Legal

Privacy Policy

What we collect, why we collect it, how long we keep it, and what you can ask us to do with it. Written to be read, not skimmed past.

Effective 17 August 2026 Version 1.0 Terms & Conditions →

The short version. We collect the minimum we need to run your account: who you are, how to bill you, and how the service is being used. The assets you upload are yours — we store, version, and deliver them on your instruction and nothing else. We do not sell personal data, and we do not use your assets to train general-purpose AI models. You can export or delete your data at any time. This summary is for orientation only; the sections below are what actually governs.

1. Who we are

Umber is a Digital Asset as a Service platform operated by Vyomr Private Limited, a company incorporated in India with its registered office at 1208, A-wing, Kanakia Silicon Valley, Powai, Mumbai 400076 (“Umber”, “we”, “us”). We operate umbercloud.io, app.umbercloud.io, api.umbercloud.io, and the Umber CLI (together, the “Service”).

Under the Digital Personal Data Protection Act, 2023 (“DPDP Act”), we act as a Data Fiduciary for personal data about our own account holders, website visitors, and people who contact us. Where you upload assets that happen to contain personal data about your users, you are the Data Fiduciary and we act as a Data Processor handling that data solely on your documented instructions.

2. Scope of this policy

This policy covers personal data we handle as a Data Fiduciary through the Service, our marketing site, and our support and sales channels. It does not cover:

  • Third-party websites or services you reach through links from ours — their own policies apply.
  • Assets you upload, beyond how we process them on your behalf (see section 5).
  • Self-hosted or on-premise deployments running entirely inside your own infrastructure, where we have no access to your data.

3. What we collect

We collect only what a specific, stated purpose requires. If you decline to provide data marked as necessary, we may not be able to provide the relevant part of the Service.

CategoryWhat it includesWhere it comes from
Account dataName, work email address, password (stored only as a salted hash), organisation name, role, team members you inviteYou, at sign-up and in account settings
Billing dataPlan, billing cycle, billing name and address, GSTIN if supplied, invoice and payment history, last four digits and brand of your cardYou and our payment processor. We never receive or store full card numbers, CVV, or UPI credentials
Asset content and metadataFiles you upload (images, video, audio, PDFs, 3D models and similar), file names, versions, environment mappings, lifecycle states, tags and descriptionsYou, via the dashboard, API, or CLI
Usage and log dataAPI requests and endpoints called, timestamps, response codes, bytes transferred, storage consumed, IP address, user agent, referring page, approximate location derived from IP (city or region level)Automatically, as you use the Service
Security dataLogin events, failed authentication attempts, API key creation and revocation, audit trail of administrative actionsAutomatically
Support and sales dataName, email, company, topic, and the content of messages you send through our contact form or by emailYou, when you contact us
Marketing dataEmail address and communication preferences, whether you opened or clicked an email we sent youYou, when you opt in

We do not deliberately collect sensitive categories of data such as health, biometric, financial account, or government identifier data, and we ask you not to place such data in fields where it is not required. We do not buy personal data from data brokers.

4. How we use it, and on what basis

Under the DPDP Act, we process personal data either with your consent or for a legitimate use permitted by the Act — including performance of a service you have voluntarily asked for, and compliance with law.

PurposeData usedBasis
Create and administer your account, authenticate you, and enforce plan limits on storage, bandwidth, users, and environmentsAccount, usagePerformance of the service you requested
Store, version, map to environments, and deliver your assets when requestedAsset content and metadataPerformance of the service you requested
Charge you, issue invoices and credit notes, and meet tax obligationsBillingContract and legal obligation
Provide support, answer sales questions, and send service notices such as outage, billing, and security alertsSupport, accountPerformance of the service you requested
Keep the Service secure — detect abuse, credential stuffing, fraud, and denial-of-service activity, and investigate incidentsSecurity, usageLegitimate use under the DPDP Act
Diagnose faults, measure reliability, and improve performance and capacity planning, using data in aggregated or de-identified form wherever it will serveUsageLegitimate use under the DPDP Act
Power optional features you switch on, such as AI search over your own asset libraryAsset metadata and content within your account onlyYour consent, per feature
Send product announcements, newsletters, and offersMarketingYour consent — withdrawable at any time
Establish, exercise, or defend legal claims, and respond to lawful requests from authoritiesAny of the above, as relevantLegal obligation and legitimate use

We do not sell personal data, and we do not share it with third parties for their own advertising. We do not carry out automated decision-making that produces legal or similarly significant effects on you.

Where processing rests on consent, you may withdraw it at any time from your account settings or by writing to privacy@umbercloud.io. Withdrawal is as easy as giving consent, takes effect going forward, and does not affect processing already carried out.

5. Your assets

The assets you upload remain yours. We claim no ownership over them. We process them only to the extent needed to provide the Service — storing them, generating and retaining versions, applying the environment mappings you configure, delivering them over our asset delivery network when a request comes in, and creating derived files such as thumbnails or transcoded variants where a feature calls for it.

Specifically, we commit that:

  • Our staff do not access the contents of your assets except where you ask us to as part of support, where an automated system flags a suspected violation of our Acceptable Use Policy, or where the law requires it — and such access is logged.
  • We do not use your assets to train general-purpose or third-party AI models. Where you enable AI search, indexes and embeddings are generated for and confined to your own account, and are deleted when you disable the feature or delete the underlying asset.
  • Assets served over public delivery URLs are, by design, retrievable by anyone holding the URL. Choosing which assets to expose publicly is your decision, and you should not place confidential material behind a public URL.

If assets you upload contain personal data about your own users, you are responsible for having a lawful basis to collect and share it with us, and for informing those individuals. For customers who need one, we will enter into a Data Processing Agreement — write to privacy@umbercloud.io.

6. Sharing and sub-processors

We share personal data only in these situations:

  • Service providers (sub-processors) who run parts of our infrastructure under contract, bound to confidentiality and to processing data only on our instructions. Current categories: cloud hosting and compute; object storage and content delivery; payment processing; transactional email delivery; customer support tooling; product analytics and error monitoring.
  • Within your organisation. Other members of your Umber workspace can see account, usage, and asset data according to the roles you assign. Your workspace administrator can access and manage the account.
  • Professional advisers — auditors, lawyers, accountants — under a duty of confidentiality.
  • Authorities, where disclosure is required by Indian law, a valid court order, or a lawful government request. Where we are legally permitted to do so, we will notify you before disclosing.
  • A successor entity in a merger, acquisition, financing, or sale of assets. We will notify you before your data becomes subject to a different privacy policy, and any successor remains bound by commitments at least as protective as these.

A current list of named sub-processors is available on request from privacy@umbercloud.io. Customers on an enterprise agreement receive advance notice of new sub-processors and may object on reasonable data-protection grounds.

7. International transfers

We primarily store and process data in India. Some of our sub-processors operate in other countries, so your data may be transferred outside India. The DPDP Act permits such transfers except to countries the Central Government restricts by notification; we monitor those notifications and will not transfer personal data to a restricted territory.

Wherever data goes, we require contractual protections at least equivalent to those in this policy, including confidentiality obligations, security standards, and deletion on termination. Enterprise customers with data residency requirements should contact sales@umbercloud.io — dedicated and on-premise deployments are available.

8. How long we keep data

We keep personal data only as long as the purpose it was collected for still holds, and then erase it — except where a law requires us to retain it for longer.

DataRetention
Account and profile dataFor the life of the account, then erased within 30 days of account closure
Assets and versionsUntil you delete them or close the account. Deleted items are purged from live systems immediately and from backups within 35 days
Invoices, payment records, and tax documentsRetained for the period required by Indian tax and company law — currently up to 8 years from the end of the relevant financial year
Access and API logs90 days, then deleted or irreversibly aggregated
Security and audit logs12 months, longer where needed for an open investigation
Support correspondence24 months from the last message in the thread
Marketing contactsUntil you unsubscribe, plus a permanent suppression record so we do not contact you again

If your account sits inactive with no login and no API activity for 24 consecutive months on a free plan, we may notify you at your registered email and then erase the account and its contents if you do not respond within 30 days.

9. Security

We take reasonable security safeguards to prevent personal data breaches, as the DPDP Act requires. These include:

  • Encryption in transit using TLS for all connections to the site, dashboard, API, and delivery network.
  • Encryption at rest for stored assets and database contents.
  • Passwords stored only as salted, computationally hard hashes — never in a recoverable form.
  • API keys shown once at creation, stored hashed, revocable at any time, and scoped to a single account.
  • Role-based access control internally, on a least-privilege basis, with access reviewed periodically and revoked on role change or exit.
  • Logging and monitoring of administrative and authentication events, with alerting on anomalies.
  • Regular backups, tested restores, and a documented incident response process.

No system is perfectly secure. If a personal data breach occurs, we will notify the Data Protection Board of India and every affected user in the manner and within the timelines prescribed under the DPDP Act and its rules. You also have a part to play: choose a strong, unique password, keep API keys out of client-side code and public repositories, and rotate keys you suspect have leaked.

To report a vulnerability, write to security@umbercloud.io. We will acknowledge within two business days and will not pursue action against good-faith researchers who follow responsible disclosure.

10. Your rights

As a Data Principal under the DPDP Act, you have the right to:

  • Access — obtain a summary of the personal data we process about you, the processing activities undertaken, and the identities of others with whom we have shared it.
  • Correction and completion — have inaccurate or misleading data corrected, incomplete data completed, and outdated data updated. Most of this you can do yourself in account settings.
  • Erasure — have your personal data deleted, unless retention is required for a legal purpose.
  • Withdraw consent — for any processing that rests on consent, at any time and as easily as it was given.
  • Grievance redressal — a readily available means of raising a complaint with us (section 11), and the right to escalate to the Data Protection Board of India if we do not resolve it.
  • Nominate — nominate another individual to exercise these rights on your behalf in the event of your death or incapacity.

You can also export your account data, including your assets and their version history, through the API or the dashboard at any time.

To exercise a right, write to privacy@umbercloud.io from the email address on your account. We respond within 30 days. If a request is manifestly unfounded or repetitive we may explain why we are declining rather than act on it, and you retain the right to complain. Please note that the DPDP Act also places duties on you as a Data Principal, including not impersonating another person and not filing false or frivolous complaints.

11. Grievance redressal

If you are unhappy with how we have handled your personal data or a request about it, contact our Grievance Officer:

Grievance Officer — Shahnaz Khan
Vyomr Private Limited, 1208, A-wing, Kanakia Silicon Valley, Powai, Mumbai 400076, India
Email: grievance@umbercloud.io

We acknowledge every grievance within 48 hours and aim to resolve it within 30 days.

If we do not resolve your grievance to your satisfaction, you may lodge a complaint with the Data Protection Board of India established under the DPDP Act.

12. Children

Umber is a business tool and is not directed at anyone under 18. We do not knowingly create accounts for children or for persons with a disability who have a lawful guardian, and we do not undertake tracking, behavioural monitoring, or targeted advertising directed at children — all of which the DPDP Act prohibits.

If we learn that we hold personal data of a child without verifiable consent from a parent or lawful guardian, we will delete it promptly. If you believe a child has provided us data, write to privacy@umbercloud.io.

13. Cookies and similar technologies

Our marketing site runs with a light touch. We use:

  • Strictly necessary cookies — session and authentication cookies that keep you logged in to the dashboard and protect against cross-site request forgery. The Service cannot function without these.
  • Preference storage — local storage remembering choices such as your billing-cycle toggle on the pricing page.
  • Analytics — aggregate measurement of page views and traffic sources so we know which pages are useful. Where analytics are not strictly necessary, we ask for your consent first, and you can decline without losing any functionality.

We do not use advertising or cross-site tracking cookies. You can clear or block cookies through your browser settings; blocking strictly necessary cookies will stop the dashboard from working. We do not currently respond to Do Not Track signals, as there is no common standard for them.

14. Users outside India

Umber is operated from India and this policy is written to the DPDP Act. If you are in the European Economic Area, the United Kingdom, or a US state with its own privacy statute, you may have additional rights — such as data portability, objection to processing, restriction of processing, or the right to opt out of “sale” or “sharing” as those terms are defined locally.

We honour such requests where those laws apply to us. We do not sell or share personal data as those terms are defined under the CCPA/CPRA, and we do not use or disclose sensitive personal information for purposes requiring a right to limit. Write to privacy@umbercloud.io and tell us which jurisdiction you are writing from. Customers who need a GDPR-compliant Data Processing Agreement with standard contractual clauses should contact the same address.

15. Changes to this policy

We update this policy when the Service or the law changes. The effective date at the top always reflects the current version. For material changes — a new purpose, a new category of recipient, or a shorter route to your data — we will give notice by email to account holders and a notice in the dashboard at least 14 days before the change takes effect. Continuing to use the Service after that date means the updated policy applies to you. Superseded versions are available on request.

16. Contact us

Questions about this policy, or about anything we hold on you:

Vyomr Private Limited, 1208, A-wing, Kanakia Silicon Valley, Powai, Mumbai 400076, India.

Still have a question about your data?

Ask us directly — a person reads every message.

Contact us Read the Terms