Jama · Legal

Privacy Policy

What Jama collects, why, and how it is protected. Your committee's content is encrypted on your device, and we can't read it.

Effective date: 29 September 2026

This Privacy Policy explains what Passhai Technologies Private Limited (“Jama”, “we”, “us”) collects and how it is protected when you use the Jama Android app, the Jama WhatsApp experience and related services (the “Service”). It should be read with our Terms of Service.

1. What we collect

DataWhat it isWhy
Phone numberVerified via Firebase OTP at sign-inYour identity on Jama; how other members' devices find and message you
Device public keysX25519 (encryption) and Ed25519 (signing) public keys your device generatesLets an organiser's device seal committee data specifically to your device, and lets us verify an action really came from you
Push notification tokenAn FCM token from GoogleWakes your app to sync when something changes. The notification itself carries no content, only “something changed, go check”
Committee content (encrypted)Contribution amounts, member names within a committee, payment records, bids, committee termsThe substance of your committee. See section 2 for why we can't read it
UPI address (optional)The UPI ID you or another member enters for receiving a payoutDisplayed to committee members so they can pay you directly, outside the app. Never sent by us to a payment processor, because there isn't one
Contacts (on-device only)Names matched against your phone's contact listTo show a person's name instead of their phone number. This lookup happens entirely on your device; your contact list is never uploaded to us
WhatsApp number, consent stateIf you use the WhatsApp channelTo message you and act on your explicit instructions there

2. Zero-knowledge encryption: what it means

Every device in a committee holds its own private keys, generated on that device and never sent to us. Committee content (amounts, names, terms, bids) is encrypted on your device before it is sent to our servers, and only devices holding that committee's key can decrypt it. Our servers store and relay that encrypted data but cannot read it. We hold ciphertext, public keys and yes/no trust signals, never the plaintext of your committee's financial content.

What we do hold in plain form: your phone number (needed to route committee invitations and let your own devices find each other), device public keys, and metadata about which committees you're in. None of this reveals what is happening inside a committee.

3. The WhatsApp channel's custodial key

If you choose to take part in a committee over WhatsApp instead of installing the app, there is no device of yours to hold a private key. In that case, our WhatsApp service holds a signing key on your behalf, encrypted at rest, so it can act on your explicit instructions (a bid you asked it to place, a payment you asked it to mark) the same way your own device would if you had installed the app.

This is the one deliberate exception to the rule that only you hold your own keys. We tell you so directly, in plain language, before any such key is created for you.

4. What we don't do

We don't show ads. We don't sell your data. We don't use your committee content for anything other than running the Service; we can't, since we can't read it. We don't process payments; there is no payment processor integrated into Jama.

5. Who we share data with

  • Firebase (Google): phone number verification and push notifications.
  • Google Cloud Platform: hosts our servers and database in India (asia-south1, Mumbai).
  • Meta / WhatsApp Business Platform: if you use the WhatsApp channel, your WhatsApp number and the messages we send you pass through Meta's platform, subject to Meta's own privacy policy.

We don't share data with anyone else, and never for advertising or marketing purposes.

6. Data retention

We keep your account data for as long as your account is active. Encrypted committee content persists as part of that committee's record for as long as the committee exists on the Service. You can request deletion at any time; see section 8.

7. Your rights

You can request access to, correction of, or deletion of your data at any time by emailing [email protected]. For deletion, follow the steps in section 8. Because committee content is encrypted end-to-end and readable only by committee members, deleting your account removes your identity and keys from our systems. Content already synced to other members' devices, like a message already delivered, is not something we can reach in and erase from their devices.

8. How to request deletion of your data

You can ask us to delete your Jama account and the data associated with it at any time. Email [email protected] using the format below.

To[email protected]

SubjectData deletion request – Jama

Message

Full name: your name
Registered mobile number (with country code): e.g. +91 98XXXXXX10
Product: Jama
What to delete: My account and all associated data
Reason (optional): …

Open a pre-filled email
  • Verification: before deleting anything, we will send a verification code on WhatsApp to the registered mobile number in your request. Reply to our email with that code to confirm the request came from the account holder. Requests that are not confirmed with the correct code will not be processed.
  • Timeline: once your code is confirmed, deletion is completed within 4–7 business days, and we will confirm by email when it is done.
  • Committee records on other phones: because committee content is end-to-end encrypted, deletion removes your identity, keys and data from our systems. Copies already synced to other members' devices stay on those devices, like a message already delivered.

9. Children's privacy

Jama is not directed at children, and we don't knowingly collect data from anyone under 18. If you believe a minor has provided us data, email [email protected] and we'll act on it.

10. Where your data is stored

Our servers and database are hosted in India, in Google Cloud's asia-south1 (Mumbai) region.

11. Security

Committee content is encrypted end-to-end (see section 2). Every action taken in a committee is cryptographically signed and verified before it is accepted. We use industry-standard practices to protect the data we hold in plain form (phone numbers, device public keys). No system is perfectly secure, and we can't guarantee absolute security.

12. Changes to this policy

We may update this Privacy Policy from time to time. Material changes will be reflected by a new effective date at the top of this page.

13. Grievance Officer

In accordance with the Information Technology Act, 2000 and the rules made under it, you can contact our Grievance Officer with any complaint about how your data is handled:

Grievance Officer, Passhai Technologies Private Limited
Email: [email protected]
Plot No. A4, Logix Technova, Sector 132, Noida, Gautam Buddha Nagar – 201304, Uttar Pradesh, India

14. Contact

Questions about this Privacy Policy: [email protected].