your email address and a password. If you sign in with Google, Discord or Facebook we receive your name, email address and profile picture from that provider — nothing else, and never your password there.
  • Profile: display name, gender, age, profile photo, and your relationship stage. Age is collected because the service is 18+ and some content is age-restricted.
  • What you create: chat messages, voice notes, love letters (typed or drawn), memory-wall photos and captions, mood check-ins, answers to the daily question, occasions and anniversary dates, and saved cards.
  • Delivery details, if you order from the shop: recipient name, 10-digit Indian mobile number, address and PIN code.
  • Support messages you send us, and our replies.
  • Waitlist details, if you joined before launch: your email address, optionally a mobile number, and a short tag recording which post or link you arrived from.

Information created as you use the service

  • Feature usage: which features you open and use, and when — for example that a mood check-in happened, or a deck was played. We record that the action happened, not the content of it.
  • Progress: streaks, medals, spin history, card sessions, and the health score derived from them.
  • Subscription and payment records: which plan you are on, when it renews, and Razorpay’s transaction identifiers. Also an audit trail of every change to your access, so we can answer “why did my plan change?” accurately.
  • Referrals: your referral code, who you referred or were referred by, and any rewards issued.
  • Sign-in security log: your IP address, browser user-agent and the time, recorded on each sign-in, sign-up and social sign-in. We use this only to detect fraud and duplicate accounts. It is never shown to you, your partner, or any other user.
  • Push notification tokens, if you turn notifications on.

What we deliberately do not collect

  • Your password. Authentication is handled by Supabase, which stores only a salted hash. We could not tell you your password if we wanted to.
  • Card, UPI or bank details. These go directly to Razorpay, which is PCI-DSS certified. We receive only their transaction references and the amount. Nothing that could be used to charge you is ever stored on our systems.
  • Your location. We do not request or store GPS or precise location data. An IP address does imply a rough region, and that is the extent of it.
  • Your contacts, calendar, camera roll or microphone in the background. Photos and voice notes are captured only when you actively record or choose them.
  • Advertising identifiers. There is no ad network in this app.

Why we use it, and on what basis

Under the DPDPA we process your data with your consent, and for the “legitimate uses” the Act permits — chiefly performing the service you have voluntarily asked us for. Specifically:

  • To run the service — creating your account, linking you with your partner, delivering the messages, letters and features you use.
  • To take payment and give you the access you paid for, including honouring a subscription across both partners in a couple.
  • To send you service messages — confirmations, password resets, receipts, notifications you asked for, and occasional reminders such as a streak about to lapse. You can turn notification categories off in Settings.
  • To keep the service safe — rate limiting, fraud and duplicate-account detection, and investigating abuse reports.
  • To improve the product — understanding which features are used and which are not, and fixing what breaks.
  • To meet legal obligations — tax, accounting, and responding to lawful requests.

We do not sell your personal data, rent it, or share it with advertisers. We do not use your private content to train AI models.

Who processes it for us

These providers process data on our instructions, under contract, to run the service. They are not permitted to use it for their own purposes.

  • Supabase (on AWS, Mumbai region) — database, sign-in, and file storage for photos, voice notes and profile pictures.
  • Vercel — application hosting and delivery. Our server functions run in Vercel’s Mumbai region.
  • Razorpay — payments, subscriptions and UPI mandates. Razorpay is its own data controller for payment information and applies its own privacy policy to it.
  • Resend — transactional email, such as confirmations and receipts.
  • Your browser’s push service — Google (FCM), Mozilla or Apple, depending on your device — if you enable notifications. Notification contents are encrypted before they leave our servers, so the push service relays them without being able to read them.
  • Sentry — error monitoring, if enabled, so we learn about crashes without waiting for someone to report one.
  • PostHog — product analytics, if enabled. Where it is used we have switched off both automatic interaction capture and session recording in our code, specifically so that the text on your screen — your messages, your letters — cannot be collected by it.
  • Vercel Analytics — aggregate page-traffic counts, without cookies or cross-site identifiers.

We may also disclose information where the law requires it: a valid order from a court or authorised agency, or to establish or defend a legal claim. If we ever sell or transfer the business, your data would move with it, and we would tell you first.

Where your data is stored

Your data is stored in India — our database, file storage and server functions all run in the Mumbai region, chosen deliberately so that data about Indian couples stays in India and the app is fast on Indian mobile networks.

Some of our providers are companies headquartered outside India and may access data from elsewhere in the course of supporting their platforms. The DPDPA permits transfers outside India except to countries the Central Government restricts by notification; we will comply with any such notification if one is issued.

How we protect it

  • Everything travels over HTTPS, and is encrypted at rest by our database and storage providers.
  • Photos, voice notes and profile pictures live in private storage. They are never on a public URL — each view is served through a short-lived signed link that expires.
  • Access is enforced in the database itself, row by row, not just in the app. A request for someone else’s data fails at the database even if the app were wrong.
  • The contents of a sealed time capsule are not sent to your partner’s device at all until it unlocks — not merely hidden by the interface.
  • Payment credentials never reach our servers in the first place.
  • Sign-in and password-reset attempts are rate limited. Administrator access requires a second factor.

Being straight with you about encryption

Your content is encrypted in transit and at rest, but it is not end-to-end encrypted. That means that in principle we hold the ability to access stored content — for example if compelled by a lawful order, or to investigate a serious abuse report. We do not read your messages or letters as a matter of course, and no routine feature of this service involves a human at Couple Sathi reading them. We would rather say this plainly than let the word “encrypted” imply a guarantee we cannot make.

Cookies and local storage

We use no advertising or cross-site tracking cookies. What we do set:

  • Sign-in cookies, which keep you logged in. Without these the service cannot work.
  • Two short-lived cookies that remember a partner invitation or referral link you followed, so it still works after you finish signing up. Both expire within an hour and are deleted as soon as they are used.
  • Settings stored on your own device — your theme, sound and vibration preferences, an unsent-message queue for when you are offline, and your shopping cart. These stay on your device, and signing out clears everything except the display preferences.

How long we keep it

  • While your account is open, we keep your data so the service works. Your history is the product.
  • When you delete your account, it is removed within 24 hours of approval, along with the data attached to it: your profile, messages, letters, memories, moods, subscription and order records, support tickets and sign-in logs.
  • Content shared with your partner — letters they received, messages in your shared chat, photos on the shared wall — may remain visible to them, as described above.
  • Waitlist entries are kept until launch and deleted within a reasonable period afterwards; you can ask us to remove yours sooner.
  • Records we must keep by law. Indian tax and accounting rules require us to retain transaction records for several years. Where that applies we retain the minimum required, and the DPDPA expressly permits us to decline erasure of records the law requires us to keep.

Your rights

Under the DPDPA you have the right to:

  • Know what we hold about you and who we have shared it with.
  • Correct or complete anything inaccurate. Most of it you can edit yourself in Settings.
  • Erase your personal data, except where the law requires us to keep it. You can start this yourself in Settings → Delete account, and cancel it before it completes.
  • Withdraw consent as easily as you gave it — turn off notifications, opt out of the leaderboard, unlink from your partner, or close your account.
  • Nominate someone to exercise these rights on your behalf if you die or become unable to.
  • Complain — to us first, and then to the Data Protection Board of India if we have not resolved it.

To exercise any of these, email support@couplesathi.app from the address on your account. We will respond within 72 hours and act within the timeframes the law sets. We may need to verify it is really you before acting on a request about someone’s private messages.

Children

Couple Sathi is for adults. You must be 18 or older to create an account, and we ask your age at sign-up. We do not knowingly collect data from anyone under 18, and the DPDPA’s rules on processing children’s data are not applicable to a service that does not admit them. If you believe someone under 18 has an account, tell us at support@couplesathi.app and we will close it.

If something goes wrong

If a personal data breach occurs, we will notify the Data Protection Board of India and every affected user as the DPDPA requires, telling you what happened, what it means for you, and what we are doing about it.

Grievance Officer

In accordance with the DPDPA 2023 and the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021:

We acknowledge complaints within 24 hours and aim to resolve them within 15 days, as those Rules require.

Changes to this policy

If we change this policy we will update the date at the top and, for anything material, tell you by email or in the app before it takes effect. Continuing to use Couple Sathi after that means you accept the updated policy.