Privacy Policy
Housome — Privacy Policy
AI Saarthi Labs LLP, an entity registered in New Delhi, India (“AI Saarthi Labs”, “Housome”, “we”, “us” or “our”), determines how and why personal data is processed through the Housome mobile application, related websites and services (collectively, the “Service”). This Policy explains what personal data we collect, where it comes from, why we use it, whom we disclose it to, how long we keep it, international transfers, and the rights and choices available to you.
On this page
- 1. Who we are and scope of this Policy
- 2. Age restriction
- 3. Personal data we collect
- 4. Sources of personal data
- 5. How and why we use personal data
- 6. Lawful bases where required
- 7. Household visibility and user-directed sharing
- 8. AI and automated processing
- 9. When we disclose personal data
- 10. Sale, targeted advertising and affiliate links
- 11. International data transfers
- 12. Data retention and deletion
- 13. Security and incident response
- 14. Your rights and choices
- 15. Region-specific information
- 16. Direct marketing and service communications
- 17. Changes to this Policy
- 18. Privacy contact and Grievance Officer
1. Who we are and scope of this Policy
AI Saarthi Labs LLP, an entity registered in New Delhi, India (“AI Saarthi Labs”, “Housome”, “we”, “us” or “our”), determines how and why personal data is processed through the Housome mobile application, related websites and services (collectively, the “Service”). For applicable privacy laws, we are generally the data fiduciary, controller or business responsible for this processing.
This Privacy Policy explains what personal data we collect, where it comes from, why we use it, whom we disclose it to, how long we keep it, international transfers, and the rights and choices available to you.
This Policy is intended to support compliance with applicable Indian law, including the Digital Personal Data Protection Act, 2023 and rules brought into force under it, the Information Technology Act, 2000 and applicable rules and directions. Where Housome is offered elsewhere, additional mandatory protections—such as the EU General Data Protection Regulation (EU GDPR), UK GDPR, or applicable United States state privacy laws—apply to eligible individuals.
This Policy does not govern a third party’s independent practices, including Google Drive files and services accessed outside Housome.
2. Age restriction
Housome is a general-audience service intended only for users aged 18 or older. We do not knowingly permit children to create accounts or intentionally collect personal data directly from children.
An adult may include limited information about a child in legitimate household content, such as a task or family event, if the adult has authority to do so and appropriately limits its visibility. If we learn that a child has created an account or directly provided personal data without legally valid authorisation, we will take reasonable steps to disable the account and delete the data, subject to applicable law.
If you believe a child is using Housome, contact saathi@aisaarthilabs.com.
3. Personal data we collect
Depending on the features you use, we may process the following categories.
3.1 Account and household data
Mobile number; OTP-verification status and related authentication records; display name; profile information you choose to provide; account identifiers; household name, membership, roles, invitations and sharing settings.
We do not need or intend to retain the OTP itself after it has served its authentication purpose, although the authentication provider may maintain security and delivery records.
3.2 Household content
Tasks, events, lists, calendar entries, household messages, notes, shared contacts, household essentials, reminders, assignments, comments, preferences and other information you enter or share.
Household content may contain personal data about you, household members or other people. Depending on what users choose to enter, it may incidentally reveal sensitive matters such as financial information, health information, religious information, family relationships or location-related plans. Do not provide sensitive information unless it is necessary and you are authorised to do so.
3.3 Financial and document content supplied by users
Bank statements, transaction files, receipts, screenshots, photographs, PDFs, document names, file metadata, expense amounts, merchants, dates, categories, balances, extracted transaction information and other files or records that you choose to upload, link or import.
Housome is not a bank and does not request banking passwords, card PINs, UPI PINs or OTPs for financial transactions. Do not upload credentials or authentication codes.
3.4 Contacts and calendar information
If you grant permission and use a relevant feature, Housome may access selected device contacts or calendar information to help you create household contacts, invitations, tasks or events. We will seek operating-system permission where required. Depending on implementation, Housome may process only the selected item or information necessary for the requested function rather than continuously collecting your entire address book or calendar.
3.5 Camera, photos and files
If you grant permission, we may access the camera, photo library or file picker so you can capture, choose, upload, scan or link a document or image. Permission does not mean we collect every item available on your device; we process items you select and technical information needed for the feature.
3.6 Google Drive information
If you connect Google Drive, we may process Google account identifiers, authorisation tokens, selected folder or file identifiers, file names, links, permissions and related metadata needed to create, locate or share documents through Housome. The underlying documents may be stored in Google Drive rather than Housome’s primary database.
We use information received from Google APIs only to provide or improve user-facing features that are prominent in Housome, to maintain security, or as otherwise permitted by Google’s API Services User Data Policy, including its Limited Use requirements. We do not use Google Drive content for advertising or sell it.
3.7 Voice and AI interaction data
When you use voice-to-text or AI features, we process the audio you choose to submit, its transcript, your text instructions, relevant context you choose to provide, AI responses, proposed actions and your confirmation or rejection.
Audio may be transmitted to a speech-processing service and processed temporarily to produce a transcript. Housome primarily uses the resulting transcript for the requested feature. If a feature will retain raw audio, we will identify that before or when it is collected.
3.8 Device, network, analytics and diagnostic data
Device and app identifiers; IP address; approximate location inferred from IP; device model; operating-system and app versions; language and time zone; notification token; event timestamps; feature interactions; session and referral information; advertising identifier if advertising is later introduced and permission or another lawful basis exists; crash reports; performance logs; and security or fraud signals.
We use Google Analytics for Firebase/GA4 and may use Firebase diagnostics or similar tools to understand feature use and app stability. Where applicable law requires consent for analytics or access to device storage or identifiers, we will seek it before activating the relevant processing.
3.9 Communications and support data
Information contained in emails, complaints, privacy requests, surveys, feedback and other communications with us, along with records of how we respond.
3.10 Future purchase and advertising data
If paid services are introduced, we may receive purchase status, product, price, currency, subscription status and transaction identifiers from an app store or payment provider. We ordinarily will not receive complete payment-card details.
If advertising or affiliate features are introduced, we may process ad impressions, clicks, conversions, consent choices and related device or advertising identifiers as described in an updated notice and consent interface.
4. Sources of personal data
We collect personal data:
- directly from you when you register, enter information, upload or link files, use voice or AI features, communicate with us or grant permissions;
- from other household members when they invite you, assign an item to you, mention you or add information relating to you;
- automatically from your device, app and network when you use the Service;
- from connected services such as Google Drive, at your direction; and
- from service providers supporting authentication, analytics, security, customer support and app operations.
If you provide another person’s personal data, you are responsible for having authority to do so and for avoiding unnecessary or excessive disclosure.
5. How and why we use personal data
We use personal data for the following purposes:
- create, authenticate and secure accounts;
- create and manage households, invitations, roles and visibility settings;
- provide tasks, events, lists, chats, contacts, calendars, reminders, notifications, expenses, documents and other requested features;
- process user-selected files, extract or categorise information and generate user-requested AI proposals;
- connect to Google Drive and maintain user-authorised file links and sharing permissions;
- provide customer support and respond to complaints and privacy requests;
- diagnose crashes, monitor performance, understand feature adoption and improve usability;
- protect users, detect abuse, prevent fraud, maintain security and enforce our Terms;
- comply with law, legal process and lawful directions, and establish, exercise or defend legal claims;
- communicate service notices, security alerts, policy changes and, where permitted, product or marketing messages;
- administer subscriptions, payments, advertisements, affiliate relationships or sponsored features if introduced with the required notice and choices; and
- create aggregated or de-identified statistics that are not reasonably capable of identifying an individual, and use them for lawful analytics, planning and improvement.
We do not use bank-statement content, private household messages, Google Drive content or AI prompts to build advertising profiles unless we first provide specific notice and obtain any consent required by law. We do not use data received through Google Drive APIs for advertising.
6. Lawful bases where required
The lawful basis depends on the activity and the law that applies.
6.1 India
We process digital personal data for lawful purposes with your consent or for another use authorised by applicable law. You may withdraw consent with comparable ease by using available controls or contacting us, although withdrawal does not affect processing already lawfully completed and may make a requested feature unavailable.
6.2 European Economic Area and United Kingdom
Where the EU GDPR or UK GDPR applies, we generally rely on:
- performance of a contract—to register and provide the Housome features you request;
- legitimate interests—to secure the Service, prevent misuse, provide support, improve non-essential aspects of the Service and establish or defend legal claims, after considering the effect on your rights;
- consent—for optional device permissions, certain analytics, direct marketing, personalised advertising and sensitive-data processing where consent is legally required; and
- legal obligation—to comply with applicable law and binding legal process.
Where you place special-category or highly sensitive data in Housome, you are choosing the content of a general household tool. We process it only as needed to provide the feature you request and, where legally required, with explicit consent or another valid legal condition. Do not upload such data if you lack authority or a valid basis.
7. Household visibility and user-directed sharing
Information marked “Only Me” is intended to be visible only to the relevant user. Information marked “Household”, posted in a shared space or inherently collaborative is made available to authorised household members at the user’s direction.
Household members are independent users. They may view, copy, download or retain information shared with them. Housome cannot reverse information already seen or copied. Carefully review household membership and item visibility, particularly for bank statements, identity documents, health records, passwords, access codes or other sensitive material.
When a member leaves or deletes an account, shared household records may remain available to other members where needed to preserve their legitimate household history or content. We may remove or de-identify the departing member’s account attribution where appropriate. We will consider valid deletion and objection requests in light of the rights of all affected users and applicable law.
8. AI and automated processing
Housome currently uses the OpenAI API for certain AI-assisted features. OpenAI states that, by default, data submitted through its business/API services is not used to train or improve its general models unless the customer expressly opts in. This does not necessarily mean zero retention: provider-side retention may occur for security, abuse monitoring or service operation according to the contracted service, endpoint and data-control settings. Where eligible and operationally appropriate, we may use reduced-retention or zero-data-retention configurations.
We may later use or replace AI and speech services with other vetted providers, including Google Gemini, DeepSeek or Sarvam AI. Before materially changing the recipients or uses of personal data, we will update this Policy, an in-app notice or a readily accessible provider list and obtain consent where law requires it. Provider selection may depend on feature, language, availability, performance, security and region.
We send an AI provider only the content and context reasonably needed to fulfil the request. Users should avoid including unnecessary personal data or confidential information. Housome does not permit a provider to use Housome user content to train its general-purpose models where our service contract or provider controls allow us to prohibit that use.
AI output may contain errors. AI-proposed actions require user confirmation before they are saved to household records. Housome does not currently make solely automated decisions that produce legal or similarly significant effects on users.
9. When we disclose personal data
We may disclose personal data to the following recipients, only for the relevant purpose.
9.1 Other household members
We disclose shared content and related account information according to household membership, permissions and user-selected visibility.
9.2 Infrastructure and service providers
Providers supporting Housome may include:
- Google Firebase—for authentication, app infrastructure, notifications, diagnostics and related services;
- Neon—for database infrastructure;
- Render—for application hosting and server infrastructure;
- Google Analytics/GA4—for usage analytics;
- Google Drive and Google APIs—for user-directed document storage, linking and sharing;
- OpenAI—for current AI-assisted processing; and
- additional vetted providers for communications, security, support, speech processing, AI, payments or other functions introduced in the future.
These providers may process data on our behalf under applicable contracts or may act as independent controllers for limited aspects of their services. Their processing locations and retention practices may vary.
9.3 Connected services and user-directed recipients
We disclose data when you instruct us to connect, share, export or send information to another service or person.
9.4 Legal, safety and rights protection
We may preserve or disclose information if reasonably necessary to comply with applicable law, a court order or lawful government request; report or investigate cyber incidents; protect life or safety; prevent fraud or abuse; enforce agreements; or establish, exercise or defend legal claims. We assess requests for legal validity and scope where permitted.
9.5 Business transactions
If AI Saarthi Labs is involved in a merger, financing, restructuring, acquisition, insolvency or transfer of all or part of the Service, personal data may be disclosed under confidentiality and transferred subject to applicable notice, consent and objection requirements.
9.6 Professional advisers
We may disclose necessary information to lawyers, auditors, insurers and other professional advisers who are subject to confidentiality obligations.
10. Sale, targeted advertising and affiliate links
As of the “Last updated” date, AI Saarthi Labs does not sell personal data and Housome does not use personal data for third-party cross-context behavioural advertising.
We may introduce advertisements, including through providers such as Google AdMob or comparable advertising platforms. Advertising SDKs may collect device or advertising identifiers, IP address, app interactions, approximate location and ad events and may use them for ad delivery, frequency control, measurement, fraud prevention or personalisation.
Before activating personalised or cross-context behavioural advertising, we will:
- update this Policy and relevant app-store disclosures;
- identify material advertising partners and purposes;
- obtain consent before collecting or using data where required, including through an appropriate consent-management platform for relevant European users;
- offer rejection, withdrawal and opt-out controls required by applicable law; and
- provide a “Do Not Sell or Share My Personal Information” or equivalent mechanism if the activity constitutes a sale or sharing under an applicable United States privacy law.
Non-personalised or contextual ads can still involve limited data processing for delivery, reporting, security and frequency control and will be disclosed accordingly.
If Housome uses affiliate links, we may receive a commission when a user follows a link or completes a qualifying transaction. The merchant or affiliate network may independently collect click, transaction and device data under its own privacy notice. Affiliate or sponsored relationships will be disclosed where required.
11. International data transfers
Housome is operated from India and uses providers that may process data in India, the United States and other countries. Those countries may have privacy laws different from those where you live.
Where transfer restrictions apply, we use an available lawful mechanism appropriate to the transfer, which may include contractual data-protection terms, the European Commission’s Standard Contractual Clauses, the UK International Data Transfer Agreement or Addendum, an adequacy decision, consent where legally valid, or another approved safeguard. We also comply with restrictions or requirements notified under Indian law.
You may contact us for further information about safeguards applicable to your data, subject to confidentiality and security limitations.
12. Data retention and deletion
We retain personal data only for as long as reasonably necessary for the purpose for which it was processed, to provide an active account, comply with law, maintain security, resolve disputes and enforce agreements. Because Housome is an early-stage service and users control different kinds of household content, retention is determined using the following criteria rather than one period for all data:
- Account and private content: retained while the account is active and until deletion is requested, consent is withdrawn where applicable, or the purpose is no longer served, subject to legal and security exceptions.
- Shared household content: retained while needed by the household or until appropriately deleted by an authorised user. If one member deletes an account, content shared with others may remain where necessary to preserve their legitimate records, with attribution removed or de-identified where appropriate.
- Google Drive content: controlled by the Google Drive file owner and applicable Drive permissions. Removing a Housome link or deleting a Housome account may not delete the underlying Drive file. OAuth tokens and Housome-held links will be deleted or invalidated when no longer needed, subject to technical and legal requirements.
- AI and voice data: Housome-held prompts, transcripts, responses and actions are retained only as needed for the requested feature, household history, safety, support or user-selected content. Provider-side retention depends on the contracted product, endpoint, security requirements and data-control configuration.
- Analytics and diagnostics: retained for the limited period configured in the relevant analytics or diagnostic service and reviewed periodically for necessity.
- Support, grievance and legal records: retained until the matter is resolved and for a reasonable period afterwards based on limitation periods, legal obligations, security and the need to establish or defend claims.
- Security and system logs: retained for the period needed to secure and audit the Service and for any minimum period required by applicable cyber-security law or binding direction.
- Backups: deleted data may remain in encrypted, access-restricted backups until those backups are overwritten under our backup cycle. Backups are not used for ordinary product purposes and, if restored, deletion controls are reapplied where reasonably practicable.
To request deletion, email saathi@aisaarthilabs.com from, or with sufficient proof of, the mobile number associated with your account. We may verify identity and authority. We will process a valid request within the period required by applicable law. We may retain limited data when necessary for legal compliance, security, fraud prevention, the rights of other users or legal claims, and will explain a refusal where required.
13. Security and incident response
We use reasonable technical and organisational safeguards appropriate to the nature and risk of the data. Measures may include encrypted network connections, access controls, authentication, least-privilege access, monitoring, backups, provider due diligence and incident-response procedures.
No system is completely secure. Protect your phone, OTPs, device access, household invite links and connected-service permissions. Do not use Housome as the only copy of critical documents.
If a personal-data breach occurs, we will investigate, contain and document it and notify affected individuals and competent authorities where and within the time required by applicable law.
14. Your rights and choices
Depending on your location and the applicable law, you may have some or all of the following rights:
- receive information about our processing;
- request access to, or a summary and copy of, personal data associated with you;
- correct, complete or update inaccurate or incomplete data;
- request deletion or erasure;
- withdraw consent, without affecting processing already lawfully completed;
- object to or restrict certain processing;
- request portability of eligible data in a usable format;
- opt out of direct marketing, sale, sharing, targeted advertising or certain profiling where applicable;
- nominate another individual to exercise rights in the event of death or incapacity where Indian law provides that right;
- complain to us and, after using our grievance process where required, complain to the Data Protection Board of India or another competent supervisory authority; and
- receive equal service and not be unlawfully discriminated against for exercising a privacy right.
You can exercise available controls in the app or email saathi@aisaarthilabs.com. Describe the right and the data concerned. We may verify identity, account control, residence and an authorised agent’s authority. We will respond within the period required by applicable law.
Rights are not absolute. We may deny or limit a request where an exception applies, the request cannot be verified, it would adversely affect another person’s rights, or retention is legally required. Where required, we will explain the decision and available appeal or complaint route.
You can revoke device permissions through operating-system settings, disconnect Google access through Google account permissions, and disable push notifications through device or app settings. Service-critical communications may continue while your account remains active.
15. Region-specific information
The following sections describe additional rights that may apply depending on where you live.
15.1 India
Eligible Data Principals may exercise rights available under the Digital Personal Data Protection Act, 2023 as and when the relevant provisions and rules apply, including access to information, correction, completion, updating, erasure, grievance redressal and nomination. Consent may be withdrawn through available controls or by contacting us. You must provide authentic information when exercising rights and must not file false or frivolous grievances.
You should first use the grievance process in Section 18. Where the statutory framework permits and after exhausting that process, you may make a complaint to the Data Protection Board of India through its officially designated mechanism.
15.2 European Economic Area and United Kingdom
Eligible individuals may have rights of access, rectification, erasure, restriction, objection and portability, the right to withdraw consent, and the right to complain to the supervisory authority where they live or work or where an alleged infringement occurred.
You have the right to object at any time to processing based on legitimate interests, including profiling based on those interests. We will stop unless we demonstrate compelling legitimate grounds or need the data for legal claims. You may object at any time to direct marketing, and we will stop using your data for that purpose.
Housome does not currently make decisions based solely on automated processing that produce legal or similarly significant effects.
If offering the Service in a jurisdiction requires an EU or UK representative, additional local contact details will be published before or when that requirement applies.
15.3 United States
Residents of certain states may have rights to know or access personal data, correct it, delete it, obtain a portable copy, opt out of sale, targeted advertising or qualifying profiling, limit certain uses of sensitive personal data, and appeal a denied request.
As of the “Last updated” date, we do not sell personal data or share it for cross-context behavioural advertising. If that changes, we will provide legally required notices and opt-out mechanisms before or when the relevant processing begins. We will honour recognised opt-out preference signals where required and technically applicable.
These state-law rights apply only if the relevant law covers AI Saarthi Labs and the processing at issue; thresholds and exceptions differ.
16. Direct marketing and service communications
We may send account, OTP, security, transaction, reminder, grievance and policy communications needed to provide or protect the Service.
We will send promotional communications only where permitted. You may opt out using the message instructions or by contacting us. Opting out of marketing does not stop essential service communications.
17. Changes to this Policy
We may update this Policy to reflect changes in law, providers, features or practices. We will post the revised version with a new “Last updated” date. If a change materially affects how we use personal data or reduces your rights, we will provide reasonable advance or in-app notice and seek renewed consent where required.
18. Privacy contact and Grievance Officer
Grievance Officer / Privacy Contact
- AI Saarthi Labs LLP
- HN. 93, First Floor, DDA SFS Flats, Hauz Khas Apartments, Hauz Khas, New Delhi 110016
- Email: saathi@aisaarthilabs.com
Use this contact for privacy questions, rights requests, account deletion, data complaints, security concerns and complaints about unlawful or privacy-invasive content.
For a grievance, include your name, contact details, registered mobile number where relevant, a description of the issue, supporting information and the remedy requested. Do not send passwords, financial PINs or OTPs.
We aim to acknowledge qualifying grievances within 24 hours and resolve them within seven days, or within another period required by the law applicable to the particular request. Certain complaints concerning intimate or impersonation content may require faster action. Privacy rights requests may follow separate statutory response periods.
If you are dissatisfied, you may have the right to approach or appeal to the Data Protection Board of India, a Grievance Appellate Committee, a court, consumer forum or another competent privacy authority, subject to applicable eligibility, exhaustion and time-limit requirements.