Privacy Policy

What data we hold, why we hold it, and how to get it deleted.

event Last updated 27 July 2026 public Governed by the laws of India

Who this is

The operator behind SparrowAI

Operated by
Abhinav Kumar Shukla
an individual (sole proprietor) operating under the trade names SparrowAI and LeftNote
Service
SparrowAI
sparrowai.leftnote.com
Address
Shri Shukla Niwas, Anchal Road, Pahar Toli, Hehal, Ranchi, Jharkhand, 834005, India
Contact
dev.leftnote@gmail.com

In this document, "we", "us" and "SparrowAI" mean Abhinav Kumar Shukla. "You" means the person or organisation holding a SparrowAI account. "Your visitors" means the people who use the chat widget on your website — they are your users, not ours.

1. What this covers

This policy explains what personal data SparrowAI collects, why, who else sees it, and how you get it removed. It covers three different groups of people, and it matters which one you are:

  • Customers — people with a SparrowAI account.
  • Website visitors — people who chat with a widget on a customer's website.
  • Site visitors — people simply browsing sparrowai.leftnote.com.

We follow the Information Technology Act, 2000 and its rules, and India's Digital Personal Data Protection Act, 2023.

2. Who is responsible for what

For your account and billing data, we decide how the data is used — we are the Data Fiduciary and you can exercise your rights against us directly.

For conversations on your website's widget, the position is different. Those messages come from your visitors, on your site, in response to your content. You are the Data Fiduciary for them; we process that data on your instructions. That means:

  • You must tell your own visitors that a chatbot is in use and that their messages are stored and processed by an AI service.
  • You must have your own privacy notice covering that.
  • If one of your visitors asks you to delete their chat, ask us and we will delete it.

3. What we collect

From customers, when you sign up

  • Your name, username and email address.
  • If you sign in with Google: the basic profile Google returns — your name, email address and profile picture. We never receive your Google password.

From customers, when you register a website

  • The website's name and domain.
  • A verification token and a secret API key we generate for it.
  • Once verified, the text of the publicly accessible pages of that domain, which we read automatically to build the chatbot's knowledge base.
  • Any PDF documents you upload, and their filenames.

Anything you put in a public web page or an uploaded PDF becomes knowledge the chatbot can repeat to a visitor who asks the right question. Do not upload documents containing other people's personal data, passwords, or anything confidential.

From conversations on your widget

  • The visitor's message and the chatbot's reply.
  • How many tokens the exchange used, which AI model answered, and when.

We do not store any identifier for your visitors. No IP address, no name, no email, no cookie, no device fingerprint is saved against a conversation. A short-lived session reference is used to keep one conversation coherent while it is happening; it is not stored with the chat record afterwards.

But visitors can type anything into a chat box — including their phone number, order number or medical question — and whatever they type is stored as part of the message and sent to our AI provider. This is the single most important reason you need your own privacy notice.

When you pay

  • The amount, the currency, whether it succeeded, and the reference IDs Razorpay gives us.
  • We never see or store your card number, CVV, UPI PIN or bank credentials. Those go directly to Razorpay, which is PCI-DSS compliant. We only receive the outcome.

When you contact us

  • The message you send through the contact form, the category you pick, and the reply address if you give a different one.
  • Whether we have replied, and any internal notes we make while handling it.

When anyone browses sparrowai.leftnote.com

  • Our analytics run on our own servers, not a third party's. They count page views and where visitors arrived from, set no cookies, and do not store IP addresses or build a profile of you.
  • If you arrive via a referral link containing a ref code, we log that code with your IP address, browser user-agent and the time, so we can credit the referrer. This is the one place we record an IP address deliberately.
  • Our hosting provider keeps standard server logs, which include IP addresses, for security and debugging.
  • See our Cookie Policy for the four cookies involved.

4. Why we hold it

  • To run your account — signing you in, showing your dashboard, keeping your websites separate from everyone else's.
  • To answer your visitors — a chatbot cannot work without reading your content and processing the question.
  • To meter usage and bill correctly — token counts are how a plan limit is enforced.
  • To show you your own analytics — chat history and usage charts are a feature you are paying for.
  • To support you — answering your contact queries.
  • To meet legal obligations — tax and accounting records, and responding to lawful requests.
  • To keep the service secure — detecting abuse and investigating incidents.

We do not sell your data. We do not sell your visitors' conversations. We do not use your content or your visitors' messages to train our own AI models, and we do not share it with other customers.

5. Who else sees it

Only the providers we need to run the service:

  • Our AI model providers. Questions, the relevant parts of your knowledge base, and your uploaded documents are sent to them to generate replies. Some of these providers operate outside India, so this data may be processed abroad.
  • Razorpay, for taking payments.
  • Google, if you choose to sign in with Google.
  • Our hosting provider, which stores the database and the files you upload.
  • Government or law enforcement, where we are legally required to disclose.

If we ever transfer the business — for example into a company incorporated to operate SparrowAI — your data moves with it under the same commitments, and we will tell you.

6. How we protect it

  • All traffic to the dashboard and the widget runs over HTTPS.
  • Passwords are stored as salted hashes; we cannot read them. Signing in with Google means we hold no password for you at all.
  • The widget carries no secret. It receives a token that expires in ten minutes and is only valid from your registered domain, so a copied token is useless elsewhere.
  • Every dashboard query is scoped to the signed-in account — one customer's data is not reachable from another's session.
  • Card details never touch our servers.

No system is perfectly secure. If a breach affects your data we will tell you and the relevant authority as the law requires.

7. How long we keep it

  • Account data — while your account exists.
  • Chat history and usage records — while the website is registered, because they are a feature you use. Deleting a website deletes its chat history.
  • Uploaded documents — until you delete them. Deleting a document also removes it from the AI provider's index.
  • Contact queries — kept as a record of support we have given, until you ask us to remove them.
  • After you ask us to close your account — we delete your personal data within 30 days, except what we must keep by law.
  • Payment and tax records — kept as long as Indian tax and accounting law requires, which can be several years, even after your account is closed. We cannot delete these on request.

8. Your rights

You can ask us to:

  • Show you the personal data we hold about you and who we have shared it with.
  • Correct anything inaccurate or incomplete.
  • Delete your data — subject to the legal-retention exception above.
  • Withdraw consent where we relied on it. Withdrawing consent for processing that the service depends on effectively means closing your account.
  • Nominate someone to exercise these rights on your behalf if you die or become incapacitated, as the DPDP Act allows.
  • Complain to our Grievance Officer, and after that to the Data Protection Board of India.

Much of this you can do yourself: delete a document, delete a website (which deletes its chats), or edit your details in the dashboard. For anything else write to dev.leftnote@gmail.com. We respond within 30 days and may ask you to confirm your identity first — we are not going to hand your data to whoever emails us.

9. Children

SparrowAI is not intended for anyone under 18 and we do not knowingly collect a child's personal data. If a child's data has reached us through a chat on your website, tell us and we will delete it.

Grievance redressal

If anything in this policy has not been honoured, or you are unhappy with how your data or your payment has been handled, write to our Grievance Officer. We acknowledge every complaint within 2 working days and aim to resolve it within 30 days.

Grievance Officer

Abhinav Kumar Shukla

dev.leftnote@gmail.com

Shri Shukla Niwas, Anchal Road, Pahar Toli, Hehal, Ranchi, Jharkhand, 834005, India

mail Raise it through your account

Changes to this policy

We may update this page as the service changes or the law does. The "last updated" date at the top always reflects the current version. If a change materially reduces your rights we will email the address on your account before it takes effect. Continuing to use SparrowAI after a change means you accept the updated terms.