Privacy Policy
Thank you for using Jinny AI (“we”, “us”, “our”, or the “Assistant”), operated by Flux Labs AI Private Limited, a company incorporated under the Companies Act, 2013, with its registered office at M-202 Pioneer Park, sector 61, Gurgaon, Haryana 122001 (“Company” or “Flux Labs”).
This Privacy Policy explains what personal data we collect, why we collect it, how we use, share, store, and protect it, and the rights and choices available to you. Please read it carefully before using the Assistant.
We comply with the Digital Personal Data Protection Act, 2023 (“DPDP Act”), the Digital Personal Data Protection Rules, 2025 (“DPDP Rules”), the Information Technology Act, 2000, and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, in each case to the extent in force. For the purposes of the DPDP Act, the Company acts as the “Data Fiduciary” in respect of personal data processed through the Assistant, and you, the registered user, are the “Data Principal”.
1. About the Assistant and how it acts on your behalf
Jinny AI is a personal AI voice assistant. It answers incoming calls when you choose not to (or cannot), screens unknown callers, understands the caller’s intent, takes messages, provides summaries, and — where you instruct it — places outbound calls and navigates automated phone systems on your behalf.
The Assistant acts only as your agent. Every action the Assistant takes on a call — answering, asking questions, sharing information you have authorised, taking a message, scheduling a follow-up — is governed by the preferences, instructions, and permissions you configure. The Assistant does not take autonomous actions outside the scope of your configuration.
Accordingly, by using the Assistant you acknowledge that:
- (a) the Assistant will interact with third-party callers on your behalf and may, in doing so, disclose contextual information that you have expressly authorised it to share (for example, that you are unavailable, or delivery instructions you have configured);
- (b) the scope of what the Assistant may say or do is defined entirely by your settings and instructions; and
- (c) you are responsible for the instructions and permissions you configure, and the Company shall not be liable for consequences of disclosures or actions made by the Assistant strictly within the scope of your configuration, except where such consequences arise from our failure to comply with this Privacy Policy or applicable law.
Grounds on which we process your personal data
- Consent (Section 6, DPDP Act): In most cases, we process your personal data on the basis of your free, specific, informed, unconditional, and unambiguous consent, given by clear affirmative action through the consent screens presented in the app before or at the time of collection. You may withdraw consent at any time with the same ease with which it was given (see Section 10).
- Legitimate uses (Section 7, DPDP Act): Where you voluntarily provide personal data to us for a specified purpose and have not indicated that you do not consent to its use — for example, details you share while setting up your account, training the Assistant, giving feedback, or contacting support — we may process that data for that specified purpose.
2. Personal data we collect and the purposes of processing
In accordance with the DPDP Act and DPDP Rules, the table below sets out an itemised description of the personal data we collect and the specific purposes for which each category is processed. We collect no more data than is necessary for the specified purpose.
| Category of personal data | What it includes | Specific purposes of processing |
|---|---|---|
| 1. Account Information | Name, mobile number, email address (optional), gender (optional — used only for voice/pronoun selection), preferred language, device identifiers, operating system | (a) Creating and verifying your account; (b) enabling the Assistant to introduce itself on your behalf; (c) personalising voice, tone, and language; (d) service communications and important notices; (e) enforcing our Terms; (f) fraud prevention and account security |
| 2. Contact Data (permission-based) | Names and phone numbers from your device phonebook, collected in encrypted form as described in Section 8 | (a) Distinguishing known callers from unknown callers so the Assistant handles each according to your preferences; (b) enabling the Assistant to address known callers appropriately. We do not use your contact data for any other purpose. |
| 3. Call Audio and Transcripts | Audio of calls handled by the Assistant (including the caller’s voice and, where you join, your voice); text transcripts of those calls | (a) Conducting the conversation in real time; (b) generating call summaries, messages, and suggested follow-ups for you; (c) letting you review how the Assistant handled a call; (d) improving the accuracy of the Assistant for your account |
| 4. Intent and Preference Data (“Derived Data”) | Labels the Assistant assigns to calls (e.g., “delivery”, “appointment reminder”, “suspected spam”), your corrections to those labels, and preferences the Assistant learns from your instructions | (a) Routing and handling calls the way you want; (b) improving spam and fraud detection for your account; (c) personalising summaries and responses; (d) contributing limited spam/fraud indicators to the cross-user protection system described in Section 3.1. Aggregated, irreversibly anonymised intent statistics (never linked to you, your contacts, or any identifiable caller) may otherwise be used to improve the service for all users, as described in Section 6 |
| 5. Usage and Device Data | App activity, feature usage, crash logs, device type, OS version, IP address, approximate region | (a) Maintaining, debugging, and improving app stability and performance; (b) detecting abuse and securing the service |
| 6. Information voluntarily disclosed during calls | New details you (or, on your instruction, the Assistant) share during a call, such as an address or delivery instruction | Captured and stored solely to generate the call summary, execute your instruction, and personalise future interactions within your settings. Not used or shared beyond your explicit configuration |
| 7. Support and Feedback Data | Communications you send us, ratings, and feedback | Responding to your queries, resolving complaints, and improving the service |
| 8. Payment Data (if you subscribe) | Processed by our payment processor, Razorpay / Cashfree / PayU or others from time to time. We do not store card numbers or payment credentials | Processing subscriptions and refunds. Governed additionally by the processor’s privacy policy to be found at their websites. |
Marketing communications. We may send you communications about new features, offers, and updates to the Assistant. You may opt out of promotional communications at any time via app settings or the unsubscribe mechanism in the communication itself. Opting out does not affect essential service communications (e.g., security alerts, changes to Terms).
3. Callers and other third parties on calls
The Assistant necessarily processes limited personal data of callers — people who call you and interact with the Assistant. We treat callers fairly and transparently:
- (a) AI disclosure. At the start of every call it handles, the Assistant clearly identifies itself as an AI assistant answering on your behalf. It never impersonates a human or impersonates you.
- (b) Data processed. For callers, we process the calling number, the audio and transcript of what the caller says to the Assistant, and any caller-ID name available from your phonebook or provided by the caller.
- (c) Purpose limitation. Caller data is processed solely to conduct the call, generate your summary, and enable you to respond — as an extension of your own handling of your incoming calls.
- (d) Caller choice. A caller who does not wish to interact with the Assistant may end the call at any time;
3.1 Spam and fraud protection signals
To protect users — particularly vulnerable users — from scam, fraud, and spam calls, we maintain a limited, cross-user database of fraud and spam indicators associated with phone numbers. This system operates under strict constraints:
- (a) What it contains: only the phone number, a category label (e.g., “suspected spam”, “reported fraud”), and aggregate signal metadata (e.g., report counts, call-pattern indicators). It never contains call content, transcripts, audio, names from any user’s phonebook, or any other personal data of the number’s holder.
- (b) What “verified” means: a number is labelled only when signals cross defined thresholds — such as independent reports from multiple unrelated users, or call patterns consistent with automated or fraudulent calling. A single user report never results in a label visible to other users.
- (c) Purpose limitation: these signals are used solely to warn users and inform how the Assistant handles calls from flagged numbers, in the interest of the safety and security of our users. They are not used for advertising, sold, licensed, or shared with third parties except as required by law.
- (d) Dispute and correction: if you believe a number (including your own) has been incorrectly labelled, you may raise a correction request at help@fluxlabs.in. We will review and respond within the timelines prescribed under applicable law, and remove or correct labels found to be inaccurate.
3.2 Outbound calls placed on your instruction
Where you instruct the Assistant to place a call on your behalf (for example, to a business, a customer-service line, or an automated phone system):
- (a) User-initiated only. The Assistant places outbound calls only on your specific instruction. It does not initiate calls autonomously and does not make marketing, telemarketing, or commercial solicitation calls.
- (b) AI disclosure. Where the Assistant reaches a human, it clearly discloses that it is an AI assistant calling on your behalf.
- (c) Recipient data. Audio and transcripts of outbound calls are processed and retained on the same terms as inbound calls under this Policy, solely to complete your instruction, generate your summary, and let you review the call.
- (d) Your responsibility. You must not instruct the Assistant to place calls that are unlawful, harassing, or deceptive; such use violates our Terms.
4. Third-party AI service providers (data processors)
To deliver the Assistant’s core functionality, we share specific categories of personal data with the third-party AI service providers listed below. Each provider is a “Data Processor” under the DPDP Act, processes data strictly on our documented instructions, and as per the terms.
Categories of data shared (only to the extent necessary for the purpose listed against each provider):
- (a) Call audio — the live audio stream of calls handled by the Assistant;
- (b) Call transcripts — text of the conversation;
- (c) Your first name — so the Assistant can introduce itself (for example: “Hi, I’m Jinny, answering on behalf of [name]”);
- (d) Gender / voice preference — solely to select voice, pronouns, and tone;
- (e) Caller name — where available, so the Assistant can address the caller appropriately;
- (f) Your configured instructions — so the Assistant responds as you have directed.
Providers, purposes, and governing policies:
| Provider | Purpose | Privacy policy |
|---|---|---|
| [Speech-to-text provider — Deepgram or other equivalent service] | Real-time speech recognition and transcription, including Indian languages | [link] |
| [LLM provider — OpenAI or other equivalent service] | Language-model processing to understand caller intent and generate the Assistant’s responses | [link] |
| [Text-to-speech provider — Cartesia or other equivalent service] | Voice synthesis so the Assistant can speak its responses | [link] |
| [Real-time voice platform — LiveKit or other equivalent service] | Orchestration of real-time voice conversations | [link] |
Terms of data processing: (i) restricts use of your data strictly to the purposes above and prohibits use of your data to train the provider’s general-purpose AI models; (ii) prohibits onward sharing, sale, or commercial exploitation of your data; (iii) requires deletion or return of your data upon termination of services or upon your account deletion (in no case later than 30 days from our deletion request); (iv) requires technical and organisational security measures substantially equivalent to Section 8 of this Policy; and (v) requires the provider to assist us in responding to your rights requests under applicable law.
By accepting this Privacy Policy through the consent mechanism presented in the app, you authorise this sharing. You may withdraw this consent at any time as described in Section 10; because these providers are essential to the Assistant’s functioning, withdrawal may require deactivation or deletion of your account.
5. Other sharing of your personal data
We do not sell your personal data. We do not share your personal data for third-party advertising. We may share personal data only:
- (a) With service providers (hosting, analytics, communications, payment processing) bound by confidentiality and data protection obligations, strictly to operate the service;
- (b) For legal reasons — to comply with applicable law, a lawful order of a court or authority, or to detect and prevent fraud, or protect the rights, property, or safety of the Company, our users, or the public; and
- (c) Business transfers — in connection with a merger, acquisition, restructuring, or sale of assets, in which case we will notify you and the successor will remain bound by commitments no less protective than this Policy.
6. Anonymised and aggregated data
We may create aggregated, irreversibly anonymised statistics from usage of the Assistant — for example, the proportion of unknown calls that are spam, or the most common categories of caller intent — to improve the service, publish insights, and develop features. Such data is not personal data: it cannot be linked back to you, your contacts, or any identifiable caller, and no individual call content is included. Audio is retained and used only as described in Sections 2, 4, and 7.
7. Storage, retention, and deletion
Where we store data. Your personal data is stored on secure servers located in India. Where any processor listed in Section 4 processes data outside India, such transfer is carried out in accordance with Section 16 of the DPDP Act and any restrictions notified by the Central Government, under contractual safeguards described in Section 4.
How long we keep it:
| Data category | Retention period |
|---|---|
| Account Information | Life of your account + deletion within 90 days of account closure |
| Contact Data | Life of your account; refreshed on each sync (stale entries replaced, no historical versions kept); deleted within 90 days of account closure |
| Call audio | Life of your account, subject to the separate audio-retention consent given at onboarding and your right to delete any individual recording at any time. If you expressly withdraw audio-retention consent, audio is deleted within 90 days of transcription while transcripts and summaries are retained. |
| Call transcripts and summaries | Life of your account, or until you delete the individual item |
| Derived Data (intent labels, preferences) | Life of your account |
| Support communications | 36 months |
Legal retention exceptions. We may retain limited data beyond these periods only where required by law (tax, accounting, fraud prevention, or to establish or defend legal claims), for no longer than the law requires, and only for that purpose. Where the DPDP Rules prescribe retention or pre-deletion notification timelines applicable to us, we will comply with them.
If your account is inactive, we will notify you before erasing your personal data in accordance with applicable timelines under the DPDP Rules.
8. Data security
We implement reasonable security safeguards as required under the DPDP Act and DPDP Rules, including:
- (a) Encryption in transit — all data moves between your device and our servers exclusively over TLS-encrypted connections;
- (b) Access controls — role-based access, logging, and monitoring of access to personal data; and
- (c) Encryption at rest for call recordings and transcripts, with encryption keys for audio recordings managed separately from those used for other data categories.
Granular consent. Consents are sought and managed separately for: (i) core call handling (essential to the service); (ii) contact synchronisation; (iii) retention of call audio recordings; and (iv) marketing communications. You may grant or withdraw each independently; only (i) is a precondition to using the Assistant.
Breach notification. In the event of a personal data breach, we will notify the Data Protection Board of India and each affected user in the form and within the timelines prescribed under the DPDP Act and DPDP Rules, including a description of the breach, its likely consequences, and the measures taken.
No method of internet transmission or storage is completely secure. While we apply the safeguards above, we cannot guarantee absolute security, and to the extent permitted by law we are not liable for breaches occurring despite our compliance with these safeguards.
9. Device permissions we request
The Assistant requests the following permissions, each with a specific purpose. You may decline or revoke any permission via your device settings; doing so may limit corresponding functionality.
- Phone / call handling (including call screening role on Android): required for the Assistant to answer, screen, or place calls on your behalf. Core to the service.
- Contacts: to distinguish known from unknown callers. If you revoke this permission, previously synced contacts continue to be treated as known callers until account deletion; new contacts added after revocation will be treated as unknown.
- Microphone: only when you speak to the Assistant or join a call it is handling.
- Notifications: (i) to alert you in real time about calls the Assistant is handling and summaries; (ii) service and security messages; and (iii) with your consent, promotional notifications (which you can disable independently).
10. Your rights
Under the DPDP Act, you have the following rights, exercisable free of charge through the app or by writing to help@fluxlabs.in:
- Right to access: obtain a summary of the personal data we process about you, the processing activities, and the identities of processors with whom it has been shared.
- Right to correction and updating: have inaccurate or incomplete personal data corrected, completed, or updated.
- Right to erasure: have your personal data erased when it is no longer necessary for the specified purpose, unless retention is required by law.
- Right to withdraw consent: withdraw any consent at any time, with ease comparable to the manner in which it was given. Withdrawal does not affect the lawfulness of processing before withdrawal. Because certain data is essential to the service, withdrawal of essential consents may require deactivation or deletion of your account; we will tell you the consequences before you confirm.
- Right to grievance redressal: raise any grievance with our Grievance Officer (Section 14), who will respond within the timelines prescribed under the DPDP Rules.
- Right to nominate: nominate another individual who may exercise your rights in the event of your death or incapacity.
Consent Managers. Where you have registered with a Consent Manager under the DPDP Act, you may give, manage, review, and withdraw consent through that Consent Manager, and we will honour such instructions.
Notice languages. You may request this notice and our consent requests in English or in any language specified in the Eighth Schedule to the Constitution of India.
Your duties. Please provide accurate information and do not impersonate another person or suppress material information when exercising your rights, as required under Section 15 of the DPDP Act.
11. Account deletion
You can manage the deletion of your data in two stages, depending on what you want removed.
Deleting your account (profile and settings). You may permanently delete your account at any time via Settings → Delete Account in the app. Upon such deletion, we will, within 90 (ninety) days, permanently and irreversibly delete or irreversibly anonymise your Account Information, Contact Data, Usage Data, and Support and Feedback Data, and you will lose access to your call history and preferences in the app.
Retention of call content after account deletion. Unless you also request deletion of your call content (as described below), we may continue to retain your call audio, transcripts, summaries, and Derived Data (intent labels and preferences learned from your calls) after your account is deleted. Any such retained call content is stored in isolated form, is not linked to any active account or profile, is not used to build any user-facing service, and is used only to the extent permitted by applicable law.
Deleting your call content. To have your call content — call audio, transcripts, summaries, and Derived Data — permanently deleted, please write to help@fluxlabs.in from the email address (or referencing the mobile number) associated with your account. Upon verification of your request, we will:
- permanently and irreversibly delete or irreversibly anonymise your call content within 90 (ninety) days of the verified request;
- instruct all processors listed in Section 4 to delete such content from their systems within the same period; and
- confirm completion of the deletion to you at the email address from which the request was made.
Legal retention. Limited data may be retained beyond the periods above only where required by law (for example, for tax, accounting, fraud-prevention, or to establish or defend legal claims), for no longer than the law requires and only for that specific purpose, and shall be isolated from any other processing until the legal requirement lapses.
Nothing in this Section 11 limits your rights under Section 10 (Your Rights), including your right to withdraw consent or to request erasure at any time, or the DPDP Rules on inactive-account erasure.
12. Children
The Assistant is intended only for persons aged 18 and above. We do not knowingly collect personal data of children, do not undertake tracking or behavioural monitoring of children, and do not direct advertising at children. If you believe a child’s data has been collected, contact us at help@fluxlabs.in and we will delete it.
13. Changes to this policy
We may update this Privacy Policy from time to time. We will notify you of material changes through the app and/or your registered contact details, with an updated Effective Date. Where a change expands the personal data collected or the purposes of processing, we will seek your fresh consent before the change applies to you.
14. Grievance redressal
- Grievance Officer
- Raghav Dalela
- help@fluxlabs.in
- Address
- M-202 Pioneer Park, sector 61, Gurgaon, Haryana 122001
We will acknowledge grievances within 48 hours and resolve them within the timelines prescribed under applicable law. If you have exhausted our grievance process and remain unsatisfied, you may complain to the Data Protection Board of India in the manner prescribed under the DPDP Act and DPDP Rules.
© 2026 Flux Labs AI Private Limited. All rights reserved.
