Last updated: August 23, 2026
Privacy Policy
1. Who we are
Saffr ("we," "us," "our") operates the Saffr mobile app, a platform for creators to build a profile, showcase their work, discover other creators, and collaborate on projects. This policy explains what personal data we collect, why, and what rights you have over it, particularly under India's Digital Personal Data Protection (DPDP) Act, 2023.
2. What we collect
| Category | Examples | Why |
|---|---|---|
| Account information | Email, password (hashed), sign-in method (Google/Apple/Facebook) | To create and secure your account |
| Profile information | Display name, handle, bio, city, date of birth, gender, avatar photo | To build and display your public creator profile |
| Portfolio & posts | Photos, videos, audio, links, captions | The content you choose to share |
| Creative field & skills | Field, roles, specialty tags | To match you with relevant creators and opportunities |
| Connections & messages | Follows, connection requests, chat messages, media shared in chat | To power messaging and networking features |
| Project activity | Projects you create or join, collaboration requests, tasks | To run the Projects/collaboration feature |
| Push notification token | A device identifier used to deliver notifications | So we can notify you about activity relevant to you |
| Referral information | Who invited you, if applicable | To attribute invites |
| Usage & device data | Screens viewed, actions taken, app crashes, device/OS type | To understand how the app is used and fix problems (via PostHog) |
We do not collect payment or financial information. Saffr does not process payments directly.
3. Who else sees your data
We use a small number of service providers ("processors") to run Saffr. They only receive what they need to perform their function:
- Supabase: our database, authentication, and file storage provider. Nearly all app data (profiles, posts, messages, files) is stored here.
- PostHog: product analytics and crash reporting. Receives usage events and device/crash data, not your messages or private content.
- Firebase Cloud Messaging (Android) and Expo Push (iOS): deliver push notifications to your device.
We do not sell your personal data to anyone, for any purpose.
4. How long we keep your data
While your account is active, your data is kept so the app can function. If you delete your account:
- Your profile and account are deactivated and removed from search/discovery immediately.
- Your account is then permanently deleted, along with associated data.
- We retain a minimal deletion record (a one-way cryptographic hash of your phone number plus the date of deletion) for compliance recordkeeping. This record cannot be used to identify you or recover your data.
5. Your rights
Under the DPDP Act, you have the right to:
- Access the personal data we hold about you
- Correct inaccurate data (most of this you can do yourself by editing your profile)
- Erase your data (via Delete Account in Settings, or by contacting us)
- Withdraw consent for processing, where consent is the basis for it
- Nominate someone to exercise these rights on your behalf in the event you're unable to
- File a grievance with us, and if unresolved, with India's Data Protection Board
To exercise any of these rights, contact our designated data officer at privacy@saffr.in. We aim to respond to all requests within a reasonable time, and no later than 90 days.
6. Children's data
Saffr is not intended for anyone under 18. We verify date of birth during onboarding and do not knowingly collect data from minors. If we learn an account belongs to someone under 18, we will suspend it.
7. Security
We rely on our infrastructure providers' security controls (encryption in transit and at rest, access controls, row-level security in our database) and follow the principle of giving each part of the app access only to the data it needs. No system is perfectly secure, and we cannot guarantee absolute security of your data.
8. Where your data is processed
Our infrastructure providers (Supabase, PostHog, Firebase, Expo) may process data outside India. We aim to comply with any restrictions the Indian government places on cross-border data transfer.
9. Changes to this policy
We may update this policy as the app changes. Material changes will be communicated in-app before they take effect.
10. Contact us
Questions, data requests, or complaints: privacy@saffr.in