How we handle data.
With nothing left unsaid.
This is not a standard legal boilerplate. Every section below is written in plain language, with technical precision, because we believe you deserve to understand exactly what happens with your data — not just trust that someone is handling it responsibly.
The short version.
App data (Sattva, KAI) lives on your device. We cannot see it, access it, or recover it.
This website only collects what you submit through the contact form. Nothing else.
No tracking cookies. One functional session cookie (security only). No consent banner needed.
AI features are bring-your-own-key, no Muladhara server in between. Sattva uses anonymised IDs; KAI never sends your business name or records.
Backups are encrypted by a key or passphrase only you hold. Without it, no one can open them — including us.
WhatsApp integration opens the WhatsApp app on your device. No data passes through Muladhara.
1. Who we are
The company behind this policy
"Muladhara Holistic Technology" is the operating brand of Muladhara Yoga Wellness OPC Private Limited, a software development company founded by Natural Yogi Noble Srinivasan. We build offline-first applications (Sattva, KAI) and enterprise software solutions.
Our business model is built on delivering complete ownership to our clients — not on managing their data, advertising to them, or monetising their usage patterns. Understanding this model is the foundation for understanding this privacy policy.
2. The architecture that protects you
Why most of this policy is straightforward
Sattva and KAI are offline-first applications. All operational data — client records, bookings, financial transactions, session notes — is stored exclusively on the user's device using the browser's local IndexedDB. No operational data is transmitted to Muladhara's servers.
This is not a privacy setting or a policy choice. It is the architectural reality of how the applications are built. There is no API call that carries your client data to our systems. There is no background sync. There is no server-side copy of your practice records.
The practical consequence: most privacy regulations require organisations to detail how they handle personal data. For Muladhara's apps, the answer for operational data is straightforward — we do not handle it, because it never reaches us.
3. What this website collects
Contact form submissions only
When you submit the contact form at /connect, we collect: your name or organisation name, email address, phone number (optional), proposal type, and project description. We also log the IP address of the submission for security purposes.
This information is used solely to evaluate your project proposal and to respond to your inquiry. It is stored in a secured database on our server. It is not shared with third parties. It is not used for marketing or advertising.
If you subscribe to updates via the newsletter form (in the footer, or on a "coming soon" page), we collect your email address, the page you subscribed from, and your IP address, stored in the same secured database. This is used only to send you updates about our products when there is something worth telling you — we do not sell, rent, or share this list, and every email includes a way to unsubscribe.
Nothing else is collected on this website. We do not run analytics. We do not use tracking pixels. We do not load third-party advertising scripts. What you see on this page is what runs on this page.
4. Cookies — the full picture
One cookie. One purpose. No consent required.
This website sets exactly one cookie: a session security token used to prevent CSRF (Cross-Site Request Forgery) attacks. This cookie:
- Contains no personal data
- Does not track your behaviour
- Does not identify you across sessions or devices
- Expires when you close your browser
- Is set as HttpOnly and Secure — inaccessible to scripts
Under GDPR Article 6(1)(f) and equivalent regulations, cookies that are strictly necessary for the technical operation of a service (security functions) are exempt from consent requirements. We do not show a cookie consent banner because this cookie does not require consent. If we ever add analytics or any non-essential cookie, we will update this policy and implement a consent mechanism.
5. Encryption and key management
Mathematical protection, not contractual
In Sattva, a random Device Encryption Key is generated on your device at install and used to encrypt your data and backups with AES-256-GCM. This key never leaves your device and is never transmitted to Muladhara. An optional PIN can be set as an additional app-lock gate — with biometric unlock and progressive lockout on repeated wrong attempts — but the PIN itself is not the encryption key.
In KAI, you choose a passphrase at the moment you export a backup. That passphrase is run through PBKDF2-SHA256 (100,000 iterations) on your device to derive the encryption key, which encrypts the export with AES-256-CBC. Neither the passphrase nor the derived key is transmitted to Muladhara — each backup file is only as recoverable as the passphrase you chose to protect it.
The consequence, for both apps: Muladhara cannot decrypt your data or backup files. This is not a promise — it is a mathematical fact. Without the correct device key or passphrase, the encrypted file is computationally indistinguishable from random data. No password reset, no master key, no court order changes this.
If you lose your device without a backup, or forget a KAI backup passphrase, that data cannot be recovered — by you or by us. We consider this a feature, not a limitation. It is the proof of genuine encryption.
6. AI features and data privacy
Bring your own key — no AI provider ever sees who the data belongs to
Neither app runs its own AI service. Every AI feature in Sattva and KAI calls out directly from your device to an AI provider you configure with your own API key — there is no Muladhara-operated server or proxy in between, and no metered or Muladhara-funded AI usage of any kind.
In Sattva, AI features operate on pseudonymised data. When you use an AI feature, the content is tagged to a randomly generated anonymous session identifier — not to your client's name, account, or any identifiable credential. The mapping between the anonymous ID and the real person exists only on your device, so the AI provider receives content and an ID, never an identity.
In KAI, the chat assistant sends only your typed question to the AI provider — never your underlying invoices, expenses, or ledger records; any lookup or action it performs runs locally on your device and is not sent back to the AI. The AI Financial Analysis feature sends aggregated numbers and your business type only, never your business name or other identifying details.
AI providers are configured by you. Muladhara does not know which AI provider you use, does not store your API keys, and is not present in your AI transaction chain.
You are responsible for the terms of service of the AI provider you configure. We recommend reviewing your chosen provider's data retention and training policies before using AI features for sensitive content.
7. WhatsApp integration
A deep link. Nothing more.
Sattva's WhatsApp feature constructs a wa.me/ deep link that opens WhatsApp on your device with a pre-filled message. When you tap the WhatsApp button, your device's WhatsApp application opens. You review the message and choose to send it.
Muladhara does not use the WhatsApp Business API. No credentials are stored. No data passes through our servers. No connection is made to your WhatsApp account. This is technically equivalent to manually opening WhatsApp and typing a message — with the convenience of pre-filled text.
8. The enterprise server model
Built by us. Owned by you. No data held by us.
When Muladhara builds an online SaaS product for an enterprise client, we design, build, and configure the server infrastructure — then deliver it completely to the client. After handover, the enterprise hosts the platform on their own infrastructure, under their own domain.
Muladhara holds no access credentials, no administrative backdoors, and no copies of data from delivered enterprise systems. The enterprise's users' data is the enterprise's responsibility — within the security architecture we designed and documented for them.
9. Compliance alignment
Where we stand relative to major privacy regulations
Sattva's offline-first, device-local, encrypted architecture reflects HIPAA's core technical safeguards. AI features use pseudonymisation. Muladhara does not process PHI on our servers. Enterprise healthcare clients requiring a Business Associate Agreement should contact us — the scope is narrow given our architecture.
No tracking cookies requiring consent. Data minimisation practiced — we collect only what is submitted. Users have the right to access, correct, or delete submitted contact data. Privacy by design is the architecture, not an add-on. For EU enterprise clients with specific GDPR obligations, Data Processing Agreements are available on request.
Contact form submissions are collected with awareness at point of submission. Personal data in Sattva and KAI apps never reaches Muladhara's systems. Data is processed only for the stated purpose. Users can request deletion of contact form data at any time.
KAI generates financial reports in MCA-compatible formats. This is format compatibility, not a compliance certification requiring ongoing oversight.
10. Data retention
How long we keep what little we hold
Contact form submissions are retained in our database for as long as necessary to evaluate the proposal and maintain business records — typically up to 3 years.
App data is stored on your device indefinitely until you delete it or uninstall the application. Muladhara holds no copies of app data. There is nothing on our side to delete.
11. Your rights
What you can ask us to do
For data submitted through this website (contact forms), you have the right to:
- Request access — what we hold about you
- Request correction — if any data is inaccurate
- Request deletion — we will remove your submission from our records
- Request data portability — receive your submitted data in a standard format
To exercise these rights, email contact@muladharaholistictechnology.com. We respond within 30 days.
For app data: since it lives on your device, you exercise all rights directly — delete records in the app, export your data using the backup function, or uninstall the application. Muladhara has no copy to provide or delete.
12. Third-party services
What external services this website and apps use
13. Changes to this policy
How and when this document may change
We may update this policy when our practices change or when regulations require it. The date at the top of this page shows when it was last updated. Substantive changes will be noted on this page.
Our architecture is unlikely to change in ways that increase data collection — our model is built on giving clients ownership and independence, not on accumulating data about them. Any change that affects data collection will be communicated clearly.
Questions about this policy?
Email contact@muladharaholistictechnology.com. We answer privacy questions personally, not through a ticket system.