Security Practices
Last updated: 3 August 2026
Vyaya asks you to share credit-card statements, so we treat that data carefully. This page describes how we handle it. For the full data policy see our privacy policy.
Handling your statements
- Statement files are parsed in memory and never stored — we do not retain the raw statement file. We keep the file's name and a fingerprint (hash) used to prevent duplicate uploads.
- We never ask for, and never store, your full card number, CVV, OTP, PIN, or net-banking credentials.
- The transactions we extract are saved to your account so your dashboard, insights, and missed-reward analysis work — until you delete them or your account.
Encryption
Data is encrypted in transit (TLS) between your browser and our servers, and encrypted at rest by our cloud infrastructure providers.
Access controls
Your account data is isolated per-user with row-level security, so one account cannot read another's balances, statements, or transactions. Privileged database access is limited to server-side services and is not exposed to the browser.
Independence of rankings
Card rankings are computed from your spending and the reward math — not from what a bank pays us. Some “Apply” links earn a commission; it never changes a card's rating or position.
Your data, your control
You can request deletion of your uploaded statements or your entire account by emailing support@vyaya.in. Deletion removes your personal data from our production systems; backups expire on a rolling schedule. We honour the rights available under India's Digital Personal Data Protection Act, 2023.
Reporting a security concern
Found a vulnerability or something that looks wrong? Please email security@vyaya.in (or support@vyaya.in) with details. We appreciate responsible disclosure and will respond as quickly as we can.
See also our privacy policy and terms of service.