Legal

Privacy Policy

Your privacy matters deeply to us. This policy explains exactly what data we collect, why we collect it, and how you stay in control of your information on मनmate.

Last updated: July 6, 2026·Effective: June 13, 2026

1. Introduction

मनmate ("we", "our", "us", or "the Platform") is a mental-health support platform operated by MannMate Technologies Private Limited, a company incorporated under the laws of India. We are committed to protecting the privacy and confidentiality of every person who uses our services.

This Privacy Policy ("Policy") describes how we collect, use, store, share, and protect your personal information when you access or use the मनmate website, mobile applications, APIs, and all associated services (collectively, the "Services"). It also describes the choices available to you regarding your personal data.

By creating an account or using any part of the Platform, you agree to the collection and use of information in accordance with this Policy. This Policy is incorporated into and forms part of our Terms & Conditions.

Note:Mental health data is among the most sensitive personal information. We treat it with the highest level of care and apply strict controls on how it is handled, accessed, and processed.

2. Information We CollectKey terms

We collect information in the following categories depending on how you interact with the Platform:

2.1 Account & Registration Data

When you create an account, we collect:

  • Full name (or display name for Listeners)
  • Email address
  • Password (stored as a secure one-way hash — we never store your plaintext password)
  • Date of birth (for age verification)
  • Role selection: Client, Listener, or Therapist
  • Profile picture (optional)
  • Language preference

2.2 Therapist Verification Data

If you register as a Therapist, we additionally collect:

  • Professional licence number and issuing council (e.g., RCI, NIMHANS)
  • Qualifications and specialisations
  • Government-issued identity document (for verification)
  • Bank account or UPI details (for fee disbursement)
  • A brief professional bio displayed on your public profile

2.3 Usage & Session Data

We automatically collect information about how you use the Platform, including:

  • Session timestamps, durations, and connection quality metrics
  • Features accessed, pages visited, and navigation paths
  • Device type, operating system, browser version, and screen resolution
  • IP address and approximate geographic location (city/region level)
  • Referral source (how you found us)
  • Error logs and crash reports

2.4 Call & Communication Data

For P2P peer listening and therapist video sessions:

  • Call logs: start time, end time, duration, and session type (text/audio/video)
  • Connection metadata: call ID, peer IDs, signalling events
  • Mood ratings or check-in responses submitted before or after a session
  • Post-session feedback and ratings you voluntarily provide
  • Text messages sent within the Platform's in-session chat (if applicable)
Note:Audio and video content of P2P peer sessions is transmitted peer-to-peer over WebRTC and is not recorded or stored on our servers by default. See Section 5 for full details.

2.5 Appointment & Calendar Data

When you book a therapist appointment:

  • Appointment date, time, and duration
  • Therapist selected and service type
  • Google Calendar event data (if you connect your Google account)
  • Google Meet link details for video appointments
  • Notes you provide in the booking form (e.g., presenting concerns)

2.6 Payment & Financial Data

We collect transaction-related information through our payment processor (Razorpay):

  • Wallet top-up amounts and transaction IDs
  • Therapist session fee deductions and refund records
  • Payment method type (UPI, card, net banking) — we do not store full card numbers
  • Razorpay order and payment IDs
  • Transaction status and timestamps

2.7 Google OAuth Data

If you sign in with Google or connect your Google account for Calendar integration, we receive:

  • Your Google account email address and display name
  • Google profile picture URL
  • Google OAuth access and refresh tokens (stored securely, used only for Calendar/Meet integration)
  • Calendar event creation and read permissions (only when you grant them)

3. How We Use Your Information

We use the information we collect for the following purposes, each of which has a corresponding lawful basis under applicable data protection law:

3.1 Providing and Operating the Services

  • Creating and managing your account
  • Matching you with available Listeners during P2P sessions
  • Processing therapist bookings, scheduling, and Google Meet link generation
  • Managing your Wallet balance, processing payments, and issuing refunds
  • Delivering in-app notifications, reminders, and session summaries

3.2 Safety, Quality, and Trust

  • Detecting and preventing fraudulent activity, abuse, and Terms violations
  • Monitoring platform integrity and connection quality metrics
  • Reviewing post-session reports or flagged content for safety purposes
  • Training and auditing our Listener and Therapist quality assurance processes

3.3 Personalisation & Product Improvement

  • Improving our matching algorithm based on session quality signals
  • Personalising your dashboard and content recommendations
  • Analysing usage patterns to identify and fix bugs or improve features
  • Conducting internal research to improve mental health support outcomes

3.4 Communication

  • Sending transactional emails (booking confirmations, receipts, password resets)
  • Sending platform announcements and critical policy updates
  • Sending optional product newsletters (you may unsubscribe at any time)
  • Responding to your support queries and feedback

3.5 Legal & Compliance

  • Complying with applicable Indian laws, regulations, and court orders
  • Enforcing our Terms & Conditions and Community Guidelines
  • Responding to legal process or government requests as required by law
  • Protecting the rights, property, and safety of our users and staff

4. Sharing & Disclosure

We do not sell your personal data. We do not share your personal data with third parties for their own marketing purposes. We may share information only in the following limited circumstances:

4.1 Service Providers

We engage trusted third-party companies to process data on our behalf. These processors are contractually bound to handle data only as instructed by us:

  • Razorpay India Pvt. Ltd. — payment processing and fraud detection
  • Google LLC — Calendar and Meet integration (only when you opt in)
  • Sarvam AI — AI-powered voice and language processing features (see Section 6)
  • MongoDB Atlas (MongoDB, Inc.) — cloud database hosting
  • Vercel Inc. — frontend hosting and edge delivery
  • Email delivery providers — transactional email dispatch

4.2 Therapist Profiles

If you are a verified Therapist, your name, professional bio, qualifications, specialisations, and availability are displayed publicly on the Platform so Clients can make informed booking decisions.

4.3 Legal Requirements

We may disclose your information if required to do so by law or in good-faith belief that such disclosure is necessary to: (a) comply with a legal obligation, court order, or government request; (b) protect and defend our legal rights; (c) prevent or investigate possible wrongdoing in connection with the Platform; or (d) protect the personal safety of users of the Platform or the public.

4.4 Emergency Situations

Where we believe in good faith that a user may be at imminent risk of harm to themselves or others, we may disclose relevant information to emergency services or appropriate authorities, even without your consent, as permitted under applicable Indian law including the Mental Healthcare Act, 2017.

4.5 Business Transfers

If MannMate Technologies Private Limited undergoes a merger, acquisition, or sale of all or substantially all its assets, your personal data may be transferred as part of that transaction. We will notify you via email and/or a prominent notice on the Platform at least 30 days before your data becomes subject to a different privacy policy.

5. P2P Session PrivacyKey terms

This section specifically addresses the privacy of real-time Person-to-Person peer listening sessions on the Platform. Please read this section carefully — it describes how audio and session data is handled during live calls.

5.1 WebRTC Architecture

Peer listening sessions use WebRTC (Web Real-Time Communication) technology. Audio streams are transmitted directly between your device and your Listener's device via an encrypted peer-to-peer channel. Your audio during a P2P session does not pass through our servers. Our servers are only used for signalling (establishing the connection) and do not receive or record your audio content.

5.2 What We Do and Do Not Record

  • We DO record: session metadata (start/end time, duration, connection quality, session ID)
  • We DO record: mood check-ins and ratings you submit before or after a session
  • We DO record: post-session feedback and any written reports you or your Listener file
  • We do NOT record: the audio content of your P2P peer listening session
  • We do NOT store: your Listener's identity in a way that allows re-identification outside the session

5.3 Session Monitoring

Our Listener Code of Conduct requires Listeners to flag sessions involving crisis situations, policy violations, or safeguarding concerns through the in-app reporting tool. Such flags are reviewed by our Trust & Safety team. The flag itself and any written context are stored; audio is not.

5.4 Anonymity

Listeners see only your display name (not your real name, email, or account details) during a session. Similarly, you see only the Listener's display name. MannMate strongly advises you not to voluntarily share personally identifying information during a session. Any information you choose to share verbally during a session is shared at your own discretion and risk.

5.5 Therapist Video Sessions

Video consultations with licensed Therapists are conducted over Google Meet. Google's privacy policy applies to the content of Google Meet sessions. MannMate facilitates the booking and link generation but does not access or store the video or audio content of therapist consultations.

6. AI & Automated Processing

6.1 Sarvam AI Integration

The Platform integrates Sarvam AI's language models to power certain features, including multilingual support, mood analysis prompts, and conversational guidance features. When these features are active, anonymised or pseudonymised conversation or input data may be processed by Sarvam AI's systems. This data is processed under a data processing agreement that requires Sarvam AI to handle data securely and only for the purposes we specify.

6.2 What Is Processed

  • Text prompts or inputs you submit to AI-powered features
  • Mood descriptions or check-in responses for personalised suggestions
  • Language preference signals for localisation

6.3 What Is Not Used for AI Training

Audio or video content from P2P sessions or therapist consultations is never used to train AI models. Text-based interactions with our AI features may be used in anonymised, aggregated form to improve model quality, only where you have provided explicit consent or where such use is permitted under applicable law.

6.4 Automated Decision-Making

Our matching algorithm for P2P sessions uses automated processing to pair Clients with available Listeners. This processing is based on queue position, availability, and platform-defined compatibility signals. No sensitive personal data (such as your mental health disclosures) is used in the matching algorithm. You have the right to request a manual review of any automated decision that significantly affects you.

7. Payments & Financial Data

7.1 Payment Processor

All payment transactions on the Platform are processed by Razorpay India Pvt. Ltd., a PCI-DSS compliant payment service provider. When you make a payment, you interact directly with Razorpay's secure checkout interface. MannMate does not store your full card number, CVV, UPI PIN, or net banking credentials.

7.2 What We Store

  • Razorpay Order ID and Payment ID (for transaction reconciliation)
  • Amount, currency, and timestamp of each transaction
  • Payment method type (UPI, card, net banking) without sensitive identifiers
  • Wallet balance and transaction history within the Platform
  • Refund records and associated session details

7.3 Wallet Data

Your in-platform Wallet balance is associated with your account and reflected in real time. All credits, deductions, and refunds are logged in your transaction history, which you can view at any time from your Dashboard.

7.4 Retention of Financial Records

We retain financial transaction records for a minimum of 7 years from the date of transaction to comply with applicable Indian accounting and tax laws (including the Income Tax Act, 1961 and GST regulations), even if you delete your account.

8. Cookies & Tracking

8.1 What We Use

We use the following types of cookies and local storage mechanisms:

  • Essential cookies: required for authentication, session management, and security (e.g., JWT token storage in localStorage)
  • Functional cookies: remember your preferences such as theme, language, and display settings
  • Analytics cookies: anonymised usage statistics to understand how users interact with the Platform (e.g., page views, feature usage)
  • Advertising cookies: the main Platform (mannmate.com) does not display ads. On our public blog (blogs.mannmate.com), Google AdSense may use cookies to serve and measure ads and, where permitted, to personalise the ads you see based on your visits to this and other websites

8.2 Authentication Tokens

We store your authentication token (JWT) in your browser's localStorage. This is necessary to keep you signed in between sessions. The token is cryptographically signed and expires after 30 days of inactivity. You can remove it by signing out or clearing your browser data.

8.3 Managing Cookies

You can control cookie behaviour through your browser settings. Disabling essential cookies will prevent you from signing in or using authenticated features. We do not respond to "Do Not Track" browser signals at this time.

8.4 Advertising & Personalisation Choices

You can opt out of personalised advertising by Google by visiting adssettings.google.com, or opt out of third-party vendors' use of cookies for personalised advertising by visiting optout.aboutads.info. These settings are independent of your MannMate account and are managed entirely by your browser and Google.

9. Data Retention

We retain personal data for no longer than is necessary for the purposes for which it was collected, or as required by law:

  • Account data: retained for the lifetime of your account plus 90 days after deletion request
  • Session metadata (call logs, timestamps, durations): retained for 2 years
  • Mood check-ins and ratings: retained for 2 years or until you request deletion
  • Appointment records: retained for 5 years (medical records obligation under Indian law)
  • Financial transaction records: retained for 7 years (tax and accounting obligations)
  • Therapist verification documents: retained for 3 years after the therapist's account is closed
  • Safety flags and incident reports: retained for 5 years
  • IP address logs: retained for 90 days for security and fraud prevention

After retention periods expire, data is securely deleted or anonymised so it can no longer be linked to you.

10. Your RightsKey terms

Under applicable Indian data protection law (including the Digital Personal Data Protection Act, 2023) and general privacy principles, you have the following rights with respect to your personal data:

10.1 Right to Access

You have the right to request a copy of the personal data we hold about you. We will provide this within 30 days of a verified request.

10.2 Right to Correction

You have the right to request correction of inaccurate or incomplete personal data. You can update most account information directly from your Dashboard settings.

10.3 Right to Erasure

You may request deletion of your personal data and account. We will process this within 30 days, subject to legal retention obligations (e.g., financial records, safety incident logs). Deleted data cannot be recovered.

10.4 Right to Withdraw Consent

Where we rely on your consent to process personal data (e.g., for optional AI features or marketing emails), you may withdraw that consent at any time. Withdrawal does not affect the lawfulness of processing before the withdrawal.

10.5 Right to Data Portability

You may request an export of your personal data in a machine-readable format (JSON or CSV). This includes your account information, session history, and mood log data.

10.6 Right to Object

You may object to processing of your personal data for certain purposes, including direct marketing. We will cease that processing unless we have compelling legitimate grounds that override your interests.

10.7 How to Exercise Your Rights

To exercise any of these rights, email us at business.mannmate@gmail.com with the subject line "Data Rights Request". We may need to verify your identity before processing the request. There is no fee for making a request unless it is manifestly unfounded or excessive, in which case we may charge a reasonable fee or refuse.

11. Data Security

11.1 Technical Safeguards

  • All data transmitted between your browser and our servers is encrypted using TLS 1.2 or higher (HTTPS)
  • P2P audio sessions use DTLS-SRTP encryption via WebRTC
  • Passwords are hashed using bcrypt with a per-user salt — we never see your plaintext password
  • Authentication tokens (JWT) are signed with RS256 and have short expiry windows
  • Database access is restricted to authorised services via IP allowlists and credential rotation
  • Sensitive fields (OAuth tokens, payment tokens) are encrypted at rest using AES-256

11.2 Organisational Safeguards

  • Access to personal data is restricted to team members with a documented need
  • All team members with data access are bound by confidentiality obligations
  • We conduct regular reviews of access permissions and data handling practices
  • Security incidents are logged and reviewed as part of our incident response process

11.3 Breach Notification

In the event of a data breach that poses a risk to your rights and freedoms, we will notify affected users and relevant authorities within 72 hours of becoming aware of the breach, as required by applicable law. The notification will include the nature of the breach, data affected, likely consequences, and steps we are taking to mitigate harm.

12. Children's Privacy

The Platform is intended for users aged 18 and above. We do not knowingly collect personal data from children under the age of 13. Users aged 13–17 may access the Platform only for general informational purposes and only with verifiable parental or guardian consent.

If we become aware that we have inadvertently collected personal data from a child under 13 without appropriate parental consent, we will take prompt steps to delete that data. If you believe a child under 13 has created an account on our Platform, please contact us at business.mannmate@gmail.com.

13. Third-Party Services

The Platform integrates with the following third-party services. Each has its own privacy policy, which we encourage you to review:

  • Google LLC (OAuth, Calendar, Meet) — policies.google.com/privacy
  • Google AdSense (Advertising on our blog at blogs.mannmate.com) — policies.google.com/technologies/ads
  • Razorpay India Pvt. Ltd. (Payments) — razorpay.com/privacy
  • Sarvam AI (AI language processing) — sarvam.ai/privacy
  • MongoDB Atlas (Database hosting) — mongodb.com/legal/privacy-policy
  • Vercel Inc. (Frontend hosting) — vercel.com/legal/privacy-policy

Our inclusion of a link to a third-party service does not constitute an endorsement of that service's privacy practices. We are not responsible for the privacy or security practices of third-party services.

14. International Data Transfers

MannMate is incorporated and operates primarily in India. Your personal data is stored and processed primarily on servers located in India (MongoDB Atlas — Mumbai region).

Some of our service providers may process data outside India (e.g., Vercel's edge network, Sarvam AI infrastructure). Where data is transferred outside India, we ensure appropriate safeguards are in place, including: (a) contractual data processing agreements; (b) the recipient country offering an equivalent level of data protection; or (c) other legally recognised transfer mechanisms.

15. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make material changes, we will:

  • Post the updated Policy on this page with a revised "Last updated" date
  • Send an email notification to your registered email address
  • Display a prominent in-app banner for at least 14 days

Your continued use of the Platform after the effective date of any changes constitutes acceptance of the revised Policy. If you do not agree to the revised Policy, you must stop using the Platform and may request deletion of your account.

Note:We recommend reviewing this Policy periodically. Material changes will always be communicated by email — make sure your registered email address is current.

16. Contact Us

If you have any questions, concerns, or complaints about this Privacy Policy or our data practices, please contact our Privacy team:

Privacy Officer
MannMate Technologies Private Limited
Response time: within 30 days of a verified request
REGISTERED ADDRESS
MannMate Technologies Private Limited
Bengaluru, Karnataka — 560001
India
MannMate Technologies Private Limited · Bengaluru, India
Last updated July 6, 2026 · Effective June 13, 2026
Terms & Conditions·Community Guidelines·