Privacy Policy
Last updated 9 August 2026
Samosa is built and run by Garv Nanwani, an independent developer based in India (“I”, “me”). There is no company behind it — one person operates this service. This policy explains what the hosted service at this site collects, why, and what happens to it. Questions: garvwashere@gmail.com.
What I collect
- Account identity. Your name and email address, from whichever provider you signed in with. I never see or store your password.
- Your conversations.The messages you send and the assistant’s replies, so your chats persist between sessions.
- Files you upload. Text extracted from documents you add, so the assistant can search them later.
- What the assistant remembers. Notes it keeps about your preferences and context, and a record of what your scheduled agents have already told you so they do not repeat themselves.
- Usage counters. How many messages and tokens you have used each day, to enforce plan limits.
- Delivery addresses. If you connect Telegram or enable email delivery, the chat id or address needed to send your briefs there.
Where your messages go
Samosa is an AI assistant, so the content of your conversations — including text extracted from files you upload and anything the assistant remembers about you — is sent to third-party model providers to generate a reply. Which provider depends on the model selected for that conversation. I do not control those providers’ own retention practices; if that matters for your data, choose your model accordingly, or do not put that material in a conversation.
Naming the model providers specifically, because that is where what you write actually goes: prompts are routed through OpenRouter to the model you picked. The models offered today are made by DeepSeek and Alibaba (Qwen), both Chinese companies. If you use web search, that one call additionally uses Google Gemini’s search grounding.
Beyond the models, the service relies on ordinary suppliers: a cloud host, a managed database, object storage for files, generated media and backups, an email delivery provider, and error monitoring that receives stack traces rather than your messages. I do not list those by name here — a published inventory of the exact stack mostly helps somebody attack it. If you need the names, for a vendor review or to exercise a data right, email me and I will give you the current list.
Your data leaves the country you are in. I operate from India, the infrastructure above sits outside India, and the model providers named above process prompts outside both India and the EU — including in China. If that is not acceptable for what you were going to put in a conversation, please do not put it in a conversation. I would rather say that plainly than bury it.
If you connect an external account (for example Google, GitHub, or an MCP connector), the assistant can read and act on data from that account when you ask it to. Access tokens are encrypted at rest and can be revoked from Settings.
Payments
Payments are handled by Dodo Payments, acting as merchant of record. They collect and process your payment details directly under their own privacy policy. I never receive or store your card details. The only billing data here is which plan you are on and when it renews.
What I do not do
- I do not sell your data.
- I do not use your conversations to train any model, and I do not build profiles of you to sell to anyone. What I cannot promise is what the model providers above do with a prompt once it reaches them — I am their customer, not their regulator. Their own policies govern that.
- I do not read your conversations. The operational tooling records who used the service and how much, never what was said. This is a commitment about how I behave, not a technical impossibility: I run the database, so treat it as a promise from one person rather than a guarantee from a system.
Retention and deletion
Your conversations, documents and assistant memory are kept until you delete them. You can delete your whole account yourself, from Settings → You → Delete account. That erases your conversations, uploaded files, assistant memory, scheduled agents, share links and generated media immediately and permanently. I cannot undo it and neither can you, so the button asks you to type the word first.
Deleting a single conversation hides it at once and erases it, along with its transcript, within 30 days. Anonymous demo sessions on the landing page are discarded automatically. Database backups are kept for a short rolling window and then overwritten, so a deleted account can persist in a backup until that window passes.
If you would rather I did it, or the button refuses because your account is part of a workspace, email garvwashere@gmail.com and I will action it within 30 days.
Security
Data is held on infrastructure I control, and connector secrets are encrypted at rest. Being straight with you: this is a one-person project, not an audited enterprise platform, and no system is perfectly secure — do not put material in a conversation you could not tolerate being disclosed.
Your rights
Depending on where you live you may have rights to access, correct, export or delete your personal data, and to object to certain processing. Two of those you can exercise yourself, without asking me and without waiting: Settings → You → Download my data gives you a JSON file of everything held under your account, and Delete account in the same place erases it. For anything else, email garvwashere@gmail.com.
Changes
I will update this page when the product changes. Material changes will be notified in the app before they take effect.