Privacy
Last updated 18 August 2026
What we collect, why we collect it, how long we keep it, who else sees it, and how to make us delete it. Notice version 2026-08-18.2.
Not yet reviewed by a lawyer
This document describes how UPSCALR actually works today, written by the team that built it. It has not been reviewed by qualified counsel and should not be relied on as a finished legal instrument until it has been.Who we are
UPSCALR is operated by Deepsoch AI Private Limited, India. For the purposes of India's Digital Personal Data Protection Act, 2023 we are the Data Fiduciary for the information described here, and you are the Data Principal.
Our Grievance Officer is Data Protection Officer, reachable at privacy@deepsoch.ai. We answer within 30 days. If we do not resolve your complaint, you may raise it with the Data Protection Board of India.
What we collect and why
Everything below is the complete list. Each entry says what it is, why we have it, on what legal basis, how long it stays, and who else sees it. You can see the same list, with your own figures against it, in your privacy centre.
Account identity
- Email address
- Display name and chosen username
- Profile photo, if uploaded
- Country and time zone, if set
- Password — stored only as a salted hash, never recoverable
- Linked Google account id, if you sign in with Google
Why: Identifying your account, signing you in, and contacting you about it.
Legal basis: To provide the service you asked for
How long: Until you delete the account.
Shared with: Google (Sign-In, reCAPTCHA), Our email delivery provider
Uploaded and generated images
- The original image you upload
- The upscaled result and any format conversions of it
- Thumbnails generated for your history list
- The original filename, and the size and dimensions of both
- Which account produced each image, so an operator can attribute it when investigating a report or abuse
Why: Producing the upscale you asked for, letting you download it again from your history, investigating problems you report, and checking the service is not used for illegal or abusive content. Operator access to images is recorded in an audit log.
Legal basis: To provide the service you asked for
How long: Signed-in results follow your retention setting (default: kept until you delete them). Anonymous free results are swept automatically within the free-tier retention window.
Shared with: Our upscaling engine provider
Processing history
- When each upscale ran, at what size and output format
- Whether it succeeded, and the error if it did not
- Credits reserved and charged
- Daily rollups of images processed and credits used
Why: Showing your history and usage, billing correctly, and diagnosing failures you report.
Legal basis: To provide the service you asked for
How long: Until you delete the job or your account.
Shared with: Nobody outside UPSCALR.
Billing and payment records
- Invoices, amounts, currency and status
- The payment gateway's transaction identifier
- Your plan and its history
- Every credit movement on your balance
- The raw callback the payment provider sends us, which can include the name, email or phone you gave them at checkout
Why: Taking payment, issuing invoices, resolving disputes and meeting tax and accounting obligations.
Legal basis: Required by law
How long: Retained after account deletion for the statutory accounting period. Card and bank details never reach us at all.
Shared with: Razorpay, Cashfree
Sign-in sessions and devices
- The IP address and browser user-agent of each sign-in
- When the session started and when it expires
- Whether two-factor is enabled
Why: Keeping you signed in, and letting you review and end sessions you do not recognise.
Legal basis: Security and abuse prevention
How long: Deleted when the session expires or you end it, and swept on expiry at most 30 days after sign-in.
Shared with: Nobody outside UPSCALR.
Anonymous free-tier metering
- A random device identifier held in a cookie
- A keyed one-way hash (HMAC) of your IP address — never the address itself
- How many free upscales that identity has used
Why: Metering the free tier so one visitor cannot consume all of it, and blocking abuse.
Legal basis: Security and abuse prevention
How long: Counters are deleted once their window has passed.
Shared with: Nobody outside UPSCALR.
API keys and request logs
- A SHA-256 digest of each API key — never the key
- Method, path, status and duration of each API call
- A hashed IP and the user-agent of the caller
- Your webhook URLs and the payloads delivered to them
Why: Authenticating API calls, enforcing rate limits, showing you your own usage, and debugging delivery failures.
Legal basis: To provide the service you asked for
How long: Request logs and webhook deliveries are pruned on the operator's retention schedule; keys until you revoke them.
Shared with: Nobody outside UPSCALR.
Consent and rights records
- Each consent you gave or withdrew, and which notice version it was against
- A hashed IP recorded alongside it as provenance
- Rights requests and grievances you raised, and how they were resolved
Why: Proving that processing was lawful, and demonstrating that your requests were answered.
Legal basis: Required by law
How long: Consent records are deleted with the account. Rights requests outlive it deliberately — completing an erasure must not destroy the evidence it was completed.
Shared with: Nobody outside UPSCALR.
Administrative audit trail
- Privileged actions taken on your account by an operator
- Who took them and when
Why: Accountability for privileged access, and answering 'who changed this'.
Legal basis: Security and abuse prevention
How long: Pruned on the operator's retention schedule.
Shared with: Nobody outside UPSCALR.
Your images are not training data
We do not use your uploads or your results to train or fine-tune models, and we do not sell them. The one exception is if you switch on “Use my images to improve the models” in your privacy centre — it is off unless you turn it on, we never assume it from silence or from continued use of the product, and switching it off stops any further use immediately.
Our operators can see uploaded and generated images in an internal console. They use it to investigate a problem you have reported, and to check that the service is not being used for illegal or abusive content. Every time an operator opens that view it is recorded in an audit log with their identity and the time, so access is accountable rather than merely promised.
Nobody outside that operator group sees your images, they are not shared or sold, and they are not used to train models unless you have separately turned that on.
What we deliberately do not keep
- Raw IP addresses for free-tier metering. Only a keyed one-way hash, salted with a secret only we hold. IPv6 is grouped to a /64 before hashing. The stored value cannot be turned back into an address.
- Your password. Only a salted hash. We cannot read it, and neither can anyone who obtains a copy of our database.
- Your API keys. Only a SHA-256 digest. The key is shown once at creation and never again.
- Card or bank details. These go straight to the payment provider and never reach our servers.
- Image metadata. Every result is decoded and re-encoded before storage, which strips the EXIF and GPS data a phone camera writes into the original.
Who else processes your data
These are our Data Processors. Each one receives only what is listed.
Our upscaling engine provider
Running the upscaling model. This is the core processing.
- The image being upscaled, fetched by the provider from a presigned URL valid for one hour
- The requested output multiplier
Their retention: The provider holds a temporary result which we copy and then stop referencing. Their own retention is governed by their terms, not ours.
Google (Sign-In, reCAPTCHA) (optional)
Optional social sign-in, and scoring signup attempts for automation.
- For sign-in: nothing from us — we receive your email, name and photo URL from them
- For reCAPTCHA: your IP and browser signals, collected by Google directly in your browser
Their retention: Governed by Google's own policies.
Razorpay (optional)
Taking payment.
- Your name and email, passed to prefill checkout
- Card and bank details, entered directly into their form — these never reach our servers
Their retention: Governed by Razorpay's terms and RBI record-keeping rules.
Cashfree (optional)
Taking payment, where enabled as the gateway.
- Your name and email, passed to prefill checkout
- Card and bank details, entered directly into their form
Their retention: Governed by Cashfree's terms and RBI record-keeping rules.
Our email delivery provider
Delivering verification, password reset, and notification email.
- Your email address
- The contents of the message being sent
Their retention: Governed by the provider; typically short-lived delivery logs.
Your rights
Under the Act you have the following rights, and all of them work:
- Access and a summary (s.11). Download everything we hold about you as one file, any time, from your privacy centre. No request, no waiting.
- Correction and erasure (s.12). Edit your details in Settings. Delete individual images, all your images, or your whole account from the privacy centre. Deletion removes the files from object storage as well as the database.
- Withdraw consent (s.6(6)). Every consent toggle switches off the same way it switched on — one click, no confirmation gauntlet, no penalty to your service.
- Grievance redressal (s.13). Raise a complaint from the privacy centre or by emailing privacy@deepsoch.ai. We answer within 30 days.
- Nomination (s.14). Name someone who may exercise these rights for you if you die or become unable to act. Set it in the privacy centre.
- Complain to the Board. If we do not resolve something, you may take it to the Data Protection Board of India.
What deletion actually does
Deleting your account removes your account row, every job and its history, your API keys and webhooks, your sessions, your consent records, and every stored file — originals, results, format conversions, thumbnails and your profile photo — from object storage as well as the database. It cannot be undone, and remaining credits are not refunded.
Two things deliberately survive, and we would rather say so:
- Invoices and payment records. Indian tax and accounting law requires us to keep these. They are detached from your account and kept as financial records.
- The record that you asked us to delete. Without it we cannot demonstrate that we honoured the request. It keeps the email address you contacted us from and nothing else.
The upscaling provider is never given your account identity — it receives a temporary link to one image and nothing that identifies you — so there is nothing there to delete by account.
Children
The Act treats anyone under 18 as a child and requires verifiable consent from a parent or guardian before their data may be processed. We are not set up to verify that, so UPSCALR is for adults only. We ask you to confirm you are 18 or over, and we do not knowingly process a child's personal data. If you believe we hold a child's data, email privacy@deepsoch.ai and we will delete it.
If something goes wrong
If personal data is exposed, the Act requires us to notify both the Data Protection Board of India and every affected person — there is no threshold below which a breach may go unreported. We keep an internal register of every incident from the moment it is suspected, not from the moment it is confirmed.
Cookies
We use cookies for signing in, for remembering your light or dark theme preference, and for metering anonymous free use. We do not use advertising or cross-site tracking cookies, and there is no analytics tracker on this site.
Changes
This notice is versioned. When we change it in a way that matters, the version changes, account holders are asked to read it again, and any consent given under the old version is marked as needing renewal. The current version is 2026-08-18.2.
Questions about this document? Email contact@deepsoch.ai.