what we hold, who can see it, and how to have it deleted
Your data is yours. It is stored in India, we collect as little as we can, we never sell it or advertise against it, and your journal is readable by nobody but you. Where something is more complicated than that — the AI features, our operations team, the things the law makes us keep — this page says so plainly instead of leaving you to find out.
Last updated 8 August 2026 · v1.0
This is in force, and it is early. It describes exactly what Cashew does today, written by the people who built it rather than copied from a template — and it has not yet been reviewed by a lawyer. Some of it will get more precise as we incorporate. Where something here is unclear or you think it is wrong, tell us and we will fix it.
Cashew is a therapy platform operating in India. Cashew is built and run in India by its founding team, who are personally answerable for it. We have not yet incorporated a company. When we do, this page will name it as the party you are dealing with, and we will tell you rather than quietly editing the page. Under the Digital Personal Data Protection Act, 2023, we are the data fiduciary for the information described here — the ones responsible for it, and the ones you can hold to this document.
This policy covers everyone who uses Cashew: clients looking for therapy, therapists practising through us, and visitors to our website. Where something applies to only one of those, it says so.
It does not cover what your therapist does independently of Cashew. Your therapist is an independent professional with their own obligations to you; where they keep their own separate records outside our platform, those are theirs to explain.
Questions, corrections or complaints about anything here go to our Grievance Officer at support@cashew.care. A person answers — see section 19.
Only what a careful match and a safe session need. Each intake question tells you, on the screen, what it is used for before you answer it.
Nothing you write here is stored until you have read and agreed to a plain-language consent screen. We record which version of that wording you saw, along with a cryptographic fingerprint of the exact text, so that what you agreed to can always be established later. If we change the wording, we ask you again.
We do not buy data about you, we do not build advertising profiles, we do not sell anything to anyone, and we do not share your information with your college, your employer or your family.
If you practise through Cashew, we collect what is needed to verify you, present you honestly to clients, and pay you:
Under the DPDP Act we process your personal data on the basis of your consent, given for the specific purposes below. You can withdraw it — see section 13.
| What we do with it | What it uses |
|---|---|
| Match you with a therapist. Our system ranks verified therapists against your answers, and then a person on our team reads the shortlist and chooses one, writing you a note explaining why. | Your intake answers |
| Run your sessions — booking, reminders, joining the call, and everything in section 7. | Account details, bookings, phone if given |
| Let your therapist do their job — see your intake, keep clinical notes, and prepare for a session. | Intake, notes, anything you have shared |
| Take payment, and keep the records the law requires us to keep. | Payment records |
| Get help to you quickly if something you write suggests you are in danger. | The intake free-text answer only — see section 9 |
| Keep the service safe, working and honest — security, fraud prevention, fixing what is broken, and understanding what is confusing. | Technical data, feedback |
| Meet our legal obligations, including responding to lawful demands. | Whatever the obligation requires |
Your journal is yours alone. Not your therapist. Not our operations team. Not us. Not any AI. The database itself refuses every request for it that does not come from you.
There is exactly one way a journal entry becomes visible to anyone else: you choose to share that entry with your therapist, one entry at a time, by a deliberate action of your own. There is no setting that shares them all, and nothing shares one by default.
An entry you have shared can then be read by your therapist and by our operations team, and it is included in the written summary described in section 8. Entries you have not shared are included in none of those things, and no query anywhere in our system can return one to another person. You can stop sharing an entry at any time.
Journal entries written during a session are attached to that session, so you can find them next to it afterwards. That attachment does not share them.
Three groups of people can see anything at all, and this is the whole of it.
| Can see | Cannot see | |
|---|---|---|
| You | Everything about you that this policy describes, including your own session recordings and any note your therapist has chosen to share with you. | Your therapist’s private session notes, unless they share a note with you. Our internal assessment notes about therapists. |
| Your therapist, once you are matched | Your name, your intake answers, your bookings, their own notes about you, journal entries you have shared, and recordings of your sessions together. | Your journal entries you have not shared. Your payment details. Anything about you before you were matched with them. Other therapists’ notes. |
| Our operations team — a small number of named people | Your record, your intake, your matches, your bookings and payments, your session notes, your documents, journal entries you have shared, and your session recordings. Every time one of them opens a recording, it is recorded in an audit log. | Your journal entries you have not shared. Your password. Your card details. |
Our operations team’s access is not decoration — it is how a match gets made, how a complaint gets investigated, how a payment gets fixed, and how someone in trouble gets reached. Every administrative action any of them takes is written to an audit trail with who did it and when.
Your therapist’s session notes are theirs by default. You cannot read them unless your therapist chooses to share a particular note with you, which they can do, and can undo. We think that is the right arrangement for a clinical record, and we would rather say so plainly than imply the notes are more open than they are.
Sessions run over a video service we use for that purpose. Audio and video are carried live between you and your therapist; unless a session is being recorded under the rules below, nothing about it is kept afterwards.
The in-session chat is not saved — not by our video provider, and not by us. When the session ends, it is gone. This is deliberate: the chat box is where people type things they cannot yet say out loud, and filing that into a permanent record nobody mentioned would be a betrayal of the moment it exists for.
A session is only ever recorded if you are asked during that session and you agree. Your therapist cannot start a recording any other way. When you agree, we store what you agreed to alongside your answer, so the scope of your consent is part of the record rather than a claim about it.
No AI is your therapist, decides anything about your care, or is left alone with a decision. Every use below produces material for a human to read and judge.
We use AI in four places, all of them narrow:
Where this processing happens matters, so we say it plainly: these features send text to Google’s Gemini API, which is not a service located in India. That includes session transcripts and therapist notes for the two clinical features above. It is the one place your information leaves Indian infrastructure — see section 10.
The draft notes and summaries an AI produces are stored on our systems as your therapist’s working material. They are not readable by clients, and nothing clinical is decided from them.
Cashew has not been incorporated yet, and until it is, these features run on Google’s free API tier. On that tier Google may use what we send to improve their own services, and their reviewers may see it. Google’s paid tier forbids both, and we move to it the moment we are a company. We are telling you now rather than letting you find out.
We do not train AI models on anything you write, and we never will. But we can only speak for ourselves, and on a free tier we cannot make that promise on Google’s behalf — so we are not going to imply it while this is the arrangement we are on.
What that means in practice, so you can decide for yourself:
We check one thing: the free-text answer you write at intake. It is scanned for words associated with being in danger. If any are found, two things happen at once — crisis resources are shown to you immediately, and a flag is raised for a person on our team to act on.
That is the whole of it. It is a simple word check, it does not assess risk, and nothing automated responds beyond raising the flag.
We do not monitor your journal, your messages during a session, or the session itself. Nothing is listening. If you are in danger, please call KIRAN on 1800-599-0019 — free, 24×7 — or your local emergency number. Cashew is not an emergency service.
Your data is stored in India. Our database, our file storage and the servers that run the website are all hosted in an Indian region, which is what the DPDP Act’s expectations and our own preference both point at.
Two honest exceptions, because “your data never leaves India” would be a nice sentence and not a true one:
With one exception, these companies process your data on our instructions, for the purpose we engaged them for, and for no purpose of their own. The exception is Google’s free AI tier, and section 8 explains it in full rather than leaving it as a footnote here.
We keep this list short on purpose, and we keep it current. Each of these does one job.
| Who | What they do for us | What they handle |
|---|---|---|
| Supabase | Our database, sign-in, and file storage — hosted in India | Effectively everything in this policy |
| Vercel | Runs the website, from servers in Mumbai | Requests to the site; ordinary server logs |
| 100ms | Carries the live video and audio, and produces recordings and transcripts when you have agreed to them | Session media; completed recordings are copied into our own storage in India |
| Google (Gemini API) | The AI features in section 8 — currently on their free tier, which they may learn from. Read that section. | Therapist notes, shared journal entries, session transcripts, feedback text |
| Google (sign-in), where you choose it | Signing you in | Your name and email address |
| Razorpay | Takes payment through their own secure checkout | Payment details, which we never see |
| Resend and MSG91 | Send our emails and SMS | Your email address or phone number, and the message |
| WhatsApp (Meta), if you opt into it | Sends session reminders on WhatsApp | Your phone number and the message |
| PostHog and Sentry | Product analytics and error reporting — see section 16 | Usage events and technical error data, never the content of notes, journals or messages |
Some of these are not switched on yet. Where a service is not configured, no data reaches it at all.
Read this bit carefully. Automatic deletion on a schedule is still being built. Today, things are deleted when a person on our team acts on a request — see section 13. The periods below are the rules we work to; we are making the system enforce them by itself.
| What | How long |
|---|---|
| Your account, profile and intake answers | For as long as your account is open. Deleted when you ask us to close it, except where something below says otherwise. |
| Your journal | For as long as your account is open. You can delete an entry yourself at any time. |
| Session notes | These are clinical records, and they are kept while your account is open and for a period after your last session, in line with your therapist’s professional record-keeping obligations. We are taking advice on what that period should be and will publish the number here. Until we do, clinical records are not deleted on a schedule — they are deleted when you ask. |
| Recordings and transcripts | Kept while they are clinically useful, and deleted on request. We are setting a maximum age after which they are deleted automatically. You can ask us to delete a single recording without closing your account. |
| Payment records | Kept for as long as tax and accounting law requires, which is longer than your account may last, and which we cannot shorten on request. |
| Consent records | Kept for as long as we hold anything the consent covers, and for a period afterwards — they are the evidence of what you agreed to, and deleting them would remove your proof as well as ours. |
| Feedback you write | Kept while it is useful to fix what it describes. It is stored separately from your account record. |
| Audit logs and security records | Kept as a security record. They contain who did what and when, not the content of what they saw. |
Under the DPDP Act you can ask us to:
To use any of these, write to support@cashew.care or use the control in your settings. We will not ask you why.
We remove what we are able to remove: your account, your intake, your journal, your bookings, your recordings, and your correspondence with us. We keep what the law requires us to keep, which in practice is the payment records, and the clinical record for as long as professional obligations require it. We will tell you specifically what was kept and why rather than saying “some data may be retained”.
A session recording involves two people. If you ask us to delete a recording of a session you were in, we will delete it — your therapist does not get a veto over a recording of you.
Feedback you send us goes to our team and is not shown back to you in the product. That is a deliberate choice — a page that reflects your own complaint back at you invites you to soften it, and we would rather have the unsoftened version. It is still your personal data: ask, and we will tell you what you sent us and delete it if you want it gone.
Cashew is for adults. You must be 18 or older to create an account, and you confirm that when you do. We are not currently set up to obtain and verify parental consent, and until we are, we cannot safely offer this service to anyone under 18.
We ask your age rather than verify it. If we find out that an account belongs to someone under 18, we will close it and delete the data, and we will do it gently — someone who has reached out for help should not be treated as a policy breach. If you believe a child has created an account, please write to us.
Nobody can honestly promise a system is impossible to breach. What we can do is say specifically what stands in the way, and these are real, checked things rather than a paragraph of adjectives:
If a breach affects your personal data, we will notify you and the Data Protection Board as the law requires, and we will tell you what happened rather than the smallest thing we can defend.
We will update this page when the product changes, and the date and version at the top will change with it. If a change materially affects what we do with your data, we will tell you directly rather than quietly editing the page — and where the change needs your agreement, we will ask you again rather than assume it.
The consent you give before the intake questions is separately versioned. If its wording changes, you are asked afresh.
Grievance Officer: support@cashew.care — a member of the founding team reads this mailbox and answers it personally. We will name them here once Cashew is incorporated.
Everything else: support@cashew.care
We do not yet have a registered office to print here, because there is not yet a company. Email reaches us, and a person — not a queue — reads it.
Write to us about anything in this document and a person will answer — not a form, and not a bot. If we have not resolved your complaint to your satisfaction, you can escalate it to the Data Protection Board of India.