Legal
Privacy Policy
Product: Asmuth (also referred to as Asmuth AI)
Last updated: 20 September 2026
Scope: Primary markets — North America (United States, Canada), Europe (European Union / EEA / United Kingdom), and Australia. We are established in India, and also serve users in Latin America (including Brazil) and other regions where the Services are offered.
Introduction
This Privacy Policy describes how Manish Kumar, trading as Asmuth (“Company,” “we,” “us,” or “our”), collects, uses, stores, and shares personal information when you use our Services, including:
- Our website at
https://asmuthai.comand related web pages (including the logged-in dashboard) - The Asmuth desktop application (Windows and any other platforms we offer)
- Related products, accounts, and communications that link to this Privacy Policy
Asmuth is offered globally, with a primary focus on users in the United States, Canada, the European Union / EEA / United Kingdom, and Australia. We are established in India, and we also serve users in Latin America (including Brazil) and elsewhere. Where local law gives you stronger rights than this Policy, those rights apply.
By using the Services, you acknowledge this Privacy Policy. If you do not agree, do not use the Services.
Questions or privacy requests? Contact [email protected].
Summary of key points
- We collect account details (such as name and email), usage meters (AI credits and listening time), and content you create in the product (chats, settings, interview analytics).
- Payments are processed by Dodo Payments; we do not store full card, UPI, or similar payment credentials.
- AI features may send prompts, transcripts, or images to subprocessors (cloud proxy, model providers, speech providers) to deliver the Service.
- We do not sell your personal information.
- You must be at least 18 (or the age of majority in your country, if higher) to use Asmuth.
- Depending on where you live, you may have rights to access, correct, delete, restrict, object, port data, or withdraw consent — see Regional privacy rights below.
- Website cookies: essential cookies for sign-in/security; optional analytics and marketing cookies stay off until you allow them via our cookie banner (see Cookies and similar technologies).
- Data may be processed in India and other countries where our providers operate; we use appropriate transfer safeguards where required.
1. What information do we collect?
1.1 Personal information you provide
Depending on how you use Asmuth, we may collect:
- Account data: user id, name, email address, and similar identifiers from our authentication provider (Supabase) when you sign in with Google OAuth (Google profile fields such as name and email; avatar may be stored by the identity provider)
- Contact & support: messages you send to
[email protected], refund requests, and related correspondence (our public Contact page is mailto-only — we do not run a contact form that posts data to our servers) - Profile & preferences (saved settings): selected AI model, interview role / subtype, response length, language, and custom system prompt
- User content: chat conversations and messages (including text derived from microphone, system/meeting audio, screen analysis, or manual input when you use the desktop app), live session status, performance / interview analytics records (scores, strengths/weaknesses, question breakdowns, summaries), and resumes or documents you upload (if that feature is enabled)
- Billing contact details: name, email, and other checkout details collected via Dodo Payments / our Site as needed to start checkout
1.2 Usage and billing meters
We maintain usage records needed to operate prepaid packs and enforce limits, including:
- AI credits used and granted AI credit limits
- Meeting-audio listening time used and granted listening limits
- Plan badge (for example free, starter, pro, pro_plus)
- Optional activity summaries (for example daily listening / response activity)
- Purchase / pack application identifiers needed for entitlements and refunds
- Associated account email on usage records
1.3 Payment-related information
If you purchase a pack, Dodo Payments processes your payment. We may receive limited transaction metadata (for example payment status, amount, currency, transaction / purchase id, product id, and your account email / user id in metadata) so we can grant the correct pack. Card numbers, UPI credentials, and similar payment instruments are handled by Dodo Payments, not stored by Asmuth as full payment credentials.
Payment methods available to you may depend on your country (for example cards, local methods, or UPI where offered). See Dodo Payments’ privacy documentation for how they process payment data.
1.4 Information collected automatically
When you use the website or desktop app, we may automatically collect:
- Technical / device data: IP address (for example in security and access logs), approximate location derived from IP, browser or WebView type, operating system, device identifiers as available, app version, language, and similar diagnostics
- Log data: timestamps, security events (for example auth failures), feature/error logs, and crash or performance diagnostics needed to secure and improve the Services
- Cookies and similar technologies on the website (see Section 5)
- Hosting / CDN logs: our infrastructure providers (for example Cloudflare) may process IP and request metadata as part of delivering the Site and downloads
Note: We do not currently run third-party marketing analytics pixels (such as Google Analytics or Meta Pixel) on the website. Optional “Analytics” and “Marketing” cookie categories exist in our preference tool so we can enable such tools later only with your consent.
1.5 Desktop audio, microphone, and screen features
The desktop app may, with your permission and for features you enable:
- Capture microphone audio (for example “Ask AI” or interview evaluation)
- Capture system / meeting audio for transcription
- Capture screenshots or screen content for screen analysis
Audio and images may be processed on your device and/or sent to our cloud proxy and subprocessors (including speech-to-text providers when STT is used) to generate transcripts or AI responses. Transcripts and related messages may sync to your account so the website dashboard and /live companion can display them. The website does not capture microphone or system audio; it primarily reads session and chat data written by the desktop app and our backend.
Important: You are responsible for complying with recording and consent laws in your country and for any third-party rules that apply to your conversations or interviews.
1.6 Sensitive / special-category information
We do not require you to provide special-category data (for example race, religion, health, or biometric templates used for identification). Content you type, speak, or capture during interviews may incidentally include sensitive details; you choose what to share. Do not use Asmuth to process data you are not allowed to share under law or third-party rules.
Where EU/UK GDPR “special category” data appears only because you voluntarily include it in prompts or recordings, we process it only as needed to provide the feature you requested, based on your consent and/or the fact that you clearly made the information public to the Service by submitting it — and you should avoid submitting such data unless necessary.
1.7 Information from third parties
We may receive account profile information from identity providers (for example Google) when you choose social login, and payment confirmation metadata from Dodo Payments.
1.8 AI prompts sent from the website
If you use website AI chat features, we may send your message, selected settings (model, system prompt, language, response length), and resume text you have stored to OpenRouter (and underlying model hosts) to generate a reply. That route does not permanently store the chat transcript by itself; other product chats are stored when synced from the desktop app.
2. How do we process your information?
We process personal information to:
- Create and manage your account and authenticate you
- Provide the desktop overlay, website dashboard, AI responses, transcription, analytics, and sync across devices
- Enforce plan limits, apply purchased packs, and prevent fraud or abuse
- Process purchases and refunds in line with our Refund Policy
- Communicate with you about the Service, security, and support
- Improve reliability, safety, and product quality (including debugging and aggregated metrics)
- Comply with law and enforce our Terms
3. Legal bases (EU / UK GDPR and similar regimes)
Where data-protection laws require a “legal basis” (including GDPR / UK GDPR), we typically rely on:
| Basis | Examples |
|---|---|
| Contract | Creating your account; delivering AI features you request; applying packs you buy |
| Legitimate interests | Security, fraud prevention, service improvement, essential product operation — balanced against your rights |
| Consent | Non-essential cookies/marketing where required; optional processing you clearly opt into (you may withdraw consent) |
| Legal obligation | Tax, accounting, responding to lawful requests |
For the United States, we process personal information as needed to provide the Services, for security and fraud prevention, and as otherwise disclosed in this Policy, consistent with applicable state privacy laws (including CCPA/CPRA where they apply).
For Canada, we process personal information with consent (express or implied as permitted) and/or as needed to provide the Services, consistent with PIPEDA and, where applicable, provincial laws such as Quebec’s Law 25.
For Australia, we handle personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs), including for providing the Services, security, and with consent where required (for example for certain disclosures or marketing).
For India, we process personal data in accordance with applicable Indian law (including the Digital Personal Data Protection Act, 2023, as it applies).
For Brazil (LGPD) and other Latin American regimes, we rely on comparable bases (performance of contract, legitimate interest, consent, legal obligation) as applicable.
4. When and with whom do we share personal information?
We may share information with:
| Recipient | Purpose |
|---|---|
| Supabase | Authentication, database, realtime, and account-related storage |
| Cloudflare (including our Worker / proxy / CDN) | Secure API proxying, usage writes, downloads, and infrastructure |
| AI / model providers (via our proxy, e.g. OpenRouter and underlying model hosts) | Generate AI responses from prompts, context, and images you submit |
| Speech-to-text providers (e.g. AssemblyAI, when STT is used in the desktop app) | Transcribe audio you choose to capture |
| Dodo Payments | Process payments and payment-related webhooks |
| OAuth sign-in (and Google Fonts CDN requests when fonts are loaded from Google) | |
| Service providers | Hosting, email, analytics (if enabled with consent), or support tools under appropriate agreements |
| Authorities | When required by law or to protect rights, safety, and security |
| Business transfers | In connection with a merger, acquisition, or sale of assets, subject to appropriate protections |
We do not sell your personal information and we do not “share” it for cross-context behavioural advertising as those terms are used under California law, except as disclosed if we later enable such advertising (we will update this Policy first).
We do not grant pack entitlements from the public website or desktop client using payment secrets; pack grants are applied by our trusted server (Cloudflare Worker) after verified payment events.
5. Cookies and similar technologies
We use first-party cookies and similar technologies on asmuthai.com as follows.
Essential (always on)
These are required for the Site to work securely:
| Name / pattern | Purpose | Duration (typical) |
|---|---|---|
sb-*-auth-token (and chunked variants) | Supabase Auth session so you stay signed in | Session / provider default |
asmuth_oauth_next | Temporary post-login redirect path after Google OAuth | About 10 minutes |
asmuth_oauth_port | Temporary desktop-app OAuth callback port | About 10 minutes |
asmuth_cookie_consent | Stores your cookie preference choice (also mirrored in local storage) | About 1 year |
Optional (off until you allow)
| Category | Purpose | Current status |
|---|---|---|
| Analytics | Understand how the Site is used | Not loaded today — reserved so we can add tools only after consent |
| Marketing | Advertising or remarketing | Not loaded today — reserved so we can add tools only after consent |
Your choices
On first visit we show a cookie banner with Accept all, Reject non-essential, and Customize, each available with equal effort on the first screen.
- Accept all — allows essential cookies plus optional analytics and marketing categories (when we enable those tools).
- Reject non-essential — keeps only essential cookies. You can continue to use the full Site and Services; optional analytics and marketing cookies stay off.
- Customize — choose analytics and/or marketing individually, then save. Saving preferences also unlocks normal use of the Site.
You can reopen preferences anytime via Cookie settings in the footer or on legal pages, or go to /privacy#cookies. Withdrawal of optional-cookie consent is as easy as granting it.
We do not require you to accept optional cookies to browse or use Asmuth, and we do not use scroll-lock or blur walls that force “Accept all.”
You can also control cookies through your browser settings. Disabling essential cookies may break sign-in.
6. Artificial intelligence features
Asmuth provides AI-assisted features (interview help, mock interviews, screen analysis, scoring, and related tools).
- Prompts, transcripts, chat history, screenshots, and related context you submit may be sent to AI subprocessors to generate outputs.
- AI outputs can be incorrect or incomplete. Do not rely on them as sole professional, legal, or career advice.
- We design the product so API keys for upstream AI providers are not embedded in the public desktop frontend; requests are proxied through our infrastructure.
- You should not submit other people’s personal data into prompts or recordings unless you have a lawful basis and any required notices/consents.
7. Social logins
If you sign in with Google (or another provider), we receive basic profile information allowed by that provider and your settings (typically name, email, and avatar). Your use of the provider is also governed by that provider’s policies. Asmuth currently supports Google sign-in only on the website.
8. How long do we keep information?
We keep personal information as long as needed to provide the Services, maintain accounts, resolve disputes, enforce agreements, and meet legal / accounting requirements.
- Account and usage data: generally for the life of the account, plus a reasonable period after deletion for backups and legal retention
- Purchase / refund records: as required for tax and payment compliance in relevant countries
- Support correspondence: as needed to resolve your request and for legitimate business records
- Cookie consent choice: until it expires or you clear cookies / change preferences
When we no longer need personal information, we delete or anonymize it where reasonably possible.
9. How do we keep information safe?
We use organizational and technical measures appropriate to our size and risk profile (for example access controls, encrypted transport (HTTPS), server-side secrets for payment and API keys, and least-privilege design for usage writes).
No method of transmission or storage is 100% secure. We cannot guarantee absolute security against unauthorized access. If a breach that must be notified occurs under applicable law, we will notify you and/or regulators as required.
10. Minors
The Services are intended for users who are at least 18 years old, or the age of majority in your jurisdiction if higher. We do not knowingly collect personal information from children. If you believe we have collected such information, contact [email protected] and we will take appropriate steps to delete it.
11. Regional privacy rights
11.1 Rights that may apply to you (summary)
Depending on where you live, you may have some or all of the following rights:
- Access / know what personal information we process
- Correct / rectify inaccurate information
- Delete / erase information (subject to legal retention)
- Portability of data you provided, in a usable format
- Restrict or object to certain processing (including profiling for marketing)
- Withdraw consent where processing is based on consent (including cookie preferences)
- Appeal a refusal (where required, e.g. some US state laws)
- Lodge a complaint with a supervisory authority
How to exercise rights: email [email protected] or use in-product account deletion where available. We may need to verify your identity. We will respond within the time required by applicable law (for example, typically within one month under GDPR, subject to extensions).
11.2 United States (including California)
If you are a California resident, you may have rights under the CCPA/CPRA to know, delete, correct, and opt out of sale/sharing of personal information, and to non-discrimination for exercising rights. We do not sell personal information as currently operated. To exercise rights, email [email protected]. Other US state privacy laws (for example Virginia, Colorado, Connecticut) may provide similar rights.
11.3 Canada (PIPEDA and provincial laws)
Canadian users may request access to and correction of personal information, and may withdraw consent (subject to legal or contractual restrictions and reasonable notice). Quebec residents may have additional rights under Law 25 (including transparency and, where applicable, rights related to automated decision-making). Contact [email protected]. You may also contact the Office of the Privacy Commissioner of Canada or your provincial commissioner.
11.4 European Union, EEA, and United Kingdom (GDPR / UK GDPR)
If you are in the EU/EEA/UK, Manish Kumar is the controller of your personal data for the Services (unless a specific feature names another controller).
You may lodge a complaint with your local data protection authority (for example your EU member-state DPA or the UK ICO). You also have the rights listed above, including objection to processing based on legitimate interests and to direct marketing.
International transfers: Your data may be transferred outside the EU/UK (including to India and countries where our providers operate). Where required, we use appropriate safeguards such as Standard Contractual Clauses (SCCs) / UK equivalent addenda, provider certifications, or other lawful transfer mechanisms.
11.5 Australia (Privacy Act / APPs)
If you are in Australia, we handle personal information in line with the Privacy Act 1988 (Cth) and the Australian Privacy Principles. You may request access to and correction of your personal information, and you may complain to us and, if unresolved, to the Office of the Australian Information Commissioner (OAIC). Contact [email protected]. Cross-border disclosure of personal information may occur as described in International processing below; we take steps consistent with APP 8 where it applies.
11.6 Brazil and other Latin America (including LGPD)
If Brazilian LGPD applies, you may have rights to confirmation of processing, access, correction, anonymization/blocking/deletion of unnecessary data, portability, information about sharing, revocation of consent, and complaint to the ANPD. Similar rights may exist under other Latin American privacy laws (for example Argentina, Chile, Colombia, Mexico) — contact [email protected] and we will honour applicable local rights.
11.7 India
Under applicable Indian law, you may have rights to access, correction, and erasure of personal data, and to grievance redressal. Contact [email protected] as our primary contact for such requests.
11.8 Other regions
If you live elsewhere (for example Singapore, Middle East, or Africa), we will honour privacy rights available under the laws that apply to you when you contact us.
12. Do-not-track and global privacy controls
Some browsers offer “Do Not Track” or Global Privacy Control (GPC) signals. Where required by law (for example certain US states), we will treat qualifying opt-out signals as a request to opt out of sale/sharing. Otherwise, there is no uniform DNT standard; you can still control cookies and exercise deletion/access rights as described above.
13. International processing
Our infrastructure and subprocessors may process data in India and/or other countries (for example where Supabase, Cloudflare, AI, STT, or payment providers operate, which may include the United States, EU, and other regions). Cross-border transfers are necessary to provide the product to users in North America, Europe, Australia, and elsewhere. We take steps consistent with applicable law (contractual clauses, vendor due diligence, and security measures).
14. Updates to this Privacy Policy
We may update this Privacy Policy from time to time. We will change the “Last updated” date above. Where required by law, we will provide additional notice or seek consent. Continued use of the Services after an update constitutes acceptance of the revised Policy where permitted by law. Material cookie-category changes may prompt you to choose again via our consent banner (versioned consent).
15. Contact us
For privacy questions or data requests:
- Email:
[email protected] - Legal entity: Manish Kumar, trading as Asmuth
- Establishment / primary operations: Delhi, India
If we appoint an EU/UK representative or Data Protection Officer in the future, we will publish those details here.
16. Review, update, or delete your data
You can review much of your profile and usage in the website dashboard and desktop app. To request a full export or deletion beyond in-product tools, contact [email protected].
This document is a product-aligned draft for Asmuth’s launch markets (North America, Europe, Australia, plus India establishment and Latin America coverage) and is not a substitute for advice from a qualified lawyer. Have it reviewed before public launch for GDPR/UK GDPR, US state privacy (including CCPA/CPRA), PIPEDA/Law 25, the Australian Privacy Act / APPs, LGPD, Indian DPDP, and consumer rules in your launch markets.