Privacy policy
Effective 21 September 2026 · Neuromesh Technologies Private Limited
This policy explains what the bigfann app and website (“bigfann”, “we”) collect, why, who sees it and for how long. bigfann is operated by Neuromesh Technologies Private Limited, LP-445, Prashanti Vihar, Patia, Bhubaneswar - 751024, Odisha, India. It is written for the Digital Personal Data Protection Act, 2023 (“DPDP Act”) and the Information Technology Act, 2000 and the rules under it.
1. The short version
- You sign in with your phone number and a one-time code. No password, no email required.
- Other members never see your phone number, name or profile. Inside a community you appear under an alias such as “Member 4821”.
- We do not collect your location, contacts or messages from other apps, and we never read SMS.
- Payments are handled by Razorpay, Apple or Google. bigfann never sees your card or UPI details.
- You can download everything we hold about you, and delete your account, from inside the app.
- We do not sell personal data and we do not show third-party advertising.
2. What we collect
| Data | Why | Who provides it |
|---|---|---|
| Phone number, one-time code, sign-in time, IP address, device type | To create and secure your account and to record your consent to these terms | You |
| Display name, photo, handle, bio, links, language; email if you add one for invoices | To show you to the creators whose communities you join and to send invoices | You (optional except the name) |
| Posts, comments, reactions, poll votes, messages to creators, files you upload | To run the community you are in; to moderate for spam and abuse | You |
| Purchases, subscriptions, orders, tickets, bookings, credits, invoices | To deliver what you bought, issue GST invoices and handle refunds | You, Razorpay, Apple, Google |
| Shipping name, phone, address and PIN code (market orders only) | To ship physical goods; visible to the creator and their staff with the Orders role | You |
| Device identifier, app version, push notification token | To sign you in on your devices, apply the two-device limit on paid courses, send notifications | Your device |
| Course progress, certificates, downloads, saved items | To resume where you left off and issue certificates | Your use of the app |
| Crash reports and performance data (phone numbers and secrets are removed before sending) | To find and fix bugs | Your device, via Sentry |
| Creators only: legal name as on PAN, PAN, date of birth, a selfie, bank account or UPI ID, social account proof, and where applicable a SEBI registration number | Identity verification, payouts, tax compliance and the verified mark | You, and our verification partner |
We keep the result of a creator’s verification, not the documents beyond what the law requires. A creator’s legal name is never shown to members.
3. What we do not collect
No location, no contacts, no calendar, no reading of SMS, no access to your other chat apps. The camera and microphone are used only when you record a reel, go live or scan a ticket, and only while you are doing it. Member imports from Telegram or WhatsApp are done by sharing a join link; we never read those chats.
4. How we use it
- To run the communities, courses, shop, events and messaging you use.
- To process payments, issue GST invoices, settle payouts and handle refunds and disputes.
- To keep communities safe: automated filters and, where needed, an automated language model review posts and messages for spam, scams and prohibited content. A human reviews reports and appeals. Community chats are not end-to-end encrypted because moderation must be able to read them; messages to a creator are private to you and that creator.
- To send you notifications you can switch off per community, and transactional SMS or email.
- To comply with Indian law, including tax, e-commerce and securities rules, and lawful requests.
- To measure and improve the app using aggregated, non-identifying statistics.
5. Who sees what
- Other members see your alias, your posts and comments in groups you both belong to, and nothing else.
- Creators see the display name, plan and activity of members of their own communities, and the shipping details on orders placed with them. Their exports never include phone numbers.
- Service providers who process data for us under contract: Razorpay (payments and payouts), Apple and Google (store billing and push notifications), MSG91 (SMS one-time codes), cloud hosting and storage, Sentry (crash reports), our identity verification partner (creators only) and an AI moderation provider (content review only).
- bigfann staff open private messages only when a report or a legal request requires it, and every such access is logged.
- Authorities, when the law requires it.
We do not sell personal data, and we do not share it with advertisers.
6. How long we keep it
| Data | Kept for |
|---|---|
| Account, profile, memberships, posts and messages | Until you delete your account, plus a 30-day grace period in which you can change your mind |
| Payment, invoice and payout records | 8 years, as required by the Companies Act and GST law |
| Moderation, safety and audit records | Up to 3 years, or longer where a dispute or legal request is open |
| Sign-in sessions and one-time codes | Sessions expire after 30 days of inactivity; codes after 10 minutes |
| Crash and performance data | 90 days |
7. Your rights
Under the DPDP Act you can:
- Access — download a copy of everything we hold about you from Profile → Language, data & downloads → Download my data.
- Correct — edit your name, photo and other profile details in the app at any time.
- Erase — delete your account from Profile → Delete account. See the account deletion page for exactly what is removed and what the law requires us to keep.
- Withdraw consent — switch notifications off, leave communities, or delete the account.
- Complain — to our grievance officer (below), and if you are not satisfied, to the Data Protection Board of India.
- Nominate — write to us to name a person who may exercise these rights for you if you are unable to.
8. Children
bigfann is for people aged 13 and over. Anyone under 18 needs the consent of a parent or guardian to use it and cannot become a creator or receive payouts. If we learn that an account belongs to a child without such consent we will delete it. See our child safety standards.
9. Security
Data travels over TLS. One-time codes expire in ten minutes and sign-in tokens are short lived and bound to the device. Paid course files are watermarked and encrypted for offline play. Access by staff is role-based and audit-logged. No system is perfect; if a breach affects you we will tell you and the Data Protection Board as the law requires.
10. Where data is stored
Data is stored on servers we control or rent from cloud providers, and may be processed outside India by the providers named above under contracts that protect it. Payment data stays with the payment provider in India.
11. Changes
When this policy changes in a way that matters, the app will ask you to read and accept the new version before you carry on. Older versions are available on request.
12. Grievance officer
Subrat Acharya, Grievance Officer
Neuromesh Technologies Private Limited
LP-445, Prashanti Vihar, Patia, Bhubaneswar - 751024, Odisha, India
mike@bigfann.com · +91 80931 08555
Complaints are acknowledged within 24 hours and resolved within 15 days, as the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021 require. You can also raise a ticket in the app under Help & support → Grievance.