What they may do · DPDP §6(4)
What UMANG does with your data
A June 2026 DPDP-aligned government policy that rules out selling data and targeted advertising, but shares data with departments, service providers and vendors, and can keep it after you delete your account.
-
Shares your data with partners
Passed to group companies, advertisers or analytics firms you never chose.
What this costs you. Your number and habits travel to companies you have never heard of and never agreed to. This is the step where the spam calls start.
Show me where they say that
UMANG’s own policy says “Personal data may be shared only on a need-to-know and purpose-limited basis with the concerned Government department, agency, local body, on-boarded service provider, technology service provider, payment gateway, cloud or hosting service provider, call-centre/support provider, or other authorised entity necessary for providing the requested service, operating the Platform, ensuring security or complying with law.”
Our summary personal data is shared on a need-to-know, purpose-limited basis with government departments and bodies, on-boarded service providers, technology and cloud/hosting vendors, payment gateways and call-centre/support providers.
-
Keeps your records long-term
Held on after you stop using the service.
What this costs you. Years after you delete the app, the record is still sitting there — and every year it sits there is another year it can leak.
Show me where they say that
UMANG’s own policy says “Upon deletion or de-registration, UMANG shall delete, anonymise or restrict further processing of personal data relating to the account, unless retention is necessary for a lawful purpose, legal compliance, audit, security, fraud prevention, investigation, dispute resolution or any other requirement under applicable law.”
Our summary after account deletion or de-registration, personal data may still be retained where any of a broad list of grounds applies, closing with 'any other requirement under applicable law' — so deletion is not guaranteed to be complete.
-
Processes your face or other biometrics
Face matching, liveness checks or similar.
What this costs you. You can change a leaked password in a minute. You cannot change your face. A biometric breach is permanent in a way nothing else is.
Show me where they say that
UMANG’s own policy says “UMANG shall not store Aadhaar numbers or Aadhaar biometric information unless specifically authorised or required under applicable law or by the concerned service.”
Our summary states it will not store Aadhaar numbers or Aadhaar biometric information, but carves out cases where storage is specifically authorised or required by law or by the service being used — so biometric data may be held in those cases.
What the policy does not mention
These are uses UMANG’s policy is silent on. Silence is not a promise — it means the document does not say, and we do not infer either way.
- Builds an advertising profile of you
- Follows you onto other websites and apps
- Trains AI models on your content
UMANG is one app. How many are on your phone?
Most people carry twenty to forty. Add yours and see the total in one screen — how many share your data, profile you for ads, or follow you across the web. Then take it back from all of them at once.
Manage my data with Saaph.in →Free to check · no account needed · built in India for the DPDP Act
Questions
What does UMANG do with my personal data?
According to UMANG's own privacy policy, read on 2026-08-14, it discloses 3 of the six uses we track: shares your data with partners, keeps your records long-term, processes your face or other biometrics.
Can I withdraw my consent from UMANG?
Section 6(4) of India's Digital Personal Data Protection Act 2023 gives you the right to withdraw consent for processing you agreed to. The Act's substantive provisions commence in stages up to May 2027, so a request made now asks for voluntary compliance and puts the date on record. Processing a company carries out under a legal obligation — such as KYC records the RBI requires — cannot be withdrawn.
Every use above is one UMANG declared in its own published privacy policy, which we
read on 2026-08-14. Quotes are verbatim; the summary beside each one is ours
and is labelled as ours. Nothing here is inferred.
Saaph.in is a DPDP consent and request management platform operated by Ronin Works
Private Limited. It is a communication facilitator, not your legal or authorised
representative. The DPDP Act 2023 commences in stages up to May 2027, so a request
made today asks for voluntary compliance and records the date you asked.
Our privacy policy