This Privacy Policy explains how Smitten Technologies ("Smitten Technologies", "Company", "we", "our", or "us") collects, uses, processes, stores, discloses, and protects information when you access or use TruSight and any related applications, websites, APIs, software, and services (collectively, the "Service").
By accessing or using the Service, you acknowledge that you have read and understood this Privacy Policy.
1. Who we are
TruSight is operated by:
Smitten Technologies Delhi, India Email: info@smitten.co.in Website: https://smitten.co.in
2. Scope of this policy
This Privacy Policy applies to:
- Mobile applications (TruSight on iOS and Android, including Share Extension, widgets, and screen-capture extensions where offered)
- Websites operated by Smitten Technologies
- APIs and backend services used to provide analysis
- Customer support interactions
- Beta features and future service enhancements
This Policy does not apply to third-party websites, applications, products, or services that may be linked through the Service. Those services have their own privacy practices.
3. Information we collect
3.1 Information you provide
We may collect information that you voluntarily provide, including:
- Name or display name
- Email address
- Phone number (when you sign in with phone verification)
- Login credentials or authentication tokens
- Profile information from supported sign-in providers
- Support requests, feedback, and communications with us
- Text, URLs, images, screenshots, videos, links, documents, transcripts, and other content you submit for analysis
3.2 Content submitted for analysis
When you use the Service, you may submit:
- Text claims
- Screenshots and images
- Video files and supported video links
- URLs and documents
- Photographs, scans, PDFs, and Word files of documents (including government identity documents, passports, invoices, tax papers, certificates, vehicle papers, and similar materials)
- OCR text extracted from images, frames, or document pages (on-device and/or on our servers, depending on the feature)
- Audio and transcripts from videos or user-initiated screen recordings
- Content shared via the iOS Share Extension or similar share flows (for example a URL, image, or video from another app)
- Limited camera or file metadata associated with a photograph you submit for Document Check (used for context; not treated as proof of authenticity by itself)
- Other media signals needed to generate results
This content is processed to provide fact-checking, media analysis, scam-risk signals, document authenticity estimates, identity-document checks, legal-record screening of reported FIR and court proceedings (where configured), writing-originality estimates, and related Service features.
You control what you submit. Do not submit content you do not have the right to analyze, including private, confidential, or illegal material. Government IDs, financial documents, and education credentials are sensitive — submit them only when you have a lawful purpose and the right to process that data.
3.3 Account and authentication information
If you create or use an account, we may collect information through supported authentication methods, including:
- Email and password (Firebase Authentication)
- Google Sign-In (name, email, account identifier, profile image where provided)
- Phone number (for SMS verification via Firebase)
- Microsoft Sign-In (name, email, account identifier where authorized by you)
- Sign in with Apple (where available on your platform)
We receive only the information made available by the authentication provider and authorized by you.
3.4 Device and technical information
We may collect limited technical information needed to operate and secure the Service, such as:
- Device type and operating system version
- Application version
- Language and locale settings
- IP address and request metadata when you call our APIs
- Push notification / Live Activity device tokens (when you grant notification permission), linked to your account so we can notify you when a check finishes
- Diagnostic or error information included in support requests
The Android app uses Firebase Crashlytics to collect crash reports (stack traces, device model, OS version, and app version) so we can diagnose and fix stability issues. Crashlytics is used for app stability only — not advertising. We do not use dedicated advertising SDKs or Firebase Analytics for marketing. The iOS app does not currently ship Crashlytics. Operational logs may also be generated on our servers when you use the Service.
3.5 Usage information
We may collect information about how the Service is used, including:
- Features used and verification requests submitted
- Session and API activity needed to provide the Service
- Error events related to analysis requests
- Security and abuse-prevention signals
3.6 Customer support information
When you contact us, we may collect:
- Email or other communications you send
- Attachments you voluntarily provide
- Diagnostic details needed to resolve your issue
Support information may be retained for quality assurance, security, legal compliance, and dispute resolution.
3.7 Local backups (device / your cloud account)
On iOS, you may optionally create encrypted history backups stored in your iCloud Drive container. Backups are encrypted on your device before upload. We do not receive your backup passphrase as part of that feature, and we do not operate Apple iCloud.
On Android, optional encrypted backups may use your Google Drive (or a file you export). The same principle applies: the backup lives in your cloud account or file, not as a TruSight-operated personal history cloud.
4. Sherlock and screen capture
TruSight provides optional Sherlock (and related) features that let you submit screenshots, short screen recordings, or other captured content for analysis.
Android: Sherlock may use a floating assist bubble (display over other apps), media projection for user-initiated screen capture, and microphone if you enable audio during recording.
iOS: Sherlock may use Control Center / Broadcast Upload for short user-initiated screen recordings, Action Button or similar flows for screenshots, photo/video library access for media you select, and microphone if you enable audio during recording. The Share Extension lets you send a link or media from another app into TruSight for analysis.
- Capture features activate only after explicit user action and operating-system permission approval.
- We do not continuously monitor your device, silently record your screen, or capture content without your initiation.
You are solely responsible for ensuring that content submitted through Sherlock or Share is lawfully obtained and may legally be analyzed.
5. How we use information
We use information to:
- Provide, operate, and improve the Service
- Generate AI-assisted analysis, scores, summaries, and reports
- Authenticate users and maintain account security
- Prevent fraud, abuse, and misuse
- Provide customer support
- Comply with legal obligations and enforce our Terms of Use
- Deliver push notifications and Live Activities (where available) about analysis progress or completion when you have granted permission
- Operate an anonymized result cache ("Truth Vault") to return faster results when similar content was recently checked, reduce cost, and improve service reliability
- Process short-lived share-ingest / background analysis jobs so Share Extension and similar flows can finish analysis and notify you
5.1 Artificial intelligence processing
Submitted content may be analyzed using artificial intelligence systems, machine learning models, OCR, search technologies, transcription tools, document-analysis tools, writing-detection tools, and automated analytical systems.
Outputs may include Trust Rings, authenticity or confidence indicators, summaries, fact-checking reports, media analysis reports, document authenticity bands, and related explanations.
AI outputs are informational only. They are not factual determinations, legal findings, KYC results, government verification, or professional advice.
5.2 Document and identity processing
If you use Document Check, we may:
- Extract text and identifiers (for example passport number, File Number, Aadhaar, PAN, driving-licence number, voter ID / EPIC, vehicle registration number, GSTIN, or similar fields visible on the document)
- Classify the document type and run format / checksum checks
- Send extracted identifiers and/or document images (or cropped / rasterized pages) to third-party registry or verification APIs where configured, solely to generate your result
- Send extracted text to AI models and, for writing checks, to third-party AI-content-detection providers
- Temporarily store job inputs and results so the app can show progress and return the completed check
We do not use Document Check submissions to sell advertising. Registry “match” or similar outcomes are not official DigiLocker, NAD, university, employer, or government clearance.
5.3 Legal-record screening (FIR and court)
This is a separate purpose from issuer-registry lookups in Section 5.2. It is not the same as issuer-registry verification (for example Surepass-class PAN, Aadhaar, passport, driving-licence, voter, RC, or GSTIN lookups).
If you use Document Check on an identity document (for example Aadhaar, PAN, passport, driving licence, or voter ID) and the feature is configured, we may send the name and address extracted from the document (and father’s name or date of birth only if already extracted) to a third-party legal-record screening API (for example a Deepvue-class FIR and court provider) to look up reported FIR and court proceedings that may relate to that identity.
We do not send Aadhaar, PAN, passport, driving-licence, or voter ID numbers, or document images, to that legal-record provider. If name or address is missing, we do not run the search.
Legal-record results:
- Do not change Document Check authenticity bands or Trust Scores
- Are not proof of guilt, conviction, or that a person is a criminal
- Are not a search of every FIR or court record in India
- Are not a regulated background check, employment screen, KYC result, or law-enforcement finding
Invoices, GSTIN-only papers, and vehicle registration certificates are not sent for this screening.
5.4 URL safety checks
To help detect phishing or malicious links in submitted content, URLs found in your submissions may be checked using Google Web Risk or similar security services. Typically only the URL (not your full message) is sent for this lookup.
6. AI processing and third-party providers
To provide the Service, information may be processed by third-party providers, including categories such as:
- Authentication providers (e.g. Firebase / Google / Apple)
- Artificial intelligence providers (e.g. OpenAI, Google Gemini, Anthropic, xAI, and other configured model providers)
- Search providers (e.g. Tavily, Brave Search, Perplexity)
- Media, transcription, OCR, and video analysis providers (e.g. Supadata, Hive, YouTube API, Google Document AI or similar OCR / document processors, as configured)
- Identity and document registry / verification APIs (e.g. Surepass-class providers for passport, PAN, Aadhaar, driving licence, voter ID, vehicle RC, GSTIN, or similar lookups where configured)
- Legal-record / FIR and court screening APIs (e.g. Deepvue-class providers, where configured for identity Document Check). These receive name and address (and father’s name or date of birth only if already extracted) — not ID numbers or images. This is not the same as issuer-registry lookups
- AI writing-detection providers (e.g. Winston AI or similar, where configured for writing authenticity)
- URL and security services (e.g. Google Web Risk)
- Cloud hosting providers (e.g. Railway or equivalent infrastructure)
- Push delivery (e.g. Apple Push Notification service on iOS)
The specific providers used may change over time as we improve the Service. Providers process data only as needed to perform their role in delivering analysis, authentication, hosting, notifications, security, registry lookups, or legal-record screening.
Where you authenticate through Google, Microsoft, or Apple, information may also be processed under those providers' own privacy policies.
Registry, legal-record, and writing-detection providers may retain data according to their policies. We cannot guarantee deletion from those systems solely because you delete your TruSight account; contact us and we will help where contractually possible.
7. Data retention
We retain information only as long as reasonably necessary to:
- Provide the Service
- Maintain security and prevent abuse
- Comply with legal obligations
- Resolve disputes and enforce agreements
Submitted analysis content: Our intended practice is to process user-submitted content to generate results and not retain full raw submissions on our servers after processing, except as described below for the anonymized result cache, share links, short-lived analysis jobs (including Document Check jobs), security logs, and legal retention.
Document Check jobs: When you run a document or identity check, we may temporarily store the uploaded file or image, extracted text, job metadata, and results (typically on the order of hours, commonly up to about 24 hours) so the app can poll status, deliver a notification, or show the completed check. We do not intend to keep raw ID images longer than needed for that job unless a longer period is required for security, abuse prevention, or law.
Anonymized result cache (Truth Vault): As part of the Service, we may store an anonymized, redacted copy of analysis results (such as verdict, score, summary, and source references) on our servers for up to 30 days. Today this cache is used primarily for claim / fact-check and similar content checks. We use a normalized fingerprint of submitted text, image, or video signals to match similar content (approximately 90% text / 80% image similarity or higher, depending on media type). When matched, we may return a cached result instead of running a full new analysis. Cache entries are not linked to your name, email, phone number, or account ID. We redact obvious sensitive tokens (such as OTP codes and phone numbers) in stored previews where feasible. Truth Vault is enabled for all users while the feature is active on our servers; there is no in-app opt-out. We may disable or change the cache globally for operational, security, or legal reasons. Entries expire automatically after 30 days. If Document Check results are later included in a similar cache, the same anonymization, retention, and non-account-linkage principles apply, and we will update this Policy accordingly.
Share-ingest / background jobs: When you submit content via Share Extension or similar flows, we may temporarily store job metadata and results (typically up to about 24 hours) so the app can poll status, deliver a notification, or show the completed check.
Shared results: If you choose to create a share link, a limited result summary (and related metadata) may be stored on our servers so the link can be opened. Shared content is stored only when you initiate sharing.
Push tokens: Device tokens used for notifications are retained while associated with your account and notification preference, and may be cleared when you sign out, uninstall, or we detect an invalid token.
Local history: Analysis history may be stored on your device under your control. You can delete local history in the app where deletion controls are provided.
Local backups: Encrypted backups in your iCloud or Google Drive remain under your cloud account until you delete them.
Account information: Authentication data is managed through Firebase. You may request account deletion as described in Section 14.
Retention periods may vary depending on the type of information, technical requirements, security needs, and applicable law.
8. Payments and subscriptions
If paid subscriptions or in-app purchases are offered in the future, payment information will be processed by the applicable app store or payment provider. We do not intentionally store complete payment card numbers. Any future billing features will be described in the app and updated in this Policy.
9. How we share information
We may disclose information:
- To service providers that help us operate the Service (hosting, AI, search, authentication, security, push delivery, document OCR, identity/registry verification, legal-record screening, writing detection)
- To legal authorities where required by law or reasonably necessary to protect rights, safety, and security
- In connection with mergers, acquisitions, financing, reorganization, or business transfers
We do not sell personal information.
Anonymized cached analysis results may be used internally to serve other users checking similar content. This is not advertising and does not involve selling personal information.
9.1 Business transfers
If Smitten Technologies is involved in a merger, acquisition, or sale of assets, information may be transferred as part of that transaction, subject to applicable law.
9.2 Legal compliance
We may disclose information where reasonably necessary to comply with law, respond to lawful requests, investigate abuse, prevent fraud, or protect users and the public.
10. International data transfers
Information may be processed, stored, or transferred outside your country of residence, including in jurisdictions with different privacy laws. By using the Service, you acknowledge that cross-border processing may occur depending on the location of our infrastructure and service providers.
11. Your rights
Subject to applicable law, you may have rights to:
- Access your personal information
- Correct inaccurate information
- Request deletion or restriction of processing
- Object to certain processing
- Withdraw consent where processing is consent-based
- Request portability of certain information
To exercise these rights, contact info@smitten.co.in or use our Data Deletion Request page.
We may need to verify your identity before processing requests.
12. GDPR notice
Where applicable, users in the European Economic Area, United Kingdom, or similar jurisdictions may have additional rights under GDPR or comparable laws. We will respond to valid requests in accordance with applicable law.
13. India DPDP Act notice
Where applicable, Smitten Technologies processes digital personal data in accordance with Indian law, including the Digital Personal Data Protection Act, 2023. Users in India may contact us regarding privacy requests or concerns at info@smitten.co.in.
14. Account and data deletion
If you created an account, you may request deletion of your account and associated personal data.
How to request deletion:
- 1. In the app: open Settings → Request account & data deletion (signed-in), which starts a pre-filled email or opens the web form, or
- 2. Email info@smitten.co.in from your registered email address (or include your registered phone number), with subject line "TruSight account deletion request", or
- 3. Visit https://smitten.co.in/data-deletion
We will verify your identity and process verified requests within 30 days, unless a longer period is permitted by law.
What may be deleted: Firebase authentication record, backend profile data associated with your account, push device tokens linked to your account, and user-initiated shared links where applicable.
What may be retained: Information we must keep for legal compliance, security, fraud prevention, dispute resolution, or limited operational logs, as described in this Policy.
Anonymized vault entries keyed by content (not your account) may remain until their 30-day expiry even after account deletion, because they are not linked to your identity.
Deleting your account does not automatically delete analysis history or encrypted backups stored locally on your device or in your iCloud / Google Drive; you can clear local history in app Settings and delete backups from your cloud account.
15. California privacy rights
Where applicable, California residents may have rights under California privacy laws. We do not sell personal information.
16. Children's privacy
The Service is not intended for children under 13. We do not knowingly collect personal information from children under 13. If you believe a child has provided us personal information, contact us and we will take appropriate steps.
17. Security
We implement reasonable technical, organizational, and administrative safeguards designed to protect information, including access controls, authentication, encryption in transit (HTTPS), and security monitoring.
No system is completely secure. We cannot guarantee absolute security.
18. Security incidents
We maintain procedures to identify, assess, and respond to security incidents. If notification is required under applicable law, we will provide notice in accordance with legal requirements.
19. Third-party links
The Service may contain links to third-party websites or services. We are not responsible for their privacy practices.
20. SDKs, local storage, and similar technologies
The Service may use software development kits (SDKs), local storage on your device, App Group / shared containers (on iOS, between the main app and extensions), authentication tokens, and similar technologies to:
- Maintain sign-in sessions
- Store preferences and local analysis history
- Hand off share or capture jobs between the main app and extensions
- Operate core app functionality
- Maintain security
You can manage certain device permissions and local data through your device settings and in-app controls.
21. Notifications and Live Activities
With your permission, the Service may use:
- System notifications when an analysis completes or fails (including after Share Extension or background jobs)
- Live Activities on iOS (where supported) to show analysis progress on the Lock Screen or Dynamic Island
- Foreground-service or capture-related notifications on Android while a user-initiated recording is in progress
You can manage notification permissions in your device settings and related in-app preferences.
22. Changes to this policy
We may update this Privacy Policy from time to time. We will post the updated version at https://smitten.co.in/privacy-policy and update the "Last updated" date. Continued use of the Service after changes become effective constitutes acceptance of the revised Policy.
23. Contact
Smitten Technologies Email: info@smitten.co.in Website: https://smitten.co.in
*End of Privacy Policy*