Trust & data handling · Last updated 5 September 2026

Trust and Data Handling

We ask businesses to trust us with contracts, employee records and the documents behind their filings. This page says what happens to them: where they are processed, which companies are involved, how long anything is kept, and what we have undertaken never to do. Where a claim depends on another company's conduct, we link their terms instead of summarising them.

Where VidhiSar Runs

The application and its API run on Vercel, pinned to the Mumbai region (bom1). Your account data, your documents and your compliance record are held in a libSQL database hosted by Turso. Requests are served over TLS only — the site sends HSTS with a two-year max-age, so a browser that has seen it once will not fall back to HTTP. Some processing necessarily happens outside India: the models that answer a legal question or read a contract are operated by providers hosted abroad, and so is our transactional email. Section 16 of the DPDP Act permits transfer outside India except to a territory the Central Government restricts by notification, and no such notification has been issued. If one is, we will move or drop the affected processor rather than ask you to accept the transfer.

Sub-Processors

Every company that touches your data on our behalf, what they do with it, and where they do it. This is the complete set VidhiSar can route to — not only those a given deployment has keys for — so there is no provider you could later discover we had not mentioned. Which inference provider serves a particular request depends on configuration. None of them may use your data for their own purposes. Each is used through its commercial API under its own terms, and we link those rather than paraphrase them: read Groq, Google, xAI, Vercel, Turso and Cashfree if the detail matters to your decision. We would rather point you at the source than have you take our summary of someone else's obligations.

  • Vercel — Hosting for the site and the API — Mumbai (bom1) for compute; global edge for static files
  • Turso — The database — accounts, documents, compliance records — Region set per deployment
  • Groq — Model inference; audio transcription of a voice note — United States
  • Google (Gemini API) — Model inference — United States / global
  • xAI (Grok) — Model inference — United States
  • Cashfree Payments — Card and UPI payments, and the mandate for autopay — India
  • Resend / Google (Gmail SMTP) — Transactional email — OTPs, receipts, account mail — United States / global
  • Tavily, Brave Search — Web lookup, only when a question needs a current source — United States
  • Google (Sign-In) — Optional login, only if you choose it — United States / global
  • Google Analytics — Aggregate site analytics on public pages — United States / global

What a Model Sees, and What It Does Not

When you ask a legal question, draft a document or scan a contract, the text involved is sent to a model provider to produce that answer, and the result comes back to you. That is the whole of it: the request is made, the answer is returned, and nothing about it is sent anywhere else.

  • We do not train models on your documents. We have no model of our own to train, and we do not license your content to anyone else to train theirs. No part of your account is a dataset.
  • We do not sell your data, and there is no ad tech in the product. Analytics runs on the public marketing pages, not inside your workspace, and it measures pages rather than people.
  • Your password never reaches a model, and neither does a document password. Account passwords are stored only as bcrypt hashes and are never recoverable. A password you set on a generated PDF is held encrypted and never leaves the server, not even as ciphertext.
  • A support person is not reading your workspace. Access through the admin console is used for an escalation you raised or for account administration, and not for browsing.

Retention and Deletion

Your account data and generated documents are kept while your account is active, because a compliance history that forgets last year's filings is not a compliance history. Delete your account from your profile and your personal data, chat history and documents are removed from our active systems. Billing records are held longer where Indian tax and accounting law requires it — that is the one exception, and it is not discretionary. Deletion is deletion, not deactivation. The full detail, including what a deletion request covers, is in the Privacy Policy.

How It Is Protected

  • In transit: TLS everywhere, with HSTS and upgrade-insecure-requests set at the edge.
  • At rest: encryption by our database and hosting providers, on their infrastructure.
  • Passwords: bcrypt hashes, never stored or transmitted in a recoverable form.
  • In the browser: a Content-Security-Policy that names every origin the page may talk to, plus nosniff, a frame policy and a permissions policy that switches off camera, microphone and geolocation outright.
  • Between accounts: a seat sees only the business it was invited to, with the access its role carries, and you can revoke it at any time.
  • Generated files: served no-store and marked noindex, so a document link cannot end up in a search result.

Exercising Your Rights

Under the DPDP Act you can ask what personal data we hold about you, have it corrected, have it erased, and nominate someone to exercise those rights if you cannot. Most of it you can do yourself from your profile without asking us at all. For anything that needs us, write to Swaraj Layek at infovidhisar@gmail.com. We acknowledge within 24 hours and resolve within 15 days — the same commitment published on the Terms of Service, because a grievance route with two different timelines on two different pages is not a commitment.

If Something Goes Wrong

If personal data in our care is breached, section 8(6) of the DPDP Act requires us to notify the Data Protection Board and every affected Data Principal. We will do that, and we will tell you what happened, what was affected and what we did about it — in the same plain language as the rest of this page, without waiting to have a tidy story first. If you think you have found a security problem, tell us at infovidhisar@gmail.com before telling anyone else, and we will work with you on it.