Privacy Policy

    Effective 18 June 2026 · Version 1.0

    One Verse AI Private Limited · CIN U63999MH2026PTC474572 · operator of XDrop AI

    This Privacy Policy forms part of, and should be read with, our Terms of Service & EULA.

    01

    Introduction

    This Privacy Policy explains how One Verse AI Private Limited (CIN U63999MH2026PTC474572), registered office at 205, Morya Classic, CTS No. 592, Off New Link Road, Andheri, Mumbai – 400053, Maharashtra, India (the “Company”, “we”, “us” or “our”), operator of XDrop AI (the “Service”), collects, uses, shares and protects personal data.

    This Policy forms part of, and should be read with, our Terms of Service & End User License Agreement (the “Agreement”). Capitalised terms not defined here have the meaning given in the Agreement. By using the Service you acknowledge the practices described in this Policy.

    02

    Scope and our role (Data Fiduciary vs. Data Processor)

    The Service is a multi-tenant platform. Your personal data is handled in two distinct roles, and it matters which applies:

    Where we determine the purpose - your account, authentication, usage and billing data - the Company is the Data Fiduciary (controller) and this Policy governs.

    Personal data inside the documents and content you upload to boardrooms (“Customer Content”) - here you are the Data Fiduciary and the Company acts only as a Data Processor, processing that data on your instructions to provide the Service. You are responsible for having a lawful basis, notices and consents for the personal data of others that you upload.

    03

    Personal data we collect

    a. Identity and contact data - first and last name, email address, mobile number, and (for business accounts) company/startup name.

    b. Account and authentication data - one-time passwords (OTPs) sent to your email and mobile, verification status, session and login records including IP address, device and browser information, and activity timestamps. We use OTP-based sign-in; we do not store account passwords.

    c. Customer Content - the files and documents you upload to boardrooms, and the questions, prompts and instructions you submit to the AI, together with related metadata. This content may itself contain personal data, for which you are the Data Fiduciary (see §2).

    d. Usage and audit data - logs of AI queries (who asked, which documents were retrieved and what was answered), feature usage, and access/sharing actions, used for security, audit and to operate the Service.

    e. Billing data - billing name, phone, GST registration number (GSTIN), billing address/state, plan, transaction identifiers and invoices. Payments are processed by a third-party payment processor; we do not store full card or bank-account details.

    f. Communications - the emails, OTPs and notifications we send you, and any support correspondence.

    g. Cookies - an essential, httpOnly session cookie used to keep you signed in (see §5).

    04

    How we use personal data, and our legal bases

    We use personal data to: create, operate, secure and support your account, workspaces, boardrooms and sharing; authenticate you and protect against unauthorised access; provide the AI Features (generating answers, citations, summaries, due-diligence gap analysis and the investor-readiness score from your documents); process payments, manage subscriptions and issue GST tax invoices; maintain security, tenant isolation, audit logs and prevent abuse; provide support and send service/transactional communications; and comply with legal, tax and regulatory obligations.

    Legal bases (DPDP Act, 2023). The DPDP Act recognises exactly two grounds for processing personal data: your consent (§6) and the certain legitimate uses listed in §7. It contains no “performance of a contract” ground. We therefore map every purpose to one of those two, and we tell you which:

    • 1. Account and security - create, operate and secure your account; authenticate you; maintain tenant isolation, audit logs and abuse prevention; provide support and transactional service messages. Ground: §7(a), data you voluntarily provided for this purpose. No consent required - necessary to run the Service.
    • 2. AI features - answers, citations, summaries, gap analysis and the readiness score from your documents, which involves sending document text and your questions to the AI sub-processors named in §6. Ground: consent (§6). Consent required, and withdrawable - withdrawing turns the AI features off; your documents and boardrooms remain accessible.
    • 3. Billing and tax - payments, subscriptions, GST tax invoices and their retention. Ground: §7(a) for the payment; §7(c), legal obligation, for issuing and retaining invoices. No consent required - we cannot lawfully delete tax records on request (see §7).
    • 4. Product communications - product updates, feature announcements and similar non-transactional messages. Ground: consent (§6). Consent required, and withdrawable at any time without affecting anything else.
    • 5. Referral programme - recording and crediting referrals if you take part. Ground: consent (§6). Consent required; withdrawing ends participation.
    • 6. AI Education partner - for that product only, sharing your name, email and mobile with our LMS partner to provision your course seat. Ground: consent (§6). Consent required; withdrawing means we cannot provision or maintain the seat.
    • 7. Legal compliance - responding to law, regulation, court order or lawful governmental request. Ground: §7(c) and §7(d). No consent required.

    Where we rely on consent, we ask for each purpose separately, we record what notice you were shown when you gave it, and withdrawal is one action in your profile - the same number of clicks as giving it (§6(4)). Withdrawal does not affect processing already carried out lawfully before you withdrew.

    05

    Cookies and similar technologies

    We use a single essential, httpOnly session cookie to keep you authenticated while you use the Service. It is necessary for the Service to function and is not used for advertising or cross-site tracking. Because it is httpOnly, it cannot be read by client-side scripts. If we introduce analytics or other non-essential cookies in future, we will update this Policy and, where required, seek your consent. See our Cookie Policy.

    06

    How we share personal data

    We do not sell your personal data, and we do not use your Customer Content to train artificial-intelligence models for the benefit of others. We share personal data only as follows:

    Service providers / Sub-processors - we use the third parties named below to operate the Service. Each is bound by confidentiality and security obligations and processes personal data only on our instructions. This is our complete current list; we will update this Policy before adding a sub-processor that receives personal data.

    • Akamai / Linode - cloud hosting, database and object storage - India (Mumbai)
    • Anthropic - AI model provider; generates AI answers, summaries and reports - United States
    • Voyage AI - generates search embeddings from document text - United States
    • Langfuse Cloud - AI observability and tracing (see §9) - United States
    • Sentry - error monitoring; prompts, completions and request bodies excluded - United States
    • Gotenberg - HTML-to-PDF rendering for documents and invoices - self-hosted, India
    • PayU - payment processing; we never store full card or bank details - India
    • Razorpay - payment processing; we never store full card or bank details - India
    • SMSCountry - SMS delivery for one-time passwords - India
    • ZeptoMail - email delivery for one-time passwords and notifications - India
    • Vimeo - video hosting and playback - United States
    • Tawai - AI Education LMS partner; seat provisioning for that product only - India

    Questions about this list: business@xdrop.ai.

    Our own authorised personnel - a small number of authorised Company personnel can access tenant accounts and boardroom content through an internal administration console. We use this only to operate the Service: investigating a fault you have reported, recovering data, responding to a lawful order, or investigating abuse or a security incident. Every such access is logged - the sign-in, each boardroom opened, and each document viewed, with NDA-gated documents recorded separately - and the log is append-only. We do not use this access to read your content for any other purpose. If you require that no Company personnel be able to access a given boardroom, contact business@xdrop.ai before uploading, and we will tell you honestly what we can and cannot offer.

    Other users you choose - Customer Content you share within a boardroom is visible to the users to whom you grant access, per the access controls you set.

    Legal and safety - where required by law, regulation, court order or governmental request, or to protect the rights, property or safety of the Company, our users or the public.

    Business transfers - in connection with a merger, acquisition, financing, reorganisation or sale of assets, subject to this Policy.

    07

    Data retention

    We retain personal data for as long as your account is active and as needed to provide the Service. Customer Content is retained until you delete it or your account is terminated, after which it is deleted within a reasonable period, subject to residual copies in routine backups for a limited time, and to records (such as GST tax invoices, and security/audit logs) that we are required to retain under applicable law. When data is no longer required and there is no legal obligation to retain it, we delete or anonymise it.

    08

    How we protect personal data

    We implement reasonable technical and organisational security measures appropriate to the Service, including tenant isolation enforced in the application authorisation layer (every request resolves the caller’s workspace membership and role before any data is returned, and the AI answers only from documents the caller is permitted to read), encryption of data in transit, access controls, OTP-based authentication and httpOnly session cookies, and audit logging of AI queries. The isolation boundary is covered by an automated regression test suite. No method of transmission or storage is completely secure, and we cannot guarantee absolute security. We will notify affected users and the Data Protection Board of personal-data breaches as and to the extent required by the DPDP Act. See Security.

    09

    International transfers

    Our primary database and document storage are located in India (Mumbai). Some of our sub-processors process personal data outside India, and we set out below which, and what reaches them:

    • Anthropic (United States) - the text of your questions and the document excerpts retrieved to answer them
    • Voyage AI (United States) - document text, in chunks, to generate search vectors
    • Langfuse Cloud (United States) - the text of your AI questions and the resulting traces, tagged with your user, session and boardroom identifiers
    • Sentry (United States) - error reports. Request bodies, AI prompts and completions are deliberately excluded; authenticating headers and cookies are redacted before transmission
    • Vimeo (United States) - videos you upload, and playback metadata
    • Tawai (India) - for AI Education purchases only: your name, email address and mobile number, to provision your course seat

    Transfers outside India are permitted under §16 of the DPDP Act, which allows transfer to any country except those the Central Government restricts by notification. We do not transfer personal data to any restricted country or territory. Each sub-processor is engaged under confidentiality and security obligations and processes data only on our instructions.

    If you need AI processing to stay within India, contact business@xdrop.ai before uploading; we will tell you honestly whether we can support that today.

    10

    Your rights (Data Principal rights under the DPDP Act)

    Subject to the DPDP Act, you have the right to: access a summary of the personal data we process and the processing activities; correction, completion and updating of your personal data; erasure where retention is no longer necessary; grievance redressal through our Grievance Officer (§13); nominate another individual to exercise your rights in the event of your death or incapacity; and withdraw consent at any time (this may limit or prevent your use of the Service).

    To exercise these rights, contact us at business@xdrop.ai. You also have the right to make a complaint to the Data Protection Board of India. Where the Company acts as a Data Processor for personal data inside Customer Content (§2), please direct requests to the relevant Data Fiduciary (the customer who uploaded the content); we will assist them as required.

    11

    Children

    The Service is intended for users aged 18 and over and is not directed at children. We do not knowingly collect personal data from children. If you believe a child has provided us personal data, contact us and we will take appropriate steps.

    12

    Third-party services

    The Service may link to or interoperate with third-party services that have their own privacy policies. We are not responsible for the privacy practices of those third parties, and we encourage you to review their policies.

    13

    Grievance Officer and contact

    In accordance with the DPDP Act, the Information Technology Act, 2000 and the rules thereunder, you may contact our Grievance Officer for any questions, requests or complaints regarding your personal data:

    Grievance Officer
    One Verse AI Private Limited
    205, Morya Classic, CTS No. 592, Off New Link Road, Andheri, Mumbai – 400053, Maharashtra, India
    Email: business@xdrop.ai

    We will acknowledge and endeavour to resolve grievances within the timelines prescribed under applicable law.

    14

    Changes to this Policy

    We may update this Privacy Policy from time to time. If a change is material, we will provide reasonable notice (for example, by email or an in-product notice). The “Effective date” above reflects the latest version. Your continued use of the Service after a change takes effect constitutes acknowledgement of the updated Policy.

    © 2026 One Verse AI Private Limited · Effective 18 June 2026 · v1.0