Privacy Policy
An itemised account of the personal data Neeli collects, the purpose behind each item, who processes it, how long we keep it, and how to make us delete it.
- Version
- 1.0
- Effective
- Last updated
- Reading time
- 17 min
On this page23 sections · ShowHide
- Who we are
- Words used in this policy
- What we collect
- Data you give us — users
- Data you give us — listeners
- Data generated by using Neeli
- Data collected automatically
- Data we receive from others
- What we do not collect
- Why we process your data
- Legal basis and consent
- Withdrawing your consent
- Permissions the app asks for
- Who we share data with
- Transfers outside India
- How long we keep data
- How we protect your data
- If there is a data breach
- Your rights
- Children
- Grievance redressal
- Changes to this policy
- Contact
This policy explains what personal data Neeli collects, why we collect it, who else touches it, how long we keep it and what you can make us do with it. It is written to be read by the person it is about, not only by a regulator, so the plain explanation comes first and the legal precision follows it.
It applies to the Neeli mobile app for users, the Neeli app for listeners, this website, and our support channels.
Who we are
Neeli is operated by XYRAVON STUDIOS LLP, with its registered office at 1st Floor, SP Castle, Farook College Road, Ramanattukara, Feroke, Kozhikode, Kerala 673633, India.
For the purposes of the Digital Personal Data Protection Act, 2023 (DPDP Act) we are a Data Fiduciary: we decide what personal data is collected and why. For the purposes of the Information Technology Act, 2000 we are an intermediary, because conversations on Neeli are created by the people having them and not by us.
Our Data Protection Officer is Aman, reachable at contact@neeliapp.com.
Words used in this policy
- User — a person who uses Neeli to talk to a listener.
- Listener — a person verified and onboarded by Neeli to receive calls from users. Listeners are independent contractors, not employees.
- Credits — the in-app balance that funds calls. Credits are a virtual in-app item, not money.
- Personal data — any data about an identifiable individual.
- Sensitive personal data — under the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, this includes financial information such as bank account details, and biometric information.
- Data Principal — you, the person the data is about.
- Processing — anything done with data: collecting, storing, using, sharing, erasing.
What we collect
We collect different data from users and from listeners. Listener onboarding is significantly heavier, because we are paying a real person and are obliged to know who they are.
Data you give us — users
| Data | Purpose | Mandatory | Kept for |
|---|---|---|---|
| Email address, display name and account identifier from your sign-in provider (Google Sign-In, or Sign in with Apple on iOS) | Creating and securing your account, signing you in, contacting you about your account | Yes | Until deletion, plus 30 days |
| Nickname | What listeners see instead of your real name | Yes | Until deletion, plus 30 days |
| Profile photo, if you upload one | Personalising your account | No | Until you remove it, or deletion |
| Reports you submit about a call | Investigating conduct and protecting other people | No | 3 years from the report |
| Problem reports and support messages | Answering you and fixing bugs | No | 24 months |
Data you give us — listeners
| Data | Purpose | Mandatory | Kept for |
|---|---|---|---|
| Full name, nickname, date of birth | Identity, eligibility (18+), payouts | Yes | Engagement plus statutory period |
| Phone number | Onboarding, payout and account-security contact | Yes | Engagement plus statutory period |
| Bio and languages spoken | Shown on the listener profile users choose from | Yes | Until removed, or deletion |
| Selfie photograph | Verifying the person applying is the person in the ID | Yes | Engagement plus statutory period |
| Government photo identity document | Verifying identity and age before a listener can be paid. Any valid one is accepted | Yes | Engagement plus statutory period |
| PAN | Tax deduction and reporting on listener earnings. Optional — without it, tax is deducted at the higher rate under section 206AA | No | 8 years (tax and company law) |
| Bank account holder name, account number and IFSC | Paying earnings out | Yes | 8 years (tax and company law) |
| Earnings, incentives and payout history | Calculating and evidencing payments, tax compliance | Yes | 8 years |
Identity documents and bank details are sensitive personal data. They are stored with restricted access, are never displayed back inside the app, and are never shared with other users or listeners.
A listener chooses which photo identity document to give us; no particular one is required. Where the document supplied is an Aadhaar, we mask it and retain only the last four digits — we do not store the full Aadhaar number, and we never use it as an account identifier.
Data generated by using Neeli
| Data | Purpose | Kept for |
|---|---|---|
| Call records: call identifier, participants, audio or video, start and end time, duration, credits used, how the call ended | Billing, safety investigations, dispute resolution, support | 24 months |
| Real-time calling identifiers: channel name, session identifier and access token | Establishing the call itself | Duration of the call, plus short-lived operational logs |
| Presence: whether you are online, busy or offline | Showing who is available to talk right now | Transient, not retained historically |
| Credit balance and transaction ledger | Running your balance, resolving billing disputes | 8 years for payment records |
| Blocks you have set | Keeping blocked accounts out of your view and preventing calls between the two accounts | Until you remove the block, or deletion |
We store call metadata. We do not store what was said. See What we do not collect.
Data collected automatically
| Data | Purpose | Kept for |
|---|---|---|
| Device identifier | Preventing repeat abuse of one-time promotional offers, and detecting fraudulent or duplicate accounts | See the retention note below |
| Push notification token | Delivering incoming-call alerts and account notifications | Until deletion or token rotation |
| App version, operating system, device model and build | Support, crash triage, compatibility | 12 months |
| IP address and server logs | Security, fraud prevention, abuse investigation, service reliability | 90 to 180 days |
| Crash diagnostics | Fixing crashes | 90 days |
One retention rule you should know about
When a one-time promotional credit — a welcome bonus or a referral reward — is claimed, we permanently record that the offer was claimed against that device and that email address. That record survives account deletion, because its entire purpose is to stop the same person claiming the same one-time offer again by opening a new account. It contains only the fact of the claim and the identifiers it was bound to.
Data we receive from others
- Google, when you sign in with Google: your email address, name and a stable account identifier. We do not receive your Google password.
- Apple, when you sign in with Apple on iOS: your name and email address, or an Apple private relay address if you choose to keep your email private. We do not receive your Apple password.
- Our payment processor, when you buy credits: the status of the payment, the order and payment reference, and the amount. We do not receive or store your card number, UPI PIN, CVV or bank credentials.
What we do not collect
Being explicit about the absences matters as much as listing the presences.
- We do not record the content of your calls. Neeli does not record, store or listen to the audio or video of a conversation. What we keep is metadata: who spoke to whom, when, for how long, and how the call ended. Recording a Neeli call is separately prohibited for both users and listeners under our Community Guidelines, and we act on reports of it.
- We do not read, store or upload your contacts.
- We do not read your SMS messages.
- We do not collect your precise location or GPS coordinates.
- We do not track you across other apps or websites.
- We do not sell personal data, and we do not share it with data brokers or advertising networks.
Why we process your data
| Purpose | Data used |
|---|---|
| Creating your account and signing you in | Sign-in provider account details, nickname |
| Connecting and running calls | Presence, calling identifiers, device permissions, call metadata |
| Charging for calls and maintaining your balance | Credit ledger, call duration, payment records |
| Verifying listeners before they can earn | Name, date of birth, phone number, photo identity document, selfie |
| Paying listeners and meeting tax obligations | Bank details, earnings history, tax identifiers |
| Preventing fraud and abuse of promotions | Device identifier, email, claim records |
| Investigating reports and keeping people safe | Reports, call metadata, block lists, account history |
| Delivering incoming calls and alerts | Push token, device details |
| Customer support | Support messages, account and call references |
| Legal compliance and responding to lawful requests | Whatever the specific obligation requires |
| Improving the product | Aggregated and de-identified usage data |
Legal basis and consent
Most processing described here is carried out on the basis of your consent, given when you create an account and accept this notice. Under the DPDP Act your consent is free, specific, informed, unconditional and unambiguous, given by a clear affirmative action, and limited to the personal data necessary for the stated purpose.
Some processing relies instead on certain legitimate uses recognised by the DPDP Act, including compliance with law, responding to a legal order, and preventing fraud.
We do not use your personal data for automated decision-making that produces legal effects for you.
Withdrawing your consent
You may withdraw consent at any time, and it must be as easy to withdraw as it was to give.
- In the app: Profile → More → Delete account
- By email: write to contact@neeliapp.com from your registered email address
- On the web: use the routes on our Account and Data Deletion page
Withdrawing consent means we can no longer provide the service, because every core function of Neeli depends on the data described above. In practice, withdrawal leads to closure of your account. Processing already carried out before withdrawal remains lawful, and data we are legally required to retain is retained — the deletion page lists exactly what that is.
When you request deletion we delete the account and the user data associated with it. The account is terminated immediately, with no waiting period and no grace period in which it can be restored; erasing the data behind it runs on the timeline set out on the Account and Data Deletion page. Temporarily deactivating, disabling or "freezing" an account is not account deletion and we do not treat it as such.
You can also disconnect Neeli from the sign-in provider you used, from inside that provider's own account settings, which revokes our access to the account you signed in with.
Permissions the app asks for
Permissions are requested at the moment they are needed, with an explanation, and you can refuse or revoke any of them in your device settings.
| Permission | Why Neeli asks | If you refuse |
|---|---|---|
| Microphone | Two-way audio during a call | You cannot make or receive calls |
| Camera | Video calls, and the verification selfie for listeners | Video calls are unavailable; listeners cannot complete verification |
| Notifications | Ringing for incoming calls, balance and call-time alerts | You will miss incoming calls and alerts |
| Photos and media | Uploading a profile picture, and identity documents for listeners | You cannot upload images |
| Display over other apps and full-screen intent | Showing the incoming-call screen when the phone is locked | Incoming calls may only appear as a normal notification |
Who we share data with
We share personal data only with the processors below, only for the purposes listed, and only to the extent needed.
| Recipient | What they receive | Why |
|---|---|---|
| Google (Firebase Authentication and Google Sign-In) | Email, name, account identifier | Signing you in and securing accounts |
| Apple (Sign in with Apple, iOS) | Name and email address, or an Apple private relay address if you choose to hide your email | Signing you in on iOS |
| Firebase Cloud Messaging | Push token, notification payloads | Delivering incoming-call and account notifications |
| Firebase Storage | Profile photos, listener verification images | Storing uploaded images |
| Agora | Real-time audio and video streams, channel identifiers, IP address | Carrying the call itself |
| Razorpay or PayU | Name, email, phone, payment instrument details, amount | Taking payment and issuing refunds |
| Hostinger | Application data, the database and server logs | Supplying the server on which the Neeli backend runs |
| Google Play and the Apple App Store | Purchase and device signals, where store billing is used | Distribution and store billing |
Each of these is an independent company with its own privacy policy. Our payment processor acts as a separate controller of payment data it collects directly from you.
We require every third party with whom we share user data — including analytics tools, advertising networks, third-party SDKs, and any parent, subsidiary or other related entity that will have access to user data — to provide the same or equal protection of user data as is stated in this privacy policy. These commitments are contractual, they restrict each recipient to processing the data only for the purposes set out above, and they oblige the recipient to apply security measures at least equivalent to our own.
We may also disclose personal data:
- to a court, regulator or law-enforcement agency under a lawful order;
- to professional advisers such as auditors and lawyers, under confidentiality;
- to an acquirer, in a merger, acquisition or restructuring, with notice to you.
Transfers outside India
The Neeli backend — your account, your profile and your call metadata — runs on servers located in India. That data stays in the country.
Some of the services we rely on operate globally, so parts of your data are processed outside India:
- real-time call traffic is routed through the nearest available edge node on our calling provider's global network;
- sign-in and push notifications are handled by Google and by Apple;
- store billing, where it is used, is handled by Google Play and the Apple App Store.
The DPDP Act permits transfer of personal data outside India except to countries restricted by the Central Government. Where data leaves India we require contractual commitments from the recipient to protect it, to process it only on our instructions, and to apply security measures at least equivalent to ours.
How long we keep data
| Category | Retention |
|---|---|
| Account and profile | Until deletion, plus 30 days |
| Call metadata | 24 months |
| Payment, invoice and tax records | 8 years, as required by the Limited Liability Partnership Act, 2008 and income-tax law |
| Listener verification documents | Duration of engagement, plus the statutory period after it ends |
| Abuse reports and moderation decisions | 3 years, including after the reporting account is deleted |
| Promotional claim records bound to a device or email | Retained permanently as an anti-fraud record |
| Server logs and crash data | 90 to 180 days |
| Backups | Purged within 90 days of deletion |
Where a legal hold, investigation or dispute applies, we retain the relevant data until it concludes.
How we protect your data
- Data is encrypted in transit using TLS.
- Data held by our managed storage providers is encrypted at rest by them.
- The Neeli backend runs on a server we operate ourselves. Our hosting provider supplies the machine and nothing more: its operating system, its security updates, its access controls and its backups are our responsibility, not theirs.
- Our database is encrypted at rest, backups run automatically on a schedule and are encrypted, and administrative access to the server requires key-based authentication — password logins are not accepted.
- Authentication tokens are held in the device's secure storage, not in plain application storage.
- Access to verification documents and bank details is restricted to the small number of staff who need it, and access is logged.
- Uploaded images are served through short-lived signed URLs, not public links.
- We follow reasonable security practices and procedures within the meaning of Rule 8 of the SPDI Rules, 2011.
No system is perfectly secure. If you believe your account has been compromised, write to contact@neeliapp.com immediately.
If there is a data breach
If a personal data breach occurs, we will notify each affected Data Principal without delay, in clear language, describing what happened, the likely consequences, the measures we have taken and what you can do.
We will also give the Data Protection Board of India an initial intimation immediately on becoming aware of the breach, and a detailed report within 72 hours covering the events leading to it, the mitigation applied, the findings on who caused it, remedial measures, and a copy of the notice sent to affected people.
Your rights
Under the DPDP Act you have the right to:
- Access a summary of the personal data we process about you and the processing activities involved;
- Correct, complete and update inaccurate or incomplete data;
- Erase your personal data, unless retention is required by law;
- Nominate another individual to exercise these rights on your behalf in the event of your death or incapacity;
- Grievance redressal through the channel below, before approaching the Board;
- Withdraw consent at any time.
To exercise any of these, write to contact@neeliapp.com from your registered email address. We may ask you to verify your identity, which protects you from someone else making requests in your name. We respond within 90 days, and usually much sooner.
You also have duties under the DPDP Act, including not impersonating another person when providing data and not filing false or frivolous grievances.
Children
Neeli is strictly for adults aged 18 and over. Under the DPDP Act a child is anyone under 18, and processing a child's personal data requires verifiable parental consent. We do not knowingly collect personal data from anyone under 18, we do not direct the service at children, and we do not carry out tracking, behavioural monitoring or targeted advertising towards children.
At sign-up we ask you to confirm your date of birth on a neutral age screen. Listeners must additionally provide a date of birth verified against an identity document.
If we discover that an account belongs to someone under 18, we terminate it immediately and delete the associated personal data, except anything we must preserve as evidence for a safety or law-enforcement matter. If you believe a child is using Neeli, tell us at contact@neeliapp.com and we will act.
Our Child Safety Standards set out this position in full.
Grievance redressal
If you are unhappy with how your personal data has been handled, contact our Grievance Officer, appointed under Rule 3(2) of the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021:
- Name: Aman
- Designation: Grievance Officer
- Email: contact@neeliapp.com
- Address: 1st Floor, SP Castle, Farook College Road, Ramanattukara, Feroke, Kozhikode, Kerala 673633, India
We acknowledge complaints within 24 hours and resolve them within 15 days. Complaints about content depicting nudity, sexual acts, impersonation or artificially morphed images of a person are acted upon within 24 hours.
If you remain dissatisfied, you may approach the Data Protection Board of India.
Changes to this policy
We keep every version of this policy, each with a version number and effective date, shown at the top of this page. If we make a material change we will notify you inside the app and by email before the new version takes effect. Continuing to use Neeli after a change takes effect means you accept the updated policy. If you do not accept it, you can delete your account.
Contact
- General support: contact@neeliapp.com
- Privacy and data rights: contact@neeliapp.com
- Data Protection Officer: Aman, contact@neeliapp.com
- Trust and safety: contact@neeliapp.com
- Child safety: contact@neeliapp.com
Full details are on our Contact us page.