Privacy Policy

Effective as of 2026-10-05

This privacy policy will only be provided in English. This privacy policy is applicable to the Pasa app (hereinafter referred to as "Application") for mobile devices, which was developed by Keshav Kumar (hereinafter referred to as "Service Provider") as a Freemium service. This service is provided "AS IS".

What information does the Application obtain and how is it used?

The Application acquires the information you supply when you download and register the Application. Registration is required to use the Application's core features.

The information collected during registration includes:

  • Email address — collected via Google Sign-In, Sign in with Apple, or Facebook Login for authentication purposes
  • Name — visible to other Pasa users, shown on invite pages and in notifications when someone uses your invite code, and used in search so others can find you
  • Username — chosen by you during onboarding
  • Profile photo — optionally uploaded by you; displayed to other users in chats, on your profile, and on your public invite page
  • Preferred language — used to determine the translation direction for your messages

The Application supports one-on-one and group chats. Messages you send — including any photos or images — are stored on Supabase servers and are visible to the other participants of each conversation.

The Service Provider may use your contact information to send important notices about the Application such as updates or changes to this policy. The Service Provider does not send marketing promotions without your explicit consent.

What information does the Application collect automatically?

The Application may collect certain information automatically, including the type of mobile device you use, your mobile device's unique device ID, the IP address of your mobile device, your mobile operating system, and information about the way you use the Application.

The Application collects and stores a push notification token issued by your device to enable delivery of push notifications when you receive new messages.

When you tap "Paste code" in the invite code entry screen, the Application reads your clipboard once to fill in the code field. The clipboard text is not stored; only the extracted code is sent to the server to look it up.

This Application does not gather precise information about the location of your mobile device.

Does the Application use Artificial Intelligence (AI) technologies?

Yes. The Application uses Anthropic's Claude AI to translate messages between languages in real time. When you send a message, the content is transmitted to Anthropic's API solely for the purpose of translation and is not retained by Anthropic beyond the duration of the translation request.

No AI is used for personalization, recommendations, behavioral analysis, or any purpose other than message translation.

Invite Codes

Every account has one permanent personal invite code — a random 5-character code created automatically when the account is created. A personal code cannot be reset by the user. Anyone who has your personal invite code can start a conversation with you immediately, bypassing the usual chat-request step. You can block, report, or delete any chat afterwards.

Group owners have a separate group invite code. Anyone holding a group code can join that group (subject to group limits) until the owner resets the code. Resetting a group code invalidates the old one. Only the group owner can see and share the group code.

Invite notifications:when someone starts a chat using your personal code, you receive a push notification that includes that person's display name.

"Invited by" record:when a new account starts a chat using someone's invite code (or an older invite link), or joins a group by invite, the app records the inviter's username on the new account. This is set only once and is not visible to other users.

Failed-attempt protection:to prevent code guessing, the system temporarily records each signed-in user's failed invite-code lookups (user ID and timestamp) for approximately one hour, and blocks further attempts after 10 failures in that period. These records are not linked to any code and are not retained beyond the one-hour window.

Public invite pages:the pages at pasa.chat/invite/<username> display that person's name, profile photo, and invite code without requiring a login. Group invite pages at pasa.chat/invite/group/<code> display the group name, photo, member count, and group code. No member names are shown on group pages.

Analytics:invite-related analytics events record only what happened (for example "invite shared" or "code submitted: valid/invalid"). The code itself is never included in analytics data.

Your invite code is deleted immediately when you delete your account.

Does the Application offer in-app purchases?

Yes. The Application offers an optional message credit pack as an in-app purchase, processed through Apple's App Store and Google Play billing systems. The Service Provider uses RevenueCat to manage and validate these purchases.

When you make a purchase, RevenueCat receives a user identifier linked to your Pasa account, along with your purchase and transaction history, in order to grant you the correct number of message credits and to prevent fraud. RevenueCat does not receive your payment card or bank details — these are handled directly by Apple or Google.

This purchase and transaction data is used solely for app functionality (granting credits, validating purchases) and the Service Provider's own analytics (understanding usage of the credit system). It is not used for advertising, shared with data brokers, or used to track you across other companies' apps or websites.

Do third parties see and/or have access to information obtained by the Application?

The Service Provider shares information with third parties only as necessary to operate the Application:

  • Message content is transmitted to Anthropic's Claude API for real-time translation. Message content is not retained by Anthropic beyond the translation request.
  • User profile data and messages are stored securely on Supabase servers.
  • Authentication is handled by Google Sign-In, Sign in with Apple, or Facebook Login, depending on which option you choose. Your account email and name are used to create your Pasa profile.
  • Purchases are processed by Apple and Google, and managed by RevenueCat, which validates transactions and manages your message credit balance.
  • Push notification tokens are processed by Expo to enable delivery of message notifications to your device.
  • Crash and error data — including device type, OS version, app version, and anonymized stack traces — is sent to Sentry for error monitoring. No message content or personal identifiers are included.
  • Usage events — such as screens viewed and features used (for example "invite shared" or "message sent") — are sent to Vexo for analytics. Events do not include message content, invite codes, or any personally identifiable information beyond a pseudonymous user ID.

No user data is sold to third parties or used for advertising purposes.

The Service Provider may also disclose your information:

  • As required by law, such as to comply with a subpoena or similar legal process
  • When necessary in good faith to protect the rights or safety of the Service Provider, users, or others
  • To investigate fraud or respond to a government request

Please note that the Application utilizes third-party services that have their own Privacy Policies governing their handling of data:

Where is your data stored?

Your profile data and messages are stored on Supabase servers. Message content is transmitted to Anthropic's servers in the United States for translation processing. By using the Application you consent to this international transfer of data.

What are my opt-out rights?

You can stop all collection of information by the Application by uninstalling it. You may use the standard uninstall processes available on your mobile device or via the app marketplace.

What is the data retention policy and how can I manage my information?

The Service Provider retains your data for as long as you maintain an active account. Upon account deletion your personal profile data (name, email, username, profile photo, language preference, and invite code) is deleted immediately. Conversations and messages you sent are retained on our servers so that other participants keep their chat history; you are shown as "Deleted User" in those conversations.

You may delete your account at any time directly within the Application by navigating to Profile → Delete Account. Deletion of your personal profile data is immediate and cannot be undone. Your invite code is also deleted immediately.

Alternatively you may contact the Service Provider at pasachatapp@gmail.com to request data deletion and we will respond within a reasonable time.

Your Data Rights (GDPR)

If you are located in the European Economic Area you have the following rights regarding your personal data:

  • Right of access — you may request a copy of the data we hold about you
  • Right to rectification — you may request correction of inaccurate data
  • Right to erasure — you may delete your account and all associated data directly in the app at any time, or contact us to request deletion
  • Right to data portability — you may request your data in a machine-readable portable format
  • Right to object — you may object to processing of your personal data
  • Right to restrict processing — you may request that we restrict processing of your data in certain circumstances

To exercise any of these rights please contact us at pasachatapp@gmail.com. We will respond within 30 days.

How does the Application address children's privacy?

The Application is not directed at children under the age of 17. The Service Provider does not knowingly collect personally identifiable information from users under 17 years of age.

If the Service Provider discovers that a user under 17 has provided personal information, it will be immediately deleted from our servers. If you are a parent or guardian and you are aware that your child has provided personal information, please contact the Service Provider at pasachatapp@gmail.com.

How is your information kept secure?

The Service Provider is committed to safeguarding the confidentiality of your information. We implement physical, electronic, and procedural safeguards to protect the information we process and maintain.

All data transmitted between the Application and our servers is encrypted in transit. Access to user data is restricted to authorized personnel only.

Please be aware that no security system can prevent all potential security breaches and the Service Provider cannot guarantee absolute security of your information.

How will you be informed of changes to this Privacy Policy?

This Privacy Policy may be updated from time to time. The Service Provider will notify you of any material changes by updating this page with the new Privacy Policy and updating the effective date. You are advised to review this Privacy Policy periodically. Continued use of the Application after changes are posted constitutes acceptance of those changes.

How do you give your consent?

By using the Application you are giving your consent to the Service Provider's processing of your information as set forth in this Privacy Policy. If you do not agree to this Privacy Policy please do not use the Application.

How can you contact us?

If you have any questions regarding privacy while using the Application, or have questions about our practices, please contact the Service Provider via email at pasachatapp@gmail.com.