Privacy Policy
Val8.app - AI-Powered Business Idea Validation
Effective Date: 24 August 2026 Last Updated: 24 August 2026
Operated by: Yashraj Awasthi (Sole Proprietorship) Registered Address: 127/669, Flat No. 301, W-Block, Panchsheel Dham, Keshav Nagar, Kanpur, Uttar Pradesh, India Contact: founder@val8.app Website: www.val8.app
This Privacy Policy ("Policy") describes how Yashraj Awasthi, operating as a sole proprietorship under the trade name Val8 ("Val8," "we," "us," or "our"), collects, uses, stores, shares, and protects your personal data when you use the Val8.app website, application, and all associated services (the "Service").
By creating an account or using the Service, you acknowledge that you have read and understood this Policy. If you do not agree with any part of this Policy, do not create an account or use the Service.
1. Data We Collect
We collect the following categories of personal data. We do not collect data beyond what is listed here.
1.1 Account Information
When you create an account, we collect:
- Email address - used as your login identifier, for account verification, for password reset, and for transactional communications (e.g., refund confirmations, policy updates).
- Password - stored only in hashed form using a one-way cryptographic hashing algorithm (bcrypt). We never store, view, or have access to your plaintext password.
- Display name - the name you choose to be identified by within the Service. This is collected after account creation and can be changed at any time.
- Age confirmation - we record a boolean/timestamped confirmation that you checked the "I confirm I am 18 years of age or older" self-certification box at signup. We do not collect an actual date of birth.
1.2 Submitted Business Idea Text
When you submit a business idea for validation, we collect the raw text of your submission ("Idea Text"). This includes whatever you type into the idea input field - the business concept description, any additional context you provide, and the refined field selections (business idea summary, target market, stage, and domain) that you confirm before a validation run begins.
1.3 Validation Run History and Results
For each validation run you initiate, we store:
- Run metadata - a unique run identifier, the date and time the run was initiated, and the run status (pending, in progress, complete, or failed).
- AI-generated validation results - the full output produced by the AI panel, including persona profiles, discussion content, scores, strengths, objections, and recommended next steps. This data is stored so that you can access your past validation reports at any time through your account.
1.4 Payment Metadata
When you purchase credits, the following payment-related data is associated with your account:
- Transaction identifier - a unique ID assigned by our payment processor (Razorpay) for each purchase.
- Credit amount purchased - the number of credits and the package selected.
- Transaction date and amount - the date, time, and monetary amount of the purchase.
- Billing currency - INR or USD, depending on your location and payment method.
What we do NOT collect or store:
- Raw credit card numbers, debit card numbers, CVV codes, or full bank account numbers. All payment card data is collected, processed, and stored exclusively by Razorpay. This data never passes through our servers, and we never have access to it.
- Billing address or full legal name associated with your payment method - this data is handled entirely by Razorpay.
1.5 Automatically Collected Technical Data
When you access the Service, our servers and hosting infrastructure may automatically collect:
- IP address - used for security purposes (e.g., detecting unauthorised access attempts) and for determining billing currency (India vs. international).
- Browser type and version, operating system, and device type - used for debugging, ensuring compatibility, and improving the user experience.
- Pages visited, timestamps, and session duration - used for understanding how the Service is used and identifying technical issues.
We do not use tracking cookies for advertising purposes. We do not serve third-party advertisements. We do not sell or share automatically collected technical data with advertisers or data brokers.
1.6 Moderation Logs
When a submitted idea is screened by our content moderation system (whether approved or rejected), we log:
- The submitted idea text.
- The moderation decision (approved, rejected as off-topic, or rejected as prohibited).
- The moderation layer that made the decision (Layer 1: OpenAI Moderation API, or Layer 2: business-context classifier).
- An internal reason code - a brief machine-generated explanation of why the decision was made. This is never shown to the user.
- Timestamp and associated user ID.
Moderation logs are retained for compliance, fraud prevention, and to improve the accuracy of our content moderation system (by identifying false positives - legitimate ideas incorrectly rejected). Moderation logs are not shared with any third party except as required by law.
2. How We Use Your Data
We use the data described in Section 1 for the following specific purposes and no others:
| Data Category | Purpose |
|---|---|
| Email address | Account authentication, password reset, transactional emails (refund confirmations, policy updates, service announcements) |
| Password (hashed) | Account authentication |
| Display name | Personalisation within the Service interface |
| Age confirmation checkbox | One-time self-certification of minimum age at registration |
| Submitted idea text | Processing through AI providers to generate your validation report; content moderation screening |
| Validation run history and results | Displaying your past reports within your account |
| Payment metadata | Maintaining your credit balance, processing refund requests, transaction record-keeping |
| Technical data (IP, browser, etc.) | Security, debugging, currency determination, service improvement |
| Moderation logs | Compliance, fraud prevention, moderation accuracy improvement |
We do not use your data for targeted advertising, behavioural profiling, or sale to third parties. We do not use your submitted idea text to train, fine-tune, or improve any AI model - ours or any third party's.
3. Third-Party Data Sharing
We share your data with the following specific third-party service providers. We do not share your data with any party not listed here, except as required by law (see Section 3.5).
3.1 DeepSeek (AI Processing)
What is shared: Your submitted idea text and the refined field selections (business idea summary, target market, stage, domain).
Why: DeepSeek's AI models (deepseek-v4-flash and deepseek-v4-pro) generate the simulated persona panel, discussion, and scoring that form your validation report. Your idea text must be sent to DeepSeek's API for this processing to occur.
Model training: Your submitted idea text is not used by Val8 to train, fine-tune, or improve any AI model. Regarding DeepSeek's own data practices: DeepSeek's API terms (as of the effective date of this Policy) state that data submitted through their API is not used for model training. We select API providers whose data handling practices are consistent with protecting user confidentiality. However, we cannot independently audit or guarantee how a third-party provider handles data after it reaches their systems. We encourage you to review DeepSeek's privacy policy and API terms of service directly.
Data retention by DeepSeek: We send data to DeepSeek via their API on a per-request basis. We do not instruct DeepSeek to retain your data beyond what is necessary to process the API request and return a response.
3.2 OpenAI (Content Moderation)
What is shared: Your submitted idea text - the raw text you enter before any processing occurs.
Why: OpenAI's Moderation API (model: omni-moderation-latest) screens your submitted text for harmful content categories (hate speech, violence, self-harm, sexual content, harassment) before any other processing begins. This is a safety measure that runs before your idea reaches DeepSeek.
Model training: OpenAI's Moderation API terms (as of the effective date of this Policy) state that data submitted to the Moderation endpoint is not used for model training. As with DeepSeek, we cannot independently audit third-party data handling beyond what their published terms state.
Data retention by OpenAI: The Moderation API processes your text and returns a classification result. We do not instruct OpenAI to retain your data beyond what is necessary to process the moderation request.
3.3 Razorpay (Payment Processing)
What is shared: Razorpay collects payment and billing data directly from you during the checkout process. This includes your payment card details, UPI ID, net banking credentials, billing name, billing address, and other payment-method-specific information. This data is collected by Razorpay's payment interface and processed on Razorpay's servers - it does not pass through Val8's servers.
We share your email address and the transaction amount with Razorpay to initiate and track payment transactions.
Why: Razorpay processes all credit purchases and refunds.
Razorpay's compliance: Razorpay is a PCI DSS-compliant payment processor regulated by the Reserve Bank of India (RBI). Their data handling is governed by their own privacy policy and applicable Indian financial regulations.
3.4 Hosting and Infrastructure
The Service is hosted using Supabase for database services and Render for application hosting. Your data (account information, idea text, validation results) is processed and stored on servers located in Singapore. We select hosting providers that maintain industry-standard security certifications and data protection practices.
3.5 Legal and Regulatory Disclosure
We may disclose your personal data if required to do so by law, regulation, legal process, or enforceable governmental request, including:
- In response to a valid court order, subpoena, or warrant issued by a court of competent jurisdiction in India.
- To comply with applicable laws and regulations, including India's Digital Personal Data Protection Act, 2023 (DPDPA) and any rules framed thereunder.
- To protect the rights, property, or safety of Val8, our users, or the public.
- To detect, prevent, or address fraud, security issues, or technical problems.
We will make reasonable efforts to notify you of any such disclosure unless prohibited by law from doing so.
4. Data Retention
4.1 Account Data
Your account information (email, hashed password, display name, age confirmation) is retained for as long as your account remains active. Upon account deletion (see Section 6.1), your account data is permanently deleted within thirty (30) calendar days.
4.2 Submitted Idea Text and Validation Results
Your submitted idea text and the associated AI-generated validation results are retained for as long as your account remains active, so that you can access your past reports at any time.
Upon account deletion, all idea text and validation results associated with your account are permanently deleted within thirty (30) calendar days.
4.3 Payment Records
Transaction records (transaction ID, amount, date, credit package) are retained for a minimum of eight (8) years from the date of the transaction, as required by Indian tax and financial record-keeping regulations (specifically, the Income Tax Act, 1961). These records are retained even after account deletion if the retention period has not yet expired. This retention basis will be updated to include GST laws if and when Val8 becomes GST-registered.
4.4 Moderation Logs
Moderation logs (including the submitted idea text for rejected submissions) are retained for twelve (12) months from the date of the moderation event. After twelve months, moderation logs are permanently deleted unless they are subject to an active legal hold or investigation.
4.5 Technical Logs
Automatically collected technical data (IP addresses, browser information, access logs) is retained for ninety (90) days for security and debugging purposes, after which it is automatically purged.
5. Data Security
We implement commercially reasonable technical and organisational measures to protect your personal data against unauthorised access, alteration, disclosure, or destruction. These measures include:
- Encryption in transit: All data transmitted between your browser and our servers is encrypted using TLS (Transport Layer Security). All API calls to third-party providers (DeepSeek, OpenAI, Razorpay) are made over encrypted HTTPS connections.
- Encryption at rest: Your data stored in our database is protected by the encryption-at-rest capabilities provided by our hosting and database infrastructure.
- Password security: User passwords are hashed using bcrypt before storage. We never store plaintext passwords.
- Access controls: Access to production systems and user data is restricted to authorised personnel (currently the sole proprietor) and is protected by strong authentication.
- Payment isolation: Raw payment card data never touches our servers. All payment data is handled exclusively by Razorpay's PCI DSS-compliant infrastructure.
No method of transmission over the internet or electronic storage is 100% secure. While we strive to use commercially reasonable means to protect your personal data, we cannot guarantee absolute security. If we become aware of a data breach that affects your personal data, we will notify you and any applicable regulatory authorities as required by law.
6. Your Rights
6.1 Account Deletion
You may request the deletion of your account and all associated personal data at any time by:
- Using the account deletion feature within the Service (accessible from your account settings).
- Sending an email to founder@val8.app with the subject line "Account Deletion Request" from the email address associated with your account.
Upon receiving a valid deletion request, we will:
- Deactivate your account within two (2) business days.
- Permanently delete your account data, submitted idea text, and validation results within thirty (30) calendar days.
- Retain only the data we are legally required to keep (payment records for tax compliance, as described in Section 4.3).
If you have unused credits and wish to request a refund before deletion, you must submit the refund request before requesting account deletion. See the Refund & Cancellation Policy for details.
6.2 Data Export
You may request a copy of the personal data we hold about you by sending an email to founder@val8.app with the subject line "Data Export Request" from the email address associated with your account.
We will provide your data in a commonly used, machine-readable format (JSON or CSV) within fifteen (15) business days of receiving a valid request. The export will include your account information, submitted idea text, and validation results. It will not include hashed passwords (which are not reversible) or internal system identifiers.
6.3 Data Correction
If any personal data we hold about you is inaccurate or incomplete, you may:
- Update your display name directly within the Service interface.
- Request correction of other data (such as your email address) by contacting founder@val8.app with the subject line "Data Correction Request."
We will process correction requests within ten (10) business days.
6.4 Right to Object or Restrict Processing
If you believe we are processing your data unlawfully or beyond the scope described in this Policy, you may object to or request restriction of processing by contacting founder@val8.app. We will review your request and respond within fifteen (15) business days. If your objection is valid, we will cease the relevant processing or delete the data in question.
7. Legal Basis for Processing and Governing Law
7.1 Legal Basis
We process your personal data on the following legal bases:
- Contractual necessity: Processing your account data, idea text, and payment metadata is necessary to perform the contract between you and Val8 (i.e., to provide the Service you have registered for and purchased credits to use).
- Legitimate interest: Processing technical data for security, fraud prevention, and service improvement is based on our legitimate interest in maintaining a secure and functional platform.
- Legal obligation: Retaining payment records for the legally required period is based on our obligation to comply with Indian tax and financial regulations.
- Consent: Where required by applicable law (e.g., for processing data of users in jurisdictions requiring explicit consent), your creation of an account and use of the Service constitutes your consent to the data processing described in this Policy. You may withdraw consent at any time by deleting your account.
7.2 India - Digital Personal Data Protection Act, 2023
This Policy is drafted in compliance with India's Digital Personal Data Protection Act, 2023 (DPDPA) and any rules framed thereunder, to the extent they are in force as of the effective date of this Policy. As a Data Fiduciary under the DPDPA, we are committed to:
- Processing personal data only for the specific, lawful purposes described in this Policy.
- Maintaining reasonable security safeguards to protect personal data.
- Providing you with the ability to access, correct, and delete your personal data.
- Notifying the Data Protection Board of India and affected users in the event of a personal data breach, as required by the DPDPA.
As the DPDPA's implementing rules and regulatory guidance evolve, we will update this Policy to remain in compliance.
7.3 GDPR Considerations (European Union and EEA Users)
If you access the Service from the European Union or the European Economic Area, the General Data Protection Regulation (GDPR) may apply to our processing of your personal data. In addition to the rights described in Section 6, EU/EEA users may have the following additional rights under the GDPR:
- Right to data portability: You may request your data in a structured, commonly used, machine-readable format (see Section 6.2).
- Right to erasure ("right to be forgotten"): You may request deletion of your personal data (see Section 6.1).
- Right to lodge a complaint: You have the right to lodge a complaint with your local data protection supervisory authority if you believe our processing of your personal data violates the GDPR.
Val8 does not currently have an establishment in the EU/EEA and does not currently appoint an EU representative under Article 27 of the GDPR. If our user base in the EU/EEA grows to a level that triggers this requirement, we will appoint a representative and update this Policy accordingly.
For GDPR-related inquiries, contact founder@val8.app.
7.4 Governing Law
This Policy and any disputes arising from it are governed by the laws of India. See the Terms of Service for full governing law and dispute resolution provisions.
8. Children's Privacy
The Service is not intended for, directed at, or designed to be used by anyone under the age of eighteen (18). We do not knowingly collect personal data from children under 18.
During account registration, we require users to self-certify their age via a checkbox confirmation. Because registration is not technically blocked by an automated age calculation, a false checkbox confirmation constitutes a Terms of Service violation discovered after the fact, rather than an action prevented at signup.
If we discover that we have inadvertently collected personal data from a user under 18 - for example, if a user provided a false checkbox confirmation during registration - we will take the following steps:
- Immediately suspend the account.
- Delete all personal data associated with the account within seven (7) calendar days.
- Forfeit any remaining credits without refund.
- We will not contact the minor directly but may notify a parent or legal guardian if we have sufficient information to do so.
If you are a parent or guardian and believe that your child under 18 has created an account on Val8, please contact us immediately at founder@val8.app and we will delete the account and all associated data.
9. Cookies and Tracking Technologies
The Service uses only essential cookies - cookies that are strictly necessary for the Service to function. These include:
- Session cookies: Used to maintain your login state while you are using the Service. These expire when you close your browser or after a defined session timeout period.
- Authentication tokens: Used to securely verify your identity across requests.
We do not use:
- Advertising or marketing cookies.
- Third-party analytics tracking cookies.
- Cross-site tracking technologies.
- Pixel trackers, web beacons, or fingerprinting technologies.
Because we use only essential cookies, no cookie consent banner is required under most jurisdictions. However, you can configure your browser to block all cookies; note that doing so will prevent you from logging into the Service.
10. International Data Transfers
If you access the Service from outside India, your data will be transferred to and processed on servers located in Singapore, where our primary hosting infrastructure operates. By using the Service from outside India, you consent to the transfer of your data to India and/or Singapore.
For EU/EEA users: such transfers may not be covered by an EU adequacy decision. By using the Service, you consent to this transfer. We implement the security measures described in Section 5 to protect your data during and after transfer.
11. Changes to This Policy
We reserve the right to update this Policy at any time. When we make changes:
- We will update the "Last Updated" date at the top of this document.
- For material changes - changes that significantly affect what data we collect, how we use it, or who we share it with - we will notify all registered users via the email address associated with their account at least fifteen (15) calendar days before the changes take effect.
- For non-material changes (clarifications, formatting, or corrections that do not alter the substance of the Policy), we will update the document without individual email notification, but the updated "Last Updated" date will reflect the change.
Your continued use of the Service after the updated Policy takes effect constitutes your acceptance of the updated Policy. If you do not agree with the changes, you may delete your account as described in Section 6.1.
12. Contact Information and Grievance Officer
12.1 General Contact
For all privacy-related inquiries, data requests, concerns, or complaints:
Email: founder@val8.app
Registered Address: Yashraj Awasthi 127/669, Flat No. 301, W-Block, Panchsheel Dham, Keshav Nagar, Kanpur, Uttar Pradesh, India
We aim to respond to general privacy-related inquiries within five (5) business days.
12.2 Grievance Officer
In accordance with Rule 3(2) of the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, the name and contact details of the Grievance Officer are provided below:
Name: Yashraj Awasthi Email: founder@val8.app Address: 127/669, Flat No. 301, W-Block, Panchsheel Dham, Keshav Nagar, Kanpur, Uttar Pradesh, India
We will acknowledge all grievances within twenty-four (24) hours of receipt and aim to resolve them within fifteen (15) days.
By creating an account and using Val8.app, you acknowledge that you have read, understood, and agree to the data practices described in this Privacy Policy.
