What they may do · DPDP §6(4)
What mPokket does with your data
Reads your financial SMS, monitors every app installed on your phone, stores KYC audio and photos, keeps your documents for ten years, shares data with credit bureaus and group companies, and takes your device advertising ID.
-
Shares your data with partners
Passed to group companies, advertisers or analytics firms you never chose.
What this costs you. Your number and habits travel to companies you have never heard of and never agreed to. This is the step where the spam calls start.
Show me where they say that
mPokket’s own policy says “Subject to applicable law, we may share any data we have collected or collect from you with our affiliates and group companies for product research and development, advertising relevant products to you, and to tailor the products for your benefit.”
Our summary shares collected data with affiliates and group companies (including for advertising relevant products), with service providers for marketing, fraud detection, cloud services and collections, and discloses credit information to the named credit bureaus TransUnion CIBIL, Equifax, CRIF and Experian, plus the Central KYC Registry.
-
Builds an advertising profile of you
They watch what you view, tap and buy, and use it to decide which ads you see.
What this costs you. Your attention gets priced. What you hesitate over becomes a bid — and a profile built to predict you is a profile built to persuade you.
Show me where they say that
mPokket’s own policy says “We also collect the AAID for advertising and analytics.”
Our summary collects the device advertising ID (AAID) for advertising and analytics, states that retained information is used "to personalize our advertising and marketing communications", and lists "For enabling Marketing and Outreach" as a purpose for account, device and usage data.
-
Follows you onto other websites and apps
Their tracking carries on after you leave, through pixels and SDKs embedded elsewhere.
What this costs you. You get recognised on sites that have nothing to do with them. Closing the app does not close the file.
Show me where they say that
mPokket’s own policy says “We and MVPL collect the data about your installed applications, including the applications and package name, installed and updated time, version name and version code for all applications installed on your device on and from the date you create your mPokket Account and the manner in which you use them.”
Our summary monitors every application installed on the device and how the user uses them (access is mandatory — the policy says the App cannot be used if it is disabled); separately says usage data includes "third-party sites or services used before or in the course of interacting with the Services", and that a third-party SDK collects data on the company's behalf.
-
Keeps your records long-term
Held on after you stop using the service.
What this costs you. Years after you delete the app, the record is still sitting there — and every year it sits there is another year it can leak.
Show me where they say that
mPokket’s own policy says “Your documents and information shall be retained by us for a period of ten years from the data of transaction.”
Our summary retains documents and information for ten years from the transaction, and states that even after an approved user's deletion request the mobile number, email ID, user ID, external user ID and profession remain archived; users with an outstanding loan cannot request deletion until the loan is closed.
-
Processes your face or other biometrics
Face matching, liveness checks or similar.
What this costs you. You can change a leaked password in a minute. You cannot change your face. A biometric breach is permanent in a way nothing else is.
Show me where they say that
mPokket’s own policy says “We require microphone permission to initiate two-way audio communication as a part of KYC journey. This may be stored for future verification purposes.”
Our summary takes microphone access for two-way audio during the KYC journey and says that audio may be stored for future verification purposes; a photograph is also collected as part of account creation and of KYC/loan processing data.
What the policy does not mention
These are uses mPokket’s policy is silent on. Silence is not a promise — it means the document does not say, and we do not infer either way.
- Trains AI models on your content
mPokket is one app. How many are on your phone?
Most people carry twenty to forty. Add yours and see the total in one screen — how many share your data, profile you for ads, or follow you across the web. Then take it back from all of them at once.
Manage my data with Saaph.in →Free to check · no account needed · built in India for the DPDP Act
Questions
What does mPokket do with my personal data?
According to mPokket's own privacy policy, read on 2026-08-14, it discloses 5 of the six uses we track: shares your data with partners, builds an advertising profile of you, follows you onto other websites and apps, keeps your records long-term, processes your face or other biometrics.
Can I withdraw my consent from mPokket?
Section 6(4) of India's Digital Personal Data Protection Act 2023 gives you the right to withdraw consent for processing you agreed to. The Act's substantive provisions commence in stages up to May 2027, so a request made now asks for voluntary compliance and puts the date on record. Processing a company carries out under a legal obligation — such as KYC records the RBI requires — cannot be withdrawn.
Does mPokket track me for advertising?
Yes — mPokket's published policy discloses this. The exact sentence it is based on is quoted on this page, with the date we read it and a link to the source.
Every use above is one mPokket declared in its own published privacy policy, which we
read on 2026-08-14. Quotes are verbatim; the summary beside each one is ours
and is labelled as ours. Nothing here is inferred.
Saaph.in is a DPDP consent and request management platform operated by Ronin Works
Private Limited. It is a communication facilitator, not your legal or authorised
representative. The DPDP Act 2023 commences in stages up to May 2027, so a request
made today asks for voluntary compliance and records the date you asked.
Our privacy policy