Skip to main content

Legal

Privacy Policy

Effective from 28 April 2026 · Last updated 13 July 2026

GST Reco is operated by Manual2AI Technologies Private Limited (“we”, “us”, “the operator”). This policy describes what data we collect when you use gstreco.m2ai.ai and the GST Reco Tally agent, why we collect it, who we share it with, and the choices you have. It explains our current privacy practices and how we address applicable obligations, including under the Digital Personal Data Protection Act, 2023 (DPDP Act).

Jump to a section
  1. 1. The data we collect
  2. 2. Why we collect it
  3. 3. How long we keep it
  4. 4. Who we share it with
  5. 5. How we keep it safe
  6. 6. Your rights
  7. 7. Cookies and local storage
  8. 8. Children
  9. 9. Policy changes
  10. 10. Contact us

1. The data we collect

Account data — when you sign up, we store your full name, work email, and the firm or company name you enter. Supabase Auth handles your authentication credentials; GST Reco does not store your plain-text password. Optionally, you provide a GSTIN at signup; if you do, we trim it, convert it to uppercase, validate it, and store the normalized value.

Books data from TallyPrime— the agent you install on your Windows machine reads vouchers (purchase invoices, sales invoices, debit/credit notes), masters (vendor list, customer list, ledger details), and metadata (Tally company name, which user is logged in) and pushes them to our server. The data leaves your machine over TLS, signed with an HMAC-SHA256 key that lives in your machine's encrypted secret store; the network path is HTTPS only.

Portal data from the GST Network (GSTN) — when you authorise the GST portal connection, we fetch GSTR-2B, GSTR-2A, GSTR-1, and GSTR-3B for the GSTINs and periods you select. The fetch goes through a licensed GST Suvidha Provider (GSP) under our subscription; we never see or store your GSTN portal password. The portal-issued session token is encrypted at rest with AES-256-GCM, bound to your tenant, and rotated every six hours.

Reconciliation outputs — match results, workbook finalization records, claim-history records created by an explicit filing-workbook finalization, and vendor follow-up notifications. These are derived from your books + portal data and stored against your tenant.

Operational telemetry — server access logs (IP address, request path, response code, user-agent), application error logs, and feature usage counters. Used for debugging and capacity planning. Retained for 90 days.

2. Why we collect each category

  • Account data — to authenticate you, scope your access to your own tenant, and contact you about your subscription or service issues.
  • Books + portal data — to run the reconciliation engine and produce the filing workbook. This is the core service.
  • Reconciliation outputs — to give you the workpapers you came to GST Reco for, and to power vendor follow-up.
  • Operational telemetry — to keep the service up and to fix bugs.

We do not use your books or portal data for advertising or market research, and we do not use it to train our own or third-party models. When an authorised user explicitly invokes an AI-assisted review, we send only the data needed for that review to Google Gemini to generate the requested response.

3. How long we keep it

  • Books + portal data — retained for the duration of your subscription plus 90 days, so a tenant that comes off-trial can resume without re-syncing. After 90 days post-cancellation, the data is hard-deleted.
  • Account data — until you delete your account or 24 months after last login, whichever is sooner.
  • Operational telemetry — 90 days, rotated.
  • Backups — encrypted Supabase point-in-time backups for 7 days, then aged out.

4. Who we share it with

We share data only with sub-processors required to run the service. Today these are:

  • Supabase — authentication, Postgres database, and object storage used to operate the service.
  • Vercel — application hosting and server-side request execution.
  • Sandbox.co.in (India), via Quicko Infosoft — licensed GSP for portal access. Your GSTN session token passes through their gateway; we have a data processing agreement with them.
  • Resend — transactional email delivery for account verification, password reset, vendor follow-up, and other messages you or an authorised operator initiate.
  • Cloudflare Turnstile — abuse prevention during account signup. Cloudflare receives the challenge response and related network information needed to verify it.
  • Google Gemini — used only when an authorised user explicitly invokes an AI-assisted review. We send the limited invoice, reconciliation, or evidence fields needed to generate that review.

We never sell your data. We never share it with advertisers, data brokers, or unrelated third parties.

5. How we keep it safe

  • TLS 1.2+ on every connection. HSTS is enforced.
  • HMAC-SHA256 request signing on the agent → server boundary.
  • AES-256-GCM encryption at rest for the agent's pairing secret and the GSP session token. Key derivation via HKDF-SHA256.
  • Postgres Row-Level Security and tenant-scoped application checks protect multi-tenant data.
  • Service-role keys live only on our server; the browser client uses a session-scoped JWT. Privileged server and operator access is restricted to approved workflows and logged.
  • Code review on every change; SECURITY DEFINER policy functions tested via JWT claim impersonation before apply.

6. Your rights under DPDP Act 2023

You can ask us to:

  • Access the personal data we hold about you.
  • Correct data that is wrong or out of date.
  • Erase your data and close your account.
  • Port your data — we will export your books, reconciliation runs, and workbook history in JSON or .xlsx.
  • Withdraw consent for any processing that is based on consent (e.g., marketing emails, optional telemetry).
  • Nominate a representative to exercise these rights on your behalf in case of incapacity or death.
  • Complain to the Data Protection Board of India if you believe we have violated DPDP.

Reach us at privacy@m2ai.ai. We respond within seven business days.

7. Cookies + local storage

We use first-party cookies for authentication (a Supabase session cookie) and local storage for theme preference. We do not use third-party analytics cookies. We do not use cross-site tracking.

8. Children

GST Reco is a B2B service for registered Indian businesses and their tax advisers. It is not directed at children, and we do not knowingly collect personal data of users under 18.

9. Changes to this policy

When we change this policy materially we will notify you by email at least 14 days before the change takes effect. Minor clarifications are updated in place; the “last updated” date at the top reflects the most recent edit.

10. Contact us

Manual2AI Technologies Private Limited
Privacy queries: privacy@m2ai.ai
General support: support@m2ai.ai