🔒 SECURITY & DATA RESIDENCY

Your data stays in India.
Encrypted. Never sold.

Saaph is a privacy product, so we hold our own infrastructure to a higher bar than most. Here's exactly where your data lives, how it's protected, and what we will never do with it.

🇮🇳 Hosted in Mumbai, India 🔐 AES-256 at rest · TLS in transit ⚖️ DPDP Act 2023 aligned
🛡️
The short version

Your data is stored in India, encrypted at rest and in transit, used only to run your scan and send removals you approve, and never sold, shared, or advertised against. Password checks happen in your browser using k-anonymity. You can delete everything anytime.

On this page
  1. Where your data lives (India)
  2. Encryption
  3. Private password checks (k-anonymity)
  4. What we collect & how it's used
  5. What we never do
  6. Your control & deletion
  7. Our infrastructure
01

Where your data lives — in India 🇮🇳

Data residency matters under the DPDP Act 2023, and for trust. Both halves of Saaph run in the Mumbai region of India:

  • Your account & scan data — stored in our database, hosted in Mumbai, India.
  • The scan service — also runs in Mumbai, India.

Your personal data is processed and stored on Indian soil — it doesn't get shipped to a US or EU data centre.

02

Encryption — at rest and in transit

Everything is encrypted, both while stored and while moving:

  • At rest: all stored data is encrypted with AES-256 by default on our cloud infrastructure — nothing is kept in plain text.
  • In transit: every connection between your browser, our scan engine, and the database uses HTTPS / TLS.
  • Authentication is handled by a dedicated, industry-standard authentication provider — we never see or store your Google/phone login credentials.
03

Private password checks — k-anonymity

When you check whether a password has leaked, the password never leaves your device. We hash it inside your browser and send only the first 5 characters of that hash to the breach database — which matches hundreds of possible hashes at once, so no service can tell which one is yours. This technique is called k-anonymity. It's the same method trusted privacy tools use, and it means we never see your password.

04

What we collect & how it's used

We collect only what's needed to find and remove your exposed data:

  • Your footprint — name, emails, phone, city, usernames you choose to add.
  • What it's used for — solely to check breach databases and Indian data brokers for your information, and to send DPDP erasure requests you approve.
  • Removal emails — sent to the company, with you CC'd, so companies reply directly to you.

We don't use your data to train models, build profiles, or target ads.

05

What we never do

  • ❌ Sell, rent, or share your personal data with third parties.
  • ❌ Show you ads or run ad-network / tracking pixels.
  • ❌ Store your data outside India.
  • ❌ Read or store your passwords.
  • ❌ Send a single removal email without your approval.
06

Your control & deletion

Under the DPDP Act 2023 you are the Data Principal and stay in control:

  • Your footprint is kept in your browser and your private Saaph account — you can delete it anytime.
  • You approve every removal email; nothing is sent on your behalf without you.
  • Questions or a deletion request? Email data@saaph.in.
07

Our infrastructure

Saaph runs on enterprise-grade cloud infrastructure pinned to India — the same class of platform that secures countless apps worldwide. Static pages are served over a global CDN; all personal data processing stays in Mumbai.

🆓
Free until December 2026

Scanning and all tools are free through Dec 2026. Run your free scan →