cashew.
HelpNeed help right now?Log inGet startedFind your therapist

Privacy policy

what we hold, who can see it, and how to have it deleted

Your data is yours. It is stored in India, we collect as little as we can, we never sell it or advertise against it, and your journal is readable by nobody but you. Where something is more complicated than that — the AI features, our operations team, the things the law makes us keep — this page says so plainly instead of leaving you to find out.

Last updated 8 August 2026 · v1.0

This is in force, and it is early. It describes exactly what Cashew does today, written by the people who built it rather than copied from a template — and it has not yet been reviewed by a lawyer. Some of it will get more precise as we incorporate. Where something here is unclear or you think it is wrong, tell us and we will fix it.

Contents

  1. 1. Who we are, and what this covers
  2. 2. What we collect from clients
  3. 3. What we collect from therapists
  4. 4. Why we collect it
  5. 5. Your journal
  6. 6. Who can see what
  7. 7. Sessions: video, messages, recordings and transcripts
  8. 8. How we use AI, and how we don’t
  9. 9. Crisis language, and the limits of what we watch
  10. 10. Where your data lives
  11. 11. The companies that process data for us
  12. 12. How long we keep things
  13. 13. Your rights, and how to use them
  14. 14. Children
  15. 15. How we protect it
  16. 16. Cookies and analytics
  17. 17. When we would share your information
  18. 18. Changes to this policy
  19. 19. Contact and grievances

1. Who we are, and what this covers

Cashew is a therapy platform operating in India. Cashew is built and run in India by its founding team, who are personally answerable for it. We have not yet incorporated a company. When we do, this page will name it as the party you are dealing with, and we will tell you rather than quietly editing the page. Under the Digital Personal Data Protection Act, 2023, we are the data fiduciary for the information described here — the ones responsible for it, and the ones you can hold to this document.

This policy covers everyone who uses Cashew: clients looking for therapy, therapists practising through us, and visitors to our website. Where something applies to only one of those, it says so.

It does not cover what your therapist does independently of Cashew. Your therapist is an independent professional with their own obligations to you; where they keep their own separate records outside our platform, those are theirs to explain.

Questions, corrections or complaints about anything here go to our Grievance Officer at support@cashew.care. A person answers — see section 19.

2. What we collect from clients

Only what a careful match and a safe session need. Each intake question tells you, on the screen, what it is used for before you answer it.

When you create an account

  • A name to call you. A first name or a nickname is genuinely enough — we do not ask for, or want, your legal identity.
  • Your email address, which we ask you to confirm before you can go further. We refuse addresses at known disposable-mail domains.
  • Your password, stored only as a cryptographic hash by our authentication provider. Nobody at Cashew can read it.
  • A phone number, if you choose to give one — used for session reminders by SMS, and nothing else. It is optional and can be removed at any time.
  • If you sign in with Google, we receive your name and email address from Google. We do not receive your Google password or anything else in your Google account.

When you answer the intake questions

Nothing you write here is stored until you have read and agreed to a plain-language consent screen. We record which version of that wording you saw, along with a cryptographic fingerprint of the exact text, so that what you agreed to can always be established later. If we change the wording, we ask you again.

  • How you are feeling, in your own words.
  • What you would like help with, the language you would like to be seen in, your budget, and when in the week you can attend.
  • Your preference, if you have one, about your therapist’s gender. This is optional; “no preference” is a real answer and the most common one.

As you use the service

  • Your journal — see section 5, which is about nothing else.
  • Bookings and your calendar — session times, cancellations and the reason given for them, reschedules, and whether a session was attended.
  • Payments — amounts, dates, status, and what they were for. We never see or store your card details; those go directly to our payment provider’s own secure checkout. We also record sessions added to your balance by our team rather than bought.
  • Session notes written by your therapist about your sessions, which are their clinical record. See section 6.
  • Recordings and transcripts of sessions, but only ones you were asked about and agreed to, session by session. See section 7.
  • Anything you write to us — feedback, support requests, and requests about your data.
  • An emergency contact, if you give one to our team.
  • Basic technical information needed to run the service: your sign-in session, and the ordinary server logs a website produces. Our error reports carry identifiers, statuses and counts only — never the content of a note, a journal entry, a message, or a crisis excerpt.

We do not buy data about you, we do not build advertising profiles, we do not sell anything to anyone, and we do not share your information with your college, your employer or your family.

3. What we collect from therapists

If you practise through Cashew, we collect what is needed to verify you, present you honestly to clients, and pay you:

  • Your name, contact details, professional credentials and registration number, years of experience, languages, modalities, fee, biography and photograph. Your photograph and profile are shown to prospective clients — everything else in this list is not, unless it appears on your profile.
  • Documents you upload to evidence your qualifications, held privately and released only through short-lived links to our operations team, whose access is logged.
  • Your own assessment of what you work with and how you work. It is recorded as a self-assessment and is labelled as such wherever our team sees it.
  • Your availability, your sessions, your earnings and your reference number.
  • Your application status, the interviews scheduled with you, and our team’s private assessment notes about those interviews. Those assessment notes are internal and are not shown to you — they exist so a hiring decision can be discussed honestly.
  • Your session notes about your clients, which are clinical records held on our systems.

4. Why we collect it

Under the DPDP Act we process your personal data on the basis of your consent, given for the specific purposes below. You can withdraw it — see section 13.

What we do with itWhat it uses
Match you with a therapist. Our system ranks verified therapists against your answers, and then a person on our team reads the shortlist and chooses one, writing you a note explaining why.Your intake answers
Run your sessions — booking, reminders, joining the call, and everything in section 7.Account details, bookings, phone if given
Let your therapist do their job — see your intake, keep clinical notes, and prepare for a session.Intake, notes, anything you have shared
Take payment, and keep the records the law requires us to keep.Payment records
Get help to you quickly if something you write suggests you are in danger.The intake free-text answer only — see section 9
Keep the service safe, working and honest — security, fraud prevention, fixing what is broken, and understanding what is confusing.Technical data, feedback
Meet our legal obligations, including responding to lawful demands.Whatever the obligation requires

5. Your journal

Your journal is yours alone. Not your therapist. Not our operations team. Not us. Not any AI. The database itself refuses every request for it that does not come from you.

There is exactly one way a journal entry becomes visible to anyone else: you choose to share that entry with your therapist, one entry at a time, by a deliberate action of your own. There is no setting that shares them all, and nothing shares one by default.

An entry you have shared can then be read by your therapist and by our operations team, and it is included in the written summary described in section 8. Entries you have not shared are included in none of those things, and no query anywhere in our system can return one to another person. You can stop sharing an entry at any time.

Journal entries written during a session are attached to that session, so you can find them next to it afterwards. That attachment does not share them.

6. Who can see what

Three groups of people can see anything at all, and this is the whole of it.

Can seeCannot see
YouEverything about you that this policy describes, including your own session recordings and any note your therapist has chosen to share with you.Your therapist’s private session notes, unless they share a note with you. Our internal assessment notes about therapists.
Your therapist, once you are matchedYour name, your intake answers, your bookings, their own notes about you, journal entries you have shared, and recordings of your sessions together.Your journal entries you have not shared. Your payment details. Anything about you before you were matched with them. Other therapists’ notes.
Our operations team — a small number of named peopleYour record, your intake, your matches, your bookings and payments, your session notes, your documents, journal entries you have shared, and your session recordings. Every time one of them opens a recording, it is recorded in an audit log.Your journal entries you have not shared. Your password. Your card details.

Our operations team’s access is not decoration — it is how a match gets made, how a complaint gets investigated, how a payment gets fixed, and how someone in trouble gets reached. Every administrative action any of them takes is written to an audit trail with who did it and when.

Your therapist’s session notes are theirs by default. You cannot read them unless your therapist chooses to share a particular note with you, which they can do, and can undo. We think that is the right arrangement for a clinical record, and we would rather say so plainly than imply the notes are more open than they are.

7. Sessions: video, messages, recordings and transcripts

The call itself

Sessions run over a video service we use for that purpose. Audio and video are carried live between you and your therapist; unless a session is being recorded under the rules below, nothing about it is kept afterwards.

Messages during a session

The in-session chat is not saved — not by our video provider, and not by us. When the session ends, it is gone. This is deliberate: the chat box is where people type things they cannot yet say out loud, and filing that into a permanent record nobody mentioned would be a betrayal of the moment it exists for.

Recording

A session is only ever recorded if you are asked during that session and you agree. Your therapist cannot start a recording any other way. When you agree, we store what you agreed to alongside your answer, so the scope of your consent is part of the record rather than a claim about it.

  • Agreeing covers three things, and the request says all three: the session is recorded, the recording is transcribed into text, and an AI writes your therapist a draft note from that transcript. See section 8.
  • Declining changes nothing about your care, and your therapist sees only that you declined — never a reason, and never an explanation you did not give.
  • You can turn the request off entirely in your settings, so it is never put to you again. Saying no should not have to be said out loud, on camera, to someone’s face, every time.
  • You can watch a recording of your own session whenever you like, from that session’s page.
  • Recordings are held in private storage that is not readable by anyone through ordinary means. Each time someone with permission watches one, a link is created for that viewing and expires within two hours.
  • If someone on our operations team opens a recording, an audit record is written. They were not in the room; that should never be untraceable.

8. How we use AI, and how we don’t

No AI is your therapist, decides anything about your care, or is left alone with a decision. Every use below produces material for a human to read and judge.

We use AI in four places, all of them narrow:

  • A summary for your therapist before a session, written from their own previous notes and from journal entries you have chosen to share. Entries you have not shared are never included.
  • A draft session note, written from the transcript of a session you agreed to have recorded. A draft is never the record. It is your therapist’s working material; the only way any of it becomes a note is your therapist reading it, editing it, and saving it themselves. The system that writes it is instructed not to diagnose and not to recommend treatment.
  • Grouping feedback. When our team reads feedback in bulk, a model clusters the messages by theme. Only message text, dates and the page it was written from are sent — never names, email addresses or account identifiers.
  • An internal assistant that helps our own team follow our own written procedures. It answers only from our documents, cites them, and refers to a person rather than improvise. It has no access to your data.

Where this processing happens matters, so we say it plainly: these features send text to Google’s Gemini API, which is not a service located in India. That includes session transcripts and therapist notes for the two clinical features above. It is the one place your information leaves Indian infrastructure — see section 10.

The draft notes and summaries an AI produces are stored on our systems as your therapist’s working material. They are not readable by clients, and nothing clinical is decided from them.

Something we would rather you heard from us

Cashew has not been incorporated yet, and until it is, these features run on Google’s free API tier. On that tier Google may use what we send to improve their own services, and their reviewers may see it. Google’s paid tier forbids both, and we move to it the moment we are a company. We are telling you now rather than letting you find out.

We do not train AI models on anything you write, and we never will. But we can only speak for ourselves, and on a free tier we cannot make that promise on Google’s behalf — so we are not going to imply it while this is the arrangement we are on.

What that means in practice, so you can decide for yourself:

  • Decline recording and no transcript of your session exists at all — there is nothing to send, to Google or to anyone. This is the biggest thing in your control, and declining costs you nothing.
  • Your journal is not involved unless you have shared an entry with your therapist. Unshared entries reach no AI, on any tier, ever.
  • Your therapist’s own notes about you can still be summarised for them before a session, and Google’s model writes that summary. It only happens when your therapist asks for one — if you would rather they didn’t, say so and they won’t.
  • Your name, your email address and your account identifiers are never sent to the model in any of these features.

9. Crisis language, and the limits of what we watch

We check one thing: the free-text answer you write at intake. It is scanned for words associated with being in danger. If any are found, two things happen at once — crisis resources are shown to you immediately, and a flag is raised for a person on our team to act on.

That is the whole of it. It is a simple word check, it does not assess risk, and nothing automated responds beyond raising the flag.

We do not monitor your journal, your messages during a session, or the session itself. Nothing is listening. If you are in danger, please call KIRAN on 1800-599-0019 — free, 24×7 — or your local emergency number. Cashew is not an emergency service.

10. Where your data lives

Your data is stored in India. Our database, our file storage and the servers that run the website are all hosted in an Indian region, which is what the DPDP Act’s expectations and our own preference both point at.

Two honest exceptions, because “your data never leaves India” would be a nice sentence and not a true one:

  • The AI features in [§](#ai) send text to Google’s Gemini API, which processes outside India. If you never have a session recorded and never share a journal entry, the only thing of yours that can reach it is feedback you write to us.
  • Some of the companies we rely on to send email, send SMS, carry video or take payment are international, and may process the information they handle for us outside India. They are listed in section 11.

With one exception, these companies process your data on our instructions, for the purpose we engaged them for, and for no purpose of their own. The exception is Google’s free AI tier, and section 8 explains it in full rather than leaving it as a footnote here.

11. The companies that process data for us

We keep this list short on purpose, and we keep it current. Each of these does one job.

WhoWhat they do for usWhat they handle
SupabaseOur database, sign-in, and file storage — hosted in IndiaEffectively everything in this policy
VercelRuns the website, from servers in MumbaiRequests to the site; ordinary server logs
100msCarries the live video and audio, and produces recordings and transcripts when you have agreed to themSession media; completed recordings are copied into our own storage in India
Google (Gemini API)The AI features in section 8 — currently on their free tier, which they may learn from. Read that section.Therapist notes, shared journal entries, session transcripts, feedback text
Google (sign-in), where you choose itSigning you inYour name and email address
RazorpayTakes payment through their own secure checkoutPayment details, which we never see
Resend and MSG91Send our emails and SMSYour email address or phone number, and the message
WhatsApp (Meta), if you opt into itSends session reminders on WhatsAppYour phone number and the message
PostHog and SentryProduct analytics and error reporting — see section 16Usage events and technical error data, never the content of notes, journals or messages

Some of these are not switched on yet. Where a service is not configured, no data reaches it at all.

12. How long we keep things

Read this bit carefully. Automatic deletion on a schedule is still being built. Today, things are deleted when a person on our team acts on a request — see section 13. The periods below are the rules we work to; we are making the system enforce them by itself.

WhatHow long
Your account, profile and intake answersFor as long as your account is open. Deleted when you ask us to close it, except where something below says otherwise.
Your journalFor as long as your account is open. You can delete an entry yourself at any time.
Session notesThese are clinical records, and they are kept while your account is open and for a period after your last session, in line with your therapist’s professional record-keeping obligations. We are taking advice on what that period should be and will publish the number here. Until we do, clinical records are not deleted on a schedule — they are deleted when you ask.
Recordings and transcriptsKept while they are clinically useful, and deleted on request. We are setting a maximum age after which they are deleted automatically. You can ask us to delete a single recording without closing your account.
Payment recordsKept for as long as tax and accounting law requires, which is longer than your account may last, and which we cannot shorten on request.
Consent recordsKept for as long as we hold anything the consent covers, and for a period afterwards — they are the evidence of what you agreed to, and deleting them would remove your proof as well as ours.
Feedback you writeKept while it is useful to fix what it describes. It is stored separately from your account record.
Audit logs and security recordsKept as a security record. They contain who did what and when, not the content of what they saw.

13. Your rights, and how to use them

Under the DPDP Act you can ask us to:

  • Tell you what we hold about you and what we have done with it.
  • Correct or complete anything that is wrong or out of date. You can change your name, phone number and password yourself in your settings.
  • Delete it. There is a permanent control for this in your settings — it is not hidden behind having got far enough through the product. A person reads the request and acts on it, and you will hear back from a person.
  • Withdraw your consent, at any time, as easily as you gave it. Withdrawing does not undo anything already done, and does not affect care you have already received.
  • Nominate someone to exercise these rights for you if you die or become incapable of exercising them yourself.
  • Complain, to us and, if we do not resolve it, to the Data Protection Board of India.

To use any of these, write to support@cashew.care or use the control in your settings. We will not ask you why.

What deletion actually means

We remove what we are able to remove: your account, your intake, your journal, your bookings, your recordings, and your correspondence with us. We keep what the law requires us to keep, which in practice is the payment records, and the clinical record for as long as professional obligations require it. We will tell you specifically what was kept and why rather than saying “some data may be retained”.

A session recording involves two people. If you ask us to delete a recording of a session you were in, we will delete it — your therapist does not get a veto over a recording of you.

One thing you cannot read back

Feedback you send us goes to our team and is not shown back to you in the product. That is a deliberate choice — a page that reflects your own complaint back at you invites you to soften it, and we would rather have the unsoftened version. It is still your personal data: ask, and we will tell you what you sent us and delete it if you want it gone.

14. Children

Cashew is for adults. You must be 18 or older to create an account, and you confirm that when you do. We are not currently set up to obtain and verify parental consent, and until we are, we cannot safely offer this service to anyone under 18.

We ask your age rather than verify it. If we find out that an account belongs to someone under 18, we will close it and delete the data, and we will do it gently — someone who has reached out for help should not be treated as a policy breach. If you believe a child has created an account, please write to us.

15. How we protect it

Nobody can honestly promise a system is impossible to breach. What we can do is say specifically what stands in the way, and these are real, checked things rather than a paragraph of adjectives:

  • Every table in our database refuses access by default, and grants it row by row to the specific person entitled to it. Your journal has the strictest rule in the system.
  • Your data travels encrypted, and files are held in private storage that is not publicly readable.
  • Session recordings have no standing access at all. A link to watch one is created for a single viewing, is checked against what that particular viewer is allowed to see, and expires within two hours.
  • Administrative actions are logged with who took them and when, and opening a recording as a member of our team is one of them.
  • Our error reports carry no personal content — identifiers, statuses and counts only. This is enforced by how the reporting works, not by asking people to be careful.
  • Access is reviewed against what each role actually needs. We have found and closed real gaps this way, including ones nobody had exploited, and we would rather find them ourselves than not look.

If a breach affects your personal data, we will notify you and the Data Protection Board as the law requires, and we will tell you what happened rather than the smallest thing we can defend.

16. Cookies and analytics

We use no advertising cookies and no advertising trackers of any kind. There is no ad network in this product, and there never will be one carrying your data.

  • Necessary cookies keep you signed in and keep your session secure. The product does not work without them.
  • Product analytics, where enabled, records which pages are visited and a small number of named events like “a session was booked” — so we can tell whether people are getting stuck. It is configured not to record clicks and keystrokes automatically, and it never receives the content of your intake, notes, journal or messages.
  • Error reporting records technical failures so we can fix them, without personal content.

17. When we would share your information

We do not sell your data. We share it only:

  • With your therapist, as described in section 6 — which is the point of the service.
  • With the companies in [§](#processors), to do the jobs listed there.
  • When the law compels us — a court order or a lawful demand from an authority. Where we are permitted to tell you, we will.
  • To prevent serious harm, where there is a real and immediate risk to someone’s life or safety.
  • If Cashew is ever acquired or merged, in which case your data would move with the service and you would be told before anything about this policy changed.

18. Changes to this policy

We will update this page when the product changes, and the date and version at the top will change with it. If a change materially affects what we do with your data, we will tell you directly rather than quietly editing the page — and where the change needs your agreement, we will ask you again rather than assume it.

The consent you give before the intake questions is separately versioned. If its wording changes, you are asked afresh.

19. Contact and grievances

Grievance Officer: support@cashew.care — a member of the founding team reads this mailbox and answers it personally. We will name them here once Cashew is incorporated.

Everything else: support@cashew.care

We do not yet have a registered office to print here, because there is not yet a company. Email reaches us, and a person — not a queue — reads it.

Write to us about anything in this document and a person will answer — not a form, and not a bot. If we have not resolved your complaint to your satisfaction, you can escalate it to the Data Protection Board of India.

  • Privacy policy
  • Terms of service
  • Cancellation policy
  • What you agree to at intake