Effective: April 4, 2026 · Last updated: April 4, 2026
Puffin AI is operated by Puffin Technologies, registered in India. For questions about this privacy policy or your personal data, contact us at: contact@puffintech.io
We practice data minimization — we only collect data that is strictly necessary for the service to function.
Email address, display name, and a securely hashed password. Collected when you voluntarily create an account. We also store a timestamp of when you gave consent.
The questions you ask and the AI-generated responses. Stored to provide conversation history. You can delete your conversations at any time from the chat sidebar.
A JSON Web Token (JWT) is stored in your browser's local storage to maintain your login session. This is not a tracking cookie — it is purely for authentication. This disclosure is made pursuant to the EU ePrivacy Directive (2002/58/EC) Art. 5.3, which covers "similar technologies" to cookies including localStorage.
| Data | Purpose | Legal Basis |
|---|---|---|
| Email & Password | Account authentication | Consent (voluntary registration) |
| Display Name | Personalization in the UI | Consent (voluntary registration) |
| Chat Messages | Generating AI responses & conversation history | Consent (you actively submit queries) |
| Provider | Purpose | Location |
|---|---|---|
| Google Cloud Platform | Database hosting, compute (Cloud Run) | United States |
| Google Gemini API | AI response generation | United States |
Under the India Digital Personal Data Protection Act (DPDP Act, 2023), the EU General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA), and other applicable data protection laws, you have the following rights:
GET /api/auth/export endpoint or email us.GET /api/auth/export endpoint.To exercise any of these rights, email contact@puffintech.io. We will respond within 30 days.
Your data is processed and stored in the United States via Google Cloud Platform. For transfers from the EU/EEA, we rely on:
For transfers from India, we comply with DPDP Act §16 and will update this policy when the Indian government publishes its list of approved transfer destinations.
Puffin Technologies does not sell, rent, or trade your personal information to third parties. We do not share your personal data for cross-context behavioral advertising.
This section applies to residents of US states with comprehensive privacy laws, including but not limited to:
Under these laws, you have the right to: access your data, delete your data, opt out of the sale of personal information (we do not sell data), and non-discrimination for exercising your rights. Use the sidebar export/delete buttons or email us to exercise these rights.
If you have a complaint about how your data is handled, contact us at contact@puffintech.io. If your complaint is not resolved satisfactorily, you may escalate it to:
Our hosting provider (Google Cloud Platform) automatically collects standard server access logs (IP address, timestamps, HTTP request details) as part of its infrastructure operations. These logs are managed by Google Cloud under their Data Processing Addendum and are not processed or stored by Puffin AI's application.
Puffin AI is not intended for use by individuals under the age of 18. We enforce this through an age confirmation checkbox during registration.
We do not knowingly collect personal data from children. In compliance with India DPDP Act §9 (parental consent for minors), US COPPA (Children 's Online Privacy Protection Act for under-13), and GDPR Art. 8 (conditions for child's consent):
In the event of a personal data breach that risks the rights and freedoms of our users, we commit to the following notification timelines:
| Jurisdiction | Authority | Timeline |
|---|---|---|
| EU / UK | Relevant DPA / ICO | Within 72 hours (GDPR Art. 33) |
| India | Data Protection Board + affected users | Without unreasonable delay (DPDP §8) |
| California | Attorney General (if >500 residents) | Expeditiously (CCPA §1798.150) |
| Other US states | State AG + affected users | Per applicable state law |
Affected individuals will be notified via email with details of: the nature of the breach, data affected, steps taken, and recommended protective measures.
In compliance with the Information Technology Act 2000 §43A and the Sensitive Personal Data or Information (SPDI) Rules 2011, Rule 8, we implement the following reasonable security practices:
We may update this privacy policy from time to time. Material changes will be communicated through the Puffin AI interface. The "Last updated" date at the top of this page reflects the most recent revision.
This policy complies with the India Digital Personal Data Protection Act (DPDP Act, 2023), the Information Technology Act 2000 & SPDI Rules 2011, the EU General Data Protection Regulation (GDPR), the UK GDPR (Data Protection Act 2018), the California Consumer Privacy Act (CCPA/CPRA), and applicable US state privacy laws.
यह नीति हिंदी में अनुरोध पर उपलब्ध है — कृपया contact@puffintech.io पर संपर्क करें।