Privacy Policy

DRENGR Privacy Policy (Draft)

AI-generated first draft — not yet legally reviewed. This document was generated by an AI assistant based on a direct review of DRENGR's actual application code and database schema as of 21 September 2026. It accurately reflects what the app currently collects and does — it is not generic boilerplate. However, it has not been reviewed by a qualified Indian lawyer and must not be published live until it has been. Give particular attention, during review, to: the refund policy referenced from the Terms of Service, the Digital Personal Data Protection Act, 2023 ("DPDP Act") compliance framing throughout, and every field marked [PLACEHOLDER: ...] below. Do not remove this notice until legal review is complete.


Last updated: [PLACEHOLDER: effective/last-updated date]

1. Who we are

This Privacy Policy ("Policy") describes how [PLACEHOLDER: legal entity name and type — e.g. "Jane Doe, sole proprietor" or "Drengr Technologies Private Limited"] ("DRENGR", "we", "us", "our"), the operator of the DRENGR fitness application and the website drengr.in (collectively, the "App" or "Service"), collects, uses, discloses, and protects personal data.

Registered address: [PLACEHOLDER: registered business address] GSTIN (if applicable): [PLACEHOLDER: GSTIN]

Under the DPDP Act, DRENGR acts as the Data Fiduciary and you, the user of the App, are the Data Principal. This Policy explains how we fulfil our obligations to you as Data Fiduciary and how you can exercise your rights as Data Principal.

By creating an account or using the App, you consent to the collection and processing of your personal data as described in this Policy. Where you are a minor, additional rules described in Section 5 apply, and certain processing will not begin until verifiable parental consent has been obtained.


2. What we collect, and why

We only collect data that supports a real, active feature of the App. The table below maps each category of personal data to the specific feature that creates it and the purpose for which we process it.

2.1 Identity and account data

DataSourcePurpose
Email addressClerk (our authentication provider) at sign-upAccount identification, login, transactional notifications (e.g. OTP emails)
Display nameYou, at profile setupShown on your profile and to other users per your visibility settings
Unique nickname/handleYou, at profile setupPublic identifier used in the follow/social graph and on shared plans
Profile picture URLYou, on uploadDisplayed on your profile

We do not store your password. Authentication (including password storage, if you use a password, or social/OAuth login) is handled entirely by Clerk, our third-party identity provider, which acts as a sub-processor for your login credentials and account email. We never see or store your raw password.

2.2 Physical and health-adjacent data

DataNotesPurpose
Height (cm)Profile fieldPersonalising workout tracking, display on profile (subject to your privacy toggle)
Weight (kg)A current profile field and, separately, a full daily history log if you opt in to the "body weight check-in" featureTracking body-weight trends over time, display on profile (subject to your privacy toggle)
Age rangeWe collect an age range only — never your exact date of birthAge-appropriate gating (e.g. minor status, see Section 5), display on profile (subject to your privacy toggle)
GenderStored AES-256-GCM encrypted at rest (not in plaintext)Personalisation, display on profile (subject to your privacy toggle)

We consider height, weight, age range, and gender to be sensitive personal data. Gender in particular is encrypted at the database layer using AES-256-GCM before it is ever written to disk, so that even direct database access does not reveal it in plaintext.

2.3 Minors' data and parental consent data

See Section 5 for a full description of this feature. In summary, if your account is flagged as belonging to a minor, we additionally process:

  • an isMinor flag and a hasParentalConsent flag on your account;
  • your parent/guardian's email address, submitted for the purpose of obtaining consent, stored AES-256-GCM encrypted — this is never stored or logged in plaintext;
  • a consent log entry recording the (encrypted) parent email and the timestamp at which consent was granted.

2.4 Workout and fitness data

  • Workout session history: dates, duration, and status (active / completed / missed).
  • Individual logged sets within each session: exercise performed, reps, weight used, a difficulty rating (easy / medium / hard), and whether the set was a warm-up or a working set.
  • Computed personal records — your best-ever lift per exercise, calculated from the above.
  • Custom workout plans you build. Plan structure (exercises, order, sets/reps prescriptions) is stored in our MongoDB Atlas datastore rather than our primary database, for technical reasons only; it receives the same contractual protection as the rest of your data (see Section 8).

This data exists solely to power the App's core training-log functionality and is not used for any advertising or profiling purpose.

2.5 Social features

  • A follow/follower graph between users.
  • Per-field privacy toggles that you control yourself: show height, show weight, show stats, show age, show gender, and show email. Each toggle is independent, defaults to OFF (private), and governs visibility to other App users on your public profile — not to DRENGR itself, which can access the underlying data regardless of your toggle settings for the purposes described in this Policy (e.g. safety, support, legal compliance).

2.6 Coach–athlete connection data ("Train")

If you use the Train feature to link a coach account and an athlete account (via a coach-generated invite code), we store your role (COACH or ATHLETE) and log lightweight "coach update events" — workout logged, day skipped, weight logged — so the linked coach can see high-level athlete activity. This is an account-linking feature analogous to a personal trainer and client sharing a paper logbook; it is not third-party data sharing, since both accounts are DRENGR users bound by DRENGR's Terms of Service, and the athlete controls the connection (it can be disconnected at any time — see Section 2.7).

2.7 OTP / verification data

One-time passcodes (OTPs) are used for: email verification, account deactivation, account deletion, coach-unlock, athlete-connect, and athlete-disconnect flows. OTPs are hashed with HMAC-SHA256 before storage — the raw code is never persisted to our database or written to logs. Each OTP expires after approximately 10 minutes, is locked after 3 incorrect attempts, and is subject to a 60-second resend cooldown.

2.8 Payment data

See Section 9 for full detail on the plan-purchase marketplace. In our own database, we store only: the identifier of the plan purchased, the buyer's and seller's user IDs, the purchase amount (in paise), a purchase status (pending / success / failed), and Razorpay's own order ID and payment ID as reference numbers.

We never see, receive, or store your card number, UPI ID, bank account details, or CVV. All of that is collected directly by Razorpay through its own hosted/embedded checkout, out of band from DRENGR's servers, in accordance with RBI and PCI-DSS requirements applicable to payment aggregators.

2.9 Preferences

Theme (light/dark) and weight-unit (kg/lb) preference. These are non-sensitive convenience settings.

2.10 What we do NOT collect

For clarity, DRENGR does not collect or use:

  • your exact date of birth (an age range only, as above);
  • precise GPS or other location tracking;
  • data from any third-party advertising SDK or tracking pixel — none is integrated into the App;
  • push-notification tokens — the App has no push-notification feature;
  • raw payment instrument data (card numbers, UPI IDs, bank details, CVV) — see Section 2.8.

3. Legal basis for processing (DPDP Act framework)

Under the DPDP Act, we process your personal data on the basis of your consent, given when you create an account and agree to this Policy, and (for minors) when a parent/guardian additionally provides verifiable consent as described in Section 5.

Where relevant, we also rely on the "certain legitimate uses" permitted under the DPDP Act without requiring fresh consent for each instance — for example, using your data to comply with a legal obligation (such as retaining payment records under tax law, see Section 6), or to respond to a medical emergency threatening life or health.

You may withdraw consent at any time, with the same ease with which it was given, by using the in-app account deactivation or deletion flow described in Section 10, or by contacting our Grievance Officer (Section 11). Withdrawing consent does not affect the lawfulness of processing carried out before withdrawal, and may mean certain features of the App are no longer available to you.


4. Purpose limitation

We use your personal data only for the purposes stated in Section 2 and this Policy: operating and improving the App's core features (training log, social graph, coach-athlete connection, plan marketplace), account security and verification, customer support, legal and tax compliance, and communicating with you about your account and transactions. We do not use your personal data for behavioural advertising, ad targeting, or sale to data brokers, because we do not run any advertising or tracking infrastructure of that kind.


5. Children's data and verifiable parental consent

DRENGR is built to accommodate younger users under Indian law, and takes this seriously through a dedicated technical flow rather than a checkbox disclaimer.

How it works:

  1. An account may be flagged internally with isMinor = true based on the age range you provide at sign-up.
  2. A minor account cannot access certain features until hasParentalConsent is set to true.
  3. To obtain consent, the App sends a one-time passcode (OTP) to the parent or guardian's email address (not the minor's).
  4. The parent/guardian enters the OTP to confirm they are a real, reachable adult who consents to their child's use of the relevant features.
  5. On success, we create a ParentalConsentLog record containing the parent's email (stored AES-256-GCM encrypted, never in plaintext) and the timestamp of consent. The OTP itself is never stored in raw form (Section 2.7).
  6. Until this flow completes, minor accounts remain gated from the features requiring consent.

What this means for you as a parent/guardian: you can decline consent, in which case the gated features simply remain unavailable to the minor's account. You may also withdraw consent at any time by contacting our Grievance Officer (Section 11), which will re-lock the relevant features.

No tracking or targeted advertising of children. In compliance with Section 9 of the DPDP Act, DRENGR does not undertake behavioural monitoring, profiling, or targeted advertising directed at any user it has identified (or ought reasonably to have identified) as a child. As stated in Section 2.10, DRENGR has no advertising or tracking infrastructure of any kind — so this restriction is met by the App's fundamental design, not merely a policy promise for this one class of user.


6. Data retention

  • Account and profile data, workout/fitness data, social graph data, coach-athlete data: retained for as long as your account remains active.
  • On account deletion: we permanently erase (or irreversibly anonymise, where immediate deletion is technically infeasible) your personal data within [PLACEHOLDER: retention window, e.g. 30 days] of the deletion request being confirmed, except as described below.
  • Deactivated (not deleted) accounts: data is retained but access-restricted, since deactivation is designed to be reversible; deactivation is not the same as erasure (see Section 10).
  • Payment / financial records (purchase records, Razorpay order and payment IDs, amounts, invoices): Indian tax law (including the Income Tax Act, 1961 and applicable GST record-keeping rules) requires us to retain financial records for a longer statutory period. We retain payment-related records for approximately 8 years, distinct from and irrespective of when the associated account is deleted.
  • OTP records: stored only in hashed form and only for the short duration needed for verification (see Section 2.7); expired/used OTP hashes are periodically purged.
  • Consent logs (including ParentalConsentLog): retained for as long as necessary to demonstrate compliance with the DPDP Act's consent requirements, even if the associated account is later deleted, unless you request earlier erasure and no legal ground requires retention.

7. How we secure your data

  • Encryption at rest for sensitive fields: gender and parental consent email are encrypted using AES-256-GCM before storage, so plaintext values are never written to our database.
  • OTP hashing: all one-time passcodes are hashed with HMAC-SHA256 before storage; raw codes are never persisted or logged, and are further protected by expiry (~10 minutes), a 3-attempt lockout, and a 60-second resend cooldown.
  • No password storage: authentication credentials are managed entirely by Clerk, our identity provider, under its own security program.
  • Payment isolation: raw payment instrument data never reaches our servers at all (Section 2.8), which meaningfully limits our exposure in the event of a breach.
  • Access to production data is restricted to personnel who need it to operate the Service, and industry-standard technical and organisational measures (encrypted transport (HTTPS/TLS), access controls, hosting-provider security) are used across our infrastructure.

No system is completely secure, and we cannot guarantee absolute security. See Section 12 for our breach-notification commitment.


8. Sharing with third parties and sub-processors

We do not sell your personal data. We share personal data only with the service providers below, each of which processes it solely to provide their specific service to us and under contractual confidentiality obligations — none of them is permitted to use your data for its own independent purposes (e.g. its own advertising).

Sub-processorRoleData it may process
ClerkAuthentication / identity providerEmail address, login/auth credentials, session data
MongoDB AtlasDatabase hosting for the exercise library and custom workout-plan contentWorkout plan structures, exercise library data
[PLACEHOLDER: our Postgres database hosting provider]Primary application database hostingAll primary-database personal data described in Section 2
VercelApplication hosting / serverless compute; Vercel Analytics and Speed InsightsRequest/hosting data; aggregate, privacy-respecting usage and performance metrics (not individual ad-tracking)
ResendTransactional email deliveryEmail address, OTP codes and notification content sent to you
RazorpayPayment processing (RBI-regulated payment aggregator, PCI-DSS compliant)Purchase amount, order/payment references, and — directly between you and Razorpay, never through us — your payment instrument details

We may also disclose personal data where required by law, in response to a valid legal process, or to protect the rights, property, or safety of DRENGR, our users, or the public.


9. Payments and the plan marketplace

Within the App, users may purchase workout plans published by other users, using Razorpay as the payment processor. When you make a purchase:

  • Razorpay's own checkout (hosted or embedded) collects your payment details directly — DRENGR's servers never receive or store your card number, UPI ID, bank details, or CVV.
  • Our database records only the plan ID, buyer and seller user IDs, the amount in paise, a purchase status, and Razorpay's order ID/payment ID as references, for reconciliation and support purposes.
  • Financial records generated this way are retained for the extended statutory period described in Section 6.

A separate UserSubscription data model exists in our database (tier FREE/PREMIUM) but is not currently a live, billed feature — no subscription billing is active, and no payment provider is currently wired up to it. This Policy will be updated before any such feature is activated.


10. Your rights, and how to exercise them

As a Data Principal under the DPDP Act, you have the right to:

  • Access a summary of the personal data we hold about you and the processing activities we carry out.
  • Correction and completion of inaccurate or incomplete personal data — most profile fields (height, weight, name, nickname, profile picture, gender, age range) can be edited directly in-app at any time.
  • Erasure of your personal data, which you can trigger yourself via the in-app account deletion flow. This is a genuine, irreversible, self-serve flow: it cascades through our database and permanently erases your account rows, subject only to the statutory retention carve-out for financial records described in Section 6.
  • Grievance redressal — see Section 11.
  • Nominate another individual to exercise your rights (including the right to erasure) in the event of your death or incapacity, as provided under the DPDP Act. To register a nominee, contact our Grievance Officer (Section 11) — as of this Policy's drafting, this is handled manually rather than via an in-app control.
  • Withdraw consent at any time (Section 3).

Deactivation vs. deletion: the App offers both a self-serve deactivation (temporary, reversible — your data is preserved and access-restricted, and you can reactivate by logging back in) and a self-serve deletion (permanent, irreversible — your data is erased as described above). Choose deletion if you want your data actually removed; deactivation only pauses your account.

To exercise any of these rights, use the relevant in-app control (Settings → Account) or contact our Grievance Officer below.


11. Grievance Officer

In accordance with the DPDP Act and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, we have appointed a Grievance Officer to address your questions, complaints, or requests concerning this Policy and your personal data.

  • Name: [PLACEHOLDER: Grievance Officer name]
  • Email: legal@drengr.in
  • Phone: [PLACEHOLDER: Grievance Officer phone number]
  • Address: [PLACEHOLDER: Grievance Officer / registered business address]

Response-time commitment: we will acknowledge your grievance within 48 hours of receipt and aim to resolve it within 30 days, in line with statutory timelines under Indian data protection law.


12. Data breach notification

In the event of a personal data breach that is likely to affect you, we will notify you and the relevant regulatory authority (the Data Protection Board of India, once constituted, and/or other authorities as required) without undue delay and in accordance with the timelines prescribed under the DPDP Act and its rules. Notification to you will describe the nature of the breach, the data likely affected, and the steps we are taking (and that you can take) in response.


13. Cross-border data storage and transfer

Some of our sub-processors (for example, Vercel and MongoDB Atlas) may store or process data on servers located outside India. The DPDP Act permits the transfer of personal data outside India except to countries specifically restricted by the Central Government (a "blacklist" mechanism, rather than the country-by-country "adequacy" model used elsewhere). As of this Policy's drafting, we do not transfer data to any government-restricted jurisdiction, and we require our sub-processors to maintain appropriate contractual and technical safeguards regardless of where they process data.


14. Cookies and local storage

DRENGR does not use tracking or advertising cookies, and does not run a cookie-consent banner because no non-essential tracking occurs. What the App does use:

  • Session cookies set by Clerk, our authentication provider, strictly necessary to keep you logged in and to secure your session.
  • A local (on-device) storage entry for your theme preference (light/dark), so the App remembers your display choice between visits. This never leaves your device as part of any tracking pipeline.

15. Children under this Policy vs. general audience

This Policy applies to all users. Section 5 describes additional protections specific to accounts flagged as belonging to minors. If you are a parent or guardian and believe your child has provided us with personal data without your consent outside of the verified flow described in Section 5, please contact our Grievance Officer immediately so we can investigate and, where appropriate, erase that data.


16. Changes to this Policy

We may update this Policy from time to time to reflect changes in the App's functionality or in applicable law. We will update the "Last updated" date at the top of this Policy and, for material changes, provide reasonable notice in-app or by email before the changes take effect.


17. Contact us

For any questions about this Policy or our data practices, contact:

  • Email: privacy@drengr.in
  • Grievance Officer: see Section 11.

18. Governing law

This Policy is governed by the laws of India, including the Digital Personal Data Protection Act, 2023, the Information Technology Act, 2000, and the rules made thereunder. Disputes arising from this Policy are subject to the jurisdiction described in our Terms of Service, Section on Governing Law & Dispute Resolution.