Smartish AI ★

Privacy Policy

Last updated: July 25, 2026 · Version 2026.07.25-A · Effective for all users of the Smartish AI mobile application, website, application programming interfaces, administrative dashboards, notification systems, and related online services (collectively, the “Service”).

Table of contents (non-exhaustive). This Privacy Policy is intentionally comprehensive. Please read every section carefully before continuing to use the Service.
  1. Introductory statements, definitions, and interpretive rules
  2. Controller identity and contact particulars
  3. Categories of personal data processed
  4. Sources of personal data
  5. Purposes of processing and legal bases
  6. Detailed processing activities by feature
  7. Artificial intelligence, search ranking, and third-party marketplace data
  8. Cookies, local storage, device identifiers, and analytics
  9. Push notifications and messaging tokens
  10. Disclosures to processors, subprocessors, and other recipients
  11. International transfers and cross-border access
  12. Retention schedules, archival practices, and deletion workflows
  13. Security measures and residual risk acknowledgements
  14. Children’s privacy and age-related restrictions
  15. Your rights, preferences, and request procedures
  16. Automated decision-making and profiling disclosures
  17. Third-party links, embeds, and marketplace redirects
  18. Changes, versioning, and continued use
  19. Governing language, severability, and miscellaneous provisions
  20. Contact, escalation, and supervisory authority information

1. Introductory statements, definitions, and interpretive rules

Smartish AI (“we”, “our”, “us”, or the “Company”) operates an artificial-intelligence-assisted product discovery, price comparison, deal aggregation, search history, wishlist, and notification platform. The Service is designed to help end users identify products, compare publicly available or otherwise accessible marketplace listings, save preferences, and receive optional alerts. We are not a seller, merchant, marketplace operator, payment processor, logistics provider, warranty provider, or manufacturer. We do not take title to goods, do not warehouse inventory, do not process checkout transactions on behalf of merchants, and do not guarantee the accuracy, availability, pricing, authenticity, shipping timelines, returns policies, or stock status of any third-party listing.

For purposes of this Privacy Policy, “Personal Data” means any information relating to an identified or identifiable natural person; “Processing” means any operation or set of operations performed on Personal Data, whether or not by automated means; “User”, “you”, or “your” means any natural person who accesses or uses the Service; “Device” means any smartphone, tablet, computer, browser, or other endpoint used to access the Service; and “Content” means text, images, links, queries, uploads, metadata, and other materials submitted to or generated through the Service. Headings are for convenience only and shall not affect interpretation. Words importing the singular include the plural and vice versa. References to “including” mean “including without limitation”.

By creating an account, signing in, uploading images, submitting product links, performing text searches, enabling notifications, saving wishlist items, or otherwise interacting with the Service, you acknowledge that you have read, understood, and agree to the practices described in this Privacy Policy. If you do not agree, you must discontinue use of the Service and, where applicable, request account deletion in accordance with Section 15.

2. Controller identity and contact particulars

Unless otherwise stated in a region-specific addendum, Smartish AI acts as the controller of Personal Data collected through the Service. Privacy-related correspondence may be directed to privacy@smartishai.com. Operational support inquiries that are not privacy-related may be routed through the support channels published on our website. We may request reasonable identity verification before responding to data-subject requests in order to prevent unauthorized disclosure.

Where we engage service providers to host infrastructure, deliver push notifications, authenticate users, store application data, analyze telemetry, or perform artificial-intelligence inference, such providers typically act as processors or independent controllers under their own terms, depending on the nature of the engagement. A non-exhaustive description appears in Sections 7, 9, and 10.

3. Categories of personal data processed

3.1 Account and authentication data

3.2 Search, history, and interaction data

3.3 Wishlist and preference data

3.4 Device, notification, and technical data

3.5 Administrative and communications data

3.6 Data we do not intentionally collect as a merchant

We do not intentionally collect payment card numbers, bank account credentials, government identity documents, precise continuous geolocation tracks, biometric templates for authentication, or health data as part of core shopping-comparison features. If such data is inadvertently submitted by a user in free-text fields or uploaded images, we may delete or redact it when discovered, subject to legal retention obligations and technical feasibility.

4. Sources of personal data

Personal Data is obtained directly from you (account registration, searches, uploads, wishlist actions, notification permission grants); automatically from your Device and software environment (tokens, logs, technical identifiers); from identity providers you choose to use for sign-in; from third-party marketplaces and publicly accessible product pages when generating comparison results; from artificial-intelligence and ranking providers used to normalize messy product metadata into structured fields; and from our own systems that generate derived data such as categories, cleaned titles, and relative price indicators. Marketplace product information is generally not Personal Data about you, but may become associated with your account when saved to History or Wishlist.

5. Purposes of processing and legal bases

Depending on applicable law, we process Personal Data on one or more of the following bases: performance of a contract (providing the Service you request); legitimate interests (securing the Service, preventing abuse, improving reliability, developing features, understanding aggregate usage patterns, and communicating service-related notices); consent (where required for optional notifications, certain cookies, or marketing communications); and legal obligation (responding to lawful requests, retaining records where required, and enforcing rights). Where consent is the applicable basis, you may withdraw consent without affecting the lawfulness of processing before withdrawal, though certain features may become unavailable.

6. Detailed processing activities by feature

6.1 Image search

When you upload or capture a product image, the image bytes and associated filename metadata are transmitted to our backend for similarity search and candidate retrieval. Candidate results may be passed through an artificial-intelligence rearrangement layer (including OpenRouter or comparable providers configured by administrators) to produce structured JSON fields such as title, short description, price, original price, discount, platform, image URL, and link. Uploaded images are processed for the search you initiate and may be retained in History snapshots associated with your account. Do not upload images containing sensitive personal information unrelated to product discovery.

6.2 Product link search

When you paste a marketplace URL, we fetch and parse publicly available product information and compare listings across supported platforms. The submitted URL, derived product identifiers, and resulting comparison payload may be stored in History if you are authenticated.

6.3 Text search

Text queries are used to retrieve shopping results and may likewise be normalized by artificial-intelligence rearrangement pipelines before display. Queries and result snapshots may be retained as History.

6.4 Deals feed

Shared deal catalogs may be refreshed periodically from third-party deal pages. Deal records typically include title, category, current price, original price, discount badge text, store name, image URL, and product link. These records are generally shared across users and are not unique to a single account, although your interactions with deals (opens, saves) may be associated with your account.

6.5 Wishlist

Wishlist entries store the product fields you choose to save and optional linked result payloads. Removing an item deletes the corresponding wishlist record subject to backup and logging retention windows described in Section 12.

6.6 Administrative dashboards

Authorized operators may access user management tools, notification sending tools, and configuration panels (including OpenRouter API key and model settings). Operator access is restricted to personnel with a need to know and is subject to internal confidentiality expectations. Configuration secrets such as API keys are stored as application settings and should be treated as confidential credentials.

7. Artificial intelligence, search ranking, and third-party marketplace data

Portions of the Service rely on automated systems to extract, clean, rank, and rearrange product metadata. These systems may transmit truncated or transformed search result payloads to third-party AI providers for the limited purpose of returning structured JSON suitable for display. AI outputs may be incomplete, outdated, approximate, or incorrect. Prices, discounts, availability, and product attributes can change without notice on merchant websites. You should verify final purchase terms on the merchant’s site before completing any transaction. We do not warrant that AI-rearranged fields will always perfectly match source pages.

Marketplace pages are owned and operated by third parties. Their privacy policies, cookie practices, tracking technologies, and terms of sale apply when you leave the Service. We are not responsible for third-party content, policies, or practices.

8. Cookies, local storage, device identifiers, and analytics

The website and dashboards may use cookies, local storage, session storage, or similar technologies to maintain authenticated sessions, remember preferences, protect against cross-site request forgery where applicable, and support basic operational analytics. Mobile applications may store session tokens and local preferences on Device storage. You can control certain cookies through browser settings; disabling cookies may impair login or dashboard functionality. Device identifiers used for push messaging are described in Section 9.

9. Push notifications and messaging tokens

If you grant notification permission, we may store an FCM device token linked to your account so that we can deliver personal or broadcast notifications regarding deals, product updates, account notices, and system messages. Tokens may become invalid when you uninstall the application, revoke permission, clear application data, or change devices. We may deactivate stale tokens. You can stop push delivery by disabling notifications in Device settings; in-app notification history may still exist separately until deleted according to retention rules.

Notification content may include product names, price indicators, and links. Avoid enabling notifications on shared devices if you do not want others to see such content on lock screens.

10. Disclosures to processors, subprocessors, and other recipients

We may disclose Personal Data to hosting and infrastructure providers; authentication providers; push notification providers (including Firebase); artificial-intelligence inference providers configured for result normalization; analytics or crash-reporting tools if enabled; professional advisors (legal, accounting, security) under confidentiality obligations; and government authorities when required by law or necessary to protect rights, safety, and integrity of the Service. We do not sell Personal Data as a consumer commodity. If a corporate transaction occurs (merger, acquisition, financing, or sale of assets), Personal Data may be transferred as part of that transaction subject to appropriate continuity of privacy commitments where required.

11. International transfers and cross-border access

The Service may be hosted, administered, or supported from jurisdictions other than your country of residence. Accordingly, Personal Data may be transferred to, stored in, or accessed from countries that may have different data-protection laws. Where required, we implement appropriate transfer mechanisms or contractual safeguards available under applicable law. By using the Service, you understand that cross-border processing may be necessary to provide global infrastructure and vendor integrations.

12. Retention schedules, archival practices, and deletion workflows

We retain account records while your account remains active and thereafter for a period reasonably necessary to comply with legal obligations, resolve disputes, enforce agreements, and maintain security logs. Search History and Wishlist records are retained until you delete them or request account deletion, subject to backup cycles and forensic log retention. Shared deal catalogs are refreshed periodically and prior deal rows may be replaced. Notification records and FCM tokens are retained while relevant to delivery and read-state tracking, then removed or anonymized when no longer needed. Exact retention intervals may vary by system component, backup policy, and legal requirement and are not guaranteed to be instantaneous upon deletion requests.

When you request deletion, we will take commercially reasonable steps to delete or de-identify Personal Data in active systems, except where retention is required or permitted by law (for example, to complete pending investigations, satisfy audit obligations, or preserve evidence of transactions and communications). Residual copies in encrypted backups may persist until overwritten in the ordinary course.

13. Security measures and residual risk acknowledgements

We implement reasonable technical and organizational measures designed to protect Personal Data against unauthorized access, alteration, disclosure, or destruction. Measures may include access controls, session tokens, transport encryption where supported, credential segregation for API keys, least-privilege operator practices, and monitoring of anomalous activity. Notwithstanding the foregoing, no method of transmission over the Internet or method of electronic storage is completely secure. You acknowledge residual risk, agree to use strong authentication credentials, keep sessions private on shared Devices, and promptly notify us of suspected unauthorized account access.

14. Children’s privacy and age-related restrictions

The Service is not directed to children under the age of 13 (or the higher age threshold required in your jurisdiction). We do not knowingly collect Personal Data from children. If you believe a child has provided Personal Data, contact us so we can take appropriate steps to delete such information. Guardians who permit adolescents to use the Service remain responsible for supervision and for ensuring lawful use.

15. Your rights, preferences, and request procedures

Subject to applicable law, you may have rights to access, correct, update, delete, restrict, or object to certain processing of Personal Data; to withdraw consent where processing is consent-based; to request portability of certain data; and to lodge a complaint with a supervisory authority. To exercise rights, email privacy@smartishai.com with sufficient detail to locate your account and specify the request. We may ask for verification information. We will respond within the timeframe required by applicable law, or otherwise within a reasonable period. Some rights are not absolute and may be limited where we have compelling legitimate grounds, legal obligations, or inability to verify identity.

15.1 Account deletion

You have the right to request deletion of your Smartish AI account and its associated personal data, including your searches, history, wishlist, saved notifications, notification read-state, and device messaging tokens. You may submit a deletion request at any time using our online form: Request account deletion.

Submitting the form does not delete your account immediately and by itself. It records your request so that our team can verify your identity and then remove your account and related records. We will action verified requests within a reasonable period, except where limited retention is required or permitted by law (for example, to satisfy audit, security, or legal-hold obligations). Residual copies in encrypted backups may persist until they are overwritten in the ordinary course. Where available, deletion controls may also be offered inside the mobile application.

16. Automated decision-making and profiling disclosures

The Service uses automated ranking, price comparison heuristics, and AI-assisted restructuring of product metadata to present results. These processes are intended to organize shopping information and are not used to determine legal effects such as creditworthiness, employment, or insurance eligibility. You may contact us for additional information about meaningful logic involved, to the extent required by law and without revealing trade secrets or security-sensitive details.

17. Third-party links, embeds, and marketplace redirects

Result cards and deal cards may deep-link to Amazon, Flipkart, Myntra, Croma, Ajio, Meesho, and other merchants. Clicking such links leaves the Service. Embedded images hosted by third parties are subject to those hosts’ availability and policies. We are not responsible for the privacy or security practices of destinations you visit after leaving Smartish AI.

18. Changes, versioning, and continued use

We may update this Privacy Policy from time to time to reflect operational, legal, or product changes. The “Last updated” date and version label at the top will change when material revisions occur. Where required by law, we will provide additional notice. Continued use of the Service after the effective date of an updated Privacy Policy constitutes acceptance of the revised terms to the maximum extent permitted by applicable law. If you do not agree to changes, you must stop using the Service and may request account deletion.

19. Governing language, severability, and miscellaneous provisions

This Privacy Policy is drafted in English. If translated, the English version controls unless local law requires otherwise. If any provision is held unenforceable, the remaining provisions remain in effect. Failure to enforce a provision is not a waiver. This Privacy Policy does not create third-party beneficiary rights except as required by applicable data-protection law. Nothing in this Privacy Policy limits non-waivable consumer or privacy rights.

For avoidance of doubt, product listings, prices, discounts, delivery estimates, ratings, and related marketplace fields displayed in the Service are informational only and may be incomplete, delayed, localized, or inaccurate. Always confirm purchase details on the merchant website or application before buying. Smartish AI disclaims liability arising from reliance on third-party marketplace data to the fullest extent permitted by law.

20. Contact, escalation, and supervisory authority information

Privacy questions, data-subject requests, and notices of suspected incidents involving Personal Data may be sent to privacy@smartishai.com. If you are located in a jurisdiction with a data protection authority, you may also have the right to lodge a complaint with that authority. We encourage you to contact us first so we can attempt to resolve concerns directly. Additional support channels may be listed on the Smartish AI website.

This document constitutes the complete Privacy Policy statement for the Service as of the effective date indicated above and supersedes prior privacy statements regarding the same subject matter, except where a separate written agreement expressly provides otherwise.

© 2026 Smartish AI. All rights reserved. Please scroll responsibly.