Privacy Policy
Last updated 13 September 2026
Samudaya helps residential communities plan events together — the people, activities, checklists, funds and a public ledger of what was spent. Doing that means handling some personal data about you and your neighbours. This policy explains what we collect, why, who can see it, and the choices you have.
It applies to the Samudaya website, the Android and iOS apps, the WhatsApp bot and the Samudaya API. It is written with India’s Digital Personal Data Protection Act, 2023 (the DPDP Act) in mind. Using Samudaya is also subject to our Terms & Conditions.
Who we are
Samudaya is operated by Gnanalytica (“we”, “us”). For the personal data needed to run your account and the service, we are the Data Fiduciary under the DPDP Act.
Each community on Samudaya is run by its own admins — usually the society’s committee. They decide which events, funds, notices and records their community keeps, and who may join. We store and process that community information so the service can work for them.
Data we collect
When you sign in. You can sign in with Google or with a one-time link sent to your email address. With Google, we receive only your name, email address and profile photo — we do not ask for access to your Gmail, contacts, calendar or files. With an email link, we receive your email address.
Your profile. Your name, email address, phone number (if you add one), profile photo and preferred language.
Your community membership. The communities you ask to join or belong to, your role (for example resident or admin), the flat or unit you live in and who else is recorded as living there, your join requests and their approval, and invite codes you create, redeem or try.
What you do in your community. Announcements you post or read, votes you cast in polls, event tasks assigned to you, activities you sign up to perform in, volunteer roles you take on, and activity ideas you suggest or show interest in. When you sign up for an activity, organisers may ask for details such as the type of performance, age group, experience and any special requirements — share only what they need.
Money records. Contributions to an event fund — the amount, the payment method you used (such as UPI), a payment reference and a receipt number — and expenses filed by admins, with the vendor, amount, who requested and approved it, and a reference to the bill. Samudaya records payments; it does not currently process card, UPI or bank payments itself, and we never receive your card number, UPI PIN or bank login.
WhatsApp. If you use the Samudaya WhatsApp bot, we store your WhatsApp phone number, the link between that number and your account, and the messages you send to and receive from the bot, including their delivery status.
Mobile app. If you allow notifications, we store a push-notification token for your device, the platform (Android or iOS) and the app version, and the in-app notifications we create for you.
Activity records. An audit trail of significant actions — for example who approved an expense or changed a fund — with the time and whether it came from the web, mobile, WhatsApp or the API. Our hosting and database providers also keep routine technical logs, such as IP addresses and request times, to operate and secure the service.
How we use it
We use personal data only to provide Samudaya, specifically to:
- sign you in and keep your session secure;
- let you join a community and let its admins approve members;
- run events: tasks, activities, volunteer roles, polls, announcements and funds;
- keep an accurate, auditable record of contributions and spending;
- answer you over WhatsApp and send notifications you have allowed;
- prevent abuse, investigate problems and keep the service secure; and
- meet our legal obligations.
We process this data on the basis of your consent, which you give by signing up and choosing to use these features, and for legitimate uses the DPDP Act allows, such as complying with law. We do not sell personal data, show advertising, or use your data to build advertising profiles.
Who in your community sees what
Samudaya is built so that a community can be transparent about money without exposing individuals more than necessary. Access rules are enforced in the database itself, not just in the app.
- Nothing is shared between communities. Members of one society cannot see another’s data.
- Members of your community can see event details, announcements, a fund’s total and its number of contributors, and approved expenses with the vendor and bill.
- The amount you contributed is visible to you and your community’s admins, not to other residents.
- Your ballot in a poll is readable only by you; others see the results.
- Admins can see member details, join requests, all contributions and expenses under review, and the audit trail for their community.
API keys and AI assistants
A community’s admins can create API keys that let other software — including an AI assistant connected through our MCP server — read or act on that community’s data. Each key is limited to the permissions the admin grants, acts as a named member of the community, and every action it takes is recorded in the audit trail.
Samudaya does not itself send your data to AI providers. If an admin connects an AI assistant, the data it retrieves is handled by that assistant’s provider under its own terms, and the admin is responsible for that choice. Admins can revoke a key at any time.
How long we keep data
We keep your account data for as long as you have an account. You can ask us to delete your account by writing to sandeep@gnanalytica.com. When we delete it:
- your profile, community memberships, flat assignments, join requests, votes, sign-ups, WhatsApp link, notification tokens and notifications are deleted;
- contributions, expenses and audit entries you were part of are kept but no longer linked to your account, because a community’s ledger has to keep adding up. A contribution can remain associated with the flat it was made for;
- messages exchanged with the WhatsApp bot are kept as operational records with your phone number but without the link to your account. We will delete them on request.
If your community is removed from Samudaya, its records are deleted with it. Backups and technical logs kept by our providers are overwritten on their normal cycles. We may keep data longer where the law requires it.
Security
Data travels over encrypted connections (HTTPS/TLS). Access to every table is controlled by row-level security rules in the database, so a member can only read what their role allows, even if the app is bypassed. API keys are stored as hashes, and administrative access to production systems is limited.
No system is perfectly secure. If a personal data breach affects you, we will notify you and the Data Protection Board of India as the DPDP Act requires.
Your rights
Under the DPDP Act you can:
- access a summary of the personal data we hold about you and how we use it;
- correct or update it — much of it you can edit yourself in the app;
- erase it, subject to the ledger records described above;
- withdraw consent at any time, for example by turning off notifications, opting out of WhatsApp by messaging STOP, or deleting your account. Withdrawal does not affect processing that already happened;
- nominate someone to exercise these rights on your behalf if you die or become unable to; and
- raise a grievance with us, and if you are not satisfied with our response, complain to the Data Protection Board of India.
To use any of these rights, email sandeep@gnanalytica.com from the address on your account. We may need to confirm your identity first.
Children
Samudaya is meant for adults. You must be 18 or older to create an account. A child may appear in a community only through their parent or guardian — for example as a participant in an activity the guardian signs them up for. If you believe a child has created an account or that we hold a child’s data without a guardian’s consent, contact us and we will delete it.
Changes to this policy
We will update this policy when the service or the law changes, and change the “Last updated” date above. If a change materially affects how we use your data, we will tell you in the app or by email before it takes effect.
Contact and grievances
Questions, requests and grievances about your personal data go to our grievance contact at Gnanalytica: sandeep@gnanalytica.com. We aim to acknowledge requests promptly and resolve grievances within the time the DPDP Act and its rules require.