NewLifeAppGen← Back to site

Privacy Policy

What we collect, why we collect it, who we share it with, and the choices you have. Written to be read, not to be skimmed past.

Effective: 12 August 2026

1. Who we are

NewLife AppGen is operated by Cedar Information Technology Pvt. Ltd., Kompally, Hyderabad, Telangana, India. For the purposes of the Digital Personal Data Protection Act, 2023 (“DPDP Act”), Cedar IT is the Data Fiduciary responsible for the personal data described in this policy.

This policy covers the Platform at newlifeappgen.in. It does not cover applications that users build with the Platform and operate themselves.

2. What we collect

Information you give us

  • Your mobile number — required to create an account and to sign in
  • Your password, stored only as a cryptographic hash and never in readable form
  • Prompts and instructions you submit to generate or edit applications
  • Project content: the names, source code and files of applications you create
  • Billing details you provide when subscribing, including GST details where you request a GST invoice
  • Anything you send us in a support enquiry

Information collected automatically

  • Session information needed to keep you signed in
  • IP address, browser and device type, recorded in server logs for security and abuse prevention
  • Usage records: credits consumed, generation requests, timestamps and error events

We do not collect your email address, we do not require any government identity document, and we do not store your card or bank details — payments, when enabled, are handled by our payment gateway.

3. Why we use it

  • To provide the service — creating your account, authenticating you, generating and storing your projects, and metering credits
  • To verify your mobile number — sending a one-time password by SMS at signup and when resetting a password
  • To take payment — processing subscriptions and issuing GST-compliant invoices
  • To keep the Platform secure — detecting abuse, rate-limiting, preventing fraudulent signups and investigating incidents
  • To support you — responding to your enquiries
  • To improve the service — understanding aggregate usage patterns and diagnosing failures
  • To meet legal obligations — including tax and accounting record-keeping

We do not sell your personal data. We do not use your data for advertising, and we do not share it with advertisers or data brokers.

4. Your prompts and AI processing

To generate an application, the Platform transmits your prompt, together with the relevant context of the project you are working on, to a third-party AI provider — currently Google, through the Gemini API. This is necessary to produce the output you request, and it is the core function of the service.

That processing is governed by the provider’s own terms. We select and configure providers with the intention that content submitted through the paid API is not used to train their models, but their terms prevail on that point, and we recommend you review them if this matters to you.

Please do not paste passwords, API keys, financial details, health information or other sensitive personal data into prompts. Treat a prompt like something you are sending to an external service — because you are.

We do not use your prompts or project source code to train any model of our own, and we do not review project content except where you ask us to for support, or where we have a concrete reason to investigate a suspected breach of our Terms or a legal requirement to do so.

5. Who we share it with

We share personal data only with service providers who help us operate the Platform, and only to the extent each needs:

  • Google (Gemini API) — receives prompts and project context to generate output
  • Our SMS provider — receives your mobile number to deliver OTP messages
  • Our payment gateway — handles payment details directly; we receive only the transaction result and invoice information
  • Our hosting provider — operates the servers on which the Platform and its database run

We may also disclose data where required by law, court order or a valid request from a government authority, or where necessary to establish or defend a legal claim.

If our business is transferred, merged or acquired, personal data may transfer with it. You would be notified before any such transfer changes how your data is handled.

6. Where your data is stored

Your account and project data is stored in a database located on servers in India. Some of our service providers, including our AI provider, may process data outside India. Such transfers are made in accordance with the DPDP Act and only to the extent needed to deliver the service.

7. How long we keep it

  • Account data — for as long as your account is active
  • Projects and generated code — until you delete them, or 30 days after account deletion
  • OTP codes — deleted or expired within minutes of being issued
  • Server and security logs — up to 12 months
  • Invoices and transaction records — 8 years, as required by Indian tax law

After account deletion, data is removed within 30 days except where a longer period is legally required, such as tax records.

8. Security

We take the following measures, among others:

  • All traffic is encrypted in transit using TLS
  • Passwords are stored using a slow, salted one-way hash and are never recoverable in readable form
  • OTP codes are hashed before storage, expire quickly, and are invalidated after a small number of failed attempts
  • The database is dedicated to this Platform, with credentials that grant no access to any other system
  • Rate limiting on authentication and OTP endpoints to deter automated abuse

No system is perfectly secure, and we cannot guarantee absolute security. If a personal data breach occurs that affects you, we will notify you and the Data Protection Board of India as required under the DPDP Act.

9. Your rights

Under the DPDP Act, you have the right to:

  • Access a summary of the personal data we hold about you and how it is processed
  • Correct or complete inaccurate or incomplete data
  • Erase your personal data where it is no longer needed for the purpose it was collected
  • Nominate another person to exercise your rights in the event of death or incapacity
  • Withdraw consent, understanding that this may prevent us from providing the service
  • Raise a grievance with us, and escalate to the Data Protection Board of India if unresolved

To exercise any of these rights, contact us at contact@cedarinfotech.com. We respond within 30 days. You can also delete your account yourself at any time from your account settings.

10. Cookies

We use a single essential cookie to keep you signed in. It is strictly necessary for the Platform to function and cannot be disabled while you remain logged in.

We do not use advertising cookies, third-party tracking pixels, or cross-site behavioural profiling.

11. Children

The Platform is not intended for anyone under 18, and we do not knowingly collect personal data from children. If we learn that we have collected data from a child, we will delete it. If you believe a child has registered, please contact us.

12. Grievance Officer

In accordance with the DPDP Act and the Information Technology Rules, our Grievance Officer can be reached at contact@cedarinfotech.com, or by post at Cedar Information Technology Pvt. Ltd., Kompally, Hyderabad, Telangana, India.

We acknowledge grievances within 48 hours and aim to resolve them within 30 days. If you are not satisfied with our response, you may escalate to the Data Protection Board of India.

13. Changes to this policy

We may update this policy as the Platform develops or the law changes. Material changes will be notified to registered users by in-app notification or SMS. The effective date at the top of this page always reflects the current version.

Contact

Cedar Information Technology Pvt. Ltd.
Kompally, Hyderabad, Telangana, India
Email: contact@cedarinfotech.com
Phone: +91 70933 40606
CIN: U72200TG2013PTC089376 · GSTIN: 36AAFCC4467P2Z1