Privacy Policy

Last updated: July 2026 · Effective immediately

The short version

Your library is private. We never sell your data. We never post on your behalf. You can export or delete everything, any time, in Settings.

Who we are

Ricorda ("the Service", "we", "us") is a product of insiderOne AI, developed and operated by Aurist Private Limited (CIN U62099AS2026PTC029818), an Indian company, under the global brand insiderOne Technologies FZE LLC. Ricorda is built and maintained by Bishnu Dev Changkakoti, Founder & CEO of insiderOne AI. For privacy inquiries, contact us at ricorda@insiderone.in.

This Policy applies to all users of Ricorda globally and is compliant with the EU General Data Protection Regulation (GDPR), India's Digital Personal Data Protection Act 2023 (DPDP Act), and the California Consumer Privacy Act (CCPA).

What we collect

When you use Ricorda, we collect:

  • Account information — your name, email address, and profile photo from Google Sign-In.
  • Saved URLs and extracted content — links you choose to save, along with structured data we extract (titles, ingredients, key points, etc.).
  • Profile data — any username, bio, or collection names you set.
  • Payment records — if you subscribe to Premium, we store Razorpay order IDs, payment status, and subscription validity. We do not store card numbers or UPI details — these are handled entirely by Razorpay.
  • Push notification tokens — only if you explicitly opt in to notifications.
  • TISH Points activity — a pseudonymous record of qualifying actions (action type, timestamp, earn/spend amount) stored in the TISH Points ledger. This contains no URL content, no names, and no payment data — only action identifiers and your user ID.
  • Technical logs — basic server-side error logs to keep the Service running. These do not identify individual users.

What we do not collect

  • We do not track your browsing activity outside of Ricorda.
  • We do not sell or share your personal data with third parties for their own commercial purposes.
  • We do not store passwords — sign-in is handled entirely by Google OAuth.

Legal basis for processing (GDPR)

We process your personal data under the following legal bases:

  • Contract performance — processing necessary to provide the Service you signed up for (storing saves, extracting content, managing subscriptions).
  • Legitimate interests — basic technical logging to maintain security and performance of the Service.
  • Consent — push notifications (withdraw any time in Settings) and analytics/advertising cookies (withdraw any time by clearing site data or declining in the cookie banner).

How we use your data

We use the data we collect solely to:

  • Provide the Ricorda service — saving, extracting, and organising your links.
  • Process Premium subscription payments via Razorpay.
  • Send push notifications about your saves (only if you opt in).
  • Display your public profile to others (only saves and collections you explicitly make public).
  • Maintain the security and reliability of the Service.

Third-party services

Ricorda uses the following third-party processors:

  • Supabase — database and authentication infrastructure. Data is stored in Supabase's infrastructure under their Data Processing Agreement.
  • Google OAuth — sign-in only. We receive your name, email, and profile photo. We do not access your Google Drive, Gmail, or any other Google data.
  • OpenRouter / Anthropic Claude / Google Gemini — AI extraction. The content of URLs you save is sent to these services to extract structured information. This content is processed under their respective privacy policies and is not used to train their models without consent.
  • Razorpay — payment processing for Premium subscriptions. Razorpay handles all payment data (cards, UPI, net banking). We receive only a payment confirmation and order ID. Razorpay is PCI DSS compliant.
  • Groq — used for audio/video transcription of saved media links.
  • Google Analytics — aggregate usage analytics (pages viewed, general engagement) to help us improve the Service. Only active if you accept analytics cookies in the cookie banner; IP addresses are anonymized.
  • Google AdSense — shows ads to free-plan users to support the Service. AdSense may set its own cookies and use data per Google's advertising policies. You can avoid this entirely by upgrading to Premium (ad-free) or declining non-essential cookies in the banner.
  • TISH Protocol (insiderOne AI) — Ricorda participates in the TISH Points Programme. When you perform qualifying actions (saving links, creating collections, referrals), Ricorda sends your pseudonymous user ID and action type to the TISH Points ledger (a Supabase database operated by insiderOne AI). No personally identifiable information (name, email, URL content) is included — only the user ID, action name, platform ID ("ricorda"), and timestamp. Legal basis: contract performance — this data sharing is necessary to deliver the TISH Points feature you opted into by using Ricorda. You can review all your TISH ledger entries in Settings → TISH Points.

Cookies and local storage

We use browser localStorage to store your authentication session token so you remain signed in between visits — this is always active and required for the Service to function. If you accept non-essential cookies in the cookie banner, we additionally enable Google Analytics and may show Google AdSense ads to free-plan users; both may set their own cookies under Google's privacy policies. If you decline, only the functional, sign-in-related storage is used.

Public profiles

Your saves are private by default. You control what others can see:

  • You can make individual saves or collections public.
  • You can set your entire profile to private at any time in Settings.
  • Only information you explicitly make public will be visible to others.

Your rights

Depending on your location, you have the following rights over your personal data. To exercise any of these, email us at ricorda@insiderone.in or use the controls in Settings.

  • Right to access — request a copy of all personal data we hold about you.
  • Right to portability — download all your data in machine-readable JSON format directly from Settings → Export my data.
  • Right to rectification — correct inaccurate data by updating your profile in Settings.
  • Right to erasure ("right to be forgotten") — permanently delete your account and all associated data from Settings → Delete account. Deletion is permanent and immediate.
  • Right to restrict processing — contact us to request that we restrict how we process your data.
  • Right to object — object to processing based on legitimate interests by contacting us.
  • Right to withdraw consent — disable push notifications at any time in Settings.

EU/EEA users may also lodge a complaint with their local Data Protection Authority. Indian users may contact the Data Protection Board of India once operational.

Data retention

We retain your data for as long as your account is active. When you delete your account, all personal data (account, saves, profile, payment records) is permanently and immediately removed from our systems. Automated backups are purged within 30 days.

Data transfers

Ricorda is operated from India. Our infrastructure (Supabase) may store data in servers located in other regions. By using the Service, you consent to the transfer of your data to these regions. We ensure all processors provide adequate data protection through their standard contractual commitments.

Security

We use industry-standard security practices: encrypted connections (HTTPS/TLS), row-level security policies on the database ensuring users can only access their own data, and short-lived session tokens. We never store passwords.

Children and minors

Ricorda is intended for users aged 18 and over. Under India's Digital Personal Data Protection Act 2023, a "child" is anyone under 18, and processing a child's personal data requires verifiable consent from a parent or lawful guardian. We do not knowingly collect personal data from anyone under 18 without such consent, and we do not undertake tracking, behavioural monitoring, or targeted advertising directed at children. By creating an account you confirm you are 18 or older, or that a parent or guardian has consented to your use. If you believe a minor has provided us with personal data without the required consent, contact us and we will delete it promptly.

How we handle a data breach

In the event of a personal data breach, we will take reasonable measures to mitigate it and, in accordance with the DPDP Act 2023, notify both the Data Protection Board of India and each affected user without undue delay. Our notice to you will describe, to the extent known, the nature of the breach, the data involved, the likely consequences, and the steps we are taking in response.

Your consent and how to withdraw it

We process your personal data on the basis of the consent you give when you create your account and accept these terms, and for the specific purposes described in this policy. We record the exact date and time you give consent (for example, when you accept the Terms of Service at sign-up) so there is a clear, verifiable record. You may withdraw your consent at any time by deleting your account in Settings, disabling optional features such as push notifications or analytics cookies, or contacting our Grievance Officer. Withdrawing consent does not affect processing carried out before the withdrawal, and some processing necessary to provide the core Service may mean the Service can no longer be offered to you once consent is withdrawn.

Grievance Officer (India — DPDP Act 2023 & IT Rules 2021)

In accordance with India's Digital Personal Data Protection Act 2023 and the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules 2021, the Grievance Officer for Ricorda is:

Bishnu Dev Changkakoti
Founder & CEO, insiderOne AI
Aurist Private Limited (Indian operations)
Email: grievance@insiderone.in
Alternate: ricorda@insiderone.in
Response time: acknowledgement within 24 hours, resolution within 15 days.

Changes to this policy

If we make material changes to this policy, we will update the date at the top of this page. For significant changes, we will notify you via email or an in-app notice. Continued use of Ricorda after changes constitutes acceptance.

Contact

Privacy questions? Email us at ricorda@insiderone.in. We respond within 30 days.