Privacy policy

PRANASARA ELEMENTS PVT. LTD.

Privacy Policy

PRĀṆA U1 & PRĀṆA Store

Effective Date: 1 June 2026 · Last Updated: 15 July 2026

1. Introduction

Pranasara Elements Pvt. Ltd. ("we", "our", "us"), registered at D Tower, 1st Floor, 64, Sahyog Vihar, Bawadiya Kalan, Bhopal, MP 462026, India, operates the PRĀṆA U1 mobile and web application ("App") and the PRĀṆA Store, our online shop for physical wellness products such as RISHI ENERGY™ (together, the "Services"). This Privacy Policy applies to both the App and the Store and explains how we collect, use, store and protect your personal data across our Services.

By using PRĀṆA U1 or the PRĀṆA Store, you consent to the practices described in this Policy. If you do not agree, please do not use the Services.

2. Data We Collect

2.1 Information You Provide

Account information: Name, email address or mobile number used to create your account.
Prakriti quiz responses: Your answers to the 21-question constitutional assessment.
Daily check-in data: Human state logs, food quality entries, fluid intake logs, digital toxicity logs.
Breath session data: Protocol used, session duration, Dhyāna Depth Index ratings.
Activity logs: Movement type, intensity, duration.
Rishi AI conversations: Your queries and our AI responses, stored in your secure account so your guidance and per-sage memory persist across sessions and devices.

2.2 Automatically Collected Data

Device information: Device type, operating system, app version, and a device identifier used only to administer your one-time free trial.
Usage data: Features accessed, session duration, crash and error logs (scrubbed of direct identifiers).
On-device cache: A working copy of your data is kept on your device (localStorage) for offline use and speed; it is synced to your secure account in our backend so it survives sign-out, reinstalls and new devices (see Section 4).

2.3 Wearable / Biosignal Data (Optional)

If you connect a wearable device (Apple Watch, Oura Ring, WHOOP, Garmin, Fitbit), we access only the data you authorise through the relevant third-party API. This data is used solely to enhance your Dosha detection and PSI accuracy and is not shared with any third party.

On Android, with your explicit consent, PRĀṆA U1 connects to Google Health Connect and reads only the following data types: heart rate, heart rate variability, resting heart rate, oxygen saturation (SpO₂), respiratory rate, steps, sleep, and mindfulness sessions. These are used only to display your biosignal insights and personalise your meditation and breathwork recommendations within the app. With your consent, the app also writes the meditation and breathwork sessions you complete in PRĀṆA U1 back to Health Connect as mindfulness records, so your practice is reflected in your other connected health apps. Health Connect data is processed only to provide these in-app features, is never sold, and is never shared with third parties or used for advertising. You can revoke this access at any time in Health Connect settings.

2.4 Store Purchase Data (PRĀṆA Store)

If you buy a physical product from the PRĀṆA Store, we collect the information needed to fulfil your order:
Order details: products purchased, quantity, price and order history.
Shipping & billing address: recipient name, postal address, pincode, and contact phone/email for delivery.
Payment confirmation: a signature-verified payment reference from Razorpay. We never receive or store your card, UPI or bank details.
This information is used only to process, ship, invoice and support your order, and to meet tax and consumer-law obligations. See our separate Store Terms of Sale, Shipping & Delivery, Refund & Returns and Cancellation policies for the commerce terms.

3. How We Use Your Data

• To personalise your daily wellness protocol (CSP, Library recommendations, Rishi AI responses).
• To calculate your PSI score and Tattva element balance.
• To operate the Prāṇa Field network (anonymised participation counts only — no personal data is shared).
• To process your Seeker tier subscription payments (via authorised payment gateways).
• To process and deliver PRĀṆA Store orders and provide order support.
• To improve the App through anonymised, aggregated analytics.
• To communicate service updates, if you have opted in.

4. Data Storage & Security

Your account and wellness data — sign-in identifier, Prakriti results, state/breath/food/activity logs and the scores derived from them, subscription status, and Rishi AI conversations — are stored in our secure cloud backend (hosted on Supabase, PostgreSQL). A working copy is also cached on your device for offline use and speed.

Per-user isolation: Every data table enforces row-level security, so you can only ever read or write your own records. Privileged server keys that can access broader data are held only on our servers, never shipped inside the App, and are used solely to process your own requests (e.g. verifying a payment or computing your scores).

Encryption & auth: Data is encrypted in transit (HTTPS/TLS) and at rest. We do not store passwords — authentication uses one-time verification (OTP) or a trusted sign-in provider (Google / Apple).

We apply industry-standard security measures including secure API endpoints, secret scanning and regular security reviews. No system is ever 100% secure, so we cannot guarantee absolute security, but we work continuously to protect your data.

5. Data Sharing

We do not sell, rent or trade your personal data to any third party, ever.

We share data only with the service providers ("sub-processors") needed to run the Services, each bound to protect it and use it solely on our instructions:
Supabase — secure database, authentication and hosting of your account data.
Razorpay — subscription and Store payment processing. We never receive or store your card details.
• AI inference partners (Groq, Anthropic, OpenAI, Google, xAI) — process conversation text to generate Rishi guidance. Each is contractually barred from training on your data and provides your data the same or equivalent protection we do. We send only the minimum context needed to generate a response — your conversation text and, when relevant, your Prakriti profile and check-in summaries — and do not include your identity beyond what the conversation requires. We ask for your explicit in-app permission before your first RISHI conversation is shared with an AI partner, and you can withdraw that permission at any time in the app under Profile → Account → AI Data Sharing.
Google / Apple — only if you choose "Continue with Google/Apple" sign-in, to verify your identity.
Apple Health / Google Health Connect / wearable APIs — only if you connect a device, to read the biosignals you authorise.
Shiprocket / logistics partners — only for PRĀṆA Store orders, to ship your product and provide delivery tracking. They receive only your shipping address and order reference.

We may also disclose data:
Legal obligations: if required by law, court order or a competent authority.
Business transfer: in a merger or acquisition, your data remains protected under equivalent terms and you will be notified.

6. Sensitive Health Data

PRĀṆA U1 collects wellness-related data that may be considered sensitive health information under applicable Indian law (DPDP Act 2023). We treat all such data with the highest level of protection. We do not use this data for advertising, profiling or any purpose beyond delivering your personalised wellness protocol.

PRĀṆA U1 is a wellness guidance platform, not a medical device or clinical service. Our recommendations are for general wellness purposes only and do not constitute medical advice, diagnosis or treatment.

7. Your Rights

Under the Digital Personal Data Protection Act (DPDP) 2023 and applicable Indian law, you have the right to:
Access the personal data we hold about you.
Correct inaccurate personal data.
Erase your account and associated data at any time.
Data portability — request an export of your data in a portable format.
Withdraw consent at any time without affecting prior lawful processing.

To exercise any of these rights, email us at: namaste@pranaelements.com. We will respond within 30 days. You may also delete your account and its data at any time from the App.

8. Data Retention & International Transfers

Retention: We keep your account and wellness data for as long as your account is active. When you delete your account, we delete your personal records from our live systems promptly (and from routine backups within 30 days), except where we must retain limited records to meet legal, tax or fraud-prevention obligations. Operational logs are kept only briefly and are scrubbed of direct identifiers.

International transfers: PRĀṆA U1 is offered globally. Your data may be processed on servers operated by our sub-processors (Section 5) located outside your country, including in India, the European Union and the United States. Where data is transferred across borders, we rely on appropriate safeguards such as the provider's Standard Contractual Clauses and equivalent measures to protect it to the standard described in this Policy.

9. Your Rights Under GDPR (EU/UK) & CCPA/CPRA (California)

If you are in the EU, EEA or UK (GDPR): Our legal bases for processing are your consent (which you may withdraw anytime), performance of our contract with you (to provide the App and your subscription), and our legitimate interests (to secure, maintain and improve the service). You have the rights to access, rectify, erase, restrict and port your data, to object to processing, and to lodge a complaint with your local data protection supervisory authority.

If you are in California (CCPA/CPRA): You have the right to know what personal information we collect and why, to request access and deletion, to correct inaccurate information, and to opt out of the "sale" or "sharing" of personal information. We do not sell or share your personal information and we do not use your wellness data for cross-context behavioural advertising. We will not discriminate against you for exercising any of these rights.

To exercise any of these rights, contact namaste@pranaelements.com. We honour requests regardless of where you live.

10. Cookies & Tracking

We use minimal, essential cookies only — for session management and security. We do not use advertising cookies, third-party tracking pixels or cross-site trackers. You may clear cookies at any time through your browser settings, though this may require you to log in again.

11. Children's Privacy

PRĀṆA U1 is intended for users aged 16 and above. We do not knowingly collect data from children under 16. If you believe a child has created an account, please contact us immediately at namaste@pranaelements.com.

12. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be notified via in-app notification at least 14 days before taking effect. Continued use of the Services after the effective date constitutes acceptance of the updated Policy.

13. Grievance Officer & Contact

In accordance with India's DPDP Act 2023 and IT Rules, our Grievance Officer can be reached for any privacy concern or to exercise your rights:

Grievance / Data Protection Officer
Pranasara Elements Pvt. Ltd.
D Tower, 1st Floor, 64, Sahyog Vihar, Bawadiya Kalan
Bhopal, MP 462026, India
Email: namaste@pranaelements.com
Phone: +91-8225968850

© 2026 Pranasara Elements Pvt. Ltd. · All rights reserved.