SyannuAI Technologies Private Limited
Effective Date: 15 June 2026 | Last Updated: 15 June 2026
Version 1.1
1. IDENTITY OF THE DATA CONTROLLER AND DATA FIDUCIARY
This Privacy Policy ("Policy") governs the collection, processing, storage, use, disclosure, and protection of personal data by SyannuAI Technologies Private Limited, a company incorporated under the Companies Act, 2013, with its registered office in Bangalore, Karnataka, India ("Company", "we", "us", or "our").
The Company operates the Silentum mobile application ("App") and associated services at www.silentumai.com ("Platform"). Under the Digital Personal Data Protection Act, 2023 ("DPDP Act"), the Company acts as a Data Fiduciary. For users in the European Economic Area or the United Kingdom, the Company acts as Data Controller under the GDPR and UK GDPR respectively. For users in the United States, the Company acts as a Business under the CCPA/CPRA where applicable.
Silentum is a privacy-first, end-to-end encrypted communication platform. Privacy is not a feature — it is the foundation of our architecture. This Policy explains with full transparency how we handle your personal data.
2. SCOPE AND APPLICATION
This Policy applies to all users of the Platform globally, including users who download, install, register, or use the App; visitors to www.silentumai.com; and any persons who contact us through any channel.
This Policy applies regardless of the device, operating system, or country from which you access the Platform. Where applicable law in your jurisdiction imposes additional or stricter obligations, those obligations are incorporated into this Policy as mandatory overlay requirements.
Use of the Platform constitutes acceptance of this Policy. If you do not agree, you must discontinue use immediately.
3. CATEGORIES OF PERSONAL DATA WE COLLECT
3.1 Account Registration Data
We collect the following at registration:
- Email address — used solely for account recovery. We do not use it for marketing.
- Phone number — used solely for contact synchronisation, to identify other Silentum users already in your device contacts.
- Display name / username — as chosen by you.
3.2 Authentication Data
Your PIN or password is stored exclusively in hashed, non-reversible form. We do not store any credential in a manner that permits recovery or reading by the Company or any third party.
3.3 Technical and Operational Data
We collect limited technical data including device type, operating system version, App version, and anonymised crash or error logs for operational stability. This data is not linked to your identity and is processed in aggregated or anonymised form only.
3.4 Communications Content — Not Collected
We do not collect, access, read, store, process, or transmit the content of your calls, messages, or file transfers. All communications are end-to-end encrypted on your device before transmission. The Company does not possess decryption keys. Silentum operates on a no-knowledge architecture with respect to communication content.
3.5 Data We Expressly Do Not Collect
We confirm that we do not collect: location data; call duration or call logs; metadata about who you communicate with; behavioural or usage profiles; biometric data; payment or financial information; any content from your device contacts other than as required for contact synchronisation as described above.
4. LAWFUL BASES FOR PROCESSING
4.1 Indian Users — DPDP Act, 2023
- Consent: freely given, specific, informed consent obtained at registration for email and phone number collection.
- Legitimate Use: technical and operational data processed for legitimate platform operation purposes.
4.2 EEA and UK Users — GDPR / UK GDPR
- Article 6(1)(b): processing necessary for performance of the contract (Terms of Service).
- Article 6(1)(f): legitimate interests in platform security, fraud prevention, and operational stability, not overridden by your rights.
- Article 6(1)(a): consent, where separately sought.
4.3 United States
Processing is described in this Policy. California residents have additional rights under CCPA/CPRA, addressed in Section 20.
5. PURPOSES OF PROCESSING
Personal data is used solely for:
- creating and managing your account and authenticating your identity;
- enabling account recovery via your registered email address;
- facilitating contact synchronisation via your phone number;
- responding to support and legal requests;
- maintaining the security, performance, and integrity of the Platform;
- detecting and preventing illegal activity, fraud, and prohibited conduct;
- complying with applicable legal and regulatory obligations, including lawful authority requests;
- improving the Platform using strictly anonymised and aggregated data.
6. CHILDREN'S PRIVACY AND AGE RESTRICTIONS
We do not process personal data for advertising, profiling, or marketing purposes. We do not sell personal data. We do not share personal data with advertisers.
6.1 Minimum Age
The Platform is available to users aged 13 and above. Users under 13 are strictly prohibited from registering or using the Platform.
6.2 Indian Users Under 18 — DPDP Act
Under the DPDP Act, 2023, all persons under 18 are children. We are required to obtain verifiable parental or guardian consent before processing personal data of any child. Users aged 13 to 17 in India must ensure their parent or legal guardian has reviewed and consented to this Policy before registration. We may implement age verification mechanisms as required by law or regulatory guidance. We will not process child data in any manner detrimental to the child's well-being.
6.3 US Users Under 13 — COPPA
We do not knowingly collect personal information from children under 13 in the United States. If we learn that we have collected such data without verifiable parental consent, we will delete it promptly. Parents may contact us at privacy@silentum.app.
6.4 No Behavioural Targeting of Children
We do not engage in behavioural monitoring, targeted processing, or profiling in respect of any user below the applicable age of majority in their jurisdiction.
7. LAWFUL INTERCEPTION, LAW ENFORCEMENT, AND GOVERNMENT REQUESTS
As a global encrypted communication platform, we recognise that lawful authority requests for user data are a reality in many jurisdictions. The following sets out our position clearly and transparently.
7.1 What We Can and Cannot Provide
Due to our end-to-end encryption architecture and no-knowledge design, the Company is technically unable to provide the content of any user communication in response to any request, regardless of its source. We do not store message content, call audio, video, or file transfer content on our servers. We cannot provide what we do not have.
What we can provide in response to a lawful, valid legal process: account registration data (email address, phone number, display name) and limited technical metadata (such as account creation date and last login date) to the extent such data is held and the legal process meets the requirements of applicable law.
7.2 Requirements for Disclosure
We will only disclose personal data to a government, law enforcement, or regulatory authority where:
- we receive a valid legal process (court order, warrant, or equivalent instrument) issued by a competent authority under applicable law;
- the request is specific, proportionate, and limited to the data required;
- the request is lawful under the laws of India or, where applicable, the laws of the requesting jurisdiction as recognised under applicable international legal assistance frameworks.
7.3 Transparency and User Notification
Where legally permissible — that is, where we are not subject to a binding legal prohibition on disclosure — we will notify affected users of any legal process served upon us seeking their data, prior to compliance, and in any event as promptly as practicable after disclosure. We will challenge overbroad, legally deficient, or improper requests.
7.4 Indian Legal Framework — Lawful Interception
Under the Information Technology Act, 2000 (Section 69) and the Indian Telegraph Act, 1885 (Section 5), the Indian Government may issue directions for interception, monitoring, or decryption of information. To the extent technically feasible, the Company will comply with lawfully issued directions. However, because communications content is end-to-end encrypted and the Company holds no decryption keys, content interception is architecturally not possible. The Company will comply with any obligation to the extent of the data it technically holds.
7.5 Intermediary Obligations — IT Rules, 2021
The Company acknowledges its potential status as a significant social media intermediary or an intermediary under the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, as may be determined by the volume of users and applicable regulatory thresholds. To the extent these Rules apply, we will comply with applicable obligations including appointment of a Grievance Officer (Section 22), publication of this Privacy Policy, and timely response to lawful authority requests.
7.6 EU-Specific Legal Requests
Requests from authorities in the European Economic Area must comply with applicable EU law, including the EU e-Evidence Regulation and any applicable Mutual Legal Assistance Treaty (MLAT) framework. We will not comply with requests that are contrary to EU law, including unlawful mass surveillance requests.
8. CONTENT MODERATION AND ILLEGAL CONTENT OBLIGATIONS
Silentum is an end-to-end encrypted platform. We do not access communication content. However, we maintain the following commitments to prevent the misuse of the Platform:
8.1 Child Sexual Abuse Material (CSAM)
The production, distribution, transmission, or storage of child sexual abuse material ("CSAM") is categorically prohibited on the Platform. In jurisdictions where we are legally required to detect, report, or remove CSAM — including under India's Protection of Children from Sexual Offences Act, 2012 (POCSO), and analogous laws — we will comply to the extent technically feasible given our end-to-end encryption architecture. We will report any CSAM we become aware of to the relevant national authority, including the National Center for Missing and Exploited Children (NCMEC) where applicable.
Users who encounter or are aware of CSAM being transmitted on the Platform must report it immediately to legal@silentum.app. We take all such reports seriously and will escalate to appropriate authorities.
8.2 Terrorism and Violent Extremism
Use of the Platform to facilitate, plan, finance, recruit for, or promote terrorism or violent extremism is absolutely prohibited. We reserve the right to report credible threats to the appropriate law enforcement authorities, notwithstanding our privacy commitments, where disclosure is required by applicable law or where there is an imminent threat to life.
8.3 User Reporting Mechanism
While communication content is encrypted and inaccessible to us, users may report accounts engaged in prohibited conduct using the support ticket mechanism within the App. We will investigate reports to the extent of the account-level information available to us and take appropriate action, including account suspension or termination and, where required, referral to authorities.
9. DATA SHARING AND DISCLOSURE
We do not sell, rent, or trade personal data. Disclosure is limited to:
9.1 Service Providers
Trusted third-party service providers processing data strictly on our instructions, bound by data processing agreements with at minimum equivalent protections to those in this Policy. Current categories include cloud infrastructure and security monitoring providers.
9.2 Lawful Authority Requests
As described in Section 7, only where a valid legal process is received and the data is technically available to us. We challenge deficient requests and notify users where legally permissible.
9.3 Safety-Related Disclosure
Where necessary to prevent imminent risk of death, serious physical harm, or other serious threat to a person's safety or rights, we may disclose account-level data to appropriate authorities without prior user notification.
9.4 Business Transfers
In a merger, acquisition, or asset sale, personal data may transfer to the acquiring entity under equivalent protections. We will provide advance notice.
9.5 Aggregated Anonymous Data
Aggregated, anonymised statistical data not capable of identifying any individual may be shared for research or analytical purposes.
10. INTERNATIONAL DATA TRANSFERS
10.1 Transfers from India
Governed by the DPDP Act and applicable Government-notified rules. We will ensure equivalent protection for any cross-border transfer.
10.2 Transfers from the EEA
Where no adequacy decision exists, we implement EU Standard Contractual Clauses (Commission Decision 2021/914). Copies available upon request at privacy@silentum.app.
10.3 Transfers from the UK
We use the UK International Data Transfer Agreement (IDTA) or equivalent UK-approved mechanism.
11. DATA RETENTION
Account deletion is available at any time via Settings > Delete Account. Deletion is permanent and irreversible.
- Account data (email, phone, display name): retained for the life of your account. Permanently deleted within 30 days of account deletion.
- Communication content: not held by the Company. Stored locally on your device per your configured message retention settings.
- Technical logs: retained in aggregated or anonymised form for up to 12 months.
- Legal hold data: retained for the duration of any applicable legal hold or regulatory obligation, notwithstanding account deletion.
12. SECURITY OF PERSONAL DATA
We implement comprehensive technical and organisational security measures:
- End-to-end encryption of all communications using industry-standard cryptographic protocols.
- AES-256 encryption of all data at rest.
- Hashed, non-reversible credential storage.
- TLS for all data in transit.
- Panic PIN for immediate irreversible local data destruction.
- Proof-of-Life device integrity verification.
- Quantum-ready cryptographic architecture.
- Regular penetration testing and security audits.
- Strict internal access controls and need-to-know principles.
- Incident response procedures compliant with applicable breach notification laws.
13. COOKIES AND TRACKING TECHNOLOGIES
The Silentum App does not use cookies. Our website at www.silentumai.com uses only strictly necessary cookies. We do not deploy analytics, advertising, tracking, or social media cookies. Please refer to our Cookie Policy for full details.
14. YOUR RIGHTS
14.1 Indian Users — DPDP Act
- Right of access to summary of personal data held and purposes of processing.
- Right to correction and erasure of inaccurate or no-longer-required personal data.
- Right to grievance redressal with our Grievance Officer within 30 days.
- Right to nominate an individual to exercise rights upon your death or incapacity.
- Right to withdraw consent, without affecting prior lawful processing.
14.2 EEA and UK Users — GDPR / UK GDPR
- Access (Article 15), Rectification (Article 16), Erasure (Article 17), Restriction (Article 18), Portability (Article 20), Objection (Article 21), Withdrawal of consent (Article 7(3)).
- Right to lodge a complaint with your EU Member State supervisory authority or the UK ICO (www.ico.org.uk).
14.3 How to Exercise Rights
Contact privacy@silentum.app. We will verify your identity and respond within the timeframe required by applicable law and no later than 30 days from receipt.
15. AUTOMATED DECISION-MAKING AND PROFILING
We do not make decisions about you through solely automated means that produce legal or similarly significant effects. We do not profile users for commercial, behavioural, or advertising purposes. If AI features are introduced in future, this section will be updated to reflect any relevant processing.
16. THIRD-PARTY SERVICES AND FUTURE INTEGRATIONS
The Platform does not currently integrate with third-party advertising, analytics, or payment services. Future planned integrations include Stripe (payments) and AI services. Any such integration will be disclosed in advance of deployment. Where required by applicable law, fresh consent will be sought. This Policy will be updated accordingly, and users notified per Section 25.
17. DATA BREACH NOTIFICATION
In the event of a personal data breach:
- We will contain the incident and assess its scope and severity as a matter of priority.
- We will notify the Data Protection Board of India (once established) within the period prescribed under the DPDP Act. For EEA users, we will notify the relevant supervisory authority within 72 hours of becoming aware of the breach, as required by Article 33 GDPR.
- Where the breach is likely to result in high risk to your rights and freedoms, we will notify you directly without undue delay in clear, plain language, including the nature of the breach, likely consequences, and the measures taken.
18. GOVERNING LAW AND JURISDICTION
This Policy is governed by the laws of the Republic of India, including the IT Act 2000, the SPDI Rules 2011, and the DPDP Act 2023. For EEA and UK users, the GDPR and UK GDPR apply as mandatory overlay requirements. For US users, applicable state privacy laws apply as mandatory overlay requirements. Disputes shall be subject to the exclusive jurisdiction of the courts at Bangalore, Karnataka, India, save where mandatory consumer protection law in your jurisdiction provides otherwise.
19. IT ACT 2000, SPDI RULES, AND INTERMEDIARY COMPLIANCE
We comply with the Information Technology Act, 2000 and the IT (SPDI) Rules, 2011. We maintain a comprehensive information security programme aligned with IS/ISO/IEC 27001 standards. To the extent any data we collect qualifies as Sensitive Personal Data or Information under the SPDI Rules, we will obtain express written consent prior to collection and comply with all heightened obligations applicable thereto.
As an intermediary, we will: publish this Policy and our Terms of Service prominently; appoint a Grievance Officer; respond to lawful authority requests within prescribed timeframes; and take down content in compliance with lawful government orders where technically feasible.
20. CALIFORNIA PRIVACY RIGHTS — CCPA / CPRA
We do not sell personal information. We do not share personal information for cross-context behavioural advertising. California residents have the right to: know what personal information is collected and how it is used; delete their personal information; correct inaccurate personal information; and be free from discrimination for exercising these rights.
To submit a verifiable consumer request, email privacy@silentum.app. We will respond within 45 days, with a possible 45-day extension where reasonably necessary.
21. OTHER JURISDICTIONS
For users in Brazil (LGPD), Canada (PIPEDA), Australia (Privacy Act 1988), Singapore (PDPA), South Korea (PIPA), Japan (APPI), UAE, and other jurisdictions with applicable data protection regimes, we apply data protection principles consistent with the highest standard set out in this Policy and will honour all legitimate data subject or data principal requests made under such regimes in good faith.
22. GRIEVANCE OFFICER — INDIA
In compliance with the IT Act, 2000 and the DPDP Act, 2023, the Company has designated a Grievance Officer:
Designation: Grievance Officer, SyannuAI Technologies Private Limited
Email: privacy@silentum.app
Address: SyannuAI Technologies Private Limited, Bangalore, Karnataka, India
The Grievance Officer will acknowledge complaints within 48 hours and endeavour to resolve them within 30 days. Unresolved complaints may be escalated to the Data Protection Board of India once established.
23. CONTACT FOR PRIVACY REQUESTS
Privacy Email: privacy@silentum.app
Legal Correspondence: SyannuAI Technologies Private Limited, Bangalore, Karnataka, India
We respond to all requests within the timeframe required by applicable law and no later than 30 days.
24. THIRD-PARTY LINKS AND EMBEDDED CONTENT
The Platform may contain links to third-party websites or services. We are not responsible for the privacy practices of any third party. The inclusion of a link does not constitute endorsement. We encourage you to review the privacy policies of any third parties you interact with.
25. AMENDMENTS TO THIS POLICY
We may amend this Policy to reflect changes in law, regulatory guidance, or our processing practices. Material changes will be communicated via in-app notification and/or email to your registered address not less than 14 days before taking effect. Your continued use of the Platform after the effective date of any amendment constitutes acceptance of the revised Policy. The current version is always available in-app and at www.silentumai.com/privacy-policy. Prior versions are available upon request.
This Privacy Policy is issued by SyannuAI Technologies Private Limited. Contact: privacy@silentum.app.