Legal
Privacy Policy
Last updated: May 2026
What We Collect
When you sign up, we collect your Google account email address and profile information. When you configure your merchant account, we store your UPI ID and business information you provide.
Gmail Access
We request read-only access to your Gmail to find bank payment alert emails. We only search for emails from known bank sender addresses. We do not read personal emails, and we do not store full email content. Only extracted payment metadata (amount, sender name, UPI reference ID, bank name) is stored for verification records.
How We Use Your Data
- Verify UPI payments by matching bank alert emails to pending payment requests
- Display payment history and analytics in your dashboard
- Enforce rate limits and usage quotas
- Improve verification accuracy
Data Storage
Your data is stored in Supabase (PostgreSQL) with row-level security. Gmail credentials are encrypted at rest using AES-256 encryption. We do not sell, share, or transfer your data to third parties.
AI Processing
Bank alert emails are sent to AI language models (Anthropic Claude) for payment detail extraction. Email content is processed in real-time and not stored by the AI provider beyond the API request lifecycle.
Cookies
We use session cookies for authentication. No tracking cookies or third-party analytics are used.
Data Deletion
You can delete your account and all associated data at any time. Gmail access can be revoked independently through your Google account settings.
Contact
For privacy concerns, contact us at upiagent.live@gmail.com.