Privacy Policy
Last updated: 20 August 2026
This policy explains what Cache Club collects, why, and what you can do about it. It covers Creator Cacheβ’ and Womeown.
The short version. Cache Club is local-first: without an account, your data stays in your own browser and never reaches us. With an account, we store what you choose to sync so it follows you between devices. We do not sell your data, and we do not run advertising trackers.
Who is responsible for your data
Data Controller / Data Fiduciary: Shivani Wankhede (Sole Proprietorship), trading as Cache Club
Registered address: Parmar Sqaure CHS, Opp. IT Ground, Near Zensar Technologies, Kharadi, Pune β 411014, Maharashtra, India
Email: cache.creators@protonmail.com
Phone: +91 81214 28947
We are a small independent business, not a large company: the person who reads your privacy request is the person who runs Cache Club. We have not appointed a separate Data Protection Officer, because our scale does not require one β write to the address above and it reaches the decision-maker directly.
1. What we collect
a. Without an account
Nothing is sent to us. Your profile, portfolio, ideas, pipeline and habits are stored in your browser's local storage on your own device. Clearing your browser data deletes them, and we cannot recover them.
b. When you register
- Email address β to identify your account, confirm it is real, and contact you about the Service.
- Mobile number β to keep accounts unique, so one person cannot hold several free accounts. We do not send marketing SMS.
- Password β stored only as a salted hash by our authentication provider. We never see it.
c. What you put into the app
Your name, headline, bio, photo, work samples, links, social handles, testimonials, client pipeline, ideas, posts and habits β whatever you enter. This is yours; we store it so you can get it back on another device.
d. Payments
Handled by PhonePe (customers in India) and Razorpay (customers everywhere else). We receive a payment reference, the amount, the currency and the status. We never receive or store your card number, UPI PIN or bank credentials.
e. Your approximate location
To show you a price in your own currency, and to send you to a payment method that works where you are, we read the country your internet connection appears to be in. This comes from your IP address and is resolved by Cloudflare.
- We use the country only β not your city, and not your coordinates.
- We do not store your IP address for this purpose; it is read as the request passes through and discarded.
- Your browser's timezone is used as a fallback when that lookup is unavailable.
You can change the market you see prices in yourself, from the pricing page. The country your payment is actually charged in is set by your billing country, not by that choice.
f. Your timezone
If you have an account, we store your timezone (for example Asia/Kolkata or America/New_York), read from your browser when you sign in.
- It exists for one reason: daily allowances such as β5 AI credits a dayβ reset at your midnight rather than ours. Without it, a member in California would see their quota reset at half past eleven in the morning.
- A timezone is coarse β it covers a whole region, not a place. It is not your address and it is not a location trail.
- It is updated when you sign in, so it follows you if you move or travel.
g. Usage
- AI usage counts per day, to apply your plan's limit and to keep the service sustainable. We record how many calls you made and roughly what they cost β not what you asked.
- Anonymous in-app event counters (which screens are opened, when an upgrade prompt appears). These live in your browser and carry no personal identifiers.
- Security logs kept by our providers. Supabase records standard authentication events β sign-in attempts, the IP address and browser they came from β as part of running an auth service securely. We do not build our own profile of you from these, and we do not use them for marketing.
2. Why we are allowed to hold it
| Data | Purpose | Basis |
|---|---|---|
| Email, password | Run your account | Performance of contract |
| Mobile number | Prevent duplicate accounts | Legitimate interest |
| Content you enter | Provide the Service | Performance of contract |
| Payment records | Billing, tax records | Legal obligation |
| AI usage counts | Enforce plan limits | Performance of contract |
| Country (from IP) | Show and charge the right price in the right currency | Performance of contract |
| Timezone | Reset daily allowances at your own midnight | Performance of contract |
| Provider security logs | Keep accounts secure, prevent abuse | Legitimate interest |
3. Who we share it with
We do not sell your personal data and we do not share it for advertising. We use a small number of processors, each only for the job named:
| Provider | What it handles |
|---|---|
| Supabase | Database and authentication |
| Cloudflare | The API layer between the app and other services |
| Google (Gemini API) | Runs the language model behind the AI assistant |
| PhonePe | Payment processing β customers in India |
| Razorpay | Payment processing β customers outside India |
| Hostinger | Website hosting |
We also disclose data where the law requires it, or to protect our rights or someone's safety.
4. What the AI assistant sends
When you use the AI assistant, the prompt β which may include details from your profile such as your headline, USP and bio β is sent to Google's Gemini API so the model can answer in your context.
- Only what is needed for that request is sent.
- We do not use your content to train any model of our own, and we do not sell it.
- Google may use it to improve their models. The assistant currently runs on the free tier of Google's Gemini API, and Google's terms for that tier permit them to use prompts sent through it to improve their services, including review by human reviewers. This is the honest trade for the assistant being free to you. If we move to a paid tier β where that use is excluded β we will say so here.
- Do not paste anything confidential β client secrets, passwords, ID numbers, anything under an NDA β into the assistant. On the free tier this matters more than usual.
5. What Post Radar reads
Post Radar looks at what you have already published, so that its suggestions come from your own work rather than from generic advice. It reads only public pages, and only for the handles you have entered yourself in your Identity Vault.
- What is read. When you press Scan my handles, our server fetches the public pages for the handles you saved β Reddit, GitHub, DEV, Medium, Substack or a blog/RSS address. These are the same pages anyone can open without logging in. Nothing private is accessed and we never ask for a password or an account connection.
- What is not read. LinkedIn, X, Instagram, Threads and TikTok are never fetched. They publish nothing readable to anyone but the account holder, and reading them another way would break their terms. Those handles are used only as context for the AI β as a note of which platform you write for.
- Video is skipped. Video posts are filtered out and counted, not analysed.
- We do not keep it. What is fetched is passed straight back to your browser and is not stored on our servers. It is held on your device until you scan again or clear it.
- If you ask for post ideas, a shortened summary of what was read β together with details from your portfolio, and anything you pasted into the box yourself β is sent to the AI as part of the prompt. Section 4 above applies in full to that request.
- You can stop all of this by removing the handles from your Identity Vault, and it never happens unless you press the button.
6. Where it is stored, and international transfers
Cache Club is operated from India, and data is held on servers run by the providers listed above, which may be located in India, the EU, the UK or the United States. Using the Service therefore involves transferring your data across borders.
- If you are in the EU or UK: transfers out of the EEA/UK are made under the European Commission's Standard Contractual Clauses (and the UK Addendum / IDTA where relevant), which our processors have entered into. You can ask us for details.
- If you are in India: processing follows the Digital Personal Data Protection Act, 2023.
- Every processor is bound by contract to protect your data to at least the standard described in this policy, and to process it only on our instructions.
We do not transfer your data to any country we are prohibited from transferring it to.
7. How long we keep it
- Account and content: while your account is open, and for 30 days after you delete it, so an accidental deletion can be undone.
- Payment records: 8 years, as required by Indian tax law.
- AI usage counts: 12 months.
- Timezone and country: for as long as your account is open β they are settings, not history, and each is overwritten rather than accumulated.
- Provider security logs: kept by Supabase under their own retention schedule, typically a few weeks. We do not copy them into our database.
8. Your rights
Wherever you live, you can ask us to:
- Show you what we hold about you;
- Correct anything wrong β most fields you can edit yourself in the app;
- Delete your account and data, subject to the payment records we must keep by law;
- Export your data in a portable format;
- Withdraw consent to optional processing.
Email cache.creators@protonmail.com from your registered address. We respond within 30 days, free of charge. We will never charge you for exercising a data right, and we do not treat you differently for using one.
If you are in the EU or UK
Under the GDPR / UK GDPR you also have the right to restrict or object to processing based on legitimate interests, and the right to lodge a complaint with your supervisory authority β your national data protection authority in the EU, or the Information Commissioner's Office in the UK. We would rather you told us first, but you do not have to.
If you are in India
Under the Digital Personal Data Protection Act, 2023 you may nominate another person to exercise your rights in the event of death or incapacity, and you may take an unresolved grievance to the Data Protection Board of India after raising it with our Grievance Officer.
If you are in California
You have the right to know what is collected, to delete it, to correct it, and to opt out of βsaleβ or βsharingβ of personal information. We do not sell or share personal information, and we do not use it for cross-context behavioural advertising β so there is nothing to opt out of, but the rights above still apply and are exercised the same way.
9. Security
- All traffic is encrypted over HTTPS.
- Passwords are hashed by our authentication provider; we never see them.
- Database row-level security means one account cannot read another's data, even if it tries.
- The credentials used to reach the AI provider are held on our server only. They are never sent to a browser, and where an account holds its own key it is encrypted at rest.
No system is perfectly secure. If a breach affects your data, we will tell you and the relevant authority without undue delay.
10. Cookies and local storage
We use no advertising or third-party tracking cookies. We use:
- Local storage β to hold your app data on your device, which is what makes Cache Club work offline;
- A session cookie from our authentication provider, to keep you signed in.
11. Children
Cache Club is not for anyone under 18. We do not knowingly collect data from children. If you believe a child has registered, contact us and we will delete the account.
12. Changes
We may update this policy. Material changes are notified by email or in the app at least 14 days before taking effect. The date at the top always shows the current version.
13. Contact and grievances
For anything about this policy, or to exercise any right in section 8, write to us:
Cache Club β operated by Shivani Wankhede (Sole Proprietorship)
Business address: Parmar Sqaure CHS, Opp. IT Ground, Near Zensar Technologies, Kharadi, Pune β 411014, Maharashtra, India
Mobile: +91 81214 28947
Grievance Officer
Under the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021 and the Digital Personal Data Protection Act, 2023, complaints that normal support does not resolve can be escalated to our Grievance Officer:
Name: Shivani Wankhede
Designation: Grievance Officer & Data Protection Contact
Email: cache.creators@protonmail.com
Address: As above.
We acknowledge every complaint within 48 hours and resolve it within 30 days of receipt.
If we do not resolve it
- India: the Data Protection Board of India, after raising it with the Grievance Officer above.
- EU: your national data protection supervisory authority.
- UK: the Information Commissioner's Office (ICO).
- Elsewhere: your local data protection or consumer authority. We will cooperate with any of them.
You do not have to come to us first β but we would rather you did, because we can usually fix it the same week.
See also the Contact page for support hours and response times.