Last updated: 27 August 2026
Expert AI Mobile Privacy Notice
This section describes data collection and privacy practices specific to the Expert AI mobile application (Android APK, version 1.0+, package: com.ssvasia.expertai), published by SSV.Asia on Google Play Store.
The full privacy policy below applies to all SSV.Asia products, including the Expert AI APK. This section clarifies mobile-specific data handling.
What Expert AI APK Collects
The Expert AI mobile app collects only the following additional data beyond what is described below (§1):
Camera Access (QR Code Pairing)
- What: Your device's camera is used ONLY to scan QR codes displayed on your desktop server terminal.
- Why: To establish a secure peer-to-peer connection between the mobile app and your local pi-coding-agent server.
- What we store: The QR code is processed in real-time and immediately discarded; we do not save the image or its contents to our servers.
- Your control: Camera permission can be granted/revoked per the Android permission system. If you deny camera access, QR pairing will not function.
- Permission disclosure: "Allow Expert AI Chat to use your camera to scan server QR codes."
Session & Workspace Data (Agent mode)
- What: Workspace names, session IDs, chat history, and coding session metadata created while using Agent mode are stored locally on your device and synced to the desktop server you've paired with.
- Why: To persist your sessions and allow offline access.
- What we store: On your device — cached until you clear app data or delete your account. On your paired desktop server — retained under that server's own storage, which you control.
- Your control: Delete sessions in-app, or clear all app data via Android Settings.
Authentication Tokens
- What: After signing in or QR pairing, the app stores an encrypted authentication token locally to maintain your session.
- Why: To keep you logged in between app restarts without requiring re-authentication.
- What we store: Token stored in Android Secure Storage (encrypted by the OS).
- Transmission: Token sent over encrypted HTTPS only; never logged or stored in plain text.
- Your control: Signing out or deleting your account revokes the token immediately.
Android Permissions & Rationale
| Permission | Why Requested | Essential? | Can Deny? |
|---|---|---|---|
| CAMERA | QR code scanning for server pairing | No (optional feature) | Can deny; QR pairing won't work, rest of app functions normally |
| RECORD_AUDIO | Voice input for chat/commands (future feature) | No | Can deny; text chat still works |
| MODIFY_AUDIO_SETTINGS | Control audio during sessions | No | Can deny; chat still works |
| READ/WRITE_EXTERNAL_STORAGE (Android 12 and below only) | Attaching an image from your camera roll to a chat message | No | Can deny; rest of app functions normally |
We request only the permissions needed for core functionality. No permissions to access contacts, location, SMS, or call logs are required or requested.
Account Deletion & Data Removal
To delete your Expert AI account and all associated data, permanently and consistently, within the same timeframe regardless of which method you use:
In-App Method (Agent mode)
- Open Expert AI → switch to Agent mode (top-bar Chat/Agent switch) → Settings
- Tap "Delete Account"
- Confirm deletion
Web Method (no app required, works even without Agent mode set up)
- Email mail@ssv.asia from the email address associated with your account, with the subject line "Account Deletion Request"
- We verify your identity against your account email and process the request
In both cases: your account and all associated data (workspaces, sessions, usage records, authentication tokens) are removed from all production systems within 30 days of your request. Backup archives may retain deleted data for up to 90 additional days before being fully purged, consistent with our data retention practices (§7 below).
Main Privacy Policy
ssv.asia respects your privacy and is committed to protecting your personal data.
SSV.Asia respects your privacy and is committed to protecting your personal data. This Policy explains what we collect, why, your rights, and how we comply with the EU/EEA & UK GDPR, the California Consumer Privacy Act (CCPA/CPRA) and similar US state laws, and India's Digital Personal Data Protection Act, 2023 (DPDP Act).
Data Controller / Data Fiduciary: Ar. Samar Singh Virdi, sole proprietor, Panchkula, Haryana, India.
Contact: mail@ssv.asia
1. Information We Collect
We deliberately collect as little as possible. Specifically:
- Email address — used to verify your membership (via Ghost) and as your account identifier. This is the only identity information we require.
- Membership tier / entitlement — which pass or access level your account holds, read from Ghost at sign-in.
- Usage & metering data — request counts, token usage, timestamps, pass type and expiry, daily request counts, and security flags (rate-limit / ban status). Stored per-account in Cloudflare Durable Objects to enforce quotas and prevent abuse.
- Payment metadata — the payment/transaction ID, amount, tier purchased, and refund status, received back from the payment partner. We do not receive or store your card details.
- IP address — processed transiently for rate-limiting and abuse prevention. Logs containing IP addresses are retained for 30 days for security purposes and then automatically deleted. IP data is not used to build a profile of you.
- Prompt & query content — what you type into Expert AI is transmitted in real time to the AI model, web-search, and retrieval providers needed to answer it. We do not store your prompts in our database. Log fragments containing your prompt content are retained for 7 days for debugging and abuse prevention, then automatically purged.
- Support communications — only if you choose to email us.
What we do NOT collect: we do not ask for your name, postal address, or phone number; we do not store payment card details; we do not use any analytics or crash-reporting SDK; we do not build advertising or behavioral profiles; and we do not sell your data.
2. Why We Process Your Data (Legal Bases — GDPR)
- Performance of a contract: to create your account, deliver passes, meter usage, and provide AI responses.
- Legal obligation: tax, accounting, and record-keeping.
- Legitimate interests: security, fraud/abuse prevention, and service improvement (balanced against your rights).
- Consent: for any optional future features requiring it; you may withdraw consent at any time.
Under India's Digital Personal Data Protection Act, 2023 (DPDP Act) — which is not yet fully enforced — we process personal data on the basis of your consent or for legitimate uses permitted by the Act, after notice. You may withdraw consent at any time (which may limit the Services we can provide).
3. Payments
Payments are processed by our payment partners — Razorpay (INR/UPI; SSV.Asia is seller of record), and Gumroad / Polar.sh (international; Merchant of Record). These partners process your payment data under their own privacy policies. SSV.Asia receives only transaction confirmation and limited metadata (e.g. email, tier, payment ID, amount), never full card details.
4. AI Model Providers & Sub-processors
To deliver the Services we share limited data with trusted sub-processors:
- AI model routing/inference (e.g. OpenRouter and the underlying model providers it routes to) — receives your prompt content to generate responses
- Web search (Tavily) — receives your search query when you use the search command
- Knowledge retrieval (Supabase) — hosts the content vault used for retrieval
- Membership/auth (Ghost) — verifies your email/membership
- Infrastructure (Cloudflare) — hosts the application and stores usage/metering records
We share the minimum necessary and do not authorize sub-processors to use your data for their own purposes beyond providing their service to us.
5. International Data Transfers
Some sub-processors are located outside India and the EU/EEA (e.g. in the United States). Where we transfer personal data internationally, we rely on appropriate safeguards such as Standard Contractual Clauses or equivalent mechanisms, as required by the GDPR and the DPDP Act.
6. Cookies
The Expert AI app and terminal set no cookies.
The SSV.Asia website uses only essential first-party cookies for:
- Session management (Ghost membership, sign-in persistence)
- Security (CSRF protection, rate-limiting)
We do not set advertising, analytics, or cross-site tracking cookies. You can manage cookies via your browser settings.
7. Data Retention
We keep data only as long as needed:
- Email + usage/metering data: kept in your per-account ledger for the life of your account so we can enforce quotas and passes; deleted on account deletion request.
- Payment metadata: retained as long as required by tax/accounting law (8 years in India, 7 years in US, as per local statutory requirements).
- Prompt content: not stored in our database. Log fragments containing your prompt content are retained for 7 days for debugging and abuse prevention, then automatically purged.
- IP-based rate-limit counters: automatically expire within their short rate-limit window.
- Account deletion: removal from all production systems and backups within 30 days of request. Backup archives may retain deleted data for up to 90 additional days before being purged.
We delete or anonymize data when it is no longer needed.
8. Your Rights
- EU/EEA & UK (GDPR): access, rectification, erasure ("right to be forgotten"), restriction, data portability, objection, and the right to withdraw consent. You may also lodge a complaint with your local data protection authority.
- United States (CCPA/CPRA & similar): the right to know/access, delete, and correct your personal information; the right to opt out of "sale" or "sharing" of personal information; and the right to non-discrimination for exercising your rights. We do not sell your personal information, and we do not share it for cross-context behavioral advertising.
- India (DPDP Act, 2023): as a Data Principal you have the right to access a summary of your personal data, the right of correction and erasure, the right of grievance redressal, and the right to nominate another person to exercise your rights in the event of death or incapacity.
To exercise any right, email mail@ssv.asia. We will verify your identity and respond within the timeframes required by applicable law.
Identity verification: To verify your identity, we may request:
- Email address used with your account
- Last 4 digits of payment method (if applicable)
- Approximate date of last login
Matching any two of the above is sufficient for verification.
9. Grievance Officer (India — DPDP Act)
For privacy questions, complaints, or to exercise your rights, contact our Grievance Officer:
Ar. Samar Singh Virdi
mail@ssv.asia
We aim to acknowledge grievances promptly and resolve them within the period prescribed under the DPDP Act and its rules.
10. Children's Data
The Services are intended for users 18 and older. Under the DPDP Act, processing a child's data requires verifiable parental consent and prohibits tracking/targeted advertising to children; we do not knowingly collect children's data. If you believe a child has provided data, contact us for deletion.
11. Data Security
We use reasonable technical and organizational measures to protect personal data, including:
- Encrypted transport (HTTPS/TLS) for all traffic
- Short-lived, HMAC-signed session tokens (not long-lived passwords)
- API keys and secrets held only server-side, never shipped in the client
- Atomic, per-account usage ledgers and IP-based rate-limiting to prevent abuse
- Access controls limiting who can administer the system
No method of transmission or storage is 100% secure, and we cannot guarantee absolute security.
12. Data Breach Notification
If a personal-data breach occurs that is likely to result in a risk to your rights, we will notify the relevant supervisory authority and affected users without undue delay, as required by the GDPR, the DPDP Act, and applicable US state laws.
13. Automated Decision-Making
We do not use your personal data for automated decision-making that produces legal or similarly significant effects about you. AI output is generated in response to your prompts and is not used to profile or score you.
14. US State Privacy Rights & "Do Not Sell"
We do not sell or share your personal information for cross-context behavioral advertising, and we do not process sensitive personal information for inferring characteristics. Residents of California and other US states with privacy laws (e.g. Virginia, Colorado, Connecticut, Utah, Texas) may exercise the rights described in §8. We honor opt-out preference signals such as Global Privacy Control (GPC) where applicable. You may use an authorized agent to submit requests, and we will not discriminate against you for exercising your rights.
15. Sub-processors
The third parties that process limited data on our behalf to deliver the Services are listed in §3 and §4 and include:
- Ghost (membership/auth)
- Cloudflare (hosting & usage records)
- OpenRouter and its underlying model providers (AI inference)
- Tavily (web search)
- Supabase (knowledge retrieval)
- Payment processors: Razorpay (INR/UPI), Gumroad (international), Polar.sh (international)
We will update this list when sub-processors change.
16. Changes & Contact
We may update this Policy; material changes are shown via the "Last updated" date and, where appropriate, notified in-product or by email.
Questions or requests: 📩 mail@ssv.asia
Grievance Officer (India DPDP Act):
For privacy questions, complaints, or to exercise your rights,
contact our Grievance Officer:
Ar. Samar Singh Virdi
mail@ssv.asia
We aim to acknowledge grievances promptly and resolve them within the period prescribed under the DPDP Act and its rules.
Privacy Policy Version: 2.1
(With Expert AI APK Addendum corrected 2026-08-27)
Last Updated: 27 August 2026
Effective Date: 12 February 2026