VIGHNIR
BrandsHouseContact

The Club · a Vighnir product

Privacy Policy

This is the whole of what The Club does with your personal data — written plainly, and limited to what the app actually does today.

Effective 3 August 2026Version 1.0India · English
ContentsWho we areThe short versionWhat we collectWhat we don’t doConsent & withdrawalGoogle user dataSign in with AppleWho else sees itWhere it is storedHow long we keep itSecurityYour rightsGrievances18 and overIf there is a breachThis websiteNot in the app todayChangesContact

1. Who we are, and what this covers

The Club is a social app for India, built and operated by Vighnir, a founder-led business based in Noida, Uttar Pradesh, India. For the purposes of India’s Digital Personal Data Protection Act, 2023 (“the DPDP Act”), Vighnir is the Data Fiduciary for the personal data described here, and you are the Data Principal.

This policy covers the mobile app The Club and this website, vighnir.com. It does not cover Vighnir’s other brands, or anything you reach by leaving the app.

Status on the effective date

The Club has not yet been released on the App Store or Google Play. This policy describes the app as it is built today and takes effect for its first release. Where something is decided but not yet shipped, it is listed in §17 — not written as if it exists.

2. The short version

  • You must be 18 or over to have an account.
  • We collect what an account needs: a way to sign you in (phone, email, Google or Apple), and the profile you fill in.
  • We do not run ads, and we do not sell your data. There is no advertising SDK, no advertising identifier and no data broker anywhere in this product.
  • The Club takes no payments today. There is no card, UPI or bank information in the app or in our database.
  • Your account database currently sits outside India, in Singapore. We say so plainly in §9 rather than leaving you to guess.
  • You can ask us for a copy of your data, ask us to correct it, or ask us to delete your account — see how.

3. What we collect, and why

Itemised, because the DPDP Rules require an itemised description rather than a category blur. Nothing else is collected by the app.

Signing in

Phone number
If you sign up with a phone number. Stored in international (E.164) form. Used to create and identify your account, and to send you a one-time password by SMS so we can prove the number is yours.
Email address
If you sign up with an email address. Same purpose: to create and identify your account, and to send you a one-time password.
Password
Signup asks you to set a password whether you started with a phone number or with an email address — with a phone number it is attached to the account the one-time password already created. So if you signed up either of those ways, we hold one. We store a salted, iterated cryptographic hash; we never store, and cannot read, your actual password. Sign in with Google and Sign in with Apple set no password at all.
One-time passwords
We store a hash of the code you were sent, when it expires, and how many attempts have been made — so a code cannot be reused or guessed. Minutes, then gone.
Google account identifier
If you use Sign in with Google. See §6 for exactly what Google sends and what we keep.
Apple user identifier
If you use Sign in with Apple. See §7.

Your profile

Name you display
Shown to other people on The Club.
Username
Unique and public. Lowercase letters, numbers and underscores.
Date of birth
To enforce the 18+ rule. The rule is enforced by a constraint in the database itself, not by the app — see §14.
Gender
One of male, female or other, as you select it during signup.
Profile photo
Optional. Chosen from your photo library — the app does not request camera or microphone access. The image is stored in Cloudflare R2 and the app holds only its address.
Interests
Optional. A list of topic tags you pick from a fixed set.
Location
Optional, and only when you ask for it — by tapping “use my location” or by searching for a place. We store the city, the country, and the latitude and longitude to six decimal places. Those coordinates are precise, so we say so rather than calling this “city-level”. You can skip this step, and the app never reads your location in the background.

Technical data, created by using the service

Session records
A hashed refresh token per signed-in device, with issue and expiry times, so you stay signed in and so a stolen token can be revoked. Email sign-in additionally records the IP address and browser/device user-agent string of the request.
Rate-limit counters
Short-lived counts keyed to your phone number, email address or account id, so nobody can spend our SMS budget or brute force a code.

We do not keep a server request log archive of our own today. Our API writes no request log, and there is no store of your IP addresses or requests anywhere we control. Indian law will require one before public release, and we have described it in advance in §17 rather than writing it here as if it already existed. Cloudflare, which runs the API, handles the request itself as part of delivering it — see §8.

What we do not ask for

The app does not read your contacts, calendar, SMS inbox, microphone or camera. It asks for exactly two permissions: access to your photos, so you can pick a profile picture, and location while the app is open, only if you use the location step. It never reads your location in the background.

4. What we don’t do

These are commitments about the code as it stands, not aspirations:

  • No advertising. No ad network, no ad SDK, no advertising identifier, no targeted advertising, no profiling for advertising.
  • No sale of personal data, and no sharing with data brokers or list buyers.
  • No analytics or crash-reporting SDK in the app today. There is no analytics package in the app at all. We intend to add crash reporting before release and have described it in advance in §17.
  • No payments. The Club does not process payments and holds no payment data.
  • No cross-app or cross-site tracking, on the app or on this website.

5. Your consent, and taking it back

We process your personal data on the basis of the consent you give when you create an account, after being shown this notice. Some processing will also be necessary to comply with law rather than because you agreed to it: once the server-log archive described in §17 exists, it will be kept because a CERT-In direction requires it, and withdrawing consent will not remove it. That archive is not built yet, so today consent is the only basis on which we hold anything of yours.

You can withdraw your consent at any time, and it is meant to be as easy to withdraw as it was to give. Write to siddhant.jaiswal@vighnir.com or use the deletion page.

Being straight with you about the consequence: your phone number or email address is your account. If you withdraw consent to us processing it, we cannot keep the account working, so withdrawal means the account is closed and the data deleted as described in §10. The DPDP Act puts the consequences of a withdrawal on you, and this is that consequence. We stop processing within a reasonable time of your request.

You can also withdraw the optional parts on their own — ask us to remove your photo, your interests or your location — and keep the account.

6. Google user data

If you tap Sign in with Google, we ask Google for three standard, non-sensitive permissions: openid, email and profile. Google then sends our server a signed ID token.

What Google sends us
A stable identifier for your Google account, your email address, whether Google has verified that address, and basic profile information.
What we store
Only the stable account identifier, linked to your Club account, so we recognise you the next time you sign in. We do not store the email address or the profile picture from that token, and we do not copy your Google profile into ours.
What we do with it
Authenticate you. Nothing else. It is not used for advertising, not sold, and not shared.

Limited Use. The Club’s use of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. Concretely: we use Google user data only to provide the sign-in feature you can see in the app; we do not transfer it to anyone except as necessary to provide that feature, to comply with applicable law, or as part of a merger or acquisition after notice to you; we do not use it for advertising; and we do not allow humans to read it, except with your explicit consent, where necessary for security purposes such as investigating abuse, or where the law requires it.

You can disconnect The Club from your Google account at any time in your Google account’s security settings. That stops future sign-ins; to remove the data we hold, use account deletion.

7. Sign in with Apple

If you use Sign in with Apple, Apple sends us a signed identity token, which our server verifies against Apple’s public keys. It contains a stable identifier for your account with us. We store that identifier and nothing else from the token.

Apple lets you hide your email address and use a private relay address instead; The Club works either way, because the identifier — not the address — is what we key your account on. Apple sends your name only on the very first authorisation; if you have not set a display name yet, we use it to fill that in, and we never overwrite a name you chose.

8. Who else processes your data

We use a small number of service providers. Each receives only what it needs to do its job.

Cloudflare
Runs our API at the network edge and stores profile photos (Cloudflare R2). Sees requests to our API and the images you upload.
Neon
Managed PostgreSQL — the database that holds your account and profile. Currently hosted in Singapore; see §9.
MSG91
Indian SMS provider, registered under TRAI’s DLT regime. Receives your phone number and the one-time password text, in order to deliver the SMS. Used only for phone signup and sign-in.
Google
Only if you choose Sign in with Google. Google knows you signed in to The Club.
Apple
Only if you choose Sign in with Apple. Same.
Vercel
Hosts this website, vighnir.com. Not part of the app. See §16.

That is the whole list. Amazon Web Services is deliberately not on it: the India log archive in §17 is not built, so AWS holds nothing of yours today. It joins this list on the day that archive starts receiving data, and this page changes in the same release.

We require any third party we share personal data with — including any parent, subsidiary or related company — to protect it to at least the standard set out in this policy. We do not give any of them permission to use your data for their own purposes.

We may also disclose personal data where we are legally required to: to a court, or to a government agency acting under a lawful order.

9. Where your data is stored, and transfers out of India

We would rather tell you an unflattering fact than a comfortable one:

Account database
Singapore (Neon, ap-southeast-1) today. Your profile, identifiers, username and session records live there. Moving it to Mumbai is planned; this page will change on the day it moves, not before.
Profile photos
Cloudflare R2, on Cloudflare’s global network.
API
Cloudflare Workers, executed at the Cloudflare location nearest to you.
Server logs
There are none to store. When the archive in §17 is built it will be in India — AWS Mumbai (ap-south-1) — and this row will say so in the present tense.

Section 16 of the DPDP Act permits personal data to be transferred outside India unless the Central Government notifies a particular country as restricted. As at the effective date of this policy, no such country has been notified, and none of the places above is restricted.

10. How long we keep things

Account and profile
For as long as your account exists. If you delete it, see account deletion — the data is removed within 30 days.
One-time passwords and verification records
Minutes. They expire, are consumed on use, and expired rows are swept.
Session and refresh tokens
Until they expire or you sign out. They rotate every time they are used.
Server request logs
None are kept today, because none are written — see §3. CERT-In’s direction of 28 April 2022 requires providers to keep ICT system logs for a rolling 180 days within Indian jurisdiction, and we are building that archive before public release (§17). From the day it starts, those records will live 180 days and then be deleted, and that is the one thing about your requests that will survive the deletion of your account.
Anything the law requires
Where a law or a court order requires us to keep something for longer, we keep only that, for only as long as required.

Beyond those cases, we erase personal data once you withdraw consent or once it is reasonable to conclude the purpose we collected it for is no longer being served.

11. Security

  • Everything travels over HTTPS/TLS. All data the app sends or receives is encrypted in transit.
  • Passwords are stored as salted, iterated hashes — never in a readable form.
  • One-time passwords are stored as hashes, expire in minutes and allow only a small number of attempts.
  • Refresh tokens are stored hashed and rotate on every use; if an old one is replayed, the whole family is revoked.
  • The database enforces access with row-level security: a signed-in device can read and write its own row and no one else’s, and that is enforced by the database rather than by the app.
  • Every rule that matters — the 18+ check, username uniqueness, proof that a phone or email was actually verified — is enforced on our servers, not in the app, because an app on someone else’s phone can be modified.

What we will not claim: The Club holds no security certification. We are not ISO 27001 certified, not SOC 2 audited, and we do not describe our storage as encrypted at rest or our messaging as end-to-end encrypted. No system is perfectly secure. If any of that changes, this section changes with it.

12. Your rights, and how to use them

Under the DPDP Act you have the following rights. To use any of them, write to siddhant.jaiswal@vighnir.com from the email address registered on your account, or — if you signed up with a phone number — tell us that number and your username so we can identify you.

Access (s.11)
A summary of the personal data we hold about you, what we are doing with it, and who we have shared it with.
Correction and erasure (s.12)
Have inaccurate data corrected, incomplete data completed, outdated data updated, or your data erased. Write to us and we will do it.
Withdraw consent (s.6(4))
At any time, as easily as you gave it — see §5.
Nominate (s.14)
Name someone to exercise these rights on your behalf if you die or become incapacitated. Write to us with their name and contact details.
Grievance redressal (s.13)
Complain to us and get an answer — see §13.

We answer within 30 days of being able to identify you. If a request would require us to break a law — for instance, deleting something a court has ordered us to preserve — we will tell you which part we could not do, and why.

Today this notice is published in English. If you would prefer it in Hindi or another language listed in the Eighth Schedule to the Constitution of India, write to us and we will provide it.

13. Grievances, and how to escalate

If you are unhappy with anything we do with your personal data, or with how we handled a request, complain to us first.

Grievance contact

Siddhant Jaiswal — Grievance Officer, Vighnir

Email: siddhant.jaiswal@vighnir.com
Post: Vighnir, Noida, Uttar Pradesh, India

We acknowledge a grievance within 24 hours and resolve it within 15 days. Complaints about content on The Club have shorter deadlines — those are set out in the Terms of Service.

If we do not answer, or you are not satisfied with our answer, you may complain to the Data Protection Board of India. The DPDP Act asks you to exhaust our grievance process first, which is why the contact above exists.

14. The Club is 18 and over

Under the DPDP Act, a “child” is anyone under 18. The Club is not for children and we do not knowingly create accounts for them.

At signup you give your date of birth, and a constraint in our database rejects it if it puts you under 18 — the check lives in the database rather than in the app precisely so that a modified app cannot get around it. We should be clear about what this is: it is a self-declared date of birth that we enforce, not a verified age. We do not run identity or document checks.

And we should be equally clear about when it happens, because the order matters to you. Signup verifies your phone number or email address first, and that step already creates an account record holding that number or address. Only afterwards does the app ask for your date of birth. So the constraint refuses the profile, not the record that already exists: someone under 18 gets no name, no username, no date of birth stored and no working account — signup can never be completed and The Club cannot be used — but the phone number or email address they verified a moment earlier is still on our servers.

Nothing sweeps those refused records automatically today. That is a gap in our implementation, not a decision about your data, and we are fixing it before public release. In the meantime we delete them on request, and we treat a request about someone under 18 as urgent. If you are under 18 and were turned away at that step, or you believe a child has signed up, write to siddhant.jaiswal@vighnir.com and we will remove what is there.

If we learn that a completed account belongs to someone under 18, we close it and delete its data.

15. If there is a data breach

If personal data we hold is breached, the DPDP Act requires us to inform the Data Protection Board of India and every affected person. We will do that, and we will tell you what happened, what data was involved and what you should do — as soon as we have facts worth sending rather than a placeholder. We are not going to promise a specific number of hours we cannot guarantee to meet.

16. This website

vighnir.com uses Vercel Web Analytics and Vercel Speed Insights in their default configuration, to count page views and measure how quickly pages load. These are cookieless and aggregate. We do not use advertising cookies, we do not track you across other sites, and we do not build a profile of you from this website.

If you email us from the address on this site, we hold that email in our mailbox for as long as we need it to deal with what you wrote about.

17. Decided, but not in the app today

Written down in advance so that this page is never the last thing to find out. None of the following is in the product on the effective date, and this policy will be updated in the same release that ships each one.

Crash and error reporting
We intend to add crash and error reporting before public release, using Sentry, hosted in the European Union (Frankfurt). When it ships it will identify you only by an internal account identifier — never a phone number, email address, date of birth or location — and personal data will be stripped before an error report leaves your device and again on our servers.
In-app account deletion
Deleting your account from inside the app is being built and will be there for the first store release. Until then, the email route on the deletion page is the way, and it is a real process a person carries out.
The India log archive
Nothing logs your requests today. Before public release we will start recording, for each request to our API, the IP address, user agent, timestamp, the path called and a request identifier, and keeping those records for 180 days in AWS Mumbai (ap-south-1), as CERT-In’s direction of 28 April 2022 requires. When it starts: Amazon Web Services becomes a processor (§8), that archive becomes the one thing that outlives account deletion (§10), and it is kept to comply with law rather than on your consent (§5). Each of those sections is written today as what is true today, and each changes in the release that ships this.
Payments
Paid bookings are part of the plan for The Club and would run through a licensed payment aggregator. Nothing about payments exists today, and we hold no payment data of any kind.
Moving the database to India
Planned. §9 will change when it happens.

18. Changes to this policy

When we change what we do with personal data, we change this page in the same release, and we update the effective date and version at the top. If a change is significant, we will tell you in the app. At least once a year we will remind you that this policy, the Terms of Service and the rules for using The Club exist and where to read them.

19. Contact

For anything about your personal data — a question, a request, a complaint — write to the person responsible for answering it:

Privacy contact: siddhant.jaiswal@vighnir.comPost: Vighnir, Noida, Uttar Pradesh, IndiaOperator: Vighnir, Noida, Uttar Pradesh, India

See also: Terms of Service · Delete your account

© MMXXVI Vighnireko · The Club · Aquarius
PrivacyTermsDelete account
Noida · India