Privacy policy
Last updated: DD Month 2026
We collect only what we need to design your AI project, run your courses and take payment. We don’t sell your data, we don’t show you ads, and nothing you tell us is used to train AI models.
1. Who we are
AI Blueprint (“we”, “us”) is run by Your full name, an individual (sole proprietor) based in City, State, India. For your personal data we are the Data Fiduciary under India’s Digital Personal Data Protection Act, 2023 (DPDP Act), and follow the Information Technology Act, 2000 and its Reasonable Security Practices Rules, 2011, which apply to sole proprietors as well as companies.
This policy covers our website and app at yourdomain.in.
2. What we collect
| Data | Where it comes from |
|---|---|
| Name, email address, profile photo | Your Google or LinkedIn sign-in, or the email you enter for a sign-in code. We never receive your Google or LinkedIn password. |
| About your work | The form: your industry, what your system does, years of experience, AI experience, how much time you have to learn, where you want to use AI (optional), and a job description if you choose to add one. |
| Your system description and conversation | What you type in the form and in the discovery conversation, plus anything you add under “Anything we should consider”. |
| Your blueprint and progress | Designs and plans we generate for you, courses you open, questions you reveal, and where you stopped. |
| Purchase records | Order amount, date, product and the payment provider’s reference, and when you accepted the refund terms at checkout. We never see or store your card, UPI PIN or bank details — the payment provider collects those directly. |
| Mobile number (at checkout) | Passed to our payment provider, which requires it for every payment and uses it for payment updates. We do not keep it on your account or use it for marketing. |
| Technical data | IP address, browser type, and security and error logs. |
We don’t ask for, and you shouldn’t give us, sensitive data such as Aadhaar or PAN numbers, health or financial information, passwords or customer data.
3. Why we use it
We process your personal data with your consent, which you give when you start the form or sign in, and for the legitimate uses the DPDP Act allows (for example, keeping records the law requires). We use it to:
- understand your work and design AI project ideas and a blueprint that fit it;
- create your account, sign you in, and keep your blueprint and course progress;
- take payment, issue receipts and keep tax and accounting records;
- send emails you need: sign-in codes, “your blueprint is ready”, receipts. Study reminders and offers only if you leave them switched on — you can turn them off in Account → Emails;
- keep the service secure, stop abuse and fix errors;
- answer your questions and complaints.
We do not sell your data, share it for advertising, or build profiles for anyone else.
4. How AI is used
Your project ideas, designs, study plan and practice material are generated by AI models (Claude, from Anthropic) using what you told us. To do this we send your answers and conversation to the model provider.
- Under the provider’s commercial terms, what we send is not used to train their models, and they delete it within 30 days unless it is needed to investigate misuse.
- We do not train or fine-tune any model on your data.
- Before your text reaches the model we check it for things like keys, passwords and card numbers, and ask you to remove them.
5. Who we share it with
We share only what each provider needs to do its job for us. Each one processes your data on our instructions, under a contract.
| Provider | What for |
|---|---|
| Amazon Web Services | Hosting, database, file storage, sign-in (Cognito) and email delivery (SES) |
| Anthropic | The AI models that generate your blueprint |
| Cashfree Payments India Pvt. Ltd. | Taking payment. They are also responsible for your payment data under their own policy |
| Google, LinkedIn | Only if you choose to sign in with them. They tell us your name, email and photo |
We may also disclose data when Indian law requires it — for example, to a court, tax authority or law enforcement with a valid legal request.
6. Data stored outside India
We host your data with AWS in Mumbai (ap-south-1) where we can. The AI model provider processes requests in the United States, and sign-in providers may process data in other countries. The DPDP Act allows this unless the Government of India restricts transfers to a country; we will follow any such restriction.
7. How long we keep it
| Data | Kept for |
|---|---|
| An unfinished form or conversation you never paid for | 90 days after you last used it, then deleted |
| Your account, blueprint and course progress | Until you delete your account (you have lifetime access until then) |
| Purchase records | As long as tax and accounting law requires (currently up to 8 years). We keep only amount, date, product and payment reference — none of your project details |
| Security and access logs | 30 days |
8. Your rights
Under the DPDP Act you can:
- Access — get a summary of the personal data we hold and what we do with it;
- Correct or update it;
- Erase it — delete your account from Account → Delete account. We finish deleting within 7 days and email you when it’s done. Purchase records we must keep by law are kept in the minimal form above;
- Withdraw consent at any time, as easily as you gave it. We then stop using your data and delete it, except what the law requires us to keep. Withdrawing doesn’t affect what we did before, and without your data we can’t provide the blueprint;
- Nominate someone to use these rights for you if you die or can’t act yourself;
- Complain to our grievance officer (section 14), and if you are not satisfied, to the Data Protection Board of India.
Email privacy@yourdomain.in from the address on your account. We reply as soon as we can and within 30 days at most.
9. Security and breaches
We encrypt data in transit (HTTPS) and at rest, limit who can access it, check your identity on every request, and keep your data separate from other users’. If a breach affects your personal data we will tell you without delay — what happened, the likely impact, what we are doing and what you can do — and report it to the Data Protection Board as the law requires.
10. Your employer’s information
Describe your system in general terms. Don’t paste internal documents, customer data, credentials, or anything your employer treats as confidential — we don’t need it, and your blueprint is better for being general. You are responsible for having the right to share what you type.
11. Age
This service is for people aged 18 and over. We don’t knowingly collect data from anyone younger. If you believe a child has used it, tell us and we’ll delete their data.
12. Cookies and storage
We use only what the app needs to work: keeping you signed in and remembering where you stopped. We use no advertising or tracking cookies. If you add analytics later, name it here and ask for consent.
13. Changes to this policy
If we change what we collect or why, we’ll update this page and the date at the top, and tell you by email or in the app before the change applies. Where the law needs your fresh consent, we’ll ask for it.
14. Grievance officer and contact
We acknowledge complaints within 48 hours and resolve them within 30 days.
See also: Terms of use · Disclaimer · Home