Legal
Privacy Policy
Your privacy is important to us. This policy explains how we collect, use, and protect your information.
Last updated: January 2026
Data Collection & Telemetry
- We collect absolute minimal telemetry necessary to guarantee system stability and security.
- User-generated content and proprietary data injected into our systems remain strictly isolated. Unless synchronized to our encrypted cloud clusters, data persists entirely on-device.
- We log anonymous operational metrics (e.g., API response times, crash vectors) to iterate and optimize our infrastructure.
- Direct communication and forms submitted via our ecosystem are retained securely to provision engineering support.
Data Processing & Utilization
- Your data is processed strictly to execute the operational parameters of the service requested.
- Capital transactions are negotiated and authenticated purely through secure external processors (Stripe, Apple, Google). We never encounter or store raw financial data.
- We analyze anonymized meta-usage patterns to dictate capital allocation and resource prioritization across our Venture domains.
Storage, Routing & Third-Party Sharing
- We enforce strict architectural boundaries. Data is never aggregated and sold to advertising firms or data brokers.
- When absolutely necessary for service execution, we route data through elite, SOC2-compliant third-party infrastructure (e.g., AWS, GCP, Vercel).
- Should legal mandates or regulatory bodies enforce warrants against Drish Labs LLP, data will be surrendered only under strict legal compulsion. We will notify affected entities unless legally prohibited.
Facial Image Processing (Passport Photo App)
- Our dedicated passport photo application processes precise facial imagery to guarantee compliance with regional government specifications.
- Temporary Buffering: Photographs are routed to Google's Gemini AI clusters purely for background ablation, biometric centering, and lighting correction.
- Zero Identification Policy: We execute zero facial recognition. We do not generate, cache, or sell biometric templates, faceprints, or geometric mapping data.
- Ephemeral Storage: Upon successful processing and localized saving to your device, the image buffer on our servers is immediately wiped. We maintain zero historical archives of your photos.
Security Architecture
- Our network perimeters are defended with enterprise-grade encryption regimes both in-transit and at-rest.
- We operate on the principle of least privilege. Internal engineering access to production databases is strictly compartmentalized and extensively logged.
- No digital infrastructure is entirely impregnable; you inject data at your own risk. However, we continuously execute red-team audits to preemptively seal vulnerabilities.
Your Autonomous Rights
- You maintain supreme authority over your data. You may execute localized deletion at will, and request complete server-side ablation of any retained metadata.
- Cookies and localized tracking objects are deployed purely for session authentication. You may sever these via your browser interface at any time.
- For any critical privacy concerns, architectural inquiries, or data extraction requests, securely contact us at query@drishlabs.com.