Privacy Policy
Product: Asmuth (also referred to as Asmuth AI)
Last updated: 1 August 2026
Scope: Global — including India, the European Union / EEA / United Kingdom, Canada, the United States, Latin America (including Brazil), and other regions where the Services are offered.
Note: The legal entity name (
LEGAL_NAME) and Indian jurisdiction state (STATE) remain TBD until finalized. Support email and site URL below are live.
Introduction
This Privacy Policy describes how TBD, trading as Asmuth (“Company,” “we,” “us,” or “our”), collects, uses, stores, and shares personal information when you use our Services, including:
- Our website at
https://asmuthai.comand related web pages (including the logged-in dashboard) - The Asmuth desktop application (Windows and any other platforms we offer)
- Related products, accounts, and communications that link to this Privacy Policy
Asmuth is offered globally. We are established in India, and we also serve users in Europe, Canada, the United States, South America, and other regions. Where local law gives you stronger rights than this Policy, those rights apply.
By using the Services, you acknowledge this Privacy Policy. If you do not agree, do not use the Services.
Questions or privacy requests? Contact support@asmuthai.com.
Summary of key points
- We collect account details (such as name and email), usage meters (AI credits and listening time), and content you create in the product (chats, settings, analytics).
- Payments are processed by Dodo Payments; we do not store full card, UPI, or similar payment credentials.
- AI features may send prompts, transcripts, or images to subprocessors (cloud proxy, model providers, speech providers) to deliver the Service.
- We do not sell your personal information.
- You must be at least 18 (or the age of majority in your country, if higher) to use Asmuth.
- Depending on where you live, you may have rights to access, correct, delete, restrict, object, port data, or withdraw consent — see Regional privacy rights below.
- Data may be processed in India and other countries where our providers operate; we use appropriate transfer safeguards where required.
1. What information do we collect?
1.1 Personal information you provide
Depending on how you use Asmuth, we may collect:
- Account data: name, email address, profile photo / avatar, and similar identifiers from Appwrite authentication or Google (or other) OAuth sign-in
- Contact & support: messages you send to support, refund requests, and related correspondence
- Profile & preferences: interview role, response settings, system prompts, and other settings you choose to save
- User content: chat conversations, messages, performance / interview analytics records, resumes or documents you upload (if that feature is enabled), and similar content you create in the Services
- Billing contact details: name, email, country, and other details needed for checkout (as collected via Dodo Payments / our Site)
1.2 Usage and billing meters
We maintain usage records needed to operate prepaid packs and enforce limits, including (field names may appear in our systems as):
aiCreditsUsed/ AI credits consumedlisteningSecondsUsed/ meeting-audio listening time- Granted limits such as
aiCreditsLimitandlisteningSecondsLimit - Plan badge (for example free, starter, pro, pro_plus)
- Optional activity summaries (for example weekly listening / response activity)
- Purchase / pack application identifiers needed for entitlements and refunds
1.3 Payment-related information
If you purchase a pack, Dodo Payments processes your payment. We may receive limited transaction metadata (for example payment status, amount, currency, transaction / purchase id, and your account email) so we can grant the correct pack. Card numbers, UPI credentials, and similar payment instruments are handled by Dodo Payments, not stored by Asmuth as full payment credentials.
Payment methods available to you may depend on your country (for example cards, local methods, or UPI where offered). See Dodo Payments’ privacy documentation for how they process payment data.
1.4 Information collected automatically
When you use the website or desktop app, we may automatically collect:
- Technical / device data: IP address, approximate location derived from IP, browser or WebView type, operating system, device identifiers as available, app version, language, and similar diagnostics
- Log data: timestamps, feature usage events, error logs, and crash or performance diagnostics needed to secure and improve the Services
- Cookies and similar technologies on the website (see Section 5)
1.5 Desktop audio, microphone, and screen features
The desktop app may, with your permission and for features you enable:
- Capture microphone audio (for example “Ask AI” or interview evaluation)
- Capture system / meeting audio for transcription
- Capture screenshots or screen content for screen analysis
Audio and images may be processed on your device and/or sent to our cloud proxy and subprocessors to generate transcripts or AI responses. You control when these features run (for example by toggling listening or screen analysis).
Important: You are responsible for complying with recording and consent laws in your country and for any third-party rules that apply to your conversations or interviews.
1.6 Sensitive / special-category information
We do not require you to provide special-category data (for example race, religion, health, or biometric templates used for identification). Content you type, speak, or capture during interviews may incidentally include sensitive details; you choose what to share. Do not use Asmuth to process data you are not allowed to share under law or third-party rules.
Where EU/UK GDPR “special category” data appears only because you voluntarily include it in prompts or recordings, we process it only as needed to provide the feature you requested, based on your consent and/or the fact that you clearly made the information public to the Service by submitting it — and you should avoid submitting such data unless necessary.
1.7 Information from third parties
We may receive account profile information from identity providers (for example Google) when you choose social login, and payment confirmation metadata from Dodo Payments.
2. How do we process your information?
We process personal information to:
- Create and manage your account and authenticate you
- Provide the desktop overlay, website dashboard, AI responses, transcription, analytics, and sync across devices
- Enforce plan limits, apply purchased packs, and prevent fraud or abuse
- Process purchases and refunds in line with our Refund Policy
- Communicate with you about the Service, security, and support
- Improve reliability, safety, and product quality (including debugging and aggregated metrics)
- Comply with law and enforce our Terms
3. Legal bases (EU / UK GDPR and similar regimes)
Where data-protection laws require a “legal basis” (including GDPR / UK GDPR), we typically rely on:
| Basis | Examples |
|---|---|
| Contract | Creating your account; delivering AI features you request; applying packs you buy |
| Legitimate interests | Security, fraud prevention, service improvement, essential product analytics — balanced against your rights |
| Consent | Non-essential cookies/marketing where required; optional processing you clearly opt into (you may withdraw consent) |
| Legal obligation | Tax, accounting, responding to lawful requests |
For India, we process personal data in accordance with applicable Indian law (including the Digital Personal Data Protection Act, 2023, as it applies).
For Canada, we process personal information with consent (express or implied as permitted) and/or as needed to provide the Services, consistent with PIPEDA and, where applicable, provincial laws such as Quebec’s Law 25.
For Brazil (LGPD) and other Latin American regimes, we rely on comparable bases (performance of contract, legitimate interest, consent, legal obligation) as applicable.
4. When and with whom do we share personal information?
We may share information with:
| Recipient | Purpose |
|---|---|
| Appwrite | Authentication, database, and account-related storage |
| Cloudflare (including our Worker / proxy) | Secure API proxying, usage writes, and infrastructure |
| AI / model providers (via our proxy, e.g. OpenRouter and underlying model hosts) | Generate AI responses from prompts, context, and images you submit |
| Speech-to-text providers (e.g. AssemblyAI, when STT is used) | Transcribe audio you choose to capture |
| Dodo Payments | Process payments and payment-related webhooks worldwide |
| Service providers | Hosting, email, analytics, or support tools under appropriate agreements |
| Authorities | When required by law or to protect rights, safety, and security |
| Business transfers | In connection with a merger, acquisition, or sale of assets, subject to appropriate protections |
We do not sell your personal information and we do not “share” it for cross-context behavioural advertising as those terms are used under California law, except as disclosed if we later enable such advertising (we will update this Policy first).
We do not grant pack entitlements from the public website or desktop client using payment secrets; pack grants are applied by our trusted server (Cloudflare Worker) after verified payment events.
5. Cookies and similar technologies
Our website may use cookies or local storage for:
- Sign-in / session continuity
- Preferences
- Security and basic analytics
Where required (for example in the EU/UK), we will present a cookie preference mechanism for non-essential cookies. You can also control cookies through your browser settings. Some features may not work if cookies are disabled.
6. Artificial intelligence features
Asmuth provides AI-assisted features (interview help, mock interviews, screen analysis, scoring, and related tools).
- Prompts, transcripts, chat history, screenshots, and related context you submit may be sent to AI subprocessors to generate outputs.
- AI outputs can be incorrect or incomplete. Do not rely on them as sole professional, legal, or career advice.
- We design the product so API keys for upstream AI providers are not embedded in the public desktop frontend; requests are proxied through our infrastructure.
- You should not submit other people’s personal data into prompts or recordings unless you have a lawful basis and any required notices/consents.
7. Social logins
If you sign in with Google (or another provider), we receive basic profile information allowed by that provider and your settings (typically name, email, and avatar). Your use of the provider is also governed by that provider’s policies.
8. How long do we keep information?
We keep personal information as long as needed to provide the Services, maintain accounts, resolve disputes, enforce agreements, and meet legal / accounting requirements.
- Account and usage data: generally for the life of the account, plus a reasonable period after deletion for backups and legal retention
- Purchase / refund records: as required for tax and payment compliance in relevant countries
- Support correspondence: as needed to resolve your request and for legitimate business records
When we no longer need personal information, we delete or anonymize it where reasonably possible.
9. How do we keep information safe?
We use organizational and technical measures appropriate to our size and risk profile (for example access controls, encrypted transport (HTTPS), server-side secrets for payment and API keys, and least-privilege design for usage writes).
No method of transmission or storage is 100% secure. We cannot guarantee absolute security against unauthorized access. If a breach that must be notified occurs under applicable law, we will notify you and/or regulators as required.
10. Minors
The Services are intended for users who are at least 18 years old, or the age of majority in your jurisdiction if higher. We do not knowingly collect personal information from children. If you believe we have collected such information, contact support@asmuthai.com and we will take appropriate steps to delete it.
11. Regional privacy rights
11.1 Rights that may apply to you (summary)
Depending on where you live, you may have some or all of the following rights:
- Access / know what personal information we process
- Correct / rectify inaccurate information
- Delete / erase information (subject to legal retention)
- Portability of data you provided, in a usable format
- Restrict or object to certain processing (including profiling for marketing)
- Withdraw consent where processing is based on consent
- Appeal a refusal (where required, e.g. some US state laws)
- Lodge a complaint with a supervisory authority
How to exercise rights: email support@asmuthai.com or use in-product account deletion where available. We may need to verify your identity. We will respond within the time required by applicable law (for example, typically within one month under GDPR, subject to extensions).
11.2 European Union, EEA, and United Kingdom (GDPR / UK GDPR)
If you are in the EU/EEA/UK, TBD is the controller of your personal data for the Services (unless a specific feature names another controller).
You may lodge a complaint with your local data protection authority (for example your EU member-state DPA or the UK ICO). You also have the rights listed above, including objection to processing based on legitimate interests and to direct marketing.
International transfers: Your data may be transferred outside the EU/UK (including to India and countries where our providers operate). Where required, we use appropriate safeguards such as Standard Contractual Clauses (SCCs) / UK equivalent addenda, provider certifications, or other lawful transfer mechanisms.
11.3 Canada (PIPEDA and provincial laws)
Canadian users may request access to and correction of personal information, and may withdraw consent (subject to legal or contractual restrictions and reasonable notice). Quebec residents may have additional rights under Law 25 (including transparency and, where applicable, rights related to automated decision-making). Contact support@asmuthai.com. You may also contact the Office of the Privacy Commissioner of Canada or your provincial commissioner.
11.4 Brazil and other Latin America (including LGPD)
If Brazilian LGPD applies, you may have rights to confirmation of processing, access, correction, anonymization/blocking/deletion of unnecessary data, portability, information about sharing, revocation of consent, and complaint to the ANPD. Similar rights may exist under other Latin American privacy laws (for example Argentina, Chile, Colombia, Mexico) — contact support@asmuthai.com and we will honour applicable local rights.
11.5 United States (including California)
If you are a California resident, you may have rights under the CCPA/CPRA to know, delete, correct, and opt out of sale/sharing of personal information, and to non-discrimination for exercising rights. We do not sell personal information as currently operated. To exercise rights, email support@asmuthai.com. Other US state privacy laws (for example Virginia, Colorado, Connecticut) may provide similar rights.
11.6 India
Under applicable Indian law, you may have rights to access, correction, and erasure of personal data, and to grievance redressal. Contact support@asmuthai.com as our primary contact for such requests.
11.7 Other regions
If you live elsewhere (for example Australia, Singapore, Middle East, Africa), we will honour privacy rights available under the laws that apply to you when you contact us.
12. Do-not-track and global privacy controls
Some browsers offer “Do Not Track” or Global Privacy Control (GPC) signals. Where required by law (for example certain US states), we will treat qualifying opt-out signals as a request to opt out of sale/sharing. Otherwise, there is no uniform DNT standard; you can still control cookies and exercise deletion/access rights as described above.
13. International processing
Our infrastructure and subprocessors may process data in India and/or other countries (for example where Appwrite, Cloudflare, AI, STT, or payment providers operate, which may include the United States and EU). Cross-border transfers are necessary to provide a global product. We take steps consistent with applicable law (contractual clauses, vendor due diligence, and security measures).
14. Updates to this Privacy Policy
We may update this Privacy Policy from time to time. We will change the “Last updated” date above. Where required by law, we will provide additional notice or seek consent. Continued use of the Services after an update constitutes acceptance of the revised Policy where permitted by law.
15. Contact us
For privacy questions or data requests:
- Email:
support@asmuthai.com - Legal entity:
TBD, trading as Asmuth - Establishment / primary operations: India
- Postal (optional):
TBD
If we appoint an EU/UK representative or Data Protection Officer in the future, we will publish those details here.
16. Review, update, or delete your data
You can review much of your profile and usage in the website dashboard and desktop app. To request a full export or deletion beyond in-product tools, contact support@asmuthai.com.
This document is a product-aligned draft for Asmuth’s global launch and is not a substitute for advice from a qualified lawyer. Have it reviewed before public launch for GDPR/UK GDPR, PIPEDA/Law 25, LGPD, US state privacy, Indian DPDP, and consumer rules in your launch markets.