Privacy Policy
Effective 17 August 2026. Covers the Varta platform, this website, and the Varta Android app (com.shivankit.varta).
Varta runs phone calls. That means we handle recordings of conversations — yours and those of people who call you — which is about as sensitive as consumer data gets. This document is specific about what happens to it, because a vague privacy policy for a product like this would be worthless.
1. Who we are
Shivankit Technologies(“Varta”, “we”) operates the Varta platform and the Varta Android app, from India.
Under India's Digital Personal Data Protection Act, 2023 (DPDPA), we are the Data Fiduciary for your account information. When your agents handle calls or messages with third parties, you are the Data Fiduciary for that conversation and we act as a Data Processor on your behalf. For users in the EEA or UK, read those roles as controller and processor respectively.
Questions, requests, or complaints: common@shivankit.com. Our Grievance Officer under §13 of the DPDPA is reachable at the same address with “Grievance” in the subject line.
2. What we collect
From your account
- Email address, and a display name if you give one. Sign-in is handled by Supabase Auth; we store the tokens it issues, never your password in readable form.
- Phone numbers you register, SIM and gateway configuration, agent prompts, and the voices you configure or clone.
- Billing details, processed by Stripe. Card numbers go to Stripe directly and never reach our servers.
- Usage and diagnostic logs: call counts, durations, error traces, IP address, browser or device type.
From calls and messages your agents handle
- The phone numbers of both parties, and call timing.
- Audio recordings of the call, encrypted at rest.
- Transcripts, and the AI-generated summaries, topics and sentiment scores derived from them.
- The content of WhatsApp or SMS messages you route through the platform.
- Contacts you import, so the agent can tell your landlord from your mother.
From the Android app specifically
This section maps one-to-one onto the app's Play Data safety declaration.
- Microphone audio — captured only while a call is active, and only with a foreground-service notification visible for the whole duration. The app does not record in the background and has no wake-word listener.
- A push token from Firebase Cloud Messaging, so the server can wake the app when an agent needs a decision. Firebase Messaging is the only Firebase product in the app — there is no Analytics and no Crashlytics SDK.
- Crash and error information, reported to our own servers, not to a third-party analytics vendor.
- Your session token, stored on the device in Android's
EncryptedSharedPreferences. That token can drive real machines, so plaintext storage was never an option.
The app does not collect location, does not read your contacts from the device, does not read your SMS inbox, and carries no advertising or analytics SDK of any kind.
If you use the on-device model, the prompt, the conversation history and the generated reply stay on your phone. That code path makes no network calls at all.
3. Why we collect it
- To run the service — route calls, transcribe them, let your agent answer sensibly, and bill you correctly.
- To keep it working — debug failures, monitor latency, find the call that broke.
- To prevent abuse — spam, fraud, harassment, and uses that would put our telephony providers in breach.
- To meet legal obligations — tax records, and lawful requests from Indian authorities.
We do not sell your data, we do not share it with data brokers, and we do not use your call content to train shared AI models. Our model providers are contractually bound to the same on the data we send them.
4. Telling the other party
Every call your agent answers opens with a spoken disclosure that the call is recorded and AI-assisted. This is not removable. The wording and the language it's spoken in are configurable; its presence is not.
Indian law generally treats single-party consent as sufficient for recording. If your use case falls under sectoral rules — lending, insurance, healthcare, debt collection — obtaining any further consent is your responsibility as the Data Fiduciary for that conversation.
5. Who else touches the data
Each of these receives only what its job requires. None of them receive your data for their own purposes.
- Supabase — account records, application database, authentication.
- Deepgram — speech-to-text, unless you have configured a local recogniser.
- OpenAI — language model inference. Sent per call under an API agreement that excludes training on submitted data.
- Cartesia — voice synthesis, including cloned voices.
- Google Firebase Cloud Messaging — push notifications to the Android app.
- Stripe — payments and invoicing.
- Resend — transactional email such as beta invites and deletion confirmations.
- Langfuse — model call tracing, used to debug agent behaviour.
- LiveKit — real-time audio transport for in-browser calls.
Speech recognition on our own infrastructure runs on GPUs in India. Some processors above operate outside India, so your data may be processed abroad; we rely on their contractual data-protection terms for those transfers. If you configure local providers for speech, language and voice, no call content leaves your own hardware at all.
6. How long we keep it
- Call recordings and transcripts — until you delete them, or until your account is deleted.
- Account records — for the life of the account.
- Diagnostic logs — 90 days, then rotated out.
- Billing records — eight years, as Indian tax law requires. These contain no call content.
- Encrypted backups — a rolling 90-day cycle. Deleted data ages out of backups on that schedule and is never restored into the live system.
7. Your rights
Under the DPDPA — and, where they apply, the GDPR — you can:
- Ask what personal data we hold about you, and get a copy.
- Correct anything inaccurate or incomplete.
- Delete your account and its data. There is a form for exactly that; it needs no sign-in and works after you've uninstalled the app.
- Withdraw consent, which ends the processing that relied on it.
- Nominate someone to exercise these rights on your behalf in the event of death or incapacity (DPDPA §14).
- Complain to us first, and then to the Data Protection Board of India if we haven't resolved it.
We answer rights requests within 30 days. Write to common@shivankit.com.
8. How we protect it
- Call audio is encrypted at rest; all transport is TLS.
- Database access is governed by row-level security, so one account's data is not reachable from another's session.
- On the phone, session tokens live in
EncryptedSharedPreferences, backed by the Android keystore. - The app refuses any server-supplied URL that could point at another host — a bearer token that can be aimed anywhere is an exfiltration primitive, so the client enforces this itself rather than trusting the server to behave.
- Administrative access is limited to named people who need it.
No system is perfect. If a breach affects your personal data we will notify you and the Data Protection Board of India as the DPDPA requires.
9. Children
Varta is not for anyone under 18. We do not knowingly collect data from children. If you believe a child has created an account, write to common@shivankit.com and we will remove it.
10. Changes to this policy
If we change how we handle your data in any material way, we'll email registered users before it takes effect and update the date at the top. Continuing to use Varta after that means the new version applies.
11. Contact
Shivankit Technologies · common@shivankit.com
Grievance Officer: same address, subject line “Grievance”.
This policy describes a product in closed beta and will be revised before general availability. It is a description of our practices, not legal advice.