Loading Sarthi

Legal

Cookie and Tracking Technologies Policy

How SarthiAI uses cookies, local storage, SDKs, session tokens and similar technologies on sarthiai.co.in and in the SarthiAI mobile applications.

  • Effective date26 July 2026
  • Last updated26 July 2026
  • Version1.0

1Purpose and Scope

This Cookie and Tracking Technologies Policy explains how Sarth AI Tech LLP, operating SarthiAI (“SarthiAI”, “we”, “us” or “our”), uses cookies and similar technologies on its websites, including sarthiai.co.in and associated subdomains, and in the SarthiAI mobile applications and related interfaces.

This Policy should be read with the SarthiAI Privacy Policy, Terms of Service and any notice displayed when a permission or technology is activated. For convenience, this Policy uses “tracking technologies” as a collective term for cookies, local storage, session storage, pixels, SDKs, session tokens, OAuth identifiers and related tools. Their inclusion in this Policy does not mean that SarthiAI uses them for advertising or tracks users across unrelated services.

2What These Technologies Are

2.1 Website technologies

Cookies are small text files placed on your device when you visit a website; they help the website function properly, remember preferences, enhance user experience and support security, performance or other disclosed features. A first‑party cookie is set by the SarthiAI domain being visited, and a third‑party cookie is set by another provider whose service is embedded in or called from the website.

Websites may also use local storage, session storage, pixels, tags, scripts, server‑side events, cache identifiers and similar technologies. These can remember a session, secure a login, store a consent choice, measure performance or enable another disclosed function necessary for the requested service.

2.2 Mobile‑app technologies

Mobile apps may use software development kits (SDKs), app‑instance identifiers, push‑notification tokens, secure device storage, crash logs, diagnostic events and operating‑system permissions. These technologies are not necessarily “cookies”, but can perform related functions, such as authentication, session management or performance measurement, and may involve personal data.

2.3 Authentication and security tokens

SarthiAI uses short‑lived or persistent session tokens and similar security tokens to authenticate a user, prevent account takeover, remember a signed‑in session and protect requests. These tokens are treated as strictly necessary security technologies, and they are not used for unrelated advertising, behavioural profiling or cross‑service tracking.

3Categories and Purposes

3.1 Strictly necessary and security technologies

Strictly necessary and security technologies are required to provide a service requested by the user or to protect the website, app, accounts and network. They may be used to:

  • keep a user signed in and maintain a secure session;
  • route traffic and balance service load;
  • prevent fraud, abuse, automated attacks and account compromise;
  • remember a privacy or consent choice;
  • complete checkout or provide a user‑requested feature; and
  • maintain basic accessibility, language or interface functions necessary for delivery.

Where permitted by law, strictly necessary technologies may operate without optional consent, provided they are limited to what is reasonably required for core functionality and security. They must not be reclassified as “necessary” merely because they are commercially useful.

3.2 Functional technologies

Functional technologies remember optional choices or enable enhanced features, such as language and interface preferences, saved learning settings, support widgets or permitted media functionality. Where consent is required, functional technologies will remain disabled until the user opts in through the preference centre or in‑app settings.

3.3 Analytics and performance technologies

Analytics and performance technologies may help SarthiAI understand whether pages and features work, identify crashes, measure latency and improve usability. Any analytics implementation must use the least intrusive configuration reasonably available, minimise identifiers and disable advertising features unless separately disclosed and lawfully supported.

For Child and unknown‑age users, analytics and SDK use must comply with applicable child‑data and app‑platform requirements. SarthiAI does not transmit prohibited advertising identifiers, does not use analytics to build behavioural advertising profiles of Children, and limits analytics for minors to strictly necessary safety, reliability and performance measurements.

3.4 Advertising, attribution and remarketing technologies

SarthiAI has adopted and now commits to Position A - no advertising. Under this position:

  • SarthiAI does not use advertising, cross‑service remarketing or behavioural‑advertising technologies on its websites, mobile applications or institution interfaces.
  • SarthiAI does not deploy advertising identifiers, tracking cookies, unique device IDs or cross‑service tags for targeted advertising to any user, including adults.
  • No technology is implemented for the purpose of audience building, ad attribution, retargeting or cross‑platform behavioural profiles.

Any technology with an advertising or attribution capability will be excluded from the production stack or configured so that advertising and remarketing features are disabled, and such a tool will not be listed as mere “analytics” if it can use data for cross‑service advertising or provider purposes.

4How Choices Are Obtained

Where consent is required, SarthiAI will present a clear banner or preference centre before activating non‑essential website technologies. The interface will:

  • identify the principal purposes in plain language;
  • offer granular category choices (for example, functional and analytics);
  • provide an equally visible method to reject non‑essential technologies;
  • avoid pre‑ticked boxes, forced consent, misleading button design and subscription or privacy dark patterns;
  • record the user’s choice and apply it to the covered domain or app; and
  • allow withdrawal or change through the “Cookie Settings” link in the website footer or the in‑app privacy settings menu.

Withdrawal applies prospectively; it may not remove data lawfully processed before withdrawal, but technologies disabled by the new choice will no longer be used for the withdrawn purpose. Strictly necessary technologies cannot be disabled through the preference centre; a user may block them through browser or device settings, but parts of the service may then stop working.

5Child and Institution‑Linked Users

SarthiAI applies age‑appropriate defaults to protect Child and unknown‑age users. For such users:

  • non‑essential tracking remains off unless lawfully enabled through the approved parental/guardian consent route or institution‑managed workflow consistent with the DPDP Act and platform rules;
  • targeted advertising, behavioural advertising and detrimental profiling are not permitted;
  • prohibited advertising identifiers are not collected or transmitted;
  • only APIs and SDKs approved for the relevant child‑directed use may operate, and child‑directed experiences are gated by minor‑safety controls and content filters;
  • institution settings cannot reduce protections required by law or app‑platform policy.

A parent, guardian or authorised institution administrator may manage the available privacy settings for a Child account, subject to the access rules disclosed during onboarding and the technical safeguards described in the Privacy Policy.

6Third‑Party Technologies

Some technologies are provided by third parties, such as authentication, cloud, analytics, crash‑reporting, content‑delivery, payments, customer support or embedded‑media providers. SarthiAI remains responsible for accurately disclosing SDK and third‑party data practices in its policies and app‑store declarations and for ensuring that such technologies are configured in line with this Policy.

Third parties may act as processors for SarthiAI or, for limited activities, as independent Data Fiduciaries. Schedule 1 identifies key providers and technologies and, where appropriate, indicates the relevant environment and processing location. SarthiAI will not state that a provider is an independent controller merely to avoid responsibility for an embedded SDK or technology that it chooses to integrate.

7Browser, Device and Platform Controls

Users can usually delete or block cookies through browser settings, reset permitted advertising identifiers, limit app tracking, revoke microphone or file access, turn off notifications and manage other permissions through device settings. Browser or device controls may operate differently from SarthiAI’s preference centre, and blocking all storage or permissions can affect authentication, uploads, voice features or other functionality. Refusing an optional permission will not prevent use of unrelated core features.

Some browsers send “Do Not Track” (DNT) or Global Privacy Control (GPC) signals. Where a signal is legally binding or technically supported in a given environment, SarthiAI will honour it as required by applicable law and platform rules. Otherwise, users should use the SarthiAI preference centre and in‑app privacy settings for a reliable and verifiable choice over non‑essential technologies.

8Retention

Each technology will operate only for the duration stated in Schedule 1 or, for other tools, for the period reasonably required for the disclosed purpose. Session technologies, such as session tokens used to keep a user signed in, expire when the browser or app session ends or shortly thereafter; persistent technologies remain until their stated expiry, deletion or withdrawal, whichever occurs first, subject to technical and legal constraints.

Optional front‑end tracking cookies and similar technologies are heavily restricted and either disabled by default or configured for the shortest reasonably effective lifespan consistent with their non‑essential function. Consent records for cookie and tracking‑technology choices, together with underlying system‑access logs and security telemetry related to those choices, are preserved for a mandatory baseline duration of one year to safely clear domestic cybersecurity (CERT‑In) regulatory tracking cycles. Security and system logs may be retained beyond one year only where justified for security, fraud, disputes or legal compliance, in line with the Privacy Policy.

9Changes to This Policy

We may update this Policy when technologies, providers, purposes or legal requirements change. We will update the “Last updated” field and, where a material new non‑essential purpose is introduced, seek fresh consent before activating it for a user.

The production release process is designed to prevent a new SDK, tag or tracking purpose from being deployed until the technology inventory, consent logic, Privacy Policy and app‑store disclosures have been reviewed and updated as necessary.

10Contact

Data Fiduciary
Sarth AI Tech LLP.
Registered office
1010 United Athashri, DN Parande Park Marg, Dhanori, Pune, Maharashtra 411047
Grievance Officer
Rushikesh Patil, rushikesh@sarthiai.co.in

Users may also contact SarthiAI through the privacy and support channels published in the Privacy Policy and on the official website.