Privacy Policy
This policy explains what data Limitly collects about you, how we use and protect it, who we share it with, and the rights you have over it. Written to be readable — if anything is unclear, email dev@limitlyapp.in.
1. Who we are
Limitly is owned and operated by Neuraledge Labs Private Limited, a company incorporated in India. In this policy, "Limitly", "we", "our", and "us" refer to Neuraledge Labs Pvt Ltd.
We are the data fiduciary for your personal data under the Digital Personal Data Protection Act, 2023 (DPDPA). For contact details and our grievance officer, see section 12.
2. What we collect
2.1 Account & identity
- Mobile number — used as your account identifier across our chat surfaces (WhatsApp, Telegram, Instagram, Messenger) and our mobile app.
- Name — what TARS calls you in conversation. Provided by you on first interaction.
- Channel identifiers — the platform-specific identifier (e.g. WhatsApp phone, Telegram chat ID, Messenger PSID) issued by the respective platform when you message TARS through it. Used to recognise you across sessions on that channel.
2.2 Linked-account credentials
- When you connect a third-party service (e.g. Swiggy, Zomato, Zepto, Instamart, Blinkit, Uber, Ola), we receive an OAuth access token and refresh token scoped to your account on that service.
- We do not see, store, or have any access to your passwords, UPI PIN, OTP, card numbers, or any payment credentials.
2.3 Conversational & order data
- Messages you send to TARS and the responses TARS sends back — to power the conversation and retain short-term context within a session.
- Order references — order IDs, status snapshots, and item summaries for orders you place through TARS, so we can show you order history and help if something goes wrong.
- Addresses — the delivery addresses you select for orders (handles only — we do not store raw address payloads beyond what's needed to display them).
2.4 Financial activity (only if you opt in to the spend-tracking module)
- Categorised transaction data derived from SMS notifications on your device, processed on-device first and then stored encrypted in your account.
- Budget targets and reminder schedules you configure.
2.5 Technical & diagnostic data
- Device information (model, OS version, app version) and approximate location (city/region from IP, not GPS unless you grant the permission).
- Crash reports and performance metrics, with bearer-token and PII redaction enforced at the logging boundary.
3. How we use it
- Service delivery — to authenticate you across channels, place orders you ask for, track them, and surface your history.
- Personalisation — to remember your preferences (default address, dietary filters, budget caps) so you don't re-enter them every time.
- Safety & fraud prevention — to detect and block account-takeover attempts, abuse of OAuth tokens, and fraudulent orders.
- Customer support — to investigate issues you report.
- Aggregated, de-identified analytics — to understand product usage at a population level. Order content (specific dishes, restaurants, prices) is never included in third-party analytics.
- Legal compliance — when required by applicable law or a valid legal request.
We do not sell your personal data. We do not use your order content, message content, or financial activity for advertising. We do not share data with data brokers.
5. Where & how we store it
Your data resides in asia-south1 (Mumbai, India). The only payload that leaves the region is the inference request to our LLM provider (Google Vertex AI), which is minimised to the specific question being answered and carries no user identifiers.
We do not transfer your personal data outside India in a way that's restricted under DPDPA without your explicit consent.
6. Security
We take security seriously. Our posture includes:
- Encryption at rest — layered. The storage layer is encrypted with customer-managed keys (CMEK). Sensitive fields (OAuth tokens, addresses, financial data) are additionally sealed at the application layer with AES-256-GCM using a per-user key derived via HKDF-SHA256 from a master key held in a hardware-security-module-backed key management service. A compromise of any one user's stored data cannot recover another user's key.
- Encryption in transit — TLS 1.3 everywhere with HSTS preload and certificate pinning in the mobile app.
- Zero-trust internal architecture — services authenticate to each other via signed mTLS; no service trusts another by network position alone.
- Least-privilege access — production access requires hardware security keys (YubiKey / Titan), single sign-on, and recorded jump-host sessions. Quarterly access review with auto-revocation of unused permissions.
- Continuous testing — daily dependency scanning, static analysis on every code change, weekly dynamic application security testing, and annual third-party penetration tests.
- Mobile-app integrity — Play Integrity (Android) and App Attest (iOS) verification on sensitive operations.
No system is perfectly secure. If you discover a vulnerability, please report it confidentially to security@limitlyapp.in. We commit to a coordinated disclosure within 90 days and will not pursue legal action against good-faith researchers.
7. How long we keep it
- OAuth tokens — until you disconnect the platform or delete your Limitly account.
- Order references — 12 months rolling. Automatically purged after that window.
- Conversational context (in-session memory) — expires within 1 hour of inactivity; never written to durable storage.
- Application logs — 30 days. Bearer tokens and PII redacted at the writer.
- Backups — 7-day point-in-time recovery window.
- Security-audit logs — 1 year, in a write-once bucket. Used for forensic investigation only.
- Account deletion — completed within 30 days of your request, including cascading purge of dependent records. A minimal cryptographic tombstone of your user ID is retained for fraud-prevention auditability and contains no personal data.
8. Your rights
Under DPDPA 2023, you have the following rights as a Data Principal:
- Right to access — request a copy of all personal data we hold about you. We deliver this as a JSON bundle within 7 days of request.
- Right to correction — ask us to correct inaccurate or incomplete data.
- Right to erasure — request deletion of your account and personal data. Completed within 30 days.
- Right to grievance redressal — contact our grievance officer (section 12) for any concerns about how we handle your data.
- Right to nominate — appoint another person to exercise these rights on your behalf in case of incapacity or death.
- Right to withdraw consent — disconnect any third-party integration at any time from Settings → Linked Accounts. Revocation is immediate and irreversible from our end.
To exercise any of these rights, email dev@limitlyapp.in. We may ask you to verify your identity before fulfilling the request.
9. Cookies & tracking
Our website uses minimal cookies — only what's needed to make pages work (e.g., a short-lived session cookie during OAuth connection flows). We do not deploy advertising trackers or third-party analytics that profile you across the web.
Our mobile app uses Firebase Analytics for anonymised funnel telemetry, with PII filtering at the SDK boundary. You can opt out from Settings → Privacy → Analytics in the app.
10. Children
Limitly is intended only for users aged 18 and older. We do not knowingly collect or process personal data of children — defined under DPDPA 2023 as anyone under the age of 18.
This restriction matches the terms of service of the platforms Limitly integrates with (Swiggy, Zomato, Zepto, Blinkit, Instamart, Uber, Ola) and the Reserve Bank of India's rules governing UPI and card-based payment instruments, which all require account holders to be 18 or older.
If you believe a child has provided personal data to us, please contact our grievance officer (section 12) and we will delete it within 72 hours.
11. Changes to this policy
We may update this policy from time to time to reflect changes in our practices, new regulations, or new features. When we make material changes, we will notify you through the app and / or via a message on one of your connected channels at least 14 days before they take effect.
The "Last updated" date at the top of this policy reflects the most recent material revision.
12. Grievance officer
For any questions, complaints, or to exercise your rights under DPDPA 2023, please contact:
Neuraledge Labs Private Limited
Attn: Grievance Officer
Email: dev@limitlyapp.in
Security disclosures: security@limitlyapp.in
We will acknowledge your complaint within 72 hours and resolve it within 30 days, in line with DPDPA 2023.