Privacy Policy

ssv.asia respects your privacy and is committed to protecting your personal data.

Last updated: 2 October 2026

Expert AI Mobile Privacy Notice

This notice describes the Android Expert AI application, package com.ssvasia.expertai, published by SSV.Asia on Google Play. This policy applies to the mobile application and the SSV.Asia services it uses.

Data controller / Data Fiduciary: Ar. Samar Singh Virdi, sole proprietor, Panchkula, Haryana, India.

Contact: mail@ssv.asia

Data the mobile application handles

Account and authentication data

  • Email address, membership or entitlement information, and authentication transaction data are used to create and sign in to an account.
  • Email sign-in uses Ghost/SSV.Asia verification. The application may send an email address, nonce, and verification code to the SSV.Asia gateway.
  • Google Sign-In may send a Google ID token to the SSV.Asia gateway for server-side verification. The gateway receives the verified Google email and relevant account identity information needed to create a session.
  • The application can also connect to GitHub for GitHub-related features. GitHub OAuth tokens and account information are stored locally when that feature is used and are sent to GitHub only to perform the requested operation.
  • The application stores its SSV.Asia session token in Android Secure Storage. Tokens are transmitted over HTTPS and are not intentionally stored as plain text in the application database.

Prompts, files, and AI responses

  • Text prompts, conversation history sent for a request, optional images, and tool-related content are transmitted to the SSV.Asia gateway and the providers needed to answer the request.
  • The gateway may send prompt content to OpenRouter and the underlying model provider selected for the request, Tavily when web search is requested, and Supabase when knowledge retrieval is requested.
  • Images selected from the camera or device library are processed only when the user chooses to attach or analyze them. They are sent to the relevant AI service needed for that request.
  • The service does not intentionally use prompts or uploaded content to build advertising profiles.

Voice and audio

  • When the user activates voice input, the application uses the device microphone and temporary audio processing to convert speech into text. Voice input is optional; text chat remains available if microphone permission is denied.
  • The application may request audio-session permissions needed for voice input or audio playback. It does not access the microphone when voice input is not active.

Agent, workspace, and paired-server data

  • Agent mode can handle workspace names, workspace identifiers, session identifiers, chat history, file names, coding-session metadata, and files or commands selected by the user.
  • This information may be stored locally on the device and transmitted to the paired desktop or local coding-agent server. The paired server may retain it under its own storage and privacy practices.
  • The app's local chat, workspace, settings, scheduled-task, and document caches remain on the device until deleted in the app, the relevant feature is cleared, app data is cleared, or the device is reset.

Camera and device permissions

  • Camera access is used for QR-code pairing and, when chosen by the user, taking an image to attach to a chat. QR images are processed for the requested action and are not intentionally retained by SSV.Asia as camera photos.
  • Media-library access may be used to select an image for a chat request.
  • Microphone access is used only for optional voice input.
  • Notifications are optional. If background agent jobs or scheduled tasks are enabled, the application may obtain a device push token and send it with the job request so the service can deliver a completion notification. Notification preferences and scheduled notifications are stored locally unless a feature explicitly sends a job to the gateway.
  • The application does not request contacts, precise location, SMS, or call-log access.

Usage, security, and payment data

  • The gateway processes account email, request counts, token usage, timestamps, pass type and expiry, entitlement state, session-revocation state, and rate-limit or ban state to provide the service and prevent abuse.
  • IP addresses are processed for rate limiting, security, and abuse prevention. Cloudflare and gateway operational logs may also contain request and error metadata.
  • Payments are processed by payment partners. SSV.Asia receives transaction confirmation and limited metadata such as email, payment ID, amount, tier, refund status, subscription status, or payment reference. SSV.Asia does not receive full card numbers or banking credentials.
  • The mobile application includes Sentry crash and error reporting in production. Sentry may receive crash reports, exception messages, stack traces, device/app version information, and limited diagnostic context needed to diagnose failures. It is not used for advertising or behavioral profiling.

Permissions

Camera, microphone, media-library, audio-session, and notification permissions are optional feature permissions. Denying them does not prevent ordinary text chat, but the related feature will not work. Android controls can be used to revoke permissions at any time.

Service providers and sharing

SSV.Asia shares only the information needed to operate the requested feature with these providers:

  • Cloudflare: gateway hosting, HTTPS delivery, rate limiting, Durable Object account/usage records, and operational infrastructure.
  • Ghost: membership records, email authentication, and account verification.
  • Google: Google Sign-In identity verification when the user chooses Google Sign-In.
  • GitHub: GitHub authentication or API operations when the user chooses a GitHub feature.
  • OpenRouter and underlying model providers: prompt, conversation, optional image, and tool content needed for AI inference.
  • Tavily: web-search queries when the user requests web search.
  • Supabase: knowledge-retrieval queries and retrieved-vault processing when the user uses the knowledge feature.
  • Sentry: production crash and error diagnostics from the mobile application.
  • Razorpay, Gumroad, and Polar: payment processing and related transaction confirmation, according to their own policies.
  • Expo/Apple/Google notification infrastructure: notification delivery when the user enables notifications or submits a background job requiring notification delivery.

These providers may process data outside India or the European Economic Area, including in the United States. We use contractual, technical, or other safeguards appropriate to the applicable law. Provider retention and use are also governed by each provider's own privacy policy and terms.

SSV.Asia does not sell personal information and does not share it for cross-context behavioral advertising.

Cookies and analytics

The mobile application does not use advertising cookies. The SSV.Asia website may use essential first-party cookies for session management and security. SSV.Asia does not use advertising or cross-site behavioral-tracking cookies.

Sentry crash/error reporting is operational diagnostics, not advertising analytics. The application does not use crash data to build an advertising or behavioral profile.

Retention

  • Account email, entitlement, usage, pass, and security records are retained while needed to operate the account, enforce quotas, prevent abuse, and maintain financial or legal records.
  • Gateway request records are limited operational metadata such as time, account, model, token totals, cost, latency, and success/failure state. Prompt content is sent to providers for the live request and is not intended to be stored as an account conversation database by the gateway.
  • Cloudflare, Sentry, Ghost, payment, AI, search, retrieval, GitHub, and notification providers may retain data according to their own policies and configured operational or legal retention periods.
  • Payment and tax records may be retained for the period required by applicable law.
  • Local app caches remain on the device until the user deletes them or clears app data. Paired desktop-server data remains under the paired server's control.

Account deletion and data removal

To request deletion, email mail@ssv.asia from the account email with the subject Account Deletion Request, or use the in-app Delete Account action where available in Agent-mode Settings.

The gateway deletion action removes the account's SSV.Asia gateway Durable Object account/usage record and invalidates the account's usable gateway state. It does not automatically delete a Ghost membership, payment/tax records that must be retained, Sentry records already collected, provider-side records, or data stored on a paired desktop server. Those records are handled under the applicable provider, legal, and paired-server retention rules.

We process deletion requests within 30 days, subject to identity verification, legal retention requirements, backup cycles, and third-party processing limits. Backups or provider systems may retain limited data for their stated retention period.

We process data to provide the service, authenticate users, process payments, comply with legal obligations, secure the service, prevent abuse, and provide optional features the user requests. Where consent is required, the user may withdraw it, although the related feature may stop working.

Depending on location, users may have rights to access, correct, delete, restrict, object to, or receive a copy of their personal data, and may have rights under the GDPR/UK GDPR, CCPA/CPRA and other US state laws, and India's Digital Personal Data Protection Act, 2023. Requests may be sent to mail@ssv.asia. We may verify identity using account information and other reasonable details.

Children

The service is intended for people aged 18 or older. We do not knowingly target or collect children's data. Contact mail@ssv.asia if you believe a child has provided personal data.

Security

We use HTTPS/TLS, HMAC-signed session tokens, server-side secrets, access controls, rate limiting, and per-account usage controls. No method of transmission or storage is completely secure.

Automated decisions and AI output

AI responses are generated from user requests and may be inaccurate or incomplete. The service does not use personal data to make legal or similarly significant decisions about a person. Users should not rely on AI output as medical, legal, financial, or other professional advice.

Changes and contact

We may update this policy when the application, gateway, providers, or legal requirements change. The effective date will be updated for material changes.

Questions, privacy requests, or complaints:

Ar. Samar Singh Virdi
mail@ssv.asia

Privacy Policy version: 2.2
Effective date: 2 October 2026

Last updated: 27 August 2026

Expert AI Mobile Privacy Notice

This section describes data collection and privacy practices specific to the Expert AI mobile application (Android APK, version 1.0+, package: com.ssvasia.expertai), published by SSV.Asia on Google Play Store.

The full privacy policy below applies to all SSV.Asia products, including the Expert AI APK. This section clarifies mobile-specific data handling.

What Expert AI APK Collects

The Expert AI mobile app collects only the following additional data beyond what is described below (§1):

Camera Access (QR Code Pairing)

  • What: Your device's camera is used ONLY to scan QR codes displayed on your desktop server terminal.
  • Why: To establish a secure peer-to-peer connection between the mobile app and your local pi-coding-agent server.
  • What we store: The QR code is processed in real-time and immediately discarded; we do not save the image or its contents to our servers.
  • Your control: Camera permission can be granted/revoked per the Android permission system. If you deny camera access, QR pairing will not function.
  • Permission disclosure: "Allow Expert AI Chat to use your camera to scan server QR codes."

Session & Workspace Data (Agent mode)

  • What: Workspace names, session IDs, chat history, and coding session metadata created while using Agent mode are stored locally on your device and synced to the desktop server you've paired with.
  • Why: To persist your sessions and allow offline access.
  • What we store: On your device — cached until you clear app data or delete your account. On your paired desktop server — retained under that server's own storage, which you control.
  • Your control: Delete sessions in-app, or clear all app data via Android Settings.

Authentication Tokens

  • What: After signing in or QR pairing, the app stores an encrypted authentication token locally to maintain your session.
  • Why: To keep you logged in between app restarts without requiring re-authentication.
  • What we store: Token stored in Android Secure Storage (encrypted by the OS).
  • Transmission: Token sent over encrypted HTTPS only; never logged or stored in plain text.
  • Your control: Signing out or deleting your account revokes the token immediately.

Android Permissions & Rationale

Permission Why Requested Essential? Can Deny?
CAMERA QR code scanning for server pairing No (optional feature) Can deny; QR pairing won't work, rest of app functions normally
RECORD_AUDIO Voice input for chat/commands (future feature) No Can deny; text chat still works
MODIFY_AUDIO_SETTINGS Control audio during sessions No Can deny; chat still works
READ/WRITE_EXTERNAL_STORAGE (Android 12 and below only) Attaching an image from your camera roll to a chat message No Can deny; rest of app functions normally

We request only the permissions needed for core functionality. No permissions to access contacts, location, SMS, or call logs are required or requested.

Account Deletion & Data Removal

To delete your Expert AI account and all associated data, permanently and consistently, within the same timeframe regardless of which method you use:

In-App Method (Agent mode)

  1. Open Expert AI → switch to Agent mode (top-bar Chat/Agent switch) → Settings
  2. Tap "Delete Account"
  3. Confirm deletion

Web Method (no app required, works even without Agent mode set up)

  1. Email mail@ssv.asia from the email address associated with your account, with the subject line "Account Deletion Request"
  2. We verify your identity against your account email and process the request

In both cases: your account and all associated data (workspaces, sessions, usage records, authentication tokens) are removed from all production systems within 30 days of your request. Backup archives may retain deleted data for up to 90 additional days before being fully purged, consistent with our data retention practices (§7 below).


Main Privacy Policy

ssv.asia respects your privacy and is committed to protecting your personal data.

SSV.Asia respects your privacy and is committed to protecting your personal data. This Policy explains what we collect, why, your rights, and how we comply with the EU/EEA & UK GDPR, the California Consumer Privacy Act (CCPA/CPRA) and similar US state laws, and India's Digital Personal Data Protection Act, 2023 (DPDP Act).

Data Controller / Data Fiduciary: Ar. Samar Singh Virdi, sole proprietor, Panchkula, Haryana, India.

Contact: mail@ssv.asia

1. Information We Collect

We deliberately collect as little as possible. Specifically:

  • Email address — used to verify your membership (via Ghost) and as your account identifier. This is the only identity information we require.
  • Membership tier / entitlement — which pass or access level your account holds, read from Ghost at sign-in.
  • Usage & metering data — request counts, token usage, timestamps, pass type and expiry, daily request counts, and security flags (rate-limit / ban status). Stored per-account in Cloudflare Durable Objects to enforce quotas and prevent abuse.
  • Payment metadata — the payment/transaction ID, amount, tier purchased, and refund status, received back from the payment partner. We do not receive or store your card details.
  • IP address — processed transiently for rate-limiting and abuse prevention. Logs containing IP addresses are retained for 30 days for security purposes and then automatically deleted. IP data is not used to build a profile of you.
  • Prompt & query content — what you type into Expert AI is transmitted in real time to the AI model, web-search, and retrieval providers needed to answer it. We do not store your prompts in our database. Log fragments containing your prompt content are retained for 7 days for debugging and abuse prevention, then automatically purged.
  • Support communications — only if you choose to email us.

What we do NOT collect: we do not ask for your name, postal address, or phone number; we do not store payment card details; we do not use any analytics or crash-reporting SDK; we do not build advertising or behavioral profiles; and we do not sell your data.

  • Performance of a contract: to create your account, deliver passes, meter usage, and provide AI responses.
  • Legal obligation: tax, accounting, and record-keeping.
  • Legitimate interests: security, fraud/abuse prevention, and service improvement (balanced against your rights).
  • Consent: for any optional future features requiring it; you may withdraw consent at any time.

Under India's Digital Personal Data Protection Act, 2023 (DPDP Act) — which is not yet fully enforced — we process personal data on the basis of your consent or for legitimate uses permitted by the Act, after notice. You may withdraw consent at any time (which may limit the Services we can provide).

3. Payments

Payments are processed by our payment partners — Razorpay (INR/UPI; SSV.Asia is seller of record), and Gumroad / Polar.sh (international; Merchant of Record). These partners process your payment data under their own privacy policies. SSV.Asia receives only transaction confirmation and limited metadata (e.g. email, tier, payment ID, amount), never full card details.

4. AI Model Providers & Sub-processors

To deliver the Services we share limited data with trusted sub-processors:

  • AI model routing/inference (e.g. OpenRouter and the underlying model providers it routes to) — receives your prompt content to generate responses
  • Web search (Tavily) — receives your search query when you use the search command
  • Knowledge retrieval (Supabase) — hosts the content vault used for retrieval
  • Membership/auth (Ghost) — verifies your email/membership
  • Infrastructure (Cloudflare) — hosts the application and stores usage/metering records

We share the minimum necessary and do not authorize sub-processors to use your data for their own purposes beyond providing their service to us.

5. International Data Transfers

Some sub-processors are located outside India and the EU/EEA (e.g. in the United States). Where we transfer personal data internationally, we rely on appropriate safeguards such as Standard Contractual Clauses or equivalent mechanisms, as required by the GDPR and the DPDP Act.

6. Cookies

The Expert AI app and terminal set no cookies.

The SSV.Asia website uses only essential first-party cookies for:

  • Session management (Ghost membership, sign-in persistence)
  • Security (CSRF protection, rate-limiting)

We do not set advertising, analytics, or cross-site tracking cookies. You can manage cookies via your browser settings.

7. Data Retention

We keep data only as long as needed:

  • Email + usage/metering data: kept in your per-account ledger for the life of your account so we can enforce quotas and passes; deleted on account deletion request.
  • Payment metadata: retained as long as required by tax/accounting law (8 years in India, 7 years in US, as per local statutory requirements).
  • Prompt content: not stored in our database. Log fragments containing your prompt content are retained for 7 days for debugging and abuse prevention, then automatically purged.
  • IP-based rate-limit counters: automatically expire within their short rate-limit window.
  • Account deletion: removal from all production systems and backups within 30 days of request. Backup archives may retain deleted data for up to 90 additional days before being purged.

We delete or anonymize data when it is no longer needed.

8. Your Rights

  • EU/EEA & UK (GDPR): access, rectification, erasure ("right to be forgotten"), restriction, data portability, objection, and the right to withdraw consent. You may also lodge a complaint with your local data protection authority.
  • United States (CCPA/CPRA & similar): the right to know/access, delete, and correct your personal information; the right to opt out of "sale" or "sharing" of personal information; and the right to non-discrimination for exercising your rights. We do not sell your personal information, and we do not share it for cross-context behavioral advertising.
  • India (DPDP Act, 2023): as a Data Principal you have the right to access a summary of your personal data, the right of correction and erasure, the right of grievance redressal, and the right to nominate another person to exercise your rights in the event of death or incapacity.

To exercise any right, email mail@ssv.asia. We will verify your identity and respond within the timeframes required by applicable law.

Identity verification: To verify your identity, we may request:

  • Email address used with your account
  • Last 4 digits of payment method (if applicable)
  • Approximate date of last login

Matching any two of the above is sufficient for verification.

9. Grievance Officer (India — DPDP Act)

For privacy questions, complaints, or to exercise your rights, contact our Grievance Officer:

Ar. Samar Singh Virdi
mail@ssv.asia

We aim to acknowledge grievances promptly and resolve them within the period prescribed under the DPDP Act and its rules.

10. Children's Data

The Services are intended for users 18 and older. Under the DPDP Act, processing a child's data requires verifiable parental consent and prohibits tracking/targeted advertising to children; we do not knowingly collect children's data. If you believe a child has provided data, contact us for deletion.

11. Data Security

We use reasonable technical and organizational measures to protect personal data, including:

  • Encrypted transport (HTTPS/TLS) for all traffic
  • Short-lived, HMAC-signed session tokens (not long-lived passwords)
  • API keys and secrets held only server-side, never shipped in the client
  • Atomic, per-account usage ledgers and IP-based rate-limiting to prevent abuse
  • Access controls limiting who can administer the system

No method of transmission or storage is 100% secure, and we cannot guarantee absolute security.

12. Data Breach Notification

If a personal-data breach occurs that is likely to result in a risk to your rights, we will notify the relevant supervisory authority and affected users without undue delay, as required by the GDPR, the DPDP Act, and applicable US state laws.

13. Automated Decision-Making

We do not use your personal data for automated decision-making that produces legal or similarly significant effects about you. AI output is generated in response to your prompts and is not used to profile or score you.

14. US State Privacy Rights & "Do Not Sell"

We do not sell or share your personal information for cross-context behavioral advertising, and we do not process sensitive personal information for inferring characteristics. Residents of California and other US states with privacy laws (e.g. Virginia, Colorado, Connecticut, Utah, Texas) may exercise the rights described in §8. We honor opt-out preference signals such as Global Privacy Control (GPC) where applicable. You may use an authorized agent to submit requests, and we will not discriminate against you for exercising your rights.

15. Sub-processors

The third parties that process limited data on our behalf to deliver the Services are listed in §3 and §4 and include:

  • Ghost (membership/auth)
  • Cloudflare (hosting & usage records)
  • OpenRouter and its underlying model providers (AI inference)
  • Tavily (web search)
  • Supabase (knowledge retrieval)
  • Payment processors: Razorpay (INR/UPI), Gumroad (international), Polar.sh (international)

We will update this list when sub-processors change.

16. Changes & Contact

We may update this Policy; material changes are shown via the "Last updated" date and, where appropriate, notified in-product or by email.

Questions or requests: 📩 mail@ssv.asia

Grievance Officer (India DPDP Act):

For privacy questions, complaints, or to exercise your rights,
contact our Grievance Officer:

Ar. Samar Singh Virdi
mail@ssv.asia

We aim to acknowledge grievances promptly and resolve them within the period prescribed under the DPDP Act and its rules.


Privacy Policy Version: 2.1
(With Expert AI APK Addendum corrected 2026-08-27)
Last Updated: 27 August 2026
Effective Date: 12 February 2026


Excellent intelligence on APK, CLI, WIN, MAC

Start using Expert AI Terminal today, Purchase a dedicated installation for your machine

AI chat, AI Agents and knowledge systems built for rigorous domain expertise and sovereign data hosting.