This Privacy Policy explains what Yaara ("we", "us") collects when you use the Yaara customer app, the Yaara Counsellor app, the website https://meetyaara.com and our related services (together, the "Service"), why we collect it, who we share it with, how long we keep it, and the rights you have. It is written to comply with the Digital Personal Data Protection Act, 2023 ("DPDP Act") and the Information Technology Act, 2000 and rules made under them. By using the Service you consent to this policy.
1. Who we are (the Data Fiduciary)
The Service is provided by Uma Shankar, an individual (sole proprietor) trading as Yaara, Ghaziabad, Uttar Pradesh, India. We decide why and how your personal data is processed, which makes us the Data Fiduciary under the DPDP Act. Contact: support@meetyaara.com.
2. What we collect and why
| Data | Who | Why we need it (purpose) |
|---|---|---|
| Google account name, email address and profile photo | Everyone | To create and sign you into your account. We use Google Sign-In and never see your Google password. |
| Profile details you choose to add (display name, gender, date of birth, languages, bio, topic tags) | Everyone | To show your profile, confirm you are 18 or older, and match languages. |
| Phone number | Counsellors; customers at first recharge | Identity verification, payout contact and payment-processor requirements. Never shown to other users. |
| KYC documents and identifiers: Aadhaar or PAN number, the document image you upload, name as on the document | Counsellors | Legally required identity verification before you can earn. Stored encrypted; visible only to authorised staff. |
| Bank account number, IFSC, UPI ID, account-holder name | Counsellors | To pay out your earnings. |
| Payment records: coin package bought, amount, Razorpay order and payment IDs, status | Customers | To credit coins and handle refunds and disputes. Card, UPI and bank details are entered on and stored by Razorpay; we never receive them. |
| Call metadata: who called whom, call type (voice/video), start and end time, duration, coins charged, earnings credited, connection quality events | Everyone | Billing, your history, dispute resolution, fraud prevention and safety review. |
| Chat messages and gifts sent or received | Everyone | To deliver the chat and gifts, and to review abuse reports. |
| Ratings, reports you file, blocks you set | Everyone | Safety, moderation and quality. |
| Push notification token (Firebase Cloud Messaging), device type, OS and app version | Everyone | To ring your phone for incoming calls and notify you of messages. |
| Crash and diagnostic logs (Firebase Crashlytics) | Everyone | To find and fix crashes. Contains your account ID, never your name or email. |
| IP address, browser and request logs | Website and app users | Security, rate limiting and abuse prevention. Kept for 90 days. |
| Messages you send through the contact form or by email | Anyone who contacts us | To reply to you. Kept for 12 months. |
We do not record calls. Audio and video travel between the two participants through our real-time communication provider (ZegoCloud) and are not stored by us or by them beyond what is needed to transmit the call.
We do not collect your contacts, location, or anything from your device beyond what is listed above. We do not use your data for advertising and we do not sell it.
3. Consent and legal basis
We process your personal data on the basis of the consent you give when you create an account and accept this policy, and, where the DPDP Act allows, for "legitimate uses" such as complying with Indian law (tax, KYC and record-keeping), responding to a medical emergency, and providing a service you have asked for. You may withdraw consent at any time by deleting your account (section 7); withdrawal does not affect processing done before it, and we may still keep records we are legally required to retain.
4. How we use it
- Provide the Service: connect calls, deliver chats, charge coins per minute, credit counsellor earnings, process payouts.
- Keep the Service safe: verify counsellors, act on abuse reports, prevent fraud and payment abuse, enforce the Community Guidelines.
- Communicate with you: incoming-call and message notifications, service and billing messages, replies to your requests. We do not send marketing messages without a separate opt-in.
- Improve the Service: crash reports and aggregated, non-identifying usage statistics.
- Comply with law: tax, KYC and record-keeping obligations, and lawful requests from authorities.
5. Who we share it with (Data Processors)
We share personal data only with providers who process it on our instructions and under contract:
| Processor | What | Why |
|---|---|---|
| Google LLC | Google Sign-In identity; push tokens (Firebase Cloud Messaging); crash logs (Firebase Crashlytics) | Sign-in, notifications, crash diagnostics |
| Razorpay Software Pvt. Ltd. | Payment amount, order ID, your name, email and phone | Payment processing and refunds |
| ZegoCloud (Zego Technology) | Anonymous room and user IDs; audio/video streams in transit | Real-time voice and video transport |
| Our hosting provider | All data at rest | Running the servers (data centre in the EU; see section 9) |
Other users see your display name, profile photo, languages and, for counsellors, bio, topics, rating and availability. Customers see the counsellor's per-minute rate; counsellors see the customer's display name during a call or chat. Your email, phone number, KYC documents and payment details are never shown to other users.
Authorities: we disclose data when required by Indian law, a court order, or to protect a user's safety.
6. How long we keep it
| Data | Retention |
|---|---|
| Account and profile | While your account is active; removed within 30 days of deletion. |
| Financial records (coin purchases, call charges, earnings, payouts, invoices) | 8 years after the transaction, as required by Indian tax and accounting law, then deleted. Retained in anonymised form after account deletion. |
| KYC documents and identifiers | 5 years after the counsellor relationship ends (Prevention of Money-laundering rules), then deleted. |
| Call metadata | Linked to your account for 12 months; anonymised afterwards (kept only as part of the financial record). |
| Chat messages | While both participants have accounts; removed within 30 days after either deletes their account. |
| Reports and moderation records | 3 years, to detect repeat abuse. |
| Push tokens | Deleted on sign-out or account deletion. |
| Crash and server logs | 90 days. |
| Contact-form messages | 12 months. |
If you have not used your account for 3 years we will notify you and then delete it, in line with the DPDP Act.
7. Deleting your account and your data
You can delete your account at any time from Profile → Delete account in either app. We immediately close the account, sign you out everywhere, and remove your name, email, phone, photo, Google sign-in link and push devices. Records we must keep by law (section 6) are kept in anonymised form. You cannot delete your account while you are on a live call, and counsellors must first withdraw or receive any pending payout.
If you no longer have the app, email support@meetyaara.com from the address on your account with the subject "Delete my account". We will verify it is you and complete the deletion within 7 days. Full instructions: Delete your account.
8. Your rights under the DPDP Act
- Access: ask what personal data we hold about you and how it is processed.
- Correction and updating: fix your profile in the app or ask us to correct anything else.
- Erasure: delete your account, or ask us to erase data we no longer need.
- Withdraw consent: at any time, as easily as you gave it, by deleting your account.
- Grievance redressal: raise a complaint with our Grievance Officer (section 12) and, if unresolved, with the Data Protection Board of India.
- Nominate: name a person who may exercise these rights for you if you are unable to.
Send requests to support@meetyaara.com. We respond within 30 days and never charge for a request.
9. Security and where your data is stored
Data is encrypted in transit (TLS 1.2+) and KYC identifiers, bank details and secrets are encrypted at rest. Administrative access needs a staff role, a second authentication factor and is logged. Our servers are hosted in a data centre in the European Union; payment processing (Razorpay) takes place in India. Where personal data leaves India it is protected by contract and by the same safeguards described here. No system is perfectly secure; if we learn of a breach affecting you we will notify you and the Data Protection Board as required by law.
10. Age limit
The Service is for adults only (18+). We do not knowingly collect data from anyone under 18. If you believe a minor has an account, contact us and we will remove it.
11. Permissions the apps ask for
- Microphone / Camera: only during a voice or video call you start or accept.
- Notifications: incoming calls and new messages.
- Full-screen notifications (Counsellor app, Android 14+): to ring like a phone call when the screen is off.
- Photos (Counsellor app): only when you choose a profile picture or upload a KYC document.
12. Grievance Officer
In accordance with the Information Technology Act, 2000, the IT (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021 and the DPDP Act, 2023:
Uma Shankar
support@meetyaara.com
Ghaziabad, Uttar Pradesh, India
We acknowledge complaints within 48 hours and resolve them within 30 days. See our Grievance Redressal page.
13. Changes to this policy
We will post changes here and update the effective date. Material changes will also be announced in the app before they take effect.