Status of this document
Sutron is currently in staging (pre-release). This policy is published so that testers, early creators, and reviewers can read the commitments we intend to operate under. It has not yet been reviewed by external counsel and is not yet in force.
Two things follow, and they are important:
- Staging data may be reset, migrated, or deleted without notice. Do not put anything into the staging environment that you would be harmed by losing.
- Some safeguards described here are implemented and verified, and some are committed but still being hardened. Where that distinction matters we say so explicitly rather than claiming a protection we have not finished building. Section 14 lists the known gaps.
1. The short version
- Your chat messages are end-to-end encrypted. We cannot read them. Not for ads, not for analytics, not for AI, not on request.
- We collect the minimum we need to run an account, deliver what you buy, take payments, keep the platform safe, and meet legal obligations.
- We do not sell your personal data, and we do not share it with advertisers for their own use.
- Advertising on Sutron is targeted by region, category, and interests you have declared — never by the content of your conversations.
- You have real, exercisable rights over your data: access, correction, erasure, portability, and the right to complain (§10).
- Data is stored in India, with limited, disclosed exceptions (§9).
The rest of this document is the detail behind those statements.
2. Who is responsible for your data
Golden Peacock Fintech Private Limited is the Data Fiduciary (controller) for personal data processed through Sutron, under the Digital Personal Data Protection Act, 2023 ("DPDP Act").
- CIN:
[TO BE COMPLETED BEFORE LAUNCH] - Registered office:
[TO BE COMPLETED BEFORE LAUNCH] - Data Protection / Privacy contact: privacy@sutron.io
- Grievance Officer: see §11
A note on Creators. When you buy from a Creator, that Creator receives the limited data needed to fulfil and support your purchase (§7.2), and becomes an independent Data Fiduciary for their own use of it. We require Creators to handle it lawfully, but we do not control how they do so. Their privacy practices are their own.
3. What we collect
3.1 Data you give us
| Category | What it includes | Why we need it |
|---|---|---|
| Account | Mobile number, @handle, display name, profile photo, language |
Create and secure your account; identify you publicly |
| Creator / Business profile | Business name, description, branding assets, category, links | Operate your storefront |
| Verification (KYC/KYB) | Government ID details, PAN, GST registration, business registration, address, and the documents evidencing them | Legal requirement before publishing paid listings or receiving payouts |
| Settlement | Bank account or UPI details for payouts | Pay you |
| Content you publish | Courses, products, listings, storefront pages, public posts, Commons files | Deliver and display what you publish |
| Communications with us | Support tickets, grievance complaints, and anything you paste into them | Answer you and keep a record |
| Reviews and ratings | Your review text, star rating, and the purchase it is tied to | Publish verified-purchase reviews |
3.2 Data generated by your use
| Category | What it includes | Why we need it |
|---|---|---|
| Device and app | Device model, OS version, app version, app install identifier, language, time zone, crash reports | Make the app work on your device; diagnose faults |
| Connection | IP address, approximate region derived from it, connection timestamps | Security, fraud prevention, abuse rate-limiting, regional compliance |
| Chat metadata | Who you exchanged messages with, when, message size, room membership, delivery and read state — never message content | Deliver messages; sync across your devices |
| Commerce | Cart contents, orders, entitlements, payment status, invoices, ledger entries, wallet and settlement records | Complete purchases; keep financial records the law requires us to keep |
| Learning | Course enrolment, lesson progress, quiz results, attendance in live sessions, certificates issued | Deliver the course and show your progress |
| Files | File names, sizes, content hashes, folder placement, who a file is shared with | Store, deduplicate, and deliver files |
| Product usage | Screens opened, features used, search queries on public catalog, performance timings | Understand what works and fix what does not |
| Trust and safety signals | Refund rate, dispute rate, review velocity, report history, login anomalies | Detect fraud, abuse, and manipulation |
3.3 Data we get from others
- Payment providers — the status of a transaction, the last four digits and instrument type of a card, and the reason for a failure. We never receive your full card number, CVV, or UPI PIN.
- Verification providers — the result of an identity or business check.
- Push notification services — a device token used to deliver notifications.
3.4 What we deliberately do not collect
- The content of your end-to-end encrypted messages, calls, and attachments.
- Your contact list, unless you explicitly choose to use a feature that needs it and grant the permission.
- Precise GPS location. We derive an approximate region from your IP address; we do not track your location.
- Biometric templates. Where you unlock the app with a fingerprint or face, that check happens on your device and the biometric never reaches us.
- The plaintext of Protected Content you consume — DRM decryption happens in device memory.
4. End-to-end encryption: the boundary, stated precisely
This is the part of the policy most privacy policies get vague about, so we will be exact.
4.1 What is encrypted end-to-end
Every one-to-one and group conversation, including its text, images, videos, documents, voice notes, and reactions. Content is encrypted on your device using the Matrix protocol's Megolm ratchet, and the keys exist only on the devices of the conversation's participants.
Your voice notes are transcribed on your device. The audio and the transcript never leave it for that purpose.
4.2 What is therefore impossible for us
We cannot read, search, index, scan, moderate proactively, hand over, or restore the content of your encrypted conversations. This is not a policy choice we could quietly reverse — the servers do not hold the keys. If a court orders us to produce message content, we can only produce what we actually have, which is the metadata in §3.2.
The consequence you must accept: if you lose every device on which a conversation exists and you have not kept an encrypted backup, that conversation is gone permanently. We cannot recover it.
4.3 What is not end-to-end encrypted
Being clear about the edges matters more than the promise:
- Public and commercial surfaces — storefronts, published courses, public community content, Commons files, reviews, and your public profile. These are published deliberately and are visible to their intended audience and to search engines.
- Chat metadata — who, when, and how much (§3.2).
- Commerce and financial records — orders, invoices, and ledger entries are encrypted in transit and at rest, but they are readable by us, because we are legally required to keep and be able to produce them.
- Anything you send to support — if you paste a message into a support ticket, you have handed it to us.
- Content you export — once decrypted and saved outside the app, it is governed by your device, not by us.
4.4 The advertising firewall
No advertising, recommendation, ranking, or AI system on Sutron ingests the content or the metadata of your encrypted conversations. Ad targeting uses only: your region, the category of public or commercial surfaces you engage with, and interests you have explicitly declared. If you subscribe to an ad-free tier, ads are removed entirely.
5. Why we process your data, and on what legal basis
Under the DPDP Act we process personal data either with your consent, or for certain legitimate uses the Act permits.
| Purpose | Basis |
|---|---|
| Creating and operating your account | Performance of our contract with you; consent at sign-up |
| Delivering messages, courses, files, and purchases | Contract |
| Taking payments, issuing invoices, settling and paying out | Contract; legal obligation |
| KYC/KYB, tax collection and reporting, record retention | Legal obligation |
| Preventing fraud, abuse, spam, and manipulation | Legitimate use — safety and security of the platform |
| Responding to your support requests and grievances | Contract; legal obligation |
| Sending service and transactional notifications | Contract |
| Product analytics and improving the platform | Consent, using pseudonymised data wherever possible |
| Marketing communications | Consent, which you may withdraw at any time |
| Personalised advertising | Consent, using only the signals in §4.4 |
| Complying with a court order or a lawful government request | Legal obligation |
Where we rely on consent, you may withdraw it at any time (§10). Withdrawal does not affect processing already carried out, and some withdrawals will mean we can no longer provide part of the service — we will tell you when that is the case.
6. How we use automated processing
- Trust and Discoverability scores. We compute scores for Creators from stored behavioural signals (refund rate, ratings, support responsiveness, verification status, growth, freshness). These influence public badges, tier-based fee rates, and where a listing appears in discovery. They are computed by versioned, auditable functions, not by an opaque model, and a Creator can see the signals that feed them.
- Fraud and abuse detection. Automated signals may flag an account for review, suppress a listing, or hold a settlement. A human reviews any decision that suspends an account or withholds money, and you can appeal (§11).
- Recommendations and ranking on public discovery surfaces, from public engagement data only.
We do not make solely automated decisions that produce legal effects on you without a route to human review.
7. Who we share data with
We do not sell your personal data. We share it only as follows.
7.1 Service providers acting on our instructions
Each is bound by contract to process data only for the purpose we specify, to keep it secure, and to delete it when the engagement ends.
| Kind of provider | What they receive |
|---|---|
| Cloud hosting and storage | Encrypted data at rest; the systems that run the Platform |
| Payment providers | Transaction amount, order reference, and the details you enter with them directly |
| Identity and business verification providers | The documents and details you submit for KYC/KYB |
| Push notification delivery | A device token and the notification payload |
| Communications (SMS, email) | Your number or address and the message content |
| Live video and audio infrastructure | Session participation data for calls, classes, and stages |
| Error monitoring and performance | Crash traces and performance timings, with personal identifiers stripped |
7.2 Creators you buy from
A Creator receives your @handle, display name, the Order details, your
enrolment and progress in their course, and any message you send them. They
receive this to fulfil and support your purchase. They do not receive your
mobile number, your payment instrument, or your data from any other Creator.
7.3 Other users
Your @handle, display name, profile photo, public profile content, published
listings, reviews you post, and your membership of public communities are visible
to other users. Your mobile number is not shown publicly.
7.4 Legal and safety disclosures
We disclose data where we are legally required to, or where we believe in good faith that it is necessary to: comply with a valid order of a court or a competent authority; enforce our Terms; detect or prevent fraud or a security incident; or protect the rights, property, or safety of any person.
Where the law permits, we will tell you before disclosing your data in response to a legal request, so that you have an opportunity to object.
7.5 Corporate transactions
If Golden Peacock is involved in a merger, acquisition, or sale of assets, your data may transfer as part of it. We will notify you, and the acquirer will remain bound by a policy at least as protective as this one.
8. How long we keep data
| Data | Retention |
|---|---|
| Account profile | While your account is open, then 30 days after closure |
| Encrypted message content | Stored on your devices; on our servers only until delivered to every device, then removed |
| Chat metadata | 90 days |
| Financial records — orders, invoices, ledger, settlement | 8 years, as required by the Companies Act, 2013 and tax law |
| KYC/KYB records | 5 years after the relationship ends, as required by law |
| Tax records | As required by the Income-tax Act, 1961 and the CGST Act, 2017 |
| Trust and safety records (bans, fraud findings) | 3 years, to prevent a banned user simply re-registering |
| Support and grievance records | 3 years |
| Server logs | 180 days, as required under the IT Rules, 2021 |
| Product analytics | 25 months, pseudonymised |
| Content you delete | Removed from live systems immediately; purged from backups as those backups expire, within 90 days |
We use soft deletion: deleted records are marked inaccessible immediately and hard-purged by an audited job. Where we must keep something after you ask us to delete it, we keep only what the law requires and nothing else.
9. Where your data is stored
Personal data is stored and processed in India.
A limited set of processors may handle data outside India — specifically error monitoring, push notification delivery, and content delivery caching. Where that happens we transfer only the minimum necessary, we require contractual safeguards, and we do not transfer to any country restricted by the Central Government under Section 16 of the DPDP Act.
End-to-end encrypted message content is never readable by any processor, anywhere, because no processor holds the keys.
10. Your rights, and how to exercise them
Under the DPDP Act you have the following rights. We do not charge for exercising them, and we respond within 30 days.
| Right | What it means | How |
|---|---|---|
| Access | Get a summary of the personal data we process about you, and who we have shared it with | In-app: Settings → Privacy → Download my data, or privacy@sutron.io |
| Correction | Correct data that is inaccurate, and complete data that is incomplete | Edit in-app where the field is editable; otherwise privacy@sutron.io |
| Erasure | Have your data deleted where we no longer need it and no law requires us to keep it | Settings → Account → Delete account, or privacy@sutron.io |
| Portability | Receive your data in a structured, machine-readable format | Settings → Privacy → Export |
| Withdraw consent | Withdraw consent for any processing based on it | Settings → Privacy, or privacy@sutron.io |
| Nominate | Nominate a person to exercise your rights if you die or become incapacitated | privacy@sutron.io |
| Grievance | Complain about how we have handled your data | §11 |
What we will need from you. To protect you, we verify identity before acting on a request about an account. We will ask you to confirm control of the account's registered mobile number.
Limits we will be honest about.
- We cannot give you the content of your encrypted messages, because we do not have it. Export it from your own device instead.
- We cannot delete financial and tax records inside their statutory retention period. We will delete everything else, and restrict the retained records to their legal purpose only.
- We cannot delete a review you posted from the Creator's public record if doing so would misrepresent an aggregate rating; we will anonymise it instead.
- Content another user has lawfully received — a message you sent them, a file you shared — is on their device and outside our reach.
Your duties. The DPDP Act asks that you provide accurate information, not impersonate anyone, and not file false or frivolous complaints.
11. Grievances and complaints
Grievance Officer
- Name:
[TO BE COMPLETED BEFORE LAUNCH] - Designation: Grievance Officer, Golden Peacock Fintech Pvt. Ltd.
- Email: grievance@sutron.io
- Privacy-specific: privacy@sutron.io
- Address:
[REGISTERED OFFICE — TO BE COMPLETED BEFORE LAUNCH]
We acknowledge within 24 hours and resolve within 15 days.
If you are not satisfied with our response, you may complain to the Data Protection Board of India under the DPDP Act, 2023. You must ordinarily raise the matter with us first.
12. Children
The Platform is intended for users aged 18 and over. Users aged 13–18 may use it only with verifiable parental or guardian consent.
Where we know a user is a child, we do not undertake tracking, behavioural monitoring, or targeted advertising directed at them, as required by Section 9 of the DPDP Act. If you believe a child has given us personal data without the required consent, write to privacy@sutron.io and we will delete it.
13. How we protect your data
- Encryption in transit — TLS on every connection, with certificate pinning in the mobile app.
- Encryption at rest — for the local database on your device and for stored data on our servers.
- End-to-end encryption — for all private conversations (§4).
- DRM — Protected Content is decrypted in device memory only, and is not written to your filesystem in plaintext unless the Creator has permitted download.
- Access control — staff access to production data is role-restricted, requires multi-factor authentication, and is logged to an immutable audit trail. Administrative override ("God Mode") requires additional approval and is fully audited.
- Separation of analytics from operations — analytics runs on a separate columnar store fed by change-data-capture, so no analytics query can reach into the live messaging or commerce path.
- Telemetry scrubbing — crash and performance reports are stripped of user identifiers, email addresses, IP addresses, and request bodies before they leave the device, and content-bearing screenshots are disabled in production builds.
- Breach notification — we will notify the Data Protection Board and affected users of a personal data breach as required by the DPDP Act.
14. Known gaps in the staging build
We would rather name these than let this document imply a protection we have not finished shipping. Each is tracked and is a launch blocker.
- Encryption keys for protected media at rest. The per-file content encryption key is being migrated to being wrapped under a master key before storage. Until that lands, treat staging DRM as a functional demonstration, not a security guarantee.
- Telemetry scrubbing. The scrubbing described in §13 is being verified end-to-end. Until that verification is signed off, do not enter real personal data into staging.
- Refunds and payouts. Neither is executable in staging. Staging balances are not money.
- Data export and in-app deletion. The self-service flows referenced in §10 are being built. During staging, send the request to privacy@sutron.io and we will handle it manually.
15. Cookies and similar technologies
The Sutron website uses:
- Strictly necessary cookies for sign-in, session security, and preferences. These cannot be switched off.
- Analytics storage, only with your consent, to understand aggregate usage.
We do not use third-party advertising cookies or cross-site tracking pixels on our website.
The mobile app does not use cookies. It stores a local app install identifier and an encrypted local database on your device.
16. Changes to this policy
We may update this policy. For material changes we will give you at least 30 days' notice in the app or by email before they take effect, and we will record the change in the log below. Where a change requires your consent, we will ask for it rather than assume it.
17. Contact us
| Purpose | Address |
|---|---|
| Privacy and data rights | privacy@sutron.io |
| Grievances | grievance@sutron.io |
| Security disclosures | security@sutron.io |
| General support | support@sutron.io |
Golden Peacock Fintech Private Limited
[REGISTERED OFFICE ADDRESS — TO BE COMPLETED BEFORE LAUNCH]
CIN: [TO BE COMPLETED BEFORE LAUNCH]
Change log
| Version | Date | Change |
|---|---|---|
| 0.1 | 1 September 2026 | First staging draft published for review. Not in force. |