What we collect: Just your email, basic business profile info, and AI prompts you type.
How we use it: Only to run the app, generate audits, and manage your account.
AI Privacy: Your data is sent to AI models (like Groq/Google) for processing, but they do not use your data to train their models.
Payments: Handled securely by Razorpay. We never see your card details.
No Creepy Ads: We do not sell your data to marketers, nor do we use Facebook Pixels or tracking ads.
Privacy Policy
Last Updated: 29 July 2026 | Effective Date: 29 July 2026
ARTIX (a proprietary company owned by Gujjari Benjamin Vishal Anand; LIN: AP-06-18-006-03857412; UDYAM: UDYAM-AP-20-0064064) (“Company”, “we”, “our”, “us”), based in Vijayawada, Andhra Pradesh, India, operates the ARTIX Funnel Creator platform accessible at artix.co.in (the “Service”). We are committed to protecting your personal data and handling it responsibly and transparently. This Privacy Policy describes what data we collect, why we collect it, how we use and share it, and what rights you have over it — in compliance with the Information Technology Act, 2000 (IT Act) and the Digital Personal Data Protection Act, 2023 (DPDP Act) of India. This platform is built exclusively for India (specifically Vijayawada, Visakhapatnam, and AP jurisdictions). We do not adhere to and are not responsible for foreign data compliance laws (such as GDPR or CCPA).
By accessing or using the Service, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with any part of it, please discontinue use of the Service.
1. Who This Policy Applies To
This Policy applies to:
Registered users — individuals who create an account on the Service using email OTP authentication.
Visitors — individuals who browse our website without creating an account.
Paying customers — users who purchase Growth, Scale, or Credit Pack plans via Razorpay.
2. Data We Collect
2.1 Information You Provide Directly
Identity & Contact: Your full name and email address, collected at signup.
Business Profile: Business name, industry, website URL, location, and other details you enter during onboarding to enable auditing and brand intelligence features.
AI Prompts & Inputs: Text, descriptions, and other content you submit to generate brand intelligence reports, website audits, SEO rewrites, scale playbooks, or other AI-powered outputs. These inputs are processed by third-party AI providers (see §6).
2.2 Information We Collect Automatically
Authentication Tokens: We issue a signed JSON Web Token (JWT) stored as an HTTP-only, Secure, SameSite=Strict cookie to maintain your logged-in session. We do not use third-party tracking cookies.
Usage Data: Credit consumption, audit history, task completion, plan status, and other usage events within the Service, stored in our database to operate the platform.
Technical Data: IP address, browser type, operating system, referring URL, and device type — collected via our error monitoring and performance tooling (see §6).
Session Replay Data: We use Sentry Session Replay to record anonymised recordings of user sessions to diagnose bugs and improve usability. Session replay is configured with maskAllText: true and blockAllMedia: true, meaning all text content you type and all media displayed on screen are automatically masked/blocked before transmission. No readable personal data is captured in replays.
Error & Performance Data: Unhandled exceptions, stack traces, and page performance metrics collected via Sentry.
2.3 Payment Data
All payment transactions are processed by Razorpay (Razorpay Software Private Limited, India). We do not collect, store, or have access to your credit/debit card numbers, UPI IDs, net banking credentials, or bank account details. Razorpay returns only a payment ID and order status to our servers to confirm a successful transaction.
3. Legal Basis for Processing (DPDP Act, 2023)
Under the Digital Personal Data Protection Act, 2023, we process your personal data on the following bases:
Consent: You consent to data processing by accepting this Privacy Policy and our Terms of Use when you create an account. You may withdraw consent at any time by deleting your account (see §9).
Contractual Necessity: Processing required to provide the Service you have signed up for — authentication, credit management, audit generation, and payment confirmation.
Legitimate Interest: Error monitoring, security, fraud prevention, and product improvement — balanced against your privacy rights.
Legal Obligation: Retention of transaction records as required by Indian tax and accounting law.
4. How We Use Your Data
Service Delivery: To authenticate you, manage your account, track your AI credit balance, generate business audits and brand intelligence reports, produce SEO rewrites and scale playbooks, and display your health score dashboard.
Payments & Billing: To verify payment completion via Razorpay webhooks and update your subscription or credit balance accordingly.
Transactional Communications: To send OTP authentication emails via our SMTP service (mail.artix.co.in), billing confirmations, and service status notifications. We do not send unsolicited marketing emails.
Security & Fraud Prevention: To detect, investigate, and prevent unauthorised access, abuse, or other security incidents.
Error Monitoring & Debugging: To identify and fix bugs using Sentry error tracking and session replays.
Legal Compliance: To comply with applicable laws, regulations, legal proceedings, or enforceable government requests.
We do not use your data to train our own AI models, and we do not sell, rent, or trade your personal data to third-party marketing companies, data brokers, or advertisers.
5. AI-Powered Features & Your Input Data
ARTIX Funnel Creator uses multiple third-party AI APIs to generate brand intelligence, audit reports, SEO content, and playbooks. When you trigger an AI-powered feature, the relevant portions of your business profile and your explicit prompt inputs are transmitted to the applicable API provider solely to generate the requested output.
We transmit only the minimum data necessary for each AI call (no unnecessary personal data is included).
We rely on standard enterprise API agreements under which providers are prohibited from using API request data to train their foundational models.
Outputs are stored in our database and associated with your account to power your dashboard.
You retain all rights to the content you input. The AI-generated outputs belong to you subject to the applicable AI provider's terms.
6. Third-Party Sub-Processors
We engage the following sub-processors to operate the Service. Each is bound by contractual data-processing obligations:
Provider
Purpose
Data Shared
Region
Razorpay
Payment processing
Order amount, currency, user email for receipt
India
Vercel
Application hosting & deployment
Request logs, IP address, device info
Global edge (nearest region)
Supabase
Database hosting (PostgreSQL)
All account and usage data
India / as configured
Groq
AI inference (LLM)
Your business profile & prompt inputs
USA
OpenRouter
AI model routing
Your business profile & prompt inputs
USA
Google Gemini
AI inference (LLM / multimodal)
Your business profile & prompt inputs
USA / EU
HuggingFace
AI inference
Your business profile & prompt inputs
USA / EU
Sentry
Error monitoring & session replay
Stack traces, masked session data, IP, device info
Germany (EU)
ARTIX SMTP (artix.co.in)
Transactional email (OTP, receipts)
Your email address, OTP code
India
Where sub-processors are located outside India (such as Vercel, Groq, OpenRouter, Google Gemini, HuggingFace, and Sentry), we rely on standard contractual clauses and the provider's compliance certifications (SOC 2, ISO 27001, etc.) to ensure adequate protection of your data.
7. Cookies & Tracking Technologies
Session Cookie: A single HTTP-only, Secure, SameSite=Strict JWT cookie is set on login. It expires when your session ends or after 7 days of inactivity. This cookie is strictly necessary for the Service to function.
No Third-Party Advertising Cookies: We do not use Google Analytics, Facebook Pixel, or any advertising tracking technologies.
Sentry SDK: The Sentry browser SDK sets no persistent cookies; it uses a transient in-memory session ID.
8. Data Retention
Account Data: Retained for as long as your account is active plus 90 days following account deletion (to allow for dispute resolution), after which it is permanently deleted.
Payment Records: Transaction logs retained for 7 years as required by Indian tax law (GST compliance).
Error & Replay Data (Sentry): Retained for 30 days by Sentry by default; we do not extend this retention.
AI Outputs: Stored in your account until you delete them or delete your account.
OTP Codes: One-time passwords are valid for 10 minutes and are permanently deleted after use or expiry.
9. Your Rights Under the DPDP Act, 2023
As a Data Principal under India's Digital Personal Data Protection Act, 2023, you have the following rights:
Right to Access: Request a summary of the personal data we hold about you.
Right to Correction: Request correction of inaccurate or incomplete personal data.
Right to Erasure: Request deletion of your personal data. You may do this by emailing info@artix.co.in or deleting your account from the Settings page. We will action verified deletion requests within 30 days.
Right to Grievance Redressal: Lodge a complaint with our designated Grievance Officer (see §13) if you believe your data rights have been violated.
Right to Nominate: Under the DPDP Act, you may nominate another individual to exercise your data rights in the event of your death or incapacity.
10. Data Security
We implement appropriate technical and organisational safeguards commensurate with the sensitivity of the data:
All passwords are hashed using bcrypt before storage.
Authentication uses signed JWTs with short expiry and HTTP-only cookies.
All data in transit is encrypted via TLS/HTTPS in production.
Database access is restricted to authorised application services only.
Rate limiting is applied to authentication and AI generation endpoints to prevent abuse.
Session replay is configured to mask all text and block all media before transmission to Sentry.
No method of electronic transmission or storage is 100% secure. While we strive to use commercially acceptable means to protect your data, we cannot guarantee absolute security.
11. Children's Privacy
The Service is not directed to, and we do not knowingly collect personal data from, individuals under the age of 13. If we become aware that a child under 13 has provided us with personal data, we will delete it immediately. If you believe a child under 13 has submitted data through our Service, please contact us at info@artix.co.in.
12. Changes to This Policy
We may update this Privacy Policy periodically. Material changes will be communicated by updating the “Last Updated” date at the top of this page and, where required by law, by sending a notification to the email address associated with your account. Your continued use of the Service after changes take effect constitutes your acceptance of the revised Policy.
13. Grievance Officer & Contact
In accordance with the Information Technology Act, 2000 and the DPDP Act, 2023, the name and contact details of the Grievance Officer are provided below:
Grievance Officer / Proprietor: Gujjari Benjamin Vishal Anand