Privacy Policy — Invincible You

Invincible You, a product/service operated by Vedanga Solutions Private Limited

1. Definitions

  • AI (Artificial Intelligence): Technology enabling systems to simulate human thinking, learning, analysis, and automated responses.
  • Authentication: Process of verifying a user’s identity before allowing access to platform services or accounts.
  • DRIFT Assessment: Behavioural and organizational assessment system evaluating leadership, personality patterns, workplace behaviour, and professional development.
  • LLM (Large Language Model): Advanced AI system capable of understanding and generating human language for coaching, conversations, and behavioural insights.
  • PostHog Analytics: Analytics platform used to monitor feature usage, user engagement, and application performance.
  • Profile Data: Personal information voluntarily provided by users, such as full name, phone number, and account-related details.
  • SGC: Small group coaching; minimum 2 and maximum 4 members.
  • Supabase Auth: Authentication service for secure account creation, password management, OTP verification, and session handling.
  • URL (Uniform Resource Locator): A web address used to access websites, applications, APIs, or online services.

2. Introduction

This Privacy Policy (“Policy”) describes how Invincible You, operated by Vedanga Solutions Private Limited, collects, uses, processes, stores, protects, transfers, and discloses personal information in connection with the use of the Invincible You mobile application, website, AI-powered systems, coaching platforms, DRIFT assessments, surveys, feedback systems, 360-degree evaluations, analytics tools, and all related services (collectively, “Services”). The platform supports both iOS and Android devices.

By accessing, registering for, or using the Services, users acknowledge that they have read, understood, and agreed to the practices described in this Policy. This Policy applies to all users including participants, admins, contracting companies, external respondents, administrators, coaches, client organizations, contractors, consultants, and all other stakeholders.

2A. Employer-Sponsored Accounts

Many users access the Services through an employer, client organization, or other sponsoring entity that purchases or subscribes to the platform on the user’s behalf (“Sponsoring Employer”). Where an account is sponsored by an employer, the user’s access, participation, and continued use of the Services is administered in connection with the commercial relationship between Invincible You and the Sponsoring Employer.

A Sponsoring Employer may be provided with limited, aggregated, and administrative information relating to its sponsored users, including completion statistics, learning progress, assessment completion status, aggregated and anonymised analytics, summary reports, and platform usage metrics, for purposes of administering the engagement and evaluating programme effectiveness.

A Sponsoring Employer shall not be granted access to a user’s AI chat or coaching conversations, reflections, journal entries, personal notes, or private coaching records, except where the user has specifically authorised such disclosure or where disclosure is required under applicable law.

Access granted to a Sponsoring Employer, its administrators, or authorised personnel is restricted through role-based permissions designed to limit visibility to only such information as is necessary for the administration of the sponsored engagement.

3. Collection of Information

Invincible You may collect and process the following categories of personal data:

  • Identity data: name, email address, phone number, and basic identification details.
  • Authentication and account access data including usernames, passwords, login credentials, security tokens, and account verification information.
  • Profile and user preference information.
  • Learning, coaching, mentoring, and development-related data.
  • Journal entries, reflections, written submissions, and self-recorded content voluntarily provided by users.
  • Assessment results, behavioural indicators, psychometric profiles, personality-related data, and evaluation records.
  • Analytics, engagement, and usage data including activity logs, interaction history, clickstream behaviour, feature utilization, and session metrics.
  • Technical identifiers and device-related information including IP addresses, browser type, operating system, device identifiers, cookies, and diagnostic data.
  • AI-generated and AI-assisted interaction records, prompts, responses, recommendations, and automated analysis outputs.
  • External respondent feedback, survey responses, 360-degree evaluations, and third-party assessment inputs.
  • Organizational, institutional, administrative, and operational metadata associated with user participation, reporting structures, or enterprise-level service administration.

4. Sensitive Behavioural & Coaching Information

Certain services involve collection and processing of behavioural patterns, coaching narratives, personality assessments, emotional signals, reflections, and journal content. Such information may be sensitive in nature. Processing occurs only where necessary for service delivery or with applicable consent.

5. Linked Devices Policy

The platform may be accessed through linked devices and connected services including mobile applications, web platforms, AI coaching systems, analytics services, and integrated backend infrastructure. Users acknowledge and consent to secure connections between the application and authorized third-party services such as DRIFT Assessment Tools, INSEE Coaching Chatbot, Supabase, PostHog, and other operational integrations required for platform functionality.

These linked systems may process user authentication data, session information, device identifiers, analytics events, coaching interactions, notification tokens, and usage-related information solely for service delivery, security, personalization, platform improvement, and user experience optimization.

Users are responsible for maintaining confidentiality of their linked devices, login credentials, OTP access, and session tokens. Unauthorized access or misuse may result in suspension or termination of platform usage rights.

6. Features Policy

The platform provides integrated features including user registration and authentication, profile creation and management, learning journeys, step-based learning, learning resources, reflections, INSEE coaching, personal journaling, AI coach interactions, INSEE personality assessments, Individual Development Plans (IDP), competency development programs, behavioural experiments, 360-degree feedback systems, reports, certificates, bookmarks, push notifications, settings and preferences, account deletion, password reset functionality, Small Group Coaching (SGC), support request management, and anonymized analytics services.

Data is collected only after the user explicitly consents to collection, processing, tracking, storage, and usage of data required for personalized experiences, coaching continuity, platform security, service optimization, reporting, research, and development purposes at first use.

7. External Respondent Policy

Who This Applies To

This notice applies to external respondents who are not registered users of the Services but who provide input in connection with a user’s participation on the platform, including 360-degree reviewers, survey participants, and other feedback providers (collectively, “External Respondents”).

Information Collected

Invincible You may collect the following categories of information from External Respondents: name (where voluntarily provided), email address, the content of survey or feedback responses, timestamps associated with submission, and technical logs such as IP address and device information.

Purpose

Information provided by External Respondents is used solely for the purposes of conducting assessments, coaching, and 360-degree evaluations, generating reports for the relevant user and, where applicable, their Sponsoring Employer, and internal analytics relating to the administration of such assessments.

Retention

Feedback and responses provided by External Respondents are retained only for so long as necessary to complete the relevant assessment or evaluation cycle and to generate associated reports, after which such information is deleted or de-identified in accordance with Invincible You’s data retention practices.

Rights

External Respondents may exercise rights of access, correction, and deletion in respect of the personal information they have provided, subject to applicable law, by contacting the Grievance Officer at mary@invincibleyou.world. External Respondents are provided with restricted, temporary, and purpose-specific access solely for participation in designated activities and shall not be granted access to confidential systems, administrative controls, proprietary resources, internal databases, or personal information belonging to other users.

8. Active Usage Policy

During active usage, users may interact with various learning, coaching, assessment, and development features that require the collection, processing, and storage of operational and behavioural data. Such data may include journey enrollments, learning progress records, step and resource completion tracking, feedback responses, ratings, comments, guided reflection responses, journal entries, AI coaching conversations, assessment responses, competency selections, behavioural experiments, bookmarks, and support requests.

All forms of such data shall only be collected if the user explicitly consents to it at the start.

9. System Data Collection Policy

Certain background and system-related data may be automatically collected to support application functionality, security, analytics, notification services, performance monitoring, and overall platform improvement. Such data may include Expo push notification tokens, analytics events, screen views, feature usage activity, session duration, crash reports, and technical error logs generated through integrated systems such as PostHog and Sentry SDKs.

Push notification data is collected only after users provide explicit device-level permission. Analytics and session tracking are disclosed within the platform Terms and may be controlled through available opt-out settings.

10. Purpose of Processing and Use of Information

Invincible You processes personal information solely for lawful, legitimate, and proportionate business purposes. Such purposes may include:

  • Account registration and management, identity verification, and platform authentication.
  • AI-powered coaching assistance, assessment administration, survey management, and behavioural analytics.
  • Engagement monitoring, personalization of user experiences, and system optimization.
  • Fraud prevention, customer support, compliance management, and security monitoring.
  • Research, product development, performance analysis, and enforcement of legal rights and platform policies.
  • Improving platform functionality, enhancing AI systems, generating insights, and evaluating feature effectiveness.

11. Legal Basis of Processing (GDPR)

Where GDPR applies, Invincible You relies upon the following legal bases under Article 6 GDPR:

  • Account creation and registration – Performance of a contract (Article 6(1)(b)).
  • Delivery of coaching, assessment, and learning services – Performance of a contract (Article 6(1)(b)).
  • Analytics and usage tracking – Consent (Article 6(1)(a)); users may opt out through platform settings.
  • Security monitoring and audit logging – Legitimate interests (Article 6(1)(f)).
  • Legal compliance and regulatory obligations – Legal obligation (Article 6(1)(c)).
  • AI-generated recommendations and behavioural profiling – Legitimate interests (Article 6(1)(f)) and/or consent (Article 6(1)(a)).
  • Processing of behavioural, coaching, personality-related, and emotional signal data – Explicit consent under Article 9(2)(a) GDPR.

Where consent is the legal basis, users may withdraw it at any time. Non-essential cookies and analytics technologies shall only be activated following explicit user consent. Data breaches likely to result in a risk to individuals shall be notified to the relevant supervisory authority within 72 hours.

12. AI Usage Policy

Invincible You utilizes AI technologies to support coaching experiences, conversational assistance, recommendations, behavioural insights, automated evaluations, engagement analysis, and related functionalities. AI-generated outputs are assistive and informational in nature and may contain inaccuracies, omissions, biases, or incomplete responses. AI outputs do not constitute professional, legal, medical, psychological, financial, or regulatory advice.

Conversations are processed by Anthropic (primary LLM) and Google Gemini (fallback). AI chat transcripts and coaching conversations may be retained for up to 24 months from the last date of engagement with the user’s employer. From then on only data de-identified from the user will be retained.

User-generated AI conversations are: (a) used for service delivery only; (b) stored only to personalize each user’s experience; (c) never used for third-party AI foundation model training.

Users may request human review where automated profiling materially affects them.

13. Third-Party Data Sharing Policy

Invincible You may engage trusted third-party vendors necessary for the provision, maintenance, monitoring, and improvement of the Services.

Invincible You shall share only the minimum amount of information necessary for authorized operational, technical, analytical, legal, security, or contractual purposes.

Sub-processors/Vendors:

  • Anthropic (USA) – AI language model processing; protected via DPA and applicable transfer mechanisms.
  • Google (USA/Global) – Fallback AI model (Gemini), cloud infrastructure; protected via SCCs and Google’s DPA.
  • Supabase (USA) – Authentication, database, and storage services; protected via DPA and SCCs.
  • PostHog (USA/EU) – Product analytics and usage monitoring; protected via DPA and SCCs.
  • Sentry (USA) – Error monitoring and crash reporting; protected via DPA and SCCs.
  • Langfuse (EU) – LLM observability and analytics; protected via DPA.
  • Resend (USA) – Sends transactional emails from the app and admin tools.
  • Microsoft Graph/Microsoft Teams (USA) – Schedules and hosts online coaching sessions.
  • Expo (US) – Delivers mobile push notifications.

Invincible You does not sell personal data to unauthorized third parties for monetary consideration or commercial exploitation.

Invincible You may update its list of sub-processors from time to time. Material changes shall be reflected within this Privacy Policy or communicated through appropriate notices.

14. Data Protection and Security

Invincible You maintains commercially reasonable administrative, technical, organizational, and physical safeguards to protect personal information.

Security measures include encryption of data in transit and at rest, HTTPS and TLS secure communication protocols, role-based access restrictions, authentication controls, secure APIs, audit logging, monitoring systems, infrastructure security reviews, backup protections, disaster recovery procedures, and incident response procedures.

Access to sensitive information is restricted to authorized personnel. No system can be guaranteed to be completely secure or immune from unauthorized access or cyber threats.

15. Analytics, Tracking Technologies, and Cookies

Invincible You may utilize analytics systems, monitoring technologies, cookies, SDKs, tracking tools, pixels, session technologies, and related mechanisms to analyze user engagement and improve functionality. Analytics technologies may collect information such as page visits, click behavior, session duration, engagement metrics, browser details, device information, feature interaction data, and performance diagnostics.

Essential cookies may be used to support authentication, security, and core functionality. Analytics and performance cookies may be used to improve platform effectiveness. Where legally required, users may be provided with consent mechanisms and opt-out controls.

16. Authentication, Access Control, and Password Security

Invincible You implements authentication and authorization mechanisms to ensure that access to systems, information, and platform functionalities is restricted solely to authorized individuals. Authentication methods may include email and password login, OTP verification, session validation systems.

Users are responsible for maintaining confidentiality and security of their login credentials. Passwords are protected using industry-standard hashing and encryption technologies, including bcrypt-based authentication. Unauthorized access attempts are strictly prohibited.

17. User Rights and Data Subject Rights

Subject to applicable laws, users may possess the following rights relating to their personal information:

  • Right of Access
  • Right to Rectification
  • Right to Erasure
  • Right to Restriction of Processing
  • Right to Data Portability
  • Right to Object
  • Right to Withdraw Consent
  • Right to Lodge a Complaint
  • Right to Human Review of Automated Decisions

All privacy rights requests shall be addressed within 30 days of receipt. Identity verification may be required before acting on a request.

Right of Nomination (DPDP): In accordance with the Digital Personal Data Protection Act, 2023, users may nominate another individual to exercise their data principal rights in the event of the user’s death or incapacity. Requests may be submitted in writing to the Grievance Officer.

Withdrawal of Consent: Users may withdraw previously granted consent at any time through account settings or by contacting the Grievance Officer at mary@invincibleyou.world.

18. Children’s Data

The Services are not intended for children below 18 years of age unless verifiable parental or guardian consent has been obtained in accordance with applicable law. Where the Company becomes aware that personal data of a child has been collected without appropriate parental consent, it shall take reasonable steps to delete such data promptly. Processing of any personal data relating to children shall be conducted with heightened care and limited to the minimum necessary.

19. Data Retention and Processing

Invincible You retains users data, including coaching chat transcripts only while a user’s account is active and their employer engagement is ongoing.

When a user deletes their account, all personal identifiers from their data are stripped and can no longer be linked to them. Only de-identified data is kept, and only for product-improvement purposes.

The same de-identification process is applied when engagement with a user’s employer ends within 2 years after the engagement ends.

No raw data linked to an identifiable person is retained after the deletion of account or from 2 years from the end of their employer engagement.

20. Automated Decision-Making and Profiling

Invincible You may utilize automated systems, profiling technologies, algorithms, AI models, behavioural analytics systems, and recommendation engines to provide personalized experiences, engagement insights, coaching recommendations, performance analytics, behavioural scoring, and operational assessments.

Where legally required, users may request additional information regarding automated processing activities and may request human review of decisions that significantly affect them. Invincible You does not make decisions producing legal or similarly significant effects solely through automated processing unless expressly disclosed and permitted by applicable law.

21. Mobile Application Permissions

The mobile application may request access to certain device permissions, including notifications, storage access, internet connectivity, microphone access, and device identification information, necessary for platform functionality, security, operational performance, or user-requested features. Permissions shall only be requested where reasonably necessary and users may manage, restrict, or revoke such permissions through device settings.

22. Support, Complaint Handling, and Grievance Redressal

Invincible You maintains structured support, complaint management, and grievance redressal mechanisms. Complaints may be investigated, reviewed, escalated, monitored, and resolved in accordance with internal procedures and applicable legal obligations.

Grievance Officer:

  • Name: Mary D’Souza
  • Designation: Grievance Officer – Privacy & Data Protection
  • Email: mary@invincibleyou.world
  • Postal Address: Invincible You / Vedanga Solutions Private Limited, Bengaluru, Karnataka, India
  • Helpline: +91 9844023428
  • Response Time: Complaints and grievances shall be addressed within 30 days of receipt.

Escalation Route: Unresolved complaints may be escalated to the Data Protection Board of India under the Digital Personal Data Protection Act, 2023, or to the relevant supervisory authority in the user’s jurisdiction.

23. Audit Logging and Monitoring

Invincible You maintains audit trails, monitoring systems, access logs, administrative records, security logs, and operational monitoring mechanisms for purposes including security management, compliance verification, fraud detection, incident investigation, troubleshooting, and lawful operational oversight. Logs may include login activity, access history, administrative actions, security events, device information, error reports, timestamps, and operational metadata.

24. International Data Transfers

Personal information may be processed, stored, transferred, or accessed in jurisdictions outside the user’s country of residence where Invincible You, its service providers, infrastructure providers, affiliates, or operational partners maintain facilities or operations. Where applicable, Invincible You shall implement commercially reasonable safeguards and data transfer mechanisms including:

  • Standard Contractual Clauses (SCCs)
  • Adequacy decisions
  • Contractual safeguards
  • Equivalent protections

Users may request further information regarding applicable international transfer safeguards by contacting the Grievance Officer.

25. Limitation of Liability

To the maximum extent permitted under applicable law, Invincible You disclaims liability for indirect, incidental, consequential, punitive, exemplary, or special damages arising out of or related to unauthorized access, cyberattacks, service interruptions, third-party misconduct, force majeure events, technical failures, AI-generated outputs, user misuse of the Services, or circumstances beyond the reasonable control of Invincible You. Nothing limits statutory rights under applicable privacy laws.

26. Policy Modifications and Updates

Invincible You reserves the right to amend, modify, revise, update, replace, or supplement this Privacy Policy at any time to reflect legal developments, operational requirements, technological advancements, security enhancements, regulatory obligations, or changes to platform functionality and business practices. Updated versions shall become effective upon publication. Continued access to or use of the Services following publication of revised policies constitutes acknowledgment and acceptance of such updates.

27. Contact Information

InvincibleYou Privacy, Security, and Compliance Department. Official support channels available through the platform and application.

Last Updated: May 23, 2026

Version: 1.0

Effective Date: July 13, 2026

© Invincible-YOU | All rights reserved