AI-generated first draft — not yet legally reviewed. This document was generated by an AI assistant based on a direct review of DRENGR's actual application code and database schema as of 21 September 2026. It accurately reflects what the app currently collects and does — it is not generic boilerplate. However, it has not been reviewed by a qualified Indian lawyer and must not be published live until it has been. Give particular attention, during review, to: the refund policy referenced from the Terms of Service, the Digital Personal Data Protection Act, 2023 ("DPDP Act") compliance framing throughout, and every field marked
[PLACEHOLDER: ...]below. Do not remove this notice until legal review is complete.
Last updated: [PLACEHOLDER: effective/last-updated date]
This Privacy Policy ("Policy") describes how [PLACEHOLDER: legal entity name and type — e.g. "Jane Doe, sole proprietor" or "Drengr Technologies Private Limited"] ("DRENGR", "we", "us", "our"), the operator of the DRENGR fitness application and the website drengr.in (collectively, the "App" or "Service"), collects, uses, discloses, and protects personal data.
Registered address: [PLACEHOLDER: registered business address]
GSTIN (if applicable): [PLACEHOLDER: GSTIN]
Under the DPDP Act, DRENGR acts as the Data Fiduciary and you, the user of the App, are the Data Principal. This Policy explains how we fulfil our obligations to you as Data Fiduciary and how you can exercise your rights as Data Principal.
By creating an account or using the App, you consent to the collection and processing of your personal data as described in this Policy. Where you are a minor, additional rules described in Section 5 apply, and certain processing will not begin until verifiable parental consent has been obtained.
We only collect data that supports a real, active feature of the App. The table below maps each category of personal data to the specific feature that creates it and the purpose for which we process it.
| Data | Source | Purpose |
|---|---|---|
| Email address | Clerk (our authentication provider) at sign-up | Account identification, login, transactional notifications (e.g. OTP emails) |
| Display name | You, at profile setup | Shown on your profile and to other users per your visibility settings |
| Unique nickname/handle | You, at profile setup | Public identifier used in the follow/social graph and on shared plans |
| Profile picture URL | You, on upload | Displayed on your profile |
We do not store your password. Authentication (including password storage, if you use a password, or social/OAuth login) is handled entirely by Clerk, our third-party identity provider, which acts as a sub-processor for your login credentials and account email. We never see or store your raw password.
| Data | Notes | Purpose |
|---|---|---|
| Height (cm) | Profile field | Personalising workout tracking, display on profile (subject to your privacy toggle) |
| Weight (kg) | A current profile field and, separately, a full daily history log if you opt in to the "body weight check-in" feature | Tracking body-weight trends over time, display on profile (subject to your privacy toggle) |
| Age range | We collect an age range only — never your exact date of birth | Age-appropriate gating (e.g. minor status, see Section 5), display on profile (subject to your privacy toggle) |
| Gender | Stored AES-256-GCM encrypted at rest (not in plaintext) | Personalisation, display on profile (subject to your privacy toggle) |
We consider height, weight, age range, and gender to be sensitive personal data. Gender in particular is encrypted at the database layer using AES-256-GCM before it is ever written to disk, so that even direct database access does not reveal it in plaintext.
See Section 5 for a full description of this feature. In summary, if your account is flagged as belonging to a minor, we additionally process:
isMinor flag and a hasParentalConsent flag on your account;This data exists solely to power the App's core training-log functionality and is not used for any advertising or profiling purpose.
If you use the Train feature to link a coach account and an athlete account (via a coach-generated invite code), we store your role (COACH or ATHLETE) and log lightweight "coach update events" — workout logged, day skipped, weight logged — so the linked coach can see high-level athlete activity. This is an account-linking feature analogous to a personal trainer and client sharing a paper logbook; it is not third-party data sharing, since both accounts are DRENGR users bound by DRENGR's Terms of Service, and the athlete controls the connection (it can be disconnected at any time — see Section 2.7).
One-time passcodes (OTPs) are used for: email verification, account deactivation, account deletion, coach-unlock, athlete-connect, and athlete-disconnect flows. OTPs are hashed with HMAC-SHA256 before storage — the raw code is never persisted to our database or written to logs. Each OTP expires after approximately 10 minutes, is locked after 3 incorrect attempts, and is subject to a 60-second resend cooldown.
See Section 9 for full detail on the plan-purchase marketplace. In our own database, we store only: the identifier of the plan purchased, the buyer's and seller's user IDs, the purchase amount (in paise), a purchase status (pending / success / failed), and Razorpay's own order ID and payment ID as reference numbers.
We never see, receive, or store your card number, UPI ID, bank account details, or CVV. All of that is collected directly by Razorpay through its own hosted/embedded checkout, out of band from DRENGR's servers, in accordance with RBI and PCI-DSS requirements applicable to payment aggregators.
Theme (light/dark) and weight-unit (kg/lb) preference. These are non-sensitive convenience settings.
For clarity, DRENGR does not collect or use:
Under the DPDP Act, we process your personal data on the basis of your consent, given when you create an account and agree to this Policy, and (for minors) when a parent/guardian additionally provides verifiable consent as described in Section 5.
Where relevant, we also rely on the "certain legitimate uses" permitted under the DPDP Act without requiring fresh consent for each instance — for example, using your data to comply with a legal obligation (such as retaining payment records under tax law, see Section 6), or to respond to a medical emergency threatening life or health.
You may withdraw consent at any time, with the same ease with which it was given, by using the in-app account deactivation or deletion flow described in Section 10, or by contacting our Grievance Officer (Section 11). Withdrawing consent does not affect the lawfulness of processing carried out before withdrawal, and may mean certain features of the App are no longer available to you.
We use your personal data only for the purposes stated in Section 2 and this Policy: operating and improving the App's core features (training log, social graph, coach-athlete connection, plan marketplace), account security and verification, customer support, legal and tax compliance, and communicating with you about your account and transactions. We do not use your personal data for behavioural advertising, ad targeting, or sale to data brokers, because we do not run any advertising or tracking infrastructure of that kind.
DRENGR is built to accommodate younger users under Indian law, and takes this seriously through a dedicated technical flow rather than a checkbox disclaimer.
How it works:
isMinor = true based on the age range you provide at sign-up.hasParentalConsent is set to true.ParentalConsentLog record containing the parent's email (stored AES-256-GCM encrypted, never in plaintext) and the timestamp of consent. The OTP itself is never stored in raw form (Section 2.7).What this means for you as a parent/guardian: you can decline consent, in which case the gated features simply remain unavailable to the minor's account. You may also withdraw consent at any time by contacting our Grievance Officer (Section 11), which will re-lock the relevant features.
No tracking or targeted advertising of children. In compliance with Section 9 of the DPDP Act, DRENGR does not undertake behavioural monitoring, profiling, or targeted advertising directed at any user it has identified (or ought reasonably to have identified) as a child. As stated in Section 2.10, DRENGR has no advertising or tracking infrastructure of any kind — so this restriction is met by the App's fundamental design, not merely a policy promise for this one class of user.
[PLACEHOLDER: retention window, e.g. 30 days] of the deletion request being confirmed, except as described below.ParentalConsentLog): retained for as long as necessary to demonstrate compliance with the DPDP Act's consent requirements, even if the associated account is later deleted, unless you request earlier erasure and no legal ground requires retention.No system is completely secure, and we cannot guarantee absolute security. See Section 12 for our breach-notification commitment.
We do not sell your personal data. We share personal data only with the service providers below, each of which processes it solely to provide their specific service to us and under contractual confidentiality obligations — none of them is permitted to use your data for its own independent purposes (e.g. its own advertising).
| Sub-processor | Role | Data it may process |
|---|---|---|
| Clerk | Authentication / identity provider | Email address, login/auth credentials, session data |
| MongoDB Atlas | Database hosting for the exercise library and custom workout-plan content | Workout plan structures, exercise library data |
[PLACEHOLDER: our Postgres database hosting provider] | Primary application database hosting | All primary-database personal data described in Section 2 |
| Vercel | Application hosting / serverless compute; Vercel Analytics and Speed Insights | Request/hosting data; aggregate, privacy-respecting usage and performance metrics (not individual ad-tracking) |
| Resend | Transactional email delivery | Email address, OTP codes and notification content sent to you |
| Razorpay | Payment processing (RBI-regulated payment aggregator, PCI-DSS compliant) | Purchase amount, order/payment references, and — directly between you and Razorpay, never through us — your payment instrument details |
We may also disclose personal data where required by law, in response to a valid legal process, or to protect the rights, property, or safety of DRENGR, our users, or the public.
Within the App, users may purchase workout plans published by other users, using Razorpay as the payment processor. When you make a purchase:
A separate UserSubscription data model exists in our database (tier FREE/PREMIUM) but is not currently a live, billed feature — no subscription billing is active, and no payment provider is currently wired up to it. This Policy will be updated before any such feature is activated.
As a Data Principal under the DPDP Act, you have the right to:
Deactivation vs. deletion: the App offers both a self-serve deactivation (temporary, reversible — your data is preserved and access-restricted, and you can reactivate by logging back in) and a self-serve deletion (permanent, irreversible — your data is erased as described above). Choose deletion if you want your data actually removed; deactivation only pauses your account.
To exercise any of these rights, use the relevant in-app control (Settings → Account) or contact our Grievance Officer below.
In accordance with the DPDP Act and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, we have appointed a Grievance Officer to address your questions, complaints, or requests concerning this Policy and your personal data.
[PLACEHOLDER: Grievance Officer name]legal@drengr.in[PLACEHOLDER: Grievance Officer phone number][PLACEHOLDER: Grievance Officer / registered business address]Response-time commitment: we will acknowledge your grievance within 48 hours of receipt and aim to resolve it within 30 days, in line with statutory timelines under Indian data protection law.
In the event of a personal data breach that is likely to affect you, we will notify you and the relevant regulatory authority (the Data Protection Board of India, once constituted, and/or other authorities as required) without undue delay and in accordance with the timelines prescribed under the DPDP Act and its rules. Notification to you will describe the nature of the breach, the data likely affected, and the steps we are taking (and that you can take) in response.
Some of our sub-processors (for example, Vercel and MongoDB Atlas) may store or process data on servers located outside India. The DPDP Act permits the transfer of personal data outside India except to countries specifically restricted by the Central Government (a "blacklist" mechanism, rather than the country-by-country "adequacy" model used elsewhere). As of this Policy's drafting, we do not transfer data to any government-restricted jurisdiction, and we require our sub-processors to maintain appropriate contractual and technical safeguards regardless of where they process data.
DRENGR does not use tracking or advertising cookies, and does not run a cookie-consent banner because no non-essential tracking occurs. What the App does use:
This Policy applies to all users. Section 5 describes additional protections specific to accounts flagged as belonging to minors. If you are a parent or guardian and believe your child has provided us with personal data without your consent outside of the verified flow described in Section 5, please contact our Grievance Officer immediately so we can investigate and, where appropriate, erase that data.
We may update this Policy from time to time to reflect changes in the App's functionality or in applicable law. We will update the "Last updated" date at the top of this Policy and, for material changes, provide reasonable notice in-app or by email before the changes take effect.
For any questions about this Policy or our data practices, contact:
privacy@drengr.inThis Policy is governed by the laws of India, including the Digital Personal Data Protection Act, 2023, the Information Technology Act, 2000, and the rules made thereunder. Disputes arising from this Policy are subject to the jurisdiction described in our Terms of Service, Section on Governing Law & Dispute Resolution.