Privacy Policy
Last updated: July 20, 2026 Β· Effective: February 19, 2026
1. Introduction
Welcome to SaiyamAI ("we," "our," "us," or the "Company"). We are a digital wellness company that helps you manage your screen time through an AI-powered application (the "App"). This Privacy Policy explains how we collect, use, disclose, store, and safeguard your personal data when you use our App.
This Privacy Policy applies to all users worldwide. Where specific regulations (such as the EU's GDPR, California's CCPA/CPRA, India's DPDPA 2023, or Brazil's LGPD) grant you additional rights, those rights are described in Section 11 below.
By installing, accessing, or using the App, you acknowledge that you have read, understood, and agree to be bound by this Privacy Policy. If you do not agree, please uninstall the App and do not use our services.
2. Data Controller Information
The data controller responsible for your personal data is:
Shrey Jain
Email: support@saiyamai.com
Address: Katni, Madhya Pradesh, India
For data protection inquiries, contact our Data Protection / Grievance Officer at: dev.shreyjain@gmail.com
3. Information We Collect
We follow the principle of data minimizationβwe collect only what is necessary to deliver our digital wellness services.
3.1. Information You Provide
| Data Category | Specific Data | Purpose |
|---|---|---|
| Account Information | Email address (required); display name (optional β you may provide it during email/password sign-up, or it is set automatically if you sign in with Google) | Authentication, account recovery |
| Onboarding Data | Age group, profession, discovery source, country (ISO code), timezone (IANA) | Personalizing the experience |
| Consent Records | Analytics consent flag, consent timestamp | Legal compliance (proving consent) |
| Plans & Schedules | App package names, daily and hourly/Pomodoro-cycle limits, strict time blocks, DND blocks, Reel/Shorts scroll caps (max scrolls per time window), active date ranges | Core service delivery |
| Memories | User-dictated notes to the AI (category + content) | AI personalization at your request |
| Chat Messages | Conversations with SaiyamAI (role, content, timestamp) | AI responses, context continuity |
3.2. Information Collected Automatically
| Data Category | Specific Data | Purpose |
|---|---|---|
| App Usage Statistics (via Android UsageStatsManager β "The Brain") | Per-app usage minutes, open count, peak hours, daily totals (top 10 apps + aggregated "others") | Enforcing limits, generating reports |
| Foreground App Detection (via AccessibilityService β "The Mind") | Package name of the currently active app; app open/close events; keyboard visibility status | Triggering nudges, blocking overlays, and managing timers |
| Reels / Shorts Surface Detection (via AccessibilityService β optional Reels Blocker and Reel Cap features) | Accessibility event metadata from Instagram's and YouTube's UI: element class names, resource IDs, and UI labels (e.g. "reels", "view likes", "reposted", YouTube's Shorts player container) β processed entirely on-device, never stored or transmitted | Detecting when the Instagram Reels or YouTube Shorts feed is active so the App can (a) perform a system Back navigation to redirect you away from Reels/Shorts when Reels Blocker is enabled, and/or (b) count scrolls against your configured Reel Cap when Reel Cap is enabled |
| Reel Cap Configuration & Scroll Counts | Per-app max-scroll limit, time window, active hours, excluded days, and current scroll count within the active window | Enforcing your self-set Reels/Shorts scroll limits; synced to your account so limits persist across devices |
| Subscription & Purchase Status (via Google Play Billing) | Subscription/product ID, purchase token, order ID, plan tier, purchase and expiry status; an obfuscated account identifier is passed to Google Play at purchase time to link the purchase to your account | Activating and managing your paid subscription, verifying entitlement, restoring purchases |
| Nudge Session Data | Session start/end times, duration, overlay count, snooze details (duration, reason), detected emotion | Service improvement, analyzing nudge effectiveness |
| Device Unlock Count | Number of times you unlock your device today, via Android's ACTION_USER_PRESENT signal | An on-device-only statistic used for in-app insights; never stored on our servers or transmitted anywhere |
| FCM Token | Firebase Cloud Messaging device token | Push notifications (weekly reports, timer bubble) |
| Sync Logs | Sync success/failure status, error messages, timestamps | Debugging, ensuring data integrity |
| Analytics & Performance Data (via Firebase Analytics) | App events (e.g., screen views, feature usage), session duration, device model, OS version, country, language; inferred age range and gender (if demographic reporting is enabled via Google Analytics) | Understanding feature usage, improving the App |
| Crash & Diagnostics Data (via Firebase Crashlytics) | Crash reports, stack traces, device state at time of crash, OS version, app version | Identifying and fixing bugs and stability issues |
| Advertising ID (ad_id / GAID) | Google Advertising ID (Android Advertising Identifier) | Used by Firebase Analytics and Crashlytics to deduplicate events and link analytics sessions; not used for advertising or ad targeting |
3.3. Information We Do NOT Collect
- β User-typed text, messages, passwords, keystrokes, or screenshots (the optional Reels Blocker and Reel Cap features read Instagram's and YouTube's UI accessibility labels on-device solely for surface detection and scroll counting β never stored or transmitted)
- β Keystrokes or typed text
- β Notification content from other apps
- β Contacts, call logs, SMS messages
- β Photos, camera, or microphone data
- β Precise GPS location
- β Browsing history or URLs visited
- β Advertising ID for ad targeting or cross-app tracking for commercial advertising purposes
3.4. What "Anonymised" Means β How We Protect Your Identity
SaiyamAI stores your data in your personal account (Firebase) linked to your account ID. This is necessary for backup, sync, and personal features like weekly progress reports. However:
- β Your personal identity (name, email, or account ID) is never shared with the Google Gemini AI model, any analytics partner, any third-party company, or any aggregated dataset used for reporting or potential data sales.
- β When we say "anonymised usage data": your personal identity is stripped before any external use. For example, we may internally know "User #A147 used Instagram for 2 hours," but any external report states only "a user in India used Instagram for 2 hours."
- β The AI model receives your plans, usage patterns, chat history, memories, and timezone β but never your name, email, or any detail that identifies you to Google or any other party.
- β If you have not opted into analytics (Checkbox 1 during onboarding), your data is excluded entirely from analytics, model improvement, and aggregated reporting.
"Anonymised" = externally de-identified, not internally unlinked. Our internal systems link data to your account to deliver the service. Externally, your identity is never exposed.
4. Android Permissions β Detailed Disclosure
Our App requires the following Android permissions. Each is used solely for the stated purpose:
4.1. Usage Access Permission ("The Brain")
- What it does: Reads aggregated app usage statistics (time spent, open counts) from the Android UsageStatsManager API.
- Why we need it: To measure your daily app usage against the limits you set.
- What we DO NOT do: We do not read the content within any app.
4.2. Accessibility Service ("The Mind")
- What it does: Detects foreground app changes (which app you opened or closed), checks for keyboard activity, and β when the optional Reels Blocker and/or Reel Cap features are enabled β detects the Instagram Reels or YouTube Shorts surface to redirect you away from it (Reels Blocker) and/or count scrolls against your configured limit (Reel Cap).
- Why we need it: To know when you open a restricted app so we can show a blocking overlay or nudge; to pause timers when you are typing; to automatically redirect you away from Instagram Reels or YouTube Shorts when Reels Blocker is enabled; and to count Reels/Shorts scrolls against your self-set limit when Reel Cap is enabled.
- What we DO NOT do:
- We do not store or transmit any text, data, or content from your screen. We use the technical capability to retrieve window content (
canRetrieveWindowContent) to: (1) detect whether the on-screen keyboard is visible, and (2) when Reels Blocker or Reel Cap is enabled, read accessibility event metadata (UI element class names, resource IDs, and labels) from Instagram or YouTube to detect the Reels/Shorts surface and count scroll events. All such data is processed entirely on-device and is never stored or transmitted β only the resulting scroll count and your cap configuration (not the underlying UI data) is synced to your account. - We do not read your notifications.
- We do not log keystrokes.
- We do not change your device settings.
- We do not interact with UI elements on your behalf, except: when the optional Reels Blocker is enabled, we perform a system Back action to navigate you away from Instagram Reels or YouTube Shorts. You control this via Settings β Reels Blocker and can disable it at any time.
- We do not bypass Android's privacy or security controls.
- We do not store or transmit any text, data, or content from your screen. We use the technical capability to retrieve window content (
- Revocation: You can revoke this permission at any time in Android Settings β Accessibility. The blocking, nudge, Reels Blocker, and Reel Cap features will stop working.
4.3. Overlay Permission ("The Body")
- What it does: Displays a floating overlay (nudge screen or blocking screen) on top of other apps.
- Why we need it: To show you the nudge/block UI when you open a restricted app.
4.4. Notification Permission ("The Helper")
- What it does: Sends local and push notifications.
- Why we need it: Persistent timer bubble (silent), usage threshold alerts, and weekly reports. We do not send marketing/spam notifications.
4.5. Battery Optimization Exemption ("The Heartbeat")
- What it does: Requests that Android exclude the App from automatic background battery restrictions (
REQUEST_IGNORE_BATTERY_OPTIMIZATIONS). - Why we need it: Many Android manufacturers aggressively kill background services to save battery. This permission is required so the App's foreground services (blocking, nudges, the accessibility service, and the timer bubble) keep running reliably instead of being silently stopped by the OS. This is one of the App's four mandatory core permissions, alongside Usage Access, Overlay, and Notifications.
- What we DO NOT do: We do not use this permission to access any additional data. It only affects whether Android is allowed to suspend the App's background processes.
- Revocation: You can revoke this at any time in Android Settings β Apps β SaiyamAI β Battery. Doing so may cause blocking, nudges, and the timer bubble to stop working reliably, especially on aggressive OEM battery management (e.g., Xiaomi, Oppo, Vivo, OnePlus).
4.6. Advertising ID (ad_id)
- What it does: Reads the Android Advertising Identifier (GAID / ad_id).
- Why we need it: Firebase Analytics and Firebase Crashlytics use the Advertising ID to deduplicate app events and correlate analytics sessions. We do not use this identifier for serving advertisements or cross-app behavioral tracking.
- User control: You can reset or opt out of Advertising ID use at any time via Android Settings β Privacy β Ads β Reset Advertising ID / Opt out of Ads Personalization. When opted out, Firebase Analytics will not associate events with your Advertising ID.
5. How We Use Your Information
5.1. Lawful Bases for Processing (GDPR Article 6)
| Purpose | Lawful Basis |
|---|---|
| Providing the core App service (plans, blocking, nudges) | Performance of a contract (Art. 6(1)(b)) |
| AI-powered conversations and personalization | Performance of a contract (Art. 6(1)(b)) |
| Cloud backup and sync (Firestore) | Performance of a contract (Art. 6(1)(b)) |
| Processing paid subscriptions (Google Play Billing) | Performance of a contract (Art. 6(1)(b)) |
| Anonymised usage analytics, AI model improvement, and aggregated regional reporting | Consent (Art. 6(1)(a)) β via onboarding Checkbox 1 (optional) |
| Sending notifications (weekly reports, timer bubble) | Consent (Art. 6(1)(a)) β via notification permission |
| Future data monetization (if activated) | Consent (Art. 6(1)(a)) β with separate, explicit opt-in |
Analytics consent (Checkbox 1) can be withdrawn at any time via Settings β Privacy β Analytics Consent. Withdrawal does not affect the lawfulness of processing before withdrawal or the core App service.
5.2. Specific Uses
- Core Functionality: Enforcing app limits, blocking apps during strict times, displaying nudge overlays, respecting DND windows.
- AI Processing: Generating contextual responses. See Section 6.
- Backup & Sync: Storing your plans, chats, memories, usage snapshots, and session data in Google Firestore for device-switching and data recovery.
- Analytics (opted-in users only): Monitoring how the AI performs and whether nudges are effective using aggregated, de-identified usage data. Only users who opted into Checkbox 1 contribute to analytics.
- AI Model Improvement (opted-in users only): We may use aggregated, de-identified interaction signals β such as which AI responses users found helpful β to improve our own AI systems. We will never use the content of your chat messages or personal details for model training. This is always tied to your analytics consent.
- Notifications: Timer bubble, threshold alerts, and weekly usage reports.
- Subscriptions: Processing and verifying paid subscription purchases made through Google Play Billing, and managing your entitlement to premium features.
6. AI Data Processing
6.1. What We Send to the AI
When you interact with SaiyamAI (in Plan Mode or Nudge Mode), we send the following context to Google's Gemini API:
| Data Sent | Mode |
|---|---|
| Your active plans, strict time rules, DND rules, No-Nudge windows, and Reel/Shorts scroll caps | Plan Mode |
| Rules you recently turned off (last 7 days), so the AI has short-term context | Plan Mode |
| Last 7 days aggregated usage (top apps, total usage) | Plan Mode |
| Current app's limit and real-time usage | Nudge Mode |
| Last 5 chat messages | Both |
| Your memories | Both |
| Your current date, time, and timezone | Both |
| Current on/off state of your Reels/Shorts Blocker, Breather pause settings (enabled/duration/cooldown), and Timer Bubble visibility | Both |
| Whether the Accessibility Service is currently enabled, and your app version | Both |
| An internal onboarding-progress marker (opaque state, not readable personal content) | Both |
Your name, email address, and account identifier are never sent to the AI model. The AI receives only the contextual wellness data listed above.
6.2. How the AI Uses It
- The AI uses this data solely to:
- Help you set or adjust screen time plans.
- Evaluate snooze/extension requests (and push back when appropriate).
- Provide personalized wellness insights.
6.3. AI Data Safeguards
- No model training: Your personal data is not used to train or fine-tune any AI model.
- No data retention by AI: Prompts and responses are processed in real-time. Google's Gemini API (when used with API key or service account) does not retain your prompt data for model improvement per Google's API Terms.
- No automated decisions with legal effect: The AI does not make decisions that produce legal effects or similarly significant effects on you. You always retain the ability to override the AI by opening the SaiyamAI app.
7. Data Sharing and Disclosure
7.1. Service Providers (Sub-Processors)
We share data with the following categories of service providers, who are contractually bound to protect your data:
| Provider | Data Shared | Purpose |
|---|---|---|
| Google Firebase (Firestore, Auth, FCM) | Account data, plans, chats, usage snapshots, memories, nudge sessions, sync logs | Cloud storage, authentication, push notifications |
| Google Firebase Analytics | App events, session data, device info, country, language, Advertising ID | App usage analytics and feature improvement |
| Google Firebase Crashlytics | Crash reports, stack traces, device state, app version, Advertising ID | Bug detection and stability improvement |
| Google Gemini API | Context data per Section 6.1 (no personal identity) | AI response generation |
| Google Play Billing | Subscription/product ID, purchase token, order ID, an obfuscated account identifier | Processing and verifying paid subscription purchases |
Google's privacy policy governs how Firebase Analytics and Crashlytics handle data: https://policies.google.com/privacy. Google acts as a data processor on our behalf for these services.
7.2. Legal Obligations
We may disclose your data if required by law, regulation, legal process, or governmental request (e.g., court order, subpoena).
7.3. Business Transfers
In the event of a merger, acquisition, reorganization, or sale of assets, your data may be transferred. We will provide prior notice and, where required by law, obtain your consent or provide an opt-out mechanism before transferring data to a new entity with a different privacy policy.
7.4. Future Data Monetization
CAUTION
We do not currently sell, rent, or share your personal data with third parties for marketing, advertising, or any commercial purpose unrelated to the App's core functionality.
Should we decide to monetize data in the future, we commit to:
- Updating this Privacy Policy with at least 30 days' advance notice.
- Providing a separate, explicit opt-in consent mechanism β not buried in ToS acceptance.
- Offering a "Do Not Sell or Share My Personal Information" opt-out (as required by CCPA/CPRA).
- Anonymizing or aggregating data before any sale wherever possible.
- Never selling raw chat logs, memories, or accessibility data.
- Any data sharing will comply with applicable laws (GDPR, CCPA, DPDPA, LGPD, etc.).
Aggregated Regional Insights: We may share or sell aggregated, regional, non-personal statistical insights (for example: "Users in [region] spend an average of X minutes on social media apps during [time period]"). This data:
- Contains no personally identifiable information and cannot be traced back to any individual.
- Is derived only from data of users who have opted into analytics (Checkbox 1).
- Constitutes statistical data, not "personal data" under applicable privacy laws (GDPR Recital 26, DPDPA).
If you have declined analytics consent, your data is excluded entirely from these aggregations.
8. International Data Transfers
Your data is stored on Google Firebase servers, which may be located in the United States or other countries outside your jurisdiction.
Safeguards for international transfers:
- Standard Contractual Clauses (SCCs): Google has adopted EU-approved SCCs for transfers from the EEA/UK/Switzerland.
- EU-U.S. Data Privacy Framework: Google LLC is certified under the EU-U.S. DPF.
- Encryption: Data is encrypted in transit (TLS/HTTPS) and at rest (AES-256) on Google's infrastructure.
By using the App, you acknowledge that your data may be transferred internationally with the safeguards described above.
9. Data Retention
| Data Category | Retention Period |
|---|---|
| Account information | Until you delete your account |
| Plans, strict time, DND schedules | Until you delete them or delete your account |
| Chat history | Retained as long as account exists; last 5 messages shown to AI as context |
| Memories | Until you delete them or your account |
| Daily usage snapshots | Retained for historical reports; deleted with account |
| Nudge session summaries | Retained for analytics; deleted with account |
| Reel Cap configuration & scroll counts | Until you delete the cap or your account |
| Subscription & purchase status | Retained while your subscription is active or as required for purchase records; Google Play retains its own transaction records per Google's policies |
| Sync logs | Retained for debugging; deleted with account |
| FCM tokens | Updated on each new session; old tokens overwritten |
| Firebase Analytics events | Retained for up to 14 months per Google's default retention; then automatically deleted by Google |
| Firebase Crashlytics reports | Retained for 90 days per Google's default retention; then automatically deleted by Google |
| Advertising ID (ad_id) | Not stored by us; used transiently by Firebase SDKs per Google's retention policies |
Upon account deletion, all your data is permanently deleted from our systems within 30 days, including from Firestore and any backups. See Section 10 for deletion procedures.
10. Account and Data Deletion
10.1. In-App Deletion
You can request complete account and data deletion directly within the App via Settings β Delete Account.
10.2. Web-Based Deletion
If you have uninstalled the App, you can request deletion via our web form at: Delete Account
10.3. Email Request
You may also email us at support@saiyamai.com with the subject "Account Deletion Request."
10.4. What Gets Deleted
Upon a valid deletion request, we permanently delete:
- Your user profile and account data
- All plans, strict time rules, and DND rules
- All memories
- All chat conversations
- All daily usage snapshots and nudge session summaries
- All sync logs
- Your FCM token
For Firebase Analytics and Crashlytics data associated with your Advertising ID: we will make reasonable efforts to delete or de-identify this data. Note that aggregate analytics data retained by Google may not be fully erasable if it has already been de-identified per Google's policies.
We will process deletion requests within 30 days. Data may be retained beyond this period only if required by applicable law (e.g., tax records, legal disputes).
11. Your Rights by Jurisdiction
11.1. European Economic Area, UK, Switzerland (GDPR / UK GDPR)
- Right to Access your personal data
- Right to Rectification of inaccurate data
- Right to Erasure ("Right to be Forgotten")
- Right to Restriction of processing
- Right to Data Portability (receive your data in a structured format)
- Right to Object to processing based on legitimate interest
- Right to Withdraw Consent at any time (without affecting prior lawful processing)
- Right to Lodge a Complaint with your local Data Protection Authority (DPA)
11.2. California, USA (CCPA / CPRA)
- Right to Know what personal information we collect and how it's used
- Right to Delete your personal information
- Right to Opt-Out of the sale/sharing of personal information (if applicable in future)
- Right to Non-Discrimination for exercising your rights
- Right to Correct inaccurate personal information
- We do not currently sell personal information. If we begin doing so, we will provide a "Do Not Sell or Share My Personal Information" link.
11.3. India (DPDPA 2023)
- Right to Information about what data is processed and why
- Right to Correction and Erasure of your personal data
- Right to Grievance Redressal β contact our Grievance Officer at dev.shreyjain@gmail.com
- Right to Nominate another person to exercise your rights in case of death or incapacity
- You may file a complaint with the Data Protection Board of India.
11.4. Brazil (LGPD)
- Right to Confirmation of processing
- Right to Access, Correction, Anonymization, Blocking, or Deletion of unnecessary or excessive data
- Right to Data Portability
- Right to Information about third parties with whom data is shared
- Right to Revoke Consent
- You may contact the ANPD (Autoridade Nacional de ProteΓ§Γ£o de Dados).
11.5. Canada (PIPEDA / Bill C-27)
- Right to Access personal information we hold about you
- Right to Challenge Accuracy of your personal information and request correction
- Right to Withdraw Consent at any time, subject to legal or contractual restrictions
- Overseas Transfers: Your data is transferred to and stored in the United States (Google Firebase). Google has implemented contractual safeguards providing protection "comparable" to PIPEDA, as required by Canadian law.
- Contact our Privacy Officer at: dev.shreyjain@gmail.com
11.6. Australia (Privacy Act 1988 β Australian Privacy Principles)
- Right to Access personal information we hold about you
- Right to Correction of inaccurate, out-of-date, incomplete, or misleading information
- Right to Complain to the Office of the Australian Information Commissioner (OAIC) at www.oaic.gov.au
- Overseas Disclosure (APP 8): Your personal data is stored on Google Firebase servers located in the United States. We have taken reasonable steps to ensure Google provides protection comparable to the Australian Privacy Principles via Standard Contractual Clauses and Google's EU-U.S. Data Privacy Framework certification.
- Contact us at: support@saiyamai.com
11.7. Singapore (Personal Data Protection Act 2012 / 2020 Amendment)
- Right to Access personal data we hold and information about how it has been used
- Right to Correction of personal data that is inaccurate or incomplete
- Right to Withdraw Consent at any time (noting that withdrawal may affect our ability to provide certain services)
- Data Protection Officer: Our Data Protection Officer can be contacted at dev.shreyjain@gmail.com
- You may lodge a complaint with the **Personal Data Protection Commission (PDPC)** at www.pdpc.gov.sg
11.8. South Africa (POPIA β Protection of Personal Information Act)
- Right to Access personal information we hold about you
- Right to Correction or Deletion of personal information that is inaccurate, irrelevant, excessive, or out of date
- Right to Object to processing of your personal information
- Right to Complain to the Information Regulator of South Africa at www.justice.gov.za/inforeg/
- Our Information Officer can be contacted at: dev.shreyjain@gmail.com
11.9. All Other Jurisdictions
We comply with applicable local data protection laws. Contact us at support@saiyamai.com to exercise any rights available to you.
Response Time: We will respond to all rights requests within 30 days (or sooner if required by local law).
12. Children's Privacy
Our App is not intended for children under 13 (or under 16 in the EEA, or under 18 in India under DPDPA).
We do not knowingly collect personal data from children below these ages. If you are a parent or guardian and believe your child has used our App, please contact us immediately at support@saiyamai.com. We will promptly delete the child's data.
13. Data Security
We implement the following security measures:
- Encryption in transit (TLS/HTTPS for all API calls and data sync)
- Encryption at rest (AES-256 via Google Firebase)
- Firebase Authentication for secure user identity verification
- Server-side access controls restricting data access to authorized services only
- No local storage of raw data on third-party servers beyond Firebase
Despite these measures, no method of electronic transmission or storage is 100% secure. We cannot guarantee absolute security.
14. Data Breach Notification
In the event of a data breach that poses a risk to your rights and freedoms, we will:
- Notify the relevant supervisory authority within 72 hours (as required by GDPR Article 33).
- Notify affected users without undue delay if the breach is likely to result in a high risk to your rights (GDPR Article 34).
- For users in Singapore: notify the Personal Data Protection Commission (PDPC) within 3 days of assessing that a notifiable data breach has occurred, in accordance with the PDPA 2020 Amendment.
- Comply with breach notification requirements under DPDPA, CCPA, POPIA, and other applicable laws.
15. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. When we make material changes:
- We will update the "Last Updated" date at the top.
- We will notify you via in-app notification or email at least 15 days before material changes take effect.
- Continued use of the App after the effective date constitutes acceptance of the updated policy.
16. Contact Us
For any questions, concerns, or data rights requests:
- Email: support@saiyamai.com
- Data Protection / Grievance Officer: dev.shreyjain@gmail.com
- Data Deletion Web Form: http://saiyamai.com/delete-my-data
- Mailing Address: Katni, Madhya Pradesh, India