This Privacy Policy explains how Corp Sesh, operated by Bahn, a sole proprietorship registered in India and owned by Sanjana Garg, (“Corp Sesh,” “we,” “us,” or “our”) collects, uses, shares, and protects your information when you use the Corp Sesh mobile application, our website at corpsesh.com, and related services (together, the “Services”).
Corp Sesh is a social app that lets you take short, shared virtual breaks with friends and group members — with real-time presence, chat, and the ability to invite or “summon” people to join you. This Policy describes how we handle personal data when you use the Services.
1. Who we are
Corp Sesh is operated by Bahn, a sole proprietorship registered in India and owned by Sanjana Garg. Bahn determines why and how your personal data is processed and acts as the Data Fiduciary where India's Digital Personal Data Protection Act, 2023 applies. For any privacy questions or requests, contact us at indiasfavsesh@gmail.com. You may use the same address to reach our Grievance contact (see Section 12).
2. Information we collect
a) Information you provide
- Email address. Used to create and secure your account and to sign you in. It is your primary account identifier.
- Password. If you sign up with email and password, we store it only in hashed form through our authentication provider — we never see or store it in plain text. Some sign-ins instead use a one-time code or magic link sent to your email.
- Google / Apple sign-in. If you choose these, you authenticate with Google or Apple and we receive a basic account identifier and your email from the provider. With “Sign in with Apple” you may hide your real email using Apple's private relay.
- Display name / username. Your public identity in the Services, visible to friends and to members of group conversations you join.
- Profile photo. Optional, and stored in our file storage (Supabase Storage). We may also review profile photos ourselves to enforce our Terms, and may remove a photo that breaks them.
- Automated content screening. Before certain profile and group content is published, we send it to OpenAI's Moderation API. This includes profile photos, the username and display name you choose at sign-up or when editing your profile, group names, and group icon images. OpenAI returns a classification so we can block harmful content before other users see it. We do not send your chat messages, email address, or other account information to OpenAI for this pre-publish check.
- Automated report review. When someone files an abuse report, we automatically review the reported content using OpenAI's Moderation API. Depending on the report, this may include a specific chat message, a reported user's profile name, username, and profile photo, or recent messages in a reported group conversation. OpenAI returns a classification on our behalf. Based on that review, we may automatically remove or redact content, clear a profile photo, or take other enforcement action described in our Terms, including banning repeat offenders. We keep a record of what the automated review found and what action was taken.
- Legal acceptance. When you create an account, we record the legal-terms version shown to you and when you accepted it. The acceptance screen links to both our Terms of Service and this Privacy Policy.
- Content you create. The chat messages you send, and the text of any abuse report or product feedback you submit to us. If a message or account is reported, we — and our automated review tools — may read the reported message, related conversation context, or reported profile information in order to decide whether it breaks our Terms.
b) Your engagement and activity
We collect how you engage with the Services — the breaks you take, the summons and invites you send, invite-link clicks, chat activity, and how you use features. This is our own first-party analytics, stored on our infrastructure and tied to your account, so we can provide the experience, keep it working, and improve it. We do not use third-party advertising or ad-analytics SDKs.
c) Friend connections
We store the connections between you and other users so we can show mutual presence, enable friend-gated direct chat, and let you summon or invite friends. Group conversations may include people who are not currently friends, and a group summon may go to eligible group members. We also store a record of users you have blocked and reported, so we can hide their content from you and stop them contacting you. Blocking in the app always includes submitting a report for our review.
d) Information collected automatically
- Push notification token and content. We store an identifier from Firebase Cloud Messaging (FCM) so we can send you summons, chat messages, friend activity, and service announcements. A chat-notification payload may include the message text, sender name and profile-photo URL, conversation title and icon URL, and identifiers needed to open the correct conversation.
- Limited technical data. Your IP address, and basic request metadata such as app version, may be logged by our infrastructure for security, abuse-prevention, and reliability. We do not run a device-fingerprinting or advertising SDK in the app.
- Diagnostics and performance monitoring. We use Sentry to diagnose crashes and errors and to measure app performance. Data sent to Sentry may include your account ID, IP address, device model and operating system version, app and framework versions, route names, performance timings, technical profiles, logs, and a trace showing where in our code an error happened.
- Session replay. When an error occurs, Sentry may capture a short replay of the app screens you were interacting with just before it, so we can reproduce the problem. We do not record replays for sessions that end without an error. Text you have typed or received, and images on screen, are masked in these replays.
e) The website and invite handoff
Opening an invite link records a deduplicated click so the inviter can see how much interest their link received. If you use an App Clip or install from Google Play through an invite, the invite code is temporarily stored on your device so the full app can attribute signup and create the eligible friend request. We do not store raw IP addresses or browser user-agent strings; a visitor identifier is derived from the IP address only to avoid counting the same click multiple times within an hour, and user-agent is checked only to skip automated bots.
f) What we do NOT collect
- We do not access your device's contacts.
- We do not access your microphone or record audio. The app only plays ambient audio locally.
- We do not collect precise location.
- We do not show third-party advertising and do not sell your personal information.
- We do not use third-party advertising or behavioural analytics SDKs. Firebase is used to deliver push notifications. Sentry is used for operational diagnostics, performance monitoring, and the error-triggered session replay described above — not for advertising or marketing analytics.
3. How we use your information
- Create and secure your account and sign you in.
- Provide the core experience: presence, breaks, chat, summons, and invites.
- Connect you with friends and group members and manage your friend graph and conversation memberships. Apply the blocks you set, so blocked users' content is hidden from you.
- Send push notifications you've enabled and service-announcement emails. Announcement emails include an unsubscribe link.
- Screen profile and group text and images automatically before they are published, so that we can block content that breaks our Terms before other users see it.
- Automatically triage abuse reports when they are filed, including sending reported content to our moderation tools, notifying our moderation team, and taking immediate enforcement action where warranted.
- Maintain, troubleshoot, and improve the Services, including first-party analytics on how features are used and Sentry diagnostics and performance monitoring.
- Prevent abuse, spam, and fraud, review reports — including reading reported messages, reviewing reported profile photos, and reviewing block-and-report events — and enforce our Terms, including through automated removal, account restrictions, and bans for repeat offenders.
- Keep records of reports we receive, what our automated review found, content we remove, and enforcement action we take, so we can handle appeals, identify repeat offenders, and meet our legal obligations.
- Comply with legal obligations.
4. Legal bases (for users in the EU/UK)
Where applicable, we process your data on the basis of: performance of a contract (to provide the Services), consent (e.g., notifications, where required), legitimate interests (security, diagnostics, and improving the Services), and legal obligation. Some screening and enforcement decisions are made automatically, as described in Sections 3 and 8. If you are in the EU or UK and a solely automated decision produces legal or similarly significant effects for you, you may ask us to have a person review it by emailing indiasfavsesh@gmail.com.
5. How we share your information
We share data with users and service providers only as needed to run the Services:
- Other users. Your display name, profile photo, presence where permitted, and the messages and summons you send are visible to the friends and group or conversation members you interact with.
- Supabase. We use Supabase for authentication, database, file storage, and real-time infrastructure. Supabase stores your account data, friend graph, group memberships, messages, and profile photo on our behalf as a data processor.
- Zoho. We use Zoho ZeptoMail to send authentication and service emails (such as sign-in codes or links), moderation notices, and service announcements, and to deliver internal operational emails to our moderation team when abuse reports are filed or need attention. Your email address is shared with Zoho when we email you directly. Announcement emails include an unsubscribe link. Report details — such as usernames and the text of a report — may be included in internal moderation emails sent to our team through Zoho; those emails are not shared with other users.
- Google / Apple (sign-in). If you use Google or Apple sign-in, you authenticate directly with them and we receive a basic identifier and email. Their handling of that authentication is governed by their own privacy policies.
- Firebase Cloud Messaging (Google). We use FCM to deliver push notifications. This involves sharing a device push token and the notification content with Google/Firebase. For chat notifications, that content may include the message text and the sender and conversation metadata listed in Section 2(d). We do not send your email address to FCM for this purpose.
- Sentry. We use Sentry to collect crash and error reports, logs, performance traces, and technical profiles. This involves sharing your account ID, IP address, device and operating system details, app version, route names, timing and profiling data, and technical error data with Sentry as a data processor, along with any session replay captured at the time of an error. Text and images are masked in session replays, and we do not intentionally include chat messages or profile photos in Sentry reports.
- Legal and safety. We may disclose information if required by law, or to protect the rights, safety, and security of our users or the public.
- OpenAI. When you publish profile or group text or images, or when content is reported to us, we send the relevant content to OpenAI's Moderation API so it can be checked for harmful content. For pre-publish screening, this includes profile photos, usernames, display names, group names, and group icons. When a report is filed, it may include a reported chat message, a reported user's profile name, username, and profile photo, or recent messages from a reported group conversation. OpenAI processes the content on our behalf as a data processor and returns a classification. We do not send your email address or other account metadata to OpenAI.
We do not sell or rent your personal information, and we do not share it for cross-context behavioral advertising.
When content is reported, it is automatically triaged using OpenAI's Moderation API and may be automatically enforced before a person reviews the report. Our moderation team also reviews reports directly. Profile photos, group icons, and profile and group names are screened automatically before they go live.
6. Data retention
We keep your information for as long as your account is active. If you delete your account, your usable Auth account and public profile and product data are removed immediately. A private, client-inaccessible deletion archive may be kept for up to 30 days and is then automatically purged. The registration and moderation records described below are retained separately for 180 days, and Sentry diagnostics expire on their own schedule. We may also retain limited information where required to comply with legal obligations, resolve disputes, or prevent abuse.
As an intermediary based in India, we are required to retain the information collected when you registered for 180 days after your account is cancelled or withdrawn. This registration record includes your email address, username, signup date and time, and signup IP address where available. We are also required to retain information we have removed — following a report, a grievance, or our own review — for 180 days from the date of removal, for investigation purposes.
Where content is reported, or a user is blocked, we retain the reported content, the report itself, and a record of the action we took for 180 days. This lets us respond to appeals, recognise repeat offenders, and answer lawful requests. Retained data of this kind is not used to provide the Services and is not visible to other users.
Crash reports, logs, performance traces, technical profiles, and any error-triggered session replay are held in Sentry and deleted automatically after 90 days. This schedule runs from the date of the event and is not shortened if you delete your account in the meantime, so Sentry data can outlive your account by up to 90 days. It is used only for diagnostics and performance monitoring and is not visible to other users.
When you delete your account, server copies of messages you authored are deleted. A message may remain temporarily in another member's offline device cache until that device synchronises again. Aggregated or de-identified data that cannot reasonably identify you may be retained.
7. International data transfers
Corp Sesh is used in India and by the Indian diaspora (including the US, UK, and Gulf). Your data may be stored and processed on servers operated by our service providers — including Supabase, Google and Apple (sign-in), Google Firebase Cloud Messaging, Zoho, Sentry, and OpenAI — which may be located outside your country of residence. Where required by law, we use appropriate transfer safeguards, such as contractual protections.
8. Your rights
Depending on where you live, you may have the right to:
- Access the personal data we hold about you.
- Correct inaccurate data.
- Delete your account and data.
- Object to or restrict certain processing.
- Data portability.
- Withdraw consent at any time (e.g., disable notifications in your device settings).
India (DPDP Act, 2023): once the relevant provisions apply, you will have the rights provided by that law, including access, correction and erasure, grievance redressal, and nomination. We already accept access, correction, deletion, and grievance requests using the contact details below.
California (CCPA/CPRA): where these laws apply, you have the right to know, delete, and correct your personal information, and to not be discriminated against for exercising these rights. We do not sell or share personal information as those terms are defined under the CCPA.
EU/UK (GDPR): you also have the right to lodge a complaint with your local data protection authority.
Some content decisions are automated — including pre-publish screening and automated review of reported content. If your content is removed or your account is restricted and you believe that is a mistake, email indiasfavsesh@gmail.com and a person will review it.
To exercise any right, email indiasfavsesh@gmail.com. You can delete your account directly in the app, from your profile settings (“Delete account”). Every announcement email includes a link to stop future announcement emails. We may need to verify your identity before acting on a request.
Your right to erasure is subject to the retention periods described in Section 6, where we are legally required to keep limited information.
9. Data security
We use industry-standard measures to protect your data, including encryption in transit (TLS), encryption at rest, row-level security and access controls that restrict client access to permitted data, and least-access controls for internal services. No method of transmission or storage is completely secure, so we cannot guarantee absolute security. If a breach affects your personal data, we will notify the Data Protection Board of India, affected users, or other authorities where and when required by applicable law.
10. Children's privacy
Corp Sesh is not directed to, and not intended for, anyone under 18 years of age. We do not knowingly collect personal information from children. If you believe someone under 18 has provided us information, contact indiasfavsesh@gmail.com and we will delete it.
11. Changes to this policy
We may update this Policy from time to time. If we make material changes, we will notify you in the app or by other reasonable means and update the “Last updated” date above. Changes take effect when stated in the notice or when posted. Where applicable law requires consent to a change, we will ask for it.
12. Contact us
Bahn (sole proprietorship), owned by Sanjana Garg, India — email indiasfavsesh@gmail.com.
Grievance contact (India): Sanjana Garg, Grievance Officer — indiasfavsesh@gmail.com. We will acknowledge and respond to grievances within the timelines required under the DPDP Act and applicable law. Under the IT Rules, 2021 we will acknowledge a complaint within 24 hours and resolve it within 15 days.