Privacy policy

Neni (heyneni.com)

Effective Date: 21 August 2026

Issued by: RAGNES Technologies

Faridabad, Haryana, India

admin@heyneni.com

https://www.heyneni.com/privacy

This policy is designed to meet the requirements of the Google Play Developer Program Policies, Apple App Store Review Guidelines, India's Digital Personal Data Protection Act 2023 (DPDPA), the US Children's Online Privacy Protection Act (COPPA), the EU/UK General Data Protection Regulation (GDPR), and the California Consumer Privacy Act (CCPA). Please read it carefully.

 

1. Introduction

RAGNES Technologies ("we", "us", "our") operates the Neni application and the website heyneni.com (collectively, "the Service"). This Privacy Policy explains what personal information we collect, why we collect it, how we use and protect it, and what rights you have over your data.

By downloading, installing, or using the Neni application, you agree to the collection and use of information in accordance with this policy. If you do not agree, please do not use the Service.

Neni is an AI-powered life operating system for families. Because the Service involves voice data, health-related information, financial data, communications content, and features accessible to children under 13, this policy contains specific and detailed disclosures for each category. We take your privacy seriously.

 

2. Data Controller / Data Fiduciary

The data controller (under GDPR) and data fiduciary (under DPDPA) responsible for your personal data is:

 

RAGNES Technologies

Faridabad, Haryana, India

Email: admin@heyneni.com

Website: https://www.heyneni.com

 

For users in the European Economic Area (EEA) or United Kingdom, RAGNES Technologies acts as the data controller. For users in India, RAGNES Technologies acts as the data fiduciary under the Digital Personal Data Protection Act, 2023.

 

3. Information We Collect

We collect information you provide directly, information generated through your use of the Service, and information from third-party services you connect to Neni. Below is a complete list:

3.1 Account and Identity Data

       Full name

       Email address

       Phone number (for account verification and WhatsApp integration)

       Profile photograph (if provided)

       Family member names, relationships, and ages (for family profiles)

       Preferred language

       Subscription plan and payment status

3.2 Voice and Audio Data

       Wake-word detection: processed entirely on-device using Picovoice Porcupine. No audio is transmitted to our servers for wake-word detection.

       Voice commands: audio captured after wake-word activation is transmitted to our voice processing partner (Vapi.ai) for speech-to-text transcription. Transcripts are then processed by our AI systems.

       AI screening call recordings: for business/HR users only — call transcripts and recordings of AI-conducted candidate screening calls are stored to provide screening reports.

Google Play and Apple App Store requirement: we disclose that microphone access is used for voice command functionality and AI-conducted calls. Users may revoke microphone permission at any time through device settings, which will disable voice features.

3.3 Communications Content

       With your explicit consent, Neni reads message content from connected services including Gmail, Telegram, Slack, and WhatsApp (where available). This content is processed to extract tasks, reminders, and important information.

       We do not store the full text of your messages beyond what is necessary to deliver the extracted summary. Raw message content is not retained after processing.

       Notification content (message previews) may be read on Android devices where notification access permission is granted.

3.4 Health and Wellness Data

       Medication names, dosages, and schedules (entered by you by voice or text)

       Doctor appointment records

       Step count and fitness data (read from Apple Health or Google Fit with your permission)

       Mental wellness check-in responses

       Lab report text (extracted from PDFs you upload)

Health data is treated as Sensitive Personal Data under DPDPA, Special Category Data under GDPR, and PHI-adjacent data under applicable regulations. It is not shared with third parties for advertising or marketing purposes under any circumstances.

3.5 Financial Data

       Bill names, amounts, and due dates (entered by you)

       SMS transaction alerts (read on Android with your permission to detect spending patterns — not transmitted to servers in raw form)

       Investment portfolio data read from connected financial platforms (Zerodha, Groww, Kuvera) via OAuth — we receive read-only access tokens only

       Payment information for subscriptions is handled by Razorpay. We do not store credit card numbers, debit card numbers, or full UPI IDs.

3.6 Location Data

       Approximate location for weather and commute alerts (using device GPS or IP-based location)

       Saved locations: home address and office address (entered by you)

       Real-time location for contextual reminders (e.g., "you are near the pharmacy") — used only on-device and not transmitted to our servers

3.7 Children's Data (Users Under 13)

Because Neni may be used by children under 13 through family profiles, we comply with COPPA (USA), DPDPA (India), and GDPR-K (EU/UK). The following applies:

       Children's profiles are created by a parent or legal guardian who must verify their identity and provide verifiable parental consent before a child's profile is activated.

       For children under 13, we collect: the child's first name, age, grade/class level, and learning activity history.

       We do not collect children's email addresses, phone numbers, photos, or location data.

       Learning content and quiz results for children are stored to provide the learning agent functionality and progress reporting to parents.

       No behavioural advertising is served to children's profiles.

       No third-party analytics or advertising SDKs have access to children's data.

       Parents may review, correct, or delete their child's data at any time by contacting admin@heyneni.com.

3.8 Device and Technical Data

       Device type, operating system, and version

       App version and crash logs

       IP address

       Device identifiers (used for push notifications — not shared with advertisers)

       App usage patterns (anonymised, used to improve the Service)

3.9 HR and Business Data (Business Users Only)

       Job descriptions uploaded or created in the app

       Candidate names, phone numbers, and email addresses (entered by HR users or extracted from resumes)

       Resume content (uploaded PDFs — text extracted and then the PDF is deleted within 30 days)

       AI screening call transcripts and scores

       Interview schedules

 

4. How We Use Your Information

We use your data only for the purposes listed below. We do not sell your personal data to third parties.

4.1 Providing the Service

       Delivering voice-commanded AI agents (life, finance, health, travel, learning, shopping, HR)

       Generating daily morning and evening briefs

       Monitoring connected communications channels for important messages

       Generating AI-powered learning videos for children

       Conducting AI voice screening calls for HR users

       Managing reminders, calendar events, and task boards

4.2 Personalisation and Memory

       Building and maintaining a personal memory graph that allows Neni to learn your preferences, key contacts, and patterns over time

       Adapting learning content to the child's age and curriculum

       Improving the relevance of morning briefs and proactive alerts

4.3 Account and Subscription Management

       Creating and managing your account

       Processing subscription payments via Razorpay

       Sending billing receipts and renewal reminders

4.4 Safety and Security

       Detecting and preventing fraudulent or unauthorised use

       Content moderation for children's profiles to ensure age-appropriateness

4.5 Legal Compliance

       Complying with applicable laws including DPDPA, COPPA, GDPR, and tax regulations

       Responding to lawful requests from government authorities

4.6 Service Improvement

       Analysing anonymised, aggregated usage data to improve the Service

       Bug fixing and performance monitoring

       Training and improving AI models using anonymised interaction data only — never using identifiable personal data or children's data for model training

 

5. Legal Basis for Processing

For users in the EU, EEA, and UK (GDPR), our legal bases for processing are:

       Contract: processing necessary to deliver the Service you have subscribed to

       Consent: processing of sensitive data (health, voice, communications content, children's data), location data, and optional features — you may withdraw consent at any time

       Legitimate interests: fraud prevention, security, and service improvement (where not overridden by your rights)

       Legal obligation: compliance with applicable laws

 

For users in India (DPDPA), we process data on the basis of:

       Consent: obtained at onboarding for each category of sensitive data

       Legitimate uses: as defined under the Act for service delivery, security, and legal compliance

 

6. How We Share Your Information

We do not sell your data. We share your data only with the following categories of recipients, and only to the extent necessary:

6.1 Service Providers (Data Processors)

Provider

Purpose

Data Shared

Location

Anthropic (Claude API)

AI text processing and response generation

Anonymised query text

USA

Vapi.ai

Voice speech-to-text and outbound AI calls

Audio streams, transcripts

USA

ElevenLabs

Text-to-speech voice synthesis

Response text only

USA

Kling AI / Runway ML

AI video generation for learning lessons

Scene description text only

USA / Global

Supabase

Cloud database and authentication

Account data, usage data

USA (Mumbai region for India users)

Razorpay

Payment processing

Payment details (card/UPI)

India

Twilio

SMS and WhatsApp notifications

Phone number, message text

USA

Google Cloud

Gmail API, Calendar API, ML Kit OCR

OAuth tokens, calendar data

USA

Picovoice

Wake-word detection

On-device only — no data transmitted

Canada

Amadeus / Booking.com

Flight and hotel search and booking

Travel query details

Global

 

6.2 Legal Disclosures

We may disclose your information if required by law, court order, or governmental authority. We will notify you of such requests where legally permitted.

6.3 Business Transfers

If RAGNES Technologies is involved in a merger, acquisition, or sale of assets, your data may be transferred. We will provide notice and ensure the acquiring entity honours this Privacy Policy.

6.4 No Sale of Data

We do not sell, rent, or trade your personal information to any third party for advertising, marketing, or commercial purposes.

 

7. International Data Transfers

Our service providers are located in multiple countries including the USA, India, and Canada. When we transfer data from India or the EU/EEA to other jurisdictions, we do so under:

       Standard Contractual Clauses (SCCs) approved by the European Commission for EU/UK data

       Data Processing Agreements with each service provider

       The adequacy and safeguard frameworks applicable under the DPDPA for cross-border transfers from India

By using the Service, you consent to the transfer of your information to these countries.

 

8. Data Retention

       Account data: retained for the duration of your subscription plus 90 days after account deletion

       Voice transcripts: retained for 30 days, then automatically deleted

       Message summaries: retained for 90 days

       Health data: retained until you delete it or your account

       Financial data (bills, reminders): retained until you delete it or your account

       HR candidate data: retained for 12 months from the date of screening, then deleted

       Resume PDFs: deleted within 30 days of upload after text extraction

       Learning videos and history: retained indefinitely or until the parent deletes the child's profile

       Call recordings (HR): retained for 6 months

       Crash logs and analytics: retained for 12 months in anonymised form

       Children's data: deleted immediately upon parent request or account deletion

 

You may request deletion of your data at any time by contacting admin@heyneni.com. We will process deletion requests within 30 days.

 

9. Your Privacy Rights

9.1 Rights for All Users

       Right to access: request a copy of the personal data we hold about you

       Right to rectification: request correction of inaccurate data

       Right to deletion: request deletion of your data (subject to legal retention obligations)

       Right to withdraw consent: for any processing based on consent, withdraw at any time without affecting the lawfulness of prior processing

       Right to data portability: receive your data in a structured, machine-readable format

9.2 Additional Rights for EU/UK Users (GDPR)

       Right to object to processing based on legitimate interests

       Right to restrict processing

       Right to lodge a complaint with your national Data Protection Authority

9.3 Additional Rights for California Users (CCPA/CPRA)

       Right to know what personal information is collected, used, disclosed, or sold

       Right to opt out of sale of personal information (note: we do not sell personal information)

       Right to non-discrimination for exercising your privacy rights

9.4 Rights for Indian Users (DPDPA)

       Right to access information about personal data processed

       Right to correction and erasure

       Right to grievance redressal — contact our Grievance Officer at admin@heyneni.com

       Right to nominate a person to exercise rights in case of death or incapacity

9.5 Parental Rights (Children's Data)

       Parents or legal guardians may review all data associated with a child's profile

       Parents may request correction or deletion of a child's data at any time

       Parents may revoke consent for a child's profile, which will delete the profile and all associated data within 30 days

       To exercise parental rights, contact: admin@heyneni.com

To exercise any of the above rights, please email admin@heyneni.com with the subject line 'Privacy Request'. We will respond within 30 days (or sooner as required by applicable law).

 

10. Children's Privacy (COPPA / GDPR-K / DPDPA Compliance)

Neni's family features are designed for use by children under parental supervision. We take our obligations seriously regarding children's privacy.

10.1 Parental Consent

       Before a child under 13 can use any feature of Neni, the parent or legal guardian must create a family account and explicitly activate the child's profile.

       By activating a child's profile, the parent provides verifiable parental consent for the collection and use of the child's data as described in this policy.

       For children in the EU/UK, we require additional consent verification in compliance with GDPR Article 8.

10.2 What We Do Not Do (Children)

       We do not serve behavioural advertising to children

       We do not collect children's precise location

       We do not allow children to make in-app purchases independently

       We do not share children's data with third-party advertising networks

       We do not use children's data to train AI models

       We do not collect more data from children than is necessary for the learning and educational features

10.3 Safe Mode

       Children's profiles operate in Safe Mode: all content is filtered for age-appropriateness before delivery

       Children's profiles have access only to the Learning agent, Reminders, and Weather — not to Finance, HR, Communications monitoring, or Travel booking

       All AI-generated content for children includes a child-safety filter that prevents inappropriate content

10.4 Parental Controls

       Parents can view all learning history, quiz results, and time spent in the app for each child profile

       Parents can assign lessons, set daily usage limits, and disable the child's profile at any time

       Parents receive a weekly digest of their child's learning activity

 

11. Data Security

       All data in transit is encrypted using TLS 1.2 or higher

       Data at rest is encrypted using AES-256

       API keys are stored in secure server-side environment variables — never in the mobile app bundle

       Access to personal data is restricted to authorised personnel on a need-to-know basis

       We conduct regular security reviews and vulnerability assessments

       In the event of a data breach, we will notify affected users and relevant authorities within 72 hours (GDPR) or as required by applicable law

       Sensitive data (health, financial, children's data) is stored in a segregated database with additional access controls

 

12. App Permissions

Neni requests the following device permissions. All permissions are optional unless noted — you can use basic text features without granting them:

Permission

Why Required

Can be denied?

Microphone

Wake-word detection and voice commands. Wake-word detection runs on-device only.

Yes — disables voice features; text still works

Notifications

Neni alerts and morning/evening brief delivery

Yes — disables proactive alerts

Location (approximate)

Weather, commute alerts, and contextual reminders

Yes — disables location-based features

Camera

Textbook page scanning for learning lessons

Yes — disables camera scan feature

Contacts (read only, Android)

Identifying senders in comms summaries by name

Yes — senders shown by number only

SMS (read only, Android)

Detecting bank transaction alerts for spending summaries

Yes — disables SMS spending tracking

Notification Access (Android)

Reading WhatsApp notification previews for group summaries

Yes — disables WhatsApp summariser

Health / Motion (iOS)

Reading step count and activity from Apple Health

Yes — disables fitness features

Biometric / Face ID

Optional app lock for privacy

Yes — no app lock enabled

 

13. Cookies and Tracking Technologies

On our website heyneni.com, we use:

       Essential cookies: required for login and session management — cannot be disabled

       Analytics cookies: Google Analytics 4 (anonymised IP) — you may opt out via browser settings or the cookie banner

       No advertising or tracking cookies are used on our website or in our app

The Neni mobile application does not use browser cookies. We use anonymised device identifiers for crash reporting and performance monitoring only.

 

14. Third-Party Services and Links

The Service integrates with and may link to third-party services including Google (Gmail, Calendar), Meta (WhatsApp), Slack, Telegram, Zerodha, Groww, Booking.com, and Amadeus. This Privacy Policy does not govern the privacy practices of those third parties. We recommend reading their respective privacy policies.

When you connect a third-party service to Neni, you grant us permission to access that service on your behalf as described in this policy. You may revoke that access at any time through your Neni settings or directly through the third-party service.

 

15. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. When we do, we will:

       Update the 'Effective Date' at the top of this document

       Send an in-app notification and email to all registered users

       For material changes affecting children's data, re-obtain parental consent where required

       Provide at least 14 days' notice before changes take effect

Your continued use of the Service after the effective date constitutes acceptance of the updated policy.

 

16. Grievance Officer (India — DPDPA)

As required under India's Digital Personal Data Protection Act, 2023, our Grievance Officer is:

 

Grievance Officer — RAGNES Technologies

Email: admin@heyneni.com

Address: Faridabad, Haryana, India

Response time: within 30 days of receipt of a grievance.

 

17. Contact Us

For any questions, concerns, or requests regarding this Privacy Policy or your personal data, please contact:

 

RAGNES Technologies — Privacy Team

Email: admin@heyneni.com

Website: https://www.heyneni.com/privacy

Address: Faridabad, Haryana, India

 

We will acknowledge your request within 48 hours and respond in full within 30 days.

 

 

© 2026 RAGNES Technologies. All rights reserved.