Privacy policy
Privacy policy
Last updated 5 October 2026. Fields marked to be filled in are pending company details and will be completed before launch.
This policy explains what Pehra collects and what it does not. It is written to match our Google Play Data Safety disclosure line for line, on purpose, so that neither can quietly drift from the other.
Who we are. Pehra is operated by BFSIJob Education LLP, a limited liability partnership registered in India, with its registered office at to be filled in. In the language of India’s Digital Personal Data Protection Act, 2023 we are the Data Fiduciary for your personal data.
1. What we collect
- Your name — so the complaint and dispute letters the app drafts are correctly addressed, and so family members can be identified within a cover.
- Your mobile number — to verify your registration and to send fraud warnings relevant to your area.
- Your pincode — to name your district cyber police station on a complaint, and to decide which area warnings apply to you. We store only the first three digits.
- An email address — only if you purchase family cover, for your receipt and to manage the people you have added.
- Anonymous counts — that a scam of a given family was checked, with a three-digit pincode prefix and a random device code. These are never stored alongside your name or number.
2. What we never collect
- The content of your messages, calls, links or screenshots. What you check is analysed on your device and discarded.
- Your contacts or call log. We do not request these permissions.
- Your location. The app requests no location permission of any kind.
- Your documents, photographs or files.
- Any detail of a fraud you suffered — your spoken account, the amounts, and the letters drafted all remain on your device.
- Biometric data. Your fingerprint or face is verified by your phone’s own security system; we never see or receive it.
3. Why we are allowed to hold it
We rely on your consent, given at registration, and we take it for a stated purpose in clear language, in Hindi or English as you choose. You may withdraw consent at any time, and withdrawing it is as easy as giving it was. Where you register a family member, you confirm that you have their permission to do so, and each member is told at first use what is held about them and how to remove it.
4. Who we share it with
We do not sell personal data, and we do not share it for advertising. We use a small number of processors under contract: our cloud database provider, our payment processor (Google Play), and our messaging provider for area warnings. Where personal data is processed outside India, it is done in line with Rule 15 of the Digital Personal Data Protection Rules, 2025. We disclose data to a government authority only where we are legally required to, and we hold very little that could be disclosed.
5. How long we keep it
Registration details are kept while your account is active and for one year after you stop using the app, after which they are deleted. Anonymous scam counts are kept for three years, and cannot be traced to you. Payment records are kept for eight years because tax law requires it; these contain your name and transaction, not your activity in the app.
6. Your rights
- To know what we hold about you and who we have shared it with.
- To correct anything inaccurate, incomplete or out of date.
- To erase your data — see our deletion page.
- To nominate another person to exercise these rights if you are unable to.
- To complain to our Grievance Officer, and then to the Data Protection Board of India if you are not satisfied.
We answer a rights request within thirty days, and within ninety days at the outside.
7. Children
Pehra is not offered to anybody under eighteen in their own right. A child may be added to a family cover only by a parent or lawful guardian, who confirms that relationship. We do not profile children, do not advertise to them, and do not monitor a child’s activity or content — where alerts are enabled with consent, a guardian receives the fact that a risky event occurred, never what was said, read or viewed.
8. Security
Data in transit is encrypted. Data at rest is encrypted. Access is restricted by role and logged. Rescue material stays on your device behind your phone’s own lock. If a personal data breach occurs we will inform affected users and the Data Protection Board of India as the Rules require.
9. Changes
If we change this policy we will update the date above, and for any material change we will tell you inside the app before it takes effect.
10. Contact
Grievance Officer: to be filled in
Email: to be filled in
Postal address: to be filled in
Response time: within thirty days of receipt.