We built Nyaya Saathi on a simple principle: a legal AI platform should be the last place your clients’ confidences could ever leak. Here is exactly how we deliver on that promise.
These are not policy statements — they are enforced by how the system is built.
Every AI message you send is processed in real-time and the response is returned to your browser. We do not write your query or the AI’s reply to any database. Your chat history lives only in your browser — not on our infrastructure. A breach of our servers cannot expose your legal conversations, because they are never there.
Case files, client names, matter details, notes, and drafted documents are stored in your browser’s local storage — on your device. We have no access to this data. If you choose cloud backup, it goes directly to your own Google Drive or OneDrive. Our servers never see or hold your clients’ information.
Nyaya Saathi uses Anthropic’s Claude API under commercial terms that explicitly prohibit using API inputs or outputs for model training. We do not use your legal questions, case facts, or documents to improve any AI system — ours or Anthropic’s. This is a contractual guarantee, not just a policy preference.
A transparent look at every data flow when you use Nyaya Saathi.
Every control listed here is live — not planned.
India’s Digital Personal Data Protection law and its 2025 Rules are the governing framework for how we handle your personal data.
How Nyaya Saathi is aligned with the Bar Council of India Rules on client confidentiality.
The BCI Rules require advocates to maintain strict confidentiality of all client communications. Nyaya Saathi is designed as a drafting and research aid, not a repository of client confidences. We have implemented the following to support your compliance:
Under the DPDPA 2023, you have the following rights as a Data Principal. Contact us at any time to exercise them.
Request a copy of the personal data we hold about you on our servers (name, email, plan, usage counts).
Request correction of any inaccurate personal data we hold about you.
Request deletion of your account and all associated data. We comply within 30 days except where law requires retention (e.g., tax records).
Withdraw your consent to data processing at any time. This may affect your ability to use the service.
Nominate another person to exercise your data rights in the event of death or incapacity.
Download a JSON file of everything we hold about you on our servers — directly from the Settings panel in the app.
We use a small number of carefully chosen third-party services. Here is exactly what each one receives.
| Service | Location | What They Receive | Safeguard |
|---|---|---|---|
| Firebase / Google Cloud Authentication & account data |
US / Global | Name, email, plan status, message count | Google SCCs · ISO 27001 · SOC 2 |
| Anthropic Claude API AI query processing |
United States | Your chat message + recent context (processed & discarded, not stored) | Commercial API terms — no training use |
| Razorpay Payment processing |
India | Email, payment amount — card/UPI handled entirely by Razorpay | PCI DSS Level 1 — highest certification |
| Indian Kanoon API Case law retrieval |
India | Search keywords only — no personal or client data | India-based; no cross-border transfer |
| Netlify Hosting & serverless functions |
United States | Server access logs (IP address, user agent — standard web hosting) | SOC 2 Type II certified |
| Resend Transactional email |
European Union | Name, email, receipt data for payment confirmations | GDPR compliant · EU data residency |
| Supabase Intake forms & operational data |
United States | Client intake form submissions (name, phone, matter type — submitted voluntarily by prospective clients to advocates) | SOC 2 Type II · GDPR compliant DPA |
We do not share your data with advertisers, data brokers, or any other parties. We never sell data.
If you have a question about this page, wish to exercise a DPDP right, or have a concern about how your data is handled, contact us directly. We will acknowledge your grievance within 48 hours and resolve it within 30 days.
If not resolved to your satisfaction, you may escalate to the Data Protection Board of India (DPBI), established under the DPDPA 2023.
This page was last reviewed: June 2026 · Full Privacy Policy · Advocate Studio