Privacy policy

Legal

Privacy Policy

Neni (heyneni.com) — Effective Date: 21 August 2026 — Issued by: RAGNES Technologies, Faridabad, Haryana, India

This policy is designed to meet the requirements of India’s Digital Personal Data Protection Act 2023 (DPDPA), Google Play Developer Program Policies, Apple App Store Review Guidelines, the US Children’s Online Privacy Protection Act (COPPA), the EU/UK General Data Protection Regulation (GDPR), and the California Consumer Privacy Act (CCPA). Please read it carefully.

RAGNES Technologies (“we”, “us”, “our”) operates the Neni application and the website heyneni.com (collectively, “the Service”). This Privacy Policy explains what personal information we collect, why we collect it, how we use and protect it, and what rights you have over your data.

By downloading, installing, or using the Neni application, you agree to the collection and use of information in accordance with this policy. If you do not agree, please do not use the Service.

Neni is an AI-powered life operating system for families. Because the Service involves voice data, health-related information, financial data, communications content, and features accessible to children under 13, this policy contains specific and detailed disclosures for each category.

RAGNES Technologies
Faridabad, Haryana, India
Email: admin@heyneni.com
Website: heyneni.com

For users in the European Economic Area (EEA) or United Kingdom, RAGNES Technologies acts as the data controller under GDPR. For users in India, RAGNES Technologies acts as the data fiduciary under the Digital Personal Data Protection Act, 2023.

3.1 Account and Identity Data

  • Full name and email address
  • Phone number (for account verification and WhatsApp integration)
  • Profile photograph (if provided)
  • Family member names, relationships, and ages (for family profiles)
  • Preferred language, subscription plan, and payment status

3.2 Voice and Audio Data

  • Wake-word detection: processed entirely on-device using Picovoice Porcupine. No audio is transmitted to our servers for wake-word detection.
  • Voice commands: audio captured after wake-word activation is transmitted to our voice processing partner (Vapi.ai) for speech-to-text transcription. Transcripts are then processed by our AI systems.
  • AI screening call recordings (HR users only): transcripts and recordings of AI-conducted candidate screening calls are stored to provide screening reports.

Microphone access is used for voice command functionality and AI-conducted calls. Users may revoke microphone permission at any time through device settings, which will disable voice features.

3.3 Communications Content

  • With your explicit consent, Neni reads message content from connected services including Gmail, Telegram, Slack, and WhatsApp (where available). Content is processed to extract tasks, reminders, and important information.
  • We do not store the full text of your messages beyond what is necessary to deliver the extracted summary. Raw message content is not retained after processing.
  • Notification content (message previews) may be read on Android devices where notification access permission is granted.

3.4 Health and Wellness Data

  • Medication names, dosages, and schedules (entered by you by voice or text)
  • Doctor appointment records and fitness/step data (from Apple Health or Google Fit)
  • Mental wellness check-in responses
  • Lab report text (extracted from PDFs you upload)

Health data is treated as Sensitive Personal Data under DPDPA, Special Category Data under GDPR, and PHI-adjacent data under applicable regulations. It is not shared with third parties for advertising or marketing under any circumstances.

3.5 Financial Data

  • Bill names, amounts, and due dates (entered by you)
  • SMS transaction alerts (read on Android with your permission to detect spending patterns — not transmitted to servers in raw form)
  • Investment portfolio data read from connected financial platforms (Zerodha, Groww, Kuvera) via OAuth — read-only access tokens only
  • Payment information for subscriptions is handled by Razorpay. We do not store credit card numbers, debit card numbers, or full UPI IDs.

3.6 Location Data

  • Approximate location for weather and commute alerts (using device GPS or IP-based location)
  • Saved locations: home address and office address (entered by you)
  • Real-time location for contextual reminders — used only on-device and not transmitted to our servers

3.7 Children’s Data (Users Under 13)

Neni complies with COPPA (USA), DPDPA (India), and GDPR-K (EU/UK) for children’s profiles:

  • Children’s profiles are created by a parent or legal guardian who must verify their identity and provide verifiable parental consent before activation.
  • For children under 13 we collect: first name, age, grade/class level, and learning activity history only.
  • We do not collect children’s email addresses, phone numbers, photos, or location data.
  • No behavioural advertising is served to children’s profiles. No third-party analytics or advertising SDKs have access to children’s data.
  • Parents may review, correct, or delete their child’s data at any time by contacting admin@heyneni.com.

3.8 Device and Technical Data

  • Device type, operating system, version, and app version
  • Crash logs, IP address, and device identifiers (used for push notifications — not shared with advertisers)
  • App usage patterns (anonymised, used to improve the Service)

3.9 HR and Business Data (Business Users Only)

  • Job descriptions uploaded or created in the app
  • Candidate names, phone numbers, and email addresses (entered by HR users or extracted from resumes)
  • Resume content (uploaded PDFs — text extracted and PDF deleted within 30 days)
  • AI screening call transcripts, scores, and interview schedules

We use your data only for the following purposes. We do not sell your personal data to third parties.

  • Providing the Service: delivering all AI agents, daily briefs, inbox monitoring, learning videos, HR screening calls, reminders, and calendar management
  • Personalisation: building and maintaining your personal memory graph; adapting learning content and briefs to your context
  • Account and subscription management: processing payments via Razorpay; sending billing receipts and renewal reminders
  • Safety and security: detecting fraudulent or unauthorised use; content moderation for children’s profiles
  • Legal compliance: complying with DPDPA, COPPA, GDPR, and tax regulations; responding to lawful government requests
  • Service improvement: analysing anonymised usage data; bug fixing; training AI models using anonymised interaction data only — never using identifiable personal data or children’s data

GDPR (EU/EEA/UK users)

  • Contract: processing necessary to deliver the Service you subscribed to
  • Consent: processing of sensitive data (health, voice, communications, children’s data), location data, and optional features. You may withdraw consent at any time.
  • Legitimate interests: fraud prevention, security, and service improvement
  • Legal obligation: compliance with applicable laws

DPDPA (India users)

  • Consent: obtained at onboarding for each category of sensitive data
  • Legitimate uses: as defined under the Act for service delivery, security, and legal compliance

6.1 Service Providers (Data Processors)

We do not sell your data. We share your data only with the following service providers, and only to the extent necessary:

Provider Purpose Data Shared Location
Anthropic (Claude API) AI text processing Anonymised query text USA
Vapi.ai Voice speech-to-text and AI calls Audio streams, transcripts USA
ElevenLabs Text-to-speech synthesis Response text only USA
Kling AI / Runway ML AI video generation for lessons Scene description text only USA / Global
Supabase Cloud database and authentication Account data, usage data USA (Mumbai region for India users)
Razorpay Payment processing Payment details (card/UPI) India
Twilio SMS and WhatsApp notifications Phone number, message text USA
Google Cloud Gmail API, Calendar API, OCR OAuth tokens, calendar data USA
Picovoice Wake-word detection On-device only — no data transmitted Canada
Amadeus / Booking.com Flight and hotel search Travel query details Global

6.2 Legal Disclosures

We may disclose your information if required by law, court order, or governmental authority. We will notify you of such requests where legally permitted.

6.3 Business Transfers

If RAGNES Technologies is involved in a merger, acquisition, or sale of assets, your data may be transferred. We will provide notice and ensure the acquiring entity honours this Privacy Policy.

Our service providers are located in multiple countries including the USA, India, and Canada. When we transfer data from India or the EU/EEA to other jurisdictions, we do so under Standard Contractual Clauses (SCCs) approved by the European Commission for EU/UK data, Data Processing Agreements with each service provider, and the adequacy and safeguard frameworks applicable under the DPDPA for cross-border transfers from India.

  • Account data: retained for the duration of your subscription plus 90 days after account deletion
  • Voice transcripts: retained for 30 days, then automatically deleted
  • Message summaries: retained for 90 days
  • Health data: retained until you delete it or your account
  • Financial data (bills, reminders): retained until you delete it or your account
  • HR candidate data: retained for 12 months from the date of screening, then deleted
  • Resume PDFs: deleted within 30 days of upload after text extraction
  • Call recordings (HR): retained for 6 months
  • Children’s data: deleted immediately upon parent request or account deletion
  • Crash logs and analytics: retained for 12 months in anonymised form

You may request deletion of your data at any time by contacting admin@heyneni.com. We will process deletion requests within 30 days.

All users

  • Right to access: request a copy of the personal data we hold about you
  • Right to rectification: request correction of inaccurate data
  • Right to deletion: request deletion of your data (subject to legal retention obligations)
  • Right to withdraw consent: for any processing based on consent, withdraw at any time
  • Right to data portability: receive your data in a structured, machine-readable format

EU/UK users (GDPR)

  • Right to object to processing based on legitimate interests
  • Right to restrict processing
  • Right to lodge a complaint with your national Data Protection Authority

California users (CCPA/CPRA)

  • Right to know what personal information is collected, used, disclosed, or sold
  • Right to opt out of sale of personal information (note: we do not sell personal information)
  • Right to non-discrimination for exercising your privacy rights

Indian users (DPDPA)

  • Right to access information about personal data processed
  • Right to correction and erasure
  • Right to grievance redressal — contact our Grievance Officer at admin@heyneni.com
  • Right to nominate a person to exercise rights in case of death or incapacity

Parental rights (children’s data)

  • Parents may review all data associated with a child’s profile at any time
  • Parents may request correction or deletion of a child’s data at any time
  • Parents may revoke consent for a child’s profile, which will delete the profile and all associated data within 30 days
  • To exercise parental rights: admin@heyneni.com

To exercise any of the above rights, email admin@heyneni.com with subject line ‘Privacy Request’. We will respond within 30 days.

Parental consent

  • Before a child under 13 can use any feature of Neni, the parent or legal guardian must create a family account and explicitly activate the child’s profile.
  • By activating a child’s profile, the parent provides verifiable parental consent for the collection and use of the child’s data as described in this policy.
  • For children in the EU/UK, we require additional consent verification in compliance with GDPR Article 8.

What we do NOT do (children)

  • We do not serve behavioural advertising to children
  • We do not collect children’s precise location
  • We do not allow children to make in-app purchases independently
  • We do not share children’s data with third-party advertising networks
  • We do not use children’s data to train AI models

Safe Mode and parental controls

  • Children’s profiles operate in Safe Mode: all content is filtered for age-appropriateness before delivery
  • Children’s profiles have access only to the Learning agent, Reminders, and Weather
  • Parents can view all learning history, quiz results, and time spent in the app for each child profile
  • Parents can assign lessons, set daily usage limits, and disable the child’s profile at any time
  • All data in transit is encrypted using TLS 1.2 or higher
  • Data at rest is encrypted using AES-256
  • API keys are stored in secure server-side environment variables — never in the mobile app bundle
  • Access to personal data is restricted to authorised personnel on a need-to-know basis
  • We conduct regular security reviews and vulnerability assessments
  • In the event of a data breach, we will notify affected users and relevant authorities within 72 hours (GDPR) or as required by applicable law

Neni requests the following device permissions. All permissions are optional unless noted — you can use basic text features without granting them:

Permission Why Required Can be denied?
Microphone Wake-word detection and voice commands. Wake-word runs on-device only. Yes — disables voice; text still works
Notifications Neni alerts and morning/evening brief delivery Yes — disables proactive alerts
Location (approximate) Weather, commute alerts, and contextual reminders Yes — disables location-based features
Camera Textbook page scanning for learning lessons Yes — disables camera scan feature
Contacts (read only, Android) Identifying senders in comms summaries by name Yes — senders shown by number only
SMS (read only, Android) Detecting bank transaction alerts for spending summaries Yes — disables SMS spending tracking
Notification Access (Android) Reading WhatsApp notification previews for group summaries Yes — disables WhatsApp summariser
Health / Motion (iOS) Reading step count and activity from Apple Health Yes — disables fitness features
Biometric / Face ID Optional app lock for privacy Yes — no app lock enabled
  • Essential cookies: required for login and session management on heyneni.com — cannot be disabled
  • Analytics cookies: Google Analytics 4 (anonymised IP) — you may opt out via browser settings or the cookie banner
  • No advertising or tracking cookies are used on our website or in our app
  • The Neni mobile application does not use browser cookies. We use anonymised device identifiers for crash reporting and performance monitoring only.

The Service integrates with and may link to third-party services including Google (Gmail, Calendar), Meta (WhatsApp), Slack, Telegram, Zerodha, Groww, Booking.com, and Amadeus. This Privacy Policy does not govern the privacy practices of those third parties. When you connect a third-party service to Neni, you grant us permission to access that service on your behalf as described in this policy. You may revoke that access at any time through your Neni settings or directly through the third-party service.

  • We will update the ‘Effective Date’ at the top of this document when changes are made
  • We will send an in-app notification and email to all registered users
  • For material changes affecting children’s data, we will re-obtain parental consent where required
  • We will provide at least 14 days’ notice before changes take effect

As required under India’s Digital Personal Data Protection Act, 2023:

Grievance Officer — RAGNES Technologies
Email: admin@heyneni.com
Address: Faridabad, Haryana, India
Response time: within 30 days of receipt of a grievance.

Contact Us

For any questions, concerns, or requests regarding this Privacy Policy or your personal data:

RAGNES Technologies — Privacy Team
Email: admin@heyneni.com
Website: heyneni.com/privacy
Address: Faridabad, Haryana, India

We will acknowledge your request within 48 hours and respond in full within 30 days.

© 2026 RAGNES Technologies. All rights reserved.