UpfynUpfyn
  • Events
  • Pricing
Upfyn Web

Legal · Thinqmesh Technologies Pvt Ltd

Privacy Policy

Effective date: 29 August 2026

This Privacy Policy explains how Thinqmesh Technologies Private Limited (“Thinqmesh”, “we”, “us”, or “our”) collects, uses, discloses, retains, and protects personal data in connection with Upfyn (the “Service”) — an AI-powered desktop application with Analyst and Developer modes, focused apps, and companion web access. Upfyn is a product of Thinqmesh Technologies Private Limited. This policy is published in accordance with India’s Digital Personal Data Protection Act, 2023 (the “DPDP Act”), the Information Technology Act, 2000 and the rules thereunder (including the SPDI Rules, 2011), and other applicable law. By using the Service, you acknowledge that you have read and understood this policy.

Terms of ServicePrivacy PolicyAcceptable UseRefund & CancellationCookie PolicySub-processors

1. Who we are (Data Fiduciary)

The data fiduciary responsible for your personal data is Thinqmesh Technologies Private Limited, a company incorporated in India with its registered office at Gautam Buddh Nagar, Uttar Pradesh – 201014, India. For any question about this policy or your personal data, contact privacy@thinqmesh.com.

This policy governs the Upfyn product. Thinqmesh may operate other products and maintain separate corporate or product-specific terms and policies; this policy applies specifically to Upfyn.

2. Personal data we collect

We collect only the data we need to provide and secure the Service:

  • Account data: your name, email address, and a hashed password. We never store passwords in plain text — credentials are hashed using industry-standard algorithms (bcrypt).
  • Authentication data: if you sign in with Google, we receive your name, email address, and profile picture from Google. We do not receive your Google password.
  • Subscription & billing data: if you purchase a paid plan, our payment processor (Razorpay) processes your payment. We receive transaction metadata (plan, amount, status, invoice identifiers). We do not store your full card or bank details — these are handled by Razorpay under its own policies.
  • Usage & device data: basic metadata such as login timestamps, session duration, feature usage, IP address, browser type, operating system, and device type, used for operating, securing, and improving the Service.
  • Connection metadata: when your desktop machine connects to the web interface, we process session metadata (connection status, timestamps) to route your session.
  • Hosted content you choose to use: conversation text synced to your account, files you upload to account storage, and media generated through hosted features, together with the metadata needed to display and manage them.
  • Support communications: information you provide when you contact us for support or to exercise your rights.

3. What remains local and what you choose to host

Upfyn keeps local execution separate from optional account-backed storage:

  • Your local project is not automatically uploaded or backed up by Upfyn. File and terminal operations run on the desktop, and remote access relays to that machine.
  • Your AI provider API keys are stored locally on your device and are not transmitted to or stored by us.
  • When you use AI features with your own keys, your prompts and context are sent directly from your machine to the AI provider you chose, under that provider’s terms — we do not receive or store them.
  • When you use UpfynAI, conversation sync, account uploads, or hosted generation, the relevant message or selected content is processed and may be stored by us and our listed sub-processors to provide that feature.
  • We do not use tracking or advertising cookies, and we do not sell, rent, or trade your personal data.

4. Purposes and legal bases for processing

We process your personal data for the following purposes, on the bases noted (consent and/or performance of our contract with you and/or legitimate uses permitted under the DPDP Act):

  • To create and authenticate your account and maintain your session (contract).
  • To provide the connection between your machine and the web interface (contract).
  • To process subscriptions, payments, invoices, and renewals (contract).
  • To send essential service communications such as password resets and security alerts (contract / legitimate use).
  • To operate, secure, troubleshoot, and improve the Service, and to detect and prevent fraud, abuse, and security incidents (legitimate use).
  • To comply with applicable legal obligations and enforce our terms (legal obligation).
  • For optional marketing communications, where you have consented (consent — you may opt out at any time).

5. Consent and how to withdraw it

Where we rely on your consent, it is sought through clear affirmative action and you may withdraw it at any time by emailing privacy@thinqmesh.com or using the controls in your account. Withdrawing consent does not affect the lawfulness of processing carried out before withdrawal, and may limit your ability to use parts of the Service that depend on that processing.

6. Sharing and disclosure

We share personal data only as needed to run the Service:

  • Sub-processors / service providers who process data on our behalf under contract — see our Sub-processors page (e.g. authentication, payments, hosting, storage).
  • Legal and safety: where required by law, court order, or lawful request, or to protect the rights, safety, and security of Thinqmesh, our users, or the public.
  • Business transfers: in connection with a merger, acquisition, or sale of assets, subject to this policy.

We do not sell your personal data or share it with third parties for their own advertising.

7. Data security

We implement reasonable security practices and procedures appropriate to the sensitivity of the data, including encryption in transit (HTTPS/TLS), encryption of credentials at rest, scoped access controls, JWT-based session authentication, and direct browser-to-machine session tunnels. No method of transmission or storage is completely secure; while we work to protect your data, we cannot guarantee absolute security.

8. Data retention

We retain personal data only for as long as necessary for the purposes set out above or as required by law. Account data is retained while your account is active; upon account deletion, associated personal data is deleted within 30 days, except where retention is required for legal, tax, accounting, or security purposes. Session and connection metadata is purged after a short period of inactivity. Billing records are retained as required under applicable tax and company law.

9. Your rights as a Data Principal

Subject to applicable law, you have the right to:

  • Access: obtain a summary of the personal data we process about you and the processing activities.
  • Correction & completion: have inaccurate or incomplete data corrected or completed.
  • Erasure: request deletion of your personal data where no longer necessary or where you withdraw consent.
  • Grievance redressal: raise a grievance with us (see Section 11).
  • Nomination: nominate another individual to exercise your rights in the event of death or incapacity.
  • Withdraw consent and, where applicable under other laws, rights to data portability, restriction, and objection.

To exercise any right, email privacy@thinqmesh.com. We will respond within the timelines required by applicable law. We may need to verify your identity before acting on a request.

10. Children

The Service is intended for users aged 18 and above. Under the DPDP Act, an individual below 18 is a “child”. We do not knowingly process the personal data of children without verifiable consent of a parent or lawful guardian, and we do not undertake tracking, behavioural monitoring, or targeted advertising directed at children. If you believe a child has provided us personal data, contact privacy@thinqmesh.com and we will take appropriate steps to delete it.

11. Grievance Officer

In accordance with India’s IT Rules and the DPDP Act, you may address any grievance regarding the processing of your personal data to our Grievance Officer:

  • Grievance Officer
  • Thinqmesh Technologies Private Limited
  • Gautam Buddh Nagar, Uttar Pradesh – 201014, India
  • Email: grievance@thinqmesh.com

We will acknowledge and endeavour to resolve grievances within the timelines prescribed by applicable law. If you are not satisfied with our response, you may approach the Data Protection Board of India established under the DPDP Act.

12. Data breach notification

In the event of a personal data breach, we will take reasonable steps to contain and remediate it and will notify the Data Protection Board of India and affected Data Principals as and to the extent required under the DPDP Act and applicable rules.

13. International transfers

We and our sub-processors may process personal data both in India and in other countries (for example, the United States). Where personal data is transferred across borders, we do so in accordance with the DPDP Act and applicable law, and require appropriate contractual safeguards. See our Sub-processors page for details.

14. Cookies

We use a strictly necessary session cookie and local browser storage for preferences. We do not use tracking or advertising cookies. See our Cookie Policy for details.

15. Google API data

If you sign in with Google, we access only your basic profile (name, email, profile picture) to create and identify your account. We do not request access to Google Drive, Gmail, Calendar, or other Google services. Upfyn’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

This applies to Upfyn’s own Google sign-in. Separately, if you choose to connect a third-party app — such as Gmail, Google Sheets, Slack or Notion — through our integrations provider, that connection is authorised by you directly with that provider under their own credentials and consent screen, and the permissions you grant there are separate from the sign-in scopes described above. You can review and disconnect those connections at any time from your integrations settings.

16. Changes to this policy

We may update this policy from time to time. We will post the updated policy here with a new effective date and, for material changes, notify registered users by email or in-product notice. Your continued use of the Service after the effective date constitutes acknowledgement of the updated policy.

17. Contact us

For privacy questions or to exercise your rights:

  • Privacy: privacy@thinqmesh.com
  • Grievances: grievance@thinqmesh.com
  • Thinqmesh Technologies Private Limited, Gautam Buddh Nagar, Uttar Pradesh – 201014, India

Thinqmesh Technologies Private Limited

Registered office: Gautam Buddh Nagar, Uttar Pradesh – 201014, India

General: legal@thinqmesh.com · Privacy: privacy@thinqmesh.com · Grievances: grievance@thinqmesh.com

Upfyn is a product of Thinqmesh Technologies Private Limited. Governed by the laws of India; courts at Gautam Buddh Nagar (Noida), Uttar Pradesh.

v ×× v
UpfynYour own AI assistant

© 2026 Thinqmesh Technologies Private Limited

Terms of UsePrivacy PolicyAcceptable Use PolicyRefundsCookies
Thinqmeshsupport@upfyn.com