← Home

Privacy Notice

Last updated: May 28, 2026 · Effective immediately

Antarjyoti Neurosciences ("we", "us") respects your privacy. This Privacy Notice explains what personal data we collect when you use GLISSA (the "Service"), why we collect it, how we use and share it, how we protect it, and the choices and rights you have. This Notice is written to satisfy the EU/UK General Data Protection Regulation (GDPR/UK GDPR), the California Consumer Privacy Act as amended by the CPRA (CCPA/CPRA), the Digital Personal Data Protection Act, 2023 of India read with the Digital Personal Data Protection Rules, 2025 (notified November 2025; phased enforcement) ("DPDP"), Brazil's LGPD, Canada's PIPEDA, Australia's Privacy Act, and other applicable privacy laws.

1. Controller / Data Fiduciary. Antarjyoti Neurosciences is the data controller (GDPR) / data fiduciary (DPDP) / business (CCPA) for personal data processed in connection with the Service. Contact our privacy team at legal@antarjyotineurosciences.com.

2. Data we collect.

  • Account — email address, hashed password, and (if you sign in with Google) the OAuth identifier and basic profile info you authorize Google to share.
  • Profile & preferences — onboarding answers, chosen protocols, default sound bed, carrier frequency, headphone preference, subscription status.
  • Sleep-session usage — for each session: protocol, sound bed, duration, completion status, and your self-reported mood (if you provide it). We do not record audio from your microphone and we do not capture biometrics.
  • Technical — device type, operating-system version, app version, language, time zone, coarse IP-derived region, crash reports, and basic event telemetry needed to operate and improve the Service.
  • Support — messages, attachments, and metadata when you contact us.
  • Payment data — we do not store full card numbers, UPI handles, or banking credentials. Subscriptions are processed by Google Play Billing (Android) and Apple In-App Purchases (iOS) under their own privacy notices; we receive only a transaction reference and subscription status.

We do not request or collect any data from your phone beyond your email address and the in-app information you choose to provide. We do not access your contacts, photos, calendar, microphone, camera, location (beyond coarse IP region for currency detection), health data, or any other on-device data.

3. Why we use your data and the legal basis.

  • Provide, personalize, and operate the Service — contract performance (GDPR Art. 6(1)(b)); necessary for the specified purpose (DPDP).
  • Authenticate accounts, prevent fraud and abuse, enforce our Terms — legitimate interests (GDPR Art. 6(1)(f)); legal obligation where applicable.
  • Customer support — contract / legitimate interests.
  • Improve protocols, fix bugs, measure feature performance — legitimate interests.
  • Process payments and prevent payment fraud — contract / legitimate interests / legal obligation (tax, anti-money-laundering).
  • Send service announcements and (only with your consent where required) optional product updates — consent.
  • Comply with legal obligations and respond to lawful requests — legal obligation.

4. Sharing — sub-processors. We share personal data only with the following categories of recipients, each under contractual confidentiality and data-processing terms:

  • Supabase (managed database, authentication, file storage) — hosting our backend.
  • Cloudflare — content delivery, DDoS protection, and edge compute.
  • Google LLC (Google Play Billing) — processes subscription purchases on Android; independent controller for payment data.
  • Apple Inc. (App Store / In-App Purchases) — processes subscription purchases on iOS; independent controller for payment data.
  • Google LLC — Google Sign-In (only if you choose this method).
  • Email delivery — transactional email provider for password resets and receipts.
  • Professional advisers (legal, accounting, audit) — under confidentiality.
  • Authorities — when required by valid legal process or to protect rights, safety, or property.
  • Successor entities — in a merger, acquisition, financing, or sale of all or part of our business, subject to equivalent protections.

We do not sell or "share" personal data for cross-context behavioural advertising as defined by the CCPA/CPRA. We do not use your data to train any third-party AI model.

5. International data transfers. Personal data may be processed in countries other than yours, including India, the United States, and the European Economic Area. Where data is transferred from the EEA/UK/Switzerland, we rely on adequacy decisions where available or on Standard Contractual Clauses (and, for UK, the UK International Data Transfer Addendum). Where data is transferred outside India, we comply with the DPDP Act, 2023.

6. Retention & deletion. We follow the DPDP principle of storage limitation. Account, profile, and session data are retained while your account is active. If you request deletion (in-app via Settings → Delete account, or via the public Account Deletion page — no sign-in required), we delete your account record, profile, preferences, sleep-session history, and customer record within 7 days (and in any case within 30 days), and purge the data from rolling encrypted backups within 30 days. After an account is inactive for 24 consecutive months, we will notify you and then delete or irreversibly anonymise the data. Payment and tax records are retained as required by tax and accounting law (typically 7–8 years). Pseudonymised abuse / fraud / security logs are retained for up to 24 months. Crash logs and basic telemetry are retained for up to 90 days. Aggregated, de-identified analytics may be retained indefinitely.

7. Security & breach notification. We use industry-standard technical and organizational measures, including TLS 1.2+ in transit, encryption at rest, hashed passwords (Argon2/bcrypt-class), least-privilege access, server-side row-level security, audit logging, vulnerability scanning, and a documented incident-response plan. No system is perfectly secure. We will notify the appropriate supervisory authority and affected users of a qualifying personal-data breach without undue delay and within the timeframes required by law — within 72 hours under GDPR/UK GDPR, as required by the Data Protection Board of India under the DPDP Act, 2023 and the DPDP Rules, 2025 (including notification to each affected Data Principal), within the timelines set by CERT-In Directions (April 2022) for cyber-incident reporting in India, and as required under CCPA/CPRA, LGPD, and other applicable laws.

8. Your rights. Depending on your jurisdiction you may have the right to:

  • Access the personal data we hold about you and request a copy in a portable format.
  • Correct inaccurate or incomplete data.
  • Delete your data ("right to be forgotten" / "right to erasure") — also available in-app via Settings → Delete account, and via our public Account Deletion page without signing in.
  • Withdraw consent at any time, as easily as it was given, without affecting the lawfulness of processing before withdrawal — email legal@antarjyotineurosciences.com or use the unsubscribe link in any optional email. Withdrawing consent for essential processing may prevent us from continuing to provide the Service.
  • Restrict or object to processing.
  • Port your data to another service.
  • Opt out of "sales" or "sharing" of personal information (CCPA/CPRA) — we do not engage in either.
  • Nominate a person to exercise your rights in case of death or incapacity (DPDP).
  • Lodge a complaint with your local data-protection authority — in the EU, your national DPA; in the UK, the ICO; in India, the Data Protection Board; in California, the California Privacy Protection Agency.

To exercise any right, email legal@antarjyotineurosciences.com. We will verify your identity and respond within the period required by law (typically 30 days under GDPR; 45 days under CCPA, extendable once).

9. Children & minors. GLISSA is intended for users aged 18+. It is not directed to children under 13 (or the higher age of digital consent in your jurisdiction — e.g. 16 in many EU member states, 13 in the US under COPPA). We do not knowingly collect personal data from children. Under the DPDP Act, 2023 and the DPDP Rules, 2025, "child" means an individual under 18; before processing the personal data of any user who self-identifies as a child or whose data we have reason to believe relates to a child, we will obtain verifiable parental consent through the means prescribed by the Rules, will not undertake tracking, behavioural monitoring, or targeted advertising directed at children, and will not process their data in a way likely to cause any detrimental effect on their well-being. If you believe a child has provided us data, contact legal@antarjyotineurosciences.com and we will delete it. Parents/guardians may use the public Account Deletion page without signing in.

10. Cookies & similar technologies. We use only strictly-necessary cookies and similar technologies to keep you signed in, remember your preferences, prevent fraud, and operate the Service. We do not use advertising, cross-site tracking, or third-party analytics that profile individual users. Because we use only strictly-necessary cookies, we do not display a consent banner where one is not legally required.

11. Automated decision-making. We do not engage in automated decision-making, including profiling, that produces legal or similarly significant effects on you.

12. California disclosures (CCPA/CPRA). In the past 12 months, we have collected the categories of personal information listed in Section 2 for the business purposes in Section 3, and disclosed those categories to the service providers listed in Section 4. We have not sold or shared personal information for cross-context behavioural advertising and have not knowingly collected the personal information of consumers under 16.

12A. Google Play Data Safety alignment. The disclosures in this Notice are designed to match the declarations made in our Google Play Data Safety form and the equivalent Apple App Store App Privacy labels. In summary: we collect Personal info (email), App activity (in-app sleep-session events), and limited Device or other IDs needed to operate the Service; all data is encrypted in transit; account deletion is available both in-app (Settings → Delete account) and via a public web form at /account-deletion that does not require sign-in; we do not sell or share personal data with third parties for advertising; and we do not collect health, location (beyond coarse IP region for currency), contacts, photos, calendar, microphone, or any other on-device data. If you ever notice a discrepancy between this Notice, our store-listing labels, and the App's actual behavior, please tell us at legal@antarjyotineurosciences.com — we will investigate and correct promptly.

12B. Consent & consent withdrawal (DPDP / GDPR). Where we rely on your consent, we ask for it through a clear, plain-language notice (in English; itemised in this Notice and at point of collection). You may withdraw consent at any time, as easily as you gave it: (i) in-app from Settings, (ii) by emailing legal@antarjyotineurosciences.com, (iii) by using the unsubscribe link in any optional email, or (iv) by deleting your account via the public Account Deletion page. Withdrawal stops further processing for the relevant purpose but does not affect the lawfulness of processing carried out before withdrawal. Under the DPDP Act, 2023, you may also nominate another individual to exercise your rights in case of death or incapacity by writing to legal@antarjyotineurosciences.com.

13. Grievance Officer & DPO contacts.

14. Changes. We may update this Notice. Material changes will be highlighted in-app or notified by email and will take effect no sooner than 14 days after notice. The "Last updated" date at the top shows when this Notice was last revised.

Antarjyoti Neurosciences

GLISSA is a wellness aid, not a medical device, and does not diagnose or treat any condition. Please read our Safety & Medical Disclaimer before your first session.

Subscriptions are handled through Google Play Billing on Android and Apple In-App Purchases on iOS.