PRIVACY POLICY

How AIRTH collects, uses, shares and protects your information when you use the AIRTH Consumer App to connect AIRTH air-quality devices over Wi-Fi and to view air quality at nearby locations.

Effective from: 1 September 2026
Last updated: 1 September 2026
Version: 1.0
Applies to: AIRTH Consumer App (Android & iOS)
Governing law: India
Primary statute: DPDP Act, 2023

CONTENTS

1. Scope and acceptance
2. Who we are
3. Definitions
4. Consent and legal basis
5. Information we collect
6. Information we do not collect
7. Device permissions
8. Connecting to your Device
9. Location data
10. How we use information
11. Sharing and disclosure
12. Cross-border transfers
13. Retention
14. Security
15. Your rights
16. Deleting your account
17. Children
18. Third-party services and links
19. Air-quality data — accuracy and permitted use
20. Not a medical or safety device
21. Service availability
22. Limitation of liability
23. Indemnity
24. Modified devices, rooted phones and misuse
25. Business transfers
26. Changes to this policy
27. Governing law and disputes
28. Grievance redressal
29. Region-specific rights
30. Severability, waiver and entire agreement

1. SCOPE AND ACCEPTANCE

This Privacy Policy governs the AIRTH Consumer App (the “App”), the AIRTH air-quality monitoring devices you connect through it (the “Devices”), and the associated cloud services, notifications and support channels (together, the “Services”).

It is published in accordance with Rule 3(1) of the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, Rule 4 of the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, and the Digital Personal Data Protection Act, 2023 (“DPDP Act”) and the rules made under it. It also serves as the notice required under Section 5 of the DPDP Act.

By downloading, installing, registering for, or using the App, you confirm that you have read and understood this Policy and that you consent to the collection and processing of your personal data as described here. If you do not agree with any part of this Policy, you must not install or use the App, and you should uninstall it and discontinue use of the Services.

This Policy should be read together with the AIRTH Terms of Service, the AIRTH warranty terms, and any annual maintenance contract (AMC) terms applicable to your Device. Where a conflict arises on a matter of personal data, this Policy prevails on that matter only.

SUMMARY — NOT A SUBSTITUTE FOR THE FULL TEXT
We collect the minimum needed to let you set up and control your Device, to show you indoor and nearby outdoor air quality, and to support and service your product. We do not sell your personal data. We do not access your camera, microphone, contacts, SMS or call logs. The App does not use Bluetooth at all. During setup your Wi-Fi password passes from your phone straight to your Device to put it on your own network — it never reaches AIRTH’s servers. Your name and mobile number are collected at sign-up only with your consent. Air-quality readings shown in the App are indicative environmental information only — they are not medical advice, not regulatory measurements, and must never be relied on for safety, emergency or health decisions.

2. WHO WE ARE

The App and Services are provided by Airth Research Private Limited, a company incorporated under the Companies Act, 2013 (CIN U73200DL2020PTC365055), with its registered office at Plot No. C-51B, Rama Park, Najafgarh Road, Uttam Nagar, New Delhi, West Delhi, Delhi 110059 (“AIRTH”, “we”, “us” or “our”).

For the purposes of the DPDP Act, AIRTH is the Data Fiduciary in respect of the personal data described in this Policy. Where the General Data Protection Regulation (EU) 2016/679 (“GDPR”) applies, AIRTH is the controller.

Privacy contact: Akshat Jain, Software Developer — privacy@airth.in
Grievance Officer (India): Shahana Khan, Customer Support — grievance@airth.in, +91 87005 29995
Postal address: Plot No. C-51B, Rama Park, Najafgarh Road, Uttam Nagar, New Delhi, West Delhi, Delhi 110059
General support: hello@airth.in

3. DEFINITIONS

Terms used throughout this Policy

Personal data
Any data about an individual who is identifiable by or in relation to such data, as defined in Section 2(t) of the DPDP Act.

Data Principal
The individual to whom the personal data relates — in most cases, you. Referred to as the “data subject” under GDPR.

Data Fiduciary
The person who determines the purpose and means of processing personal data. AIRTH is the Data Fiduciary under this Policy.

Data Processor
A third party that processes personal data on AIRTH’s behalf and on AIRTH’s instructions, under a written contract.

Device Data
Sensor readings, operating state, diagnostics and identifiers generated by an AIRTH Device.

Ambient AQI Data
Outdoor air-quality information for nearby locations, sourced from third-party monitoring networks, government stations or modelled data providers.

Processing
Any operation performed on personal data, including collection, storage, use, sharing, alteration, retention and erasure.

SPDI
Sensitive personal data or information as defined in Rule 3 of the SPDI Rules, 2011 — including passwords and financial information.

4. CONSENT AND LEGAL BASIS

4.1 Consent

We process your personal data on the basis of your free, specific, informed, unconditional and unambiguous consent, given by a clear affirmative action, as required by Section 6 of the DPDP Act. Consent is requested at the point of collection, itemised by purpose, and limited to the personal data necessary for the specified purpose.

In practice: before you provide your name and mobile number at sign-up, the App shows you an itemised notice setting out what is being collected, the purpose of each item, how to withdraw consent, and how to complain to the Data Protection Board of India. Your account is created only after you give that consent by a clear affirmative action. We do not use pre-ticked boxes, we do not treat continued use of the App as consent, and we do not bundle unrelated purposes into a single consent.

4.2 Legitimate uses

Where the DPDP Act permits, we may also process personal data for certain legitimate uses without separate consent — including where you have voluntarily provided data for a specified purpose and have not indicated an objection, for compliance with any law or judgment in force in India, for responding to a medical emergency or threat to life, and for taking measures to provide assistance during a disaster or breakdown of public order.

4.3 Withdrawal of consent

You may withdraw your consent at any time, with the same ease with which it was given, through the App’s privacy settings or by writing to privacy@airth.in. Withdrawal takes effect prospectively and does not affect the lawfulness of processing carried out before withdrawal.

Consequence of withdrawal. Some processing is necessary for the App to function. If you withdraw consent for that processing, we will cease it and, where the affected data is essential to the Service, the associated feature or your account may no longer be available. Withdrawal of consent does not entitle you to a refund of any amount already paid for a Device, subscription or AMC, except as required by applicable law.

4.4 Consent Managers

Once the framework under the DPDP Act is operational, you may give, manage, review and withdraw your consent through a Consent Manager registered with the Data Protection Board of India. We will honour valid instructions received through such a Consent Manager.

4.5 Legal bases where GDPR applies

Article 6 GDPR bases relied upon

Consent, Art. 6(1)(a)
Location access, optional analytics, marketing communications, push notifications.

Contract, Art. 6(1)(b)
Account creation, Device pairing and control, warranty and AMC administration, customer support.

Legal obligation, Art. 6(1)(c)
Tax and accounting records, statutory retention, lawful requests from authorities.

Legitimate interests, Art. 6(1)(f)
Security monitoring, fraud and abuse prevention, aggregated product improvement, defence of legal claims.

Vital interests, Art. 6(1)(d)
Rare cases involving a threat to life or a medical emergency.

5. INFORMATION WE COLLECT

We collect only what the Services need. The categories below are exhaustive for the App as at the effective date of this Policy.

5.1 Account and identity data

•  Name, mobile number and email address — you provide these yourself when you create an account, and we collect them only with your consent, given after the itemised notice described in Section 4. We do not obtain your name or number from your phone, your SIM, your contacts, or any third-party source
•  Account password, stored only as a salted cryptographic hash — we never store or have visibility of your password in plain text
•  Profile preferences: language, units, notification settings, temperature and AQI index preference
•  Where you sign in through a third-party identity provider, the basic profile identifiers that provider returns to us — we do not receive your password for that provider

5.2 Device and pairing data

•  Your AIRTH Device’s serial number, model, MAC address and firmware version — these identify AIRTH hardware, not your phone and not any other device you own
•  The name and room label you assign to a Device
•  Pairing, provisioning and connection logs, including timestamps and failure reasons
•  Setup and connection diagnostics — signal quality, connection success or failure — and the name (SSID) of the network your Device is connected to, so we can help you when it drops offline. See Section 8

5.3 Air-quality and operational data from your Device

•  Sensor readings, which may include particulate matter (PM2.5, PM10), temperature, relative humidity, volatile organic compounds and CO2-equivalent, depending on your Device model
•  Operating state: power status, fan or mode setting, filter runtime and remaining filter life, error and fault codes
•  Device uptime, connectivity quality and over-the-air update status

Device Data is associated with your account and with the location you assign to the Device so that we can display history, trends and filter-life estimates.

5.4 Location data

Described in full in Section 9. In summary, we use location to show air quality near you, and on older Android versions because the operating system requires it before an app may see Wi-Fi networks.

5.5 Ambient AQI data

Outdoor air-quality readings for nearby places are not measured by AIRTH. They are retrieved from third-party sources, which may include government monitoring networks such as the Central Pollution Control Board’s CAAQMS stations, and independent or modelled data providers, currently OpenAQ and the Google Air Quality API. To retrieve them we send an approximate location — a coordinate or region — to the relevant provider or to our own servers acting as an intermediary.

5.6 Transaction, warranty and service data

•  Order reference, purchase date, invoice number, Device registration and warranty status
•  AMC plan, plan validity and service-visit history
•  Service address and PIN code, where you request installation or servicing

We do not collect or store card numbers, CVV, UPI PINs, net-banking credentials or bank account numbers. Payments, where applicable, are processed by PCI-DSS compliant payment gateways or by the Apple App Store or Google Play. We receive only a transaction reference and status.

5.7 App usage, diagnostics and technical data

•  Device model, OS version, app version, screen and locale settings
•  Crash reports, stack traces, exception logs and performance metrics
•  Screens visited, features used, session duration, and in-app events
•  Pseudonymous in-app interaction data — which screens you open, where you tap and scroll, and how long a session lasts — collected through Microsoft Clarity so we can find screens that confuse people or fail. This records how you move through the App, not the content of anything you type
•  IP address and derived approximate region, and access timestamps
•  A pseudonymous app instance identifier and, where applicable, a mobile advertising identifier — used only for attribution and analytics, never for cross-app tracking without your consent

5.8 Communications

•  Support tickets, emails, chat transcripts and call records with our support team
•  Push notification tokens, so we can send Device alerts and service reminders
•  Feedback, ratings, survey responses and product reviews you choose to submit

6. INFORMATION WE DO NOT COLLECT

For the avoidance of doubt, the App does not collect, access, request or transmit any of the following:

•  Audio from your microphone, or images or video from your camera, other than a photograph you deliberately attach to a support ticket
•  Your contacts, call logs, SMS or other messages, or the content of your clipboard
•  Anything over Bluetooth. The App does not use Bluetooth at all — it requests no Bluetooth permission, performs no Bluetooth scanning or pairing, and has no technical means of detecting any Bluetooth device around you
•  The password to your own Wi-Fi network. You enter it during setup so your Device can join your network, but it passes from your phone straight to the Device — it never reaches AIRTH’s servers and no member of AIRTH staff can see it
•  Your phone’s list of saved Wi-Fi networks, or a retained record of the Wi-Fi networks around you. Network names in range are read during setup so you can pick yours, and are not kept afterwards
•  Biometric data, including fingerprints or face data — where you unlock the App with biometrics, authentication is performed entirely by your phone’s operating system and no biometric data reaches AIRTH
•  Health records, medical history or any data about physical or mental health conditions
•  Caste, religion, political affiliation, sexual orientation or any other special-category data
•  The content of your files, photo library or documents
•  A list of other applications installed on your phone
•  Continuous background location, unless you separately and explicitly enable a feature that requires it and grant the corresponding permission

AIRTH Devices are air-quality sensors. They contain no microphone, no camera and no audio or video recording capability, and they do not capture the content of any communication.

7. DEVICE PERMISSIONS

The App requests only the permissions it needs, at the moment it needs them. You may decline any permission or revoke it later in your phone settings; the table sets out what stops working if you do.

Android permissions

ACCESS_FINE_LOCATION, ACCESS_COARSE_LOCATION
Status: Optional
Why we need it and what happens if you decline: To show air quality at your current and nearby locations, and — on older Android versions — because the operating system requires location permission before an app may see Wi-Fi networks at all. If declined: nearby AQI is unavailable, and on older Android versions the App may not be able to find your Device’s network. You can still search for a city manually and control an already-paired Device.

ACCESS_WIFI_STATE, CHANGE_WIFI_STATE, NEARBY_WIFI_DEVICES
Status: Required for setup
Why we need it and what happens if you decline: To find your AIRTH Device’s own Wi-Fi network and connect your phone to it. This is the only network the App joins on your behalf. If declined: the App cannot reach your Device.

INTERNET, ACCESS_NETWORK_STATE
Status: Required
Why we need it and what happens if you decline: To communicate with AIRTH cloud services and to detect whether you are online.

POST_NOTIFICATIONS
Status: Optional
Why we need it and what happens if you decline: To alert you to air-quality thresholds, filter replacement, Device faults and service reminders. If declined: you will not receive alerts.

CAMERA
Status: Optional
Why we need it and what happens if you decline: Only to scan a QR code printed on the Device or its packaging during setup. No image is stored or transmitted; the frame is decoded on your phone and discarded. If declined: enter the Device code manually.

FOREGROUND_SERVICE
Status: Conditional
Why we need it and what happens if you decline: To keep a firmware update or a Device provisioning session alive while the screen is off. Runs only during that operation.

iOS permissions

Location — While Using
Status: Optional
Why we need it and what happens if you decline: Nearby AQI. You may grant Precise or Approximate location; approximate is sufficient for the nearby-AQI feature. If declined: search for a city manually.

Local Network
Status: Required for setup
Why we need it and what happens if you decline: To communicate with your AIRTH Device over its own Wi-Fi network. If declined: the App cannot reach your Device.

Notifications
Status: Optional
Why we need it and what happens if you decline: Air-quality, filter and fault alerts.

Camera
Status: Optional
Why we need it and what happens if you decline: QR-code scanning during setup only.

App Tracking Transparency
Status: Not requested
Why we need it and what happens if you decline: We do not track you across apps and websites owned by other companies, so no ATT prompt is shown.

PROMINENT DISCLOSURE — LOCATION
Before we request location permission, the App displays an in-app explanation stating that AIRTH collects location data to show air quality at nearby locations and to enable Device discovery during setup, and that this happens only while the App is in use. Location is not collected in the background and is not used for advertising.

8. CONNECTING TO YOUR DEVICE

Your AIRTH Device broadcasts its own Wi-Fi network during setup. Your phone joins that network so the App can configure the Device, and you then give the Device your own Wi-Fi details so it can join your network and reach the internet. This section explains exactly what happens to those credentials.

8.1 How setup works

•  The Device broadcasts a Wi-Fi network of its own, identified by the Device name and protected by a setup password supplied with the product
•  Your phone joins that network, and the App communicates with the Device directly over it
•  The App reads the names (SSIDs) of Wi-Fi networks in range so that you can select yours, along with their signal strength and security type so it can warn you about a weak or unsupported network
•  You select your network and enter its password, which is passed to the Device so it can connect
•  Once the Device is on your network, its own setup network is no longer needed for day-to-day use

8.2 What happens to your Wi-Fi password

CREDENTIAL HANDLING
Your Wi-Fi network name and password are collected for one purpose only: to connect your Device to your network. Wi-Fi passwords are “sensitive personal data or information” under the SPDI Rules, 2011, and we handle them on that footing.
Your Wi-Fi password is transmitted directly from your phone to the Device over the Device’s own local setup network. It is not transmitted to AIRTH servers, is not stored in the App once setup completes, and is not accessible to AIRTH personnel. The Device holds it in its own protected memory for the sole purpose of reconnecting to your network, and erases it when the Device is factory reset.
We do not use your Wi-Fi credentials for any other purpose. We do not disclose them to any third party. We do not use them to identify, profile or locate you.

8.3 The App does not use Bluetooth

BLUETOOTH
The AIRTH Consumer App does not use Bluetooth in any form. It requests no Bluetooth permission, performs no Bluetooth scanning or pairing, and has no technical means of detecting any Bluetooth device around you — phones, wearables, headphones, speakers, beacons, vehicles or anything else. No Bluetooth data of any kind is collected, logged or transmitted to AIRTH.

8.4 The Device setup password

PLEASE READ — THE SETUP PASSWORD IS NOT UNIQUE TO YOUR DEVICE
The password protecting a Device’s own setup network is the same across AIRTH Devices of the same model and is supplied with the product. It guards the short setup window; it is not a secret unique to your unit. Anyone within Wi-Fi range of a Device that is sitting in setup mode, and who knows that password, can connect to that Device.
You should therefore complete setup promptly and in a place you control, and avoid leaving a Device in setup mode unattended, in a shared building, or anywhere its network is reachable by people you do not know.

8.5 Your network, your responsibility

You remain responsible for the security of your own Wi-Fi network and router, for the strength of your network password, and for the security of any phone on which the App is installed. AIRTH is not responsible for unauthorised access to a Device or to a network that results from a weak, shared or disclosed network password, a compromised router, an unsecured guest network, or your having granted another person access to your account, your phone or your network.

9. LOCATION DATA

9.1 Why we use it

•  To show the outdoor air quality index for places near you
•  To label a Device with the location you install it at, so you can compare indoor and outdoor readings
•  To route service requests to the correct service area, based on PIN code
•  On older Android versions, because the operating system conditions Wi-Fi visibility on location permission — this is an operating-system requirement, not a use AIRTH makes of your location

9.2 Precision and control

The nearby-AQI feature works with approximate location. Where your operating system offers a choice, you may grant approximate rather than precise location and the feature will continue to function. You may also skip location entirely and search for a city or area by name.

9.3 Foreground only

Location is collected only while the App is open and in use. We do not collect location in the background, we do not run geofences, and we do not build a location history or movement profile. Coordinates sent to obtain ambient AQI are used for that request and are not retained in a form linked to your identity beyond the retention period stated in Section 13.

9.4 No sale, no advertising

We do not sell, rent, licence or otherwise disclose location data to data brokers, advertising networks, or any third party for advertising, profiling or monetisation purposes.

10. HOW WE USE INFORMATION

Purpose limitation — each category is used only as stated

Account and access
Identity data, to create and authenticate your account and secure it against unauthorised access.

Device setup and control
Device and pairing data, network diagnostics, to connect your Device and let you operate it remotely.

Air-quality display
Device Data and approximate location, to show live readings, history, trends and comparisons.

Alerts and reminders
Push tokens, Device Data, to notify you of thresholds, filter life, faults and service dates.

Filter life and maintenance
Runtime and sensor data, to estimate remaining filter life and schedule AMC visits.

Support
Identity, Device, transaction and communication data, to diagnose and resolve your issues.

Warranty and AMC
Transaction and service data, to verify entitlement and administer your plan.

Firmware updates
Device model and firmware version, to deliver correct and secure over-the-air updates.

Product improvement
Aggregated and de-identified usage, performance and sensor data, to improve accuracy, reliability and design. We do not re-identify de-identified data.

Security and abuse prevention
Access logs, IP address, device identifiers, to detect fraud, abuse, credential stuffing and unauthorised access.

Legal compliance
Any category, to the extent required by law, regulation, court order or a lawful request from a government authority.

Marketing
Contact details, only with your separate opt-in consent, and always with a one-click unsubscribe.

10.1 No automated decisions with legal effect

We do not make decisions producing legal or similarly significant effects concerning you based solely on automated processing. Automated logic in the App is limited to threshold alerts, filter-life estimation and fault detection, all of which are advisory.

10.2 New purposes

If we intend to process your personal data for a purpose materially different from those listed above, we will provide a fresh notice and, where required, obtain fresh consent before doing so.

11. SHARING AND DISCLOSURE

OUR COMMITMENT
AIRTH does not sell your personal data. AIRTH does not share your personal data for cross-context behavioural advertising. AIRTH does not disclose your personal data to data brokers.

We disclose personal data only in the circumstances below, and only to the extent necessary.

Recipient categories

Cloud and hosting providers, Amazon Web Services (India region)
All categories, for storage, compute and delivery of the Services under a data processing agreement.

Analytics and product usage, Google Firebase; Microsoft Clarity
Pseudonymous usage, device and crash data, to diagnose defects and improve stability. Microsoft Clarity additionally records in-app interaction data — screens opened, taps, scrolls and session duration — in pseudonymous form, to show us where the App is confusing or broken.

Push notification services, Firebase Cloud Messaging; Apple Push Notification service
Notification tokens and message payloads, to deliver alerts.

Communications providers
Mobile number and email, to send OTPs, transactional messages and service updates.

AQI data providers, OpenAQ; Google Air Quality API
An approximate location or region, to retrieve outdoor air-quality readings. No account identifier is sent.

Payment processors
Transaction amount and reference. We never transmit card or bank credentials because we never hold them.

Service and installation partners
Name, contact number, service address and Device details, only where you request installation, repair or an AMC visit.

Professional advisers
Auditors, lawyers and insurers, under confidentiality obligations, where necessary.

Government and law enforcement
As required by law, or where disclosure is necessary to comply with a legally valid order, to enforce our terms, or to protect the rights, property or safety of AIRTH, our users or the public.

11.1 Processor obligations

Every processor is engaged under a written contract that limits them to processing on our documented instructions, requires appropriate technical and organisational security measures, prohibits use of the data for their own purposes, and obliges them to delete or return the data at the end of the engagement.

11.2 Aggregated and de-identified data

We may create, use, publish and share aggregated or de-identified statistics — for example, average indoor PM2.5 levels across a city — provided the data cannot reasonably be used to identify you. Such data is not personal data and this Policy does not restrict its use.

12. CROSS-BORDER TRANSFERS

Personal data is primarily stored and processed in India, on Amazon Web Services infrastructure located in an Indian region. Some of our processors operate infrastructure or support functions outside India, so limited categories of data may be transferred to and processed in other countries. Specifically, Google (Firebase analytics and messaging, and the Google Air Quality API) and Microsoft (Clarity product analytics) process data on infrastructure outside India. The data reaching them is pseudonymous usage, device, crash and interaction data — not your name, mobile number or Device sensor history.

Where we transfer personal data outside India, we do so in accordance with Section 16 of the DPDP Act and will not transfer to any territory that the Central Government restricts by notification. Where we transfer personal data outside the European Economic Area or the United Kingdom, we rely on an adequacy decision where one exists, and otherwise on Standard Contractual Clauses approved by the European Commission or the UK International Data Transfer Addendum, together with any supplementary measures required following a transfer risk assessment.

You may request a copy of the safeguards applicable to a transfer by writing to privacy@airth.in.

13. RETENTION

We retain personal data only for as long as the purpose for which it was collected is being served, or as required by law — whichever is longer. When the purpose is exhausted and no legal retention obligation applies, we erase the data or irreversibly de-identify it.

Indicative retention schedule

Account and profile data
Retention: Life of account + 90 days
Basis: Grace period for recovery after deletion, then erasure.

Device Data — high resolution
Retention: 90 days
Basis: To display recent history and trends.

Device Data — aggregated
Retention: 24 months
Basis: Long-range trends and filter-life modelling; de-identified thereafter.

Pairing and connection logs
Retention: 180 days
Basis: Troubleshooting and security investigation.

Location coordinates for AQI lookup
Retention: Not retained beyond the session, other than in short-lived server logs
Basis: Purpose exhausted on response.

Support tickets and transcripts
Retention: 36 months
Basis: Warranty administration and dispute defence.

Transaction, invoice and tax records
Retention: 8 financial years
Basis: Companies Act, 2013 and Income-tax Act, 1961.

Warranty and AMC records
Retention: Term of cover + 36 months
Basis: Entitlement verification and limitation period.

Security and access logs
Retention: 180 days
Basis: Rule 3(1)(h) and 4(1) obligations, security monitoring.

Marketing consent records
Retention: Until withdrawal + 3 years
Basis: Evidence of consent.

Data subject to a legal hold
Retention: Until the hold is lifted
Basis: Litigation, investigation or regulatory requirement.

Backups are retained on a rolling cycle and are overwritten in the ordinary course. Where data has been erased from live systems, residual copies in backups are deleted on the next backup rotation and are not restored to live systems except as part of a disaster recovery event.

14. SECURITY

We implement reasonable security practices and procedures as required by Section 8(5) of the DPDP Act and Rule 8 of the SPDI Rules, 2011, proportionate to the nature of the data and the risks involved. These include:

•  Encryption in transit using TLS 1.2 or above for all communication between the App, our servers and your Device’s cloud connection
•  Encryption at rest for stored personal data
•  Passwords stored only as salted hashes using a modern key-derivation function
•  Role-based access control, least-privilege provisioning and multi-factor authentication for administrative access
•  Network segmentation, logging and monitoring of administrative and data access
•  Secure development practices, dependency scanning and periodic vulnerability assessment and penetration testing
•  Signed firmware images, so a Device will reject an update that is not authentically AIRTH’s
•  Contractual security obligations imposed on every processor
•  Employee confidentiality undertakings and privacy training

14.1 Breach notification

In the event of a personal data breach, we will notify the Data Protection Board of India and each affected Data Principal in the form and manner prescribed under the DPDP Act and the rules made under it. Where GDPR applies, we will notify the competent supervisory authority within 72 hours of becoming aware of the breach where the notification threshold is met, and affected individuals without undue delay where the breach is likely to result in a high risk to their rights and freedoms.

LIMITS OF SECURITY — PLEASE READ
No method of transmission over the internet and no method of electronic storage is completely secure. While we apply security measures designed to protect your personal data, we cannot and do not guarantee absolute security, and we do not warrant that the Services will be uninterrupted, error-free or free of viruses or other harmful components.
You are responsible for keeping your account credentials confidential, for using a strong and unique password, for securing the phone on which the App is installed, and for notifying us immediately at privacy@airth.in if you suspect unauthorised access. AIRTH is not liable for loss arising from your failure to do so, from your sharing of credentials, or from a compromise of your own device, network or email account.

15. YOUR RIGHTS

Subject to verification of your identity, you have the following rights in respect of your personal data.

Rights available to all users under the DPDP Act

Access, s. 11
A summary of the personal data we process about you, the processing activities undertaken, and the identities of other Data Fiduciaries and Processors with whom it has been shared.

Correction and erasure, s. 12
Correction of inaccurate or misleading data, completion of incomplete data, updating, and erasure of data no longer necessary for the purpose — unless retention is required by law.

Grievance redressal, s. 13
A readily available means to raise a grievance, which we must respond to within the prescribed period. See Section 28.

Nomination, s. 14
To nominate another individual to exercise your rights in the event of your death or incapacity.

Withdraw consent, s. 6(4)–(6)
To withdraw consent at any time, as easily as it was given.

15.1 How to exercise them

Use the privacy controls in the App, or write to privacy@airth.in from the email address registered to your account. We will respond within 30 days, or within any shorter period prescribed by applicable law. If we need more time because of the complexity or volume of requests, we will tell you why and when to expect a response.

15.2 Verification

To protect you, we will verify your identity before acting on a request. If we cannot verify it to a reasonable degree of certainty, we may decline to act and will tell you why. Requests made by an authorised agent must be accompanied by proof of authorisation.

15.3 Your duties

Section 15 of the DPDP Act places duties on you as a Data Principal, including not impersonating another person while providing your data, not suppressing material information, not raising a false or frivolous grievance, and providing only verifiably authentic information when seeking correction or erasure. Non-compliance may attract a penalty under the DPDP Act, and we may decline to act on a request that we reasonably determine to be false, frivolous, vexatious or repetitive.

15.4 Limits

We may decline or limit a request where acting on it would compromise the rights of another person, breach a legal obligation or court order, prejudice an ongoing investigation, or be manifestly unfounded or excessive. We will tell you the reason.

16. DELETING YOUR ACCOUNT

You may delete your AIRTH account at any time:

•  In the App — Profile → Account → Delete Account
•  On the web — https://airth.in/account-deletion
•  By email — privacy@airth.in from your registered address

What deletion does

Account, profile, preferences
Deleted after a 90-day recovery window.

Device pairings and names
Deleted; Devices are unlinked and returned to unprovisioned state on factory reset.

Device Data history
Deleted or irreversibly de-identified.

Support history
Retained for the period in Section 13, then deleted.

Invoices and tax records
Retained as required by law; cannot be deleted on request.

Warranty and AMC entitlement
Deleting your account may end your ability to claim warranty or AMC service, since we will no longer hold the record linking you to the Device.

You may alternatively request deletion of specific data without closing your account. Uninstalling the App does not by itself delete data held on our servers.

17. CHILDREN

Under the DPDP Act, a child is an individual who has not completed eighteen years of age. The App is intended for use by adults. We do not knowingly create accounts for, or knowingly process the personal data of, a child except with the verifiable consent of a parent or lawful guardian, obtained in the manner prescribed under the DPDP Act.

We do not undertake tracking or behavioural monitoring of children, and we do not direct advertising at children.

If you are a parent or guardian and believe a child has provided us personal data without your consent, write to privacy@airth.in. On verification we will delete the data and close the account.

Where GDPR applies, we do not knowingly process the personal data of a child below the age of digital consent in their member state without parental authorisation. Where COPPA applies, the App is not directed to children under 13 and we do not knowingly collect their personal information.

18. THIRD-PARTY SERVICES AND LINKS

The App may link to, embed or interoperate with third-party services — app stores, payment gateways, mapping and AQI data providers, identity providers, and support tools. Those services are operated by independent third parties under their own terms and privacy policies.

We do not control and are not responsible for the privacy practices, content, accuracy, availability or security of any third-party service. Your use of a third-party service is governed by that party’s terms, and we encourage you to read them. Any dispute arising from a third-party service is between you and that provider.

Where a third party acts as our processor, we remain accountable for their processing of your personal data on our instructions, as described in Section 11. Where a third party acts as an independent controller — for example, an app store — we are not accountable for their independent processing.

18.1 Cookies and similar technologies

The App itself does not use browser cookies. Our software development kits and any in-app web views may use local storage, device identifiers and similar technologies to keep you signed in, remember preferences and measure performance. Our website’s use of cookies is described in the cookie notice published there.

19. AIR-QUALITY DATA — ACCURACY AND PERMITTED USE

This section is important. It defines what the numbers in the App are, and — just as importantly — what they are not.

19.1 Indicative information only

All air-quality values displayed in the App, whether measured by an AIRTH Device or sourced from a third party, are provided for general informational and awareness purposes only, on an “as is” and “as available” basis. They are indicative estimates, not certified measurements.

19.2 Limitations of sensor measurement

AIRTH Devices use consumer-grade sensors. Their readings are not equivalent to, and should not be compared with, reference-grade or regulatory monitoring instruments. Accuracy is affected by, among other things:

•  Ambient temperature and relative humidity, which affect optical particle counting
•  Sensor drift and ageing over the life of the Device
•  Placement — proximity to windows, doors, cooking areas, air outlets, direct sunlight or obstructions
•  Particle composition, size distribution and refractive index, which optical sensors cannot distinguish
•  Cross-sensitivity of gas sensors to compounds other than the target compound
•  Calibration state, firmware version, filter condition and general maintenance

We do not warrant that Device readings are accurate, complete, current, calibrated, or fit for any particular purpose.

19.3 Limitations of nearby AQI

Nearby air-quality information is not measured by AIRTH. It is obtained from third-party monitoring networks, government stations and modelled datasets. Accordingly:

•  The nearest reporting station may be several kilometres from you, and conditions at your exact position may differ substantially
•  Values may be delayed, interpolated, modelled, provisional, revised or unavailable
•  Stations go offline for maintenance, and providers change methodology without notice
•  Different index standards — the CPCB National AQI, the US EPA AQI and others — convert the same pollutant concentration into different index values and category labels

AIRTH does not verify, endorse, control or accept responsibility for third-party air-quality data, and disclaims all liability arising from its accuracy, completeness, timeliness or availability.

19.4 Prohibited uses

DO NOT RELY ON APP DATA FOR THESE PURPOSES
Air-quality data from the App and Devices must not be used for: regulatory reporting or environmental compliance; occupational health and safety monitoring or workplace exposure assessment; clean-room, laboratory, pharmaceutical, food-processing or industrial process control; legal proceedings, insurance claims or expert evidence; property valuation or transaction decisions; academic or scientific publication without independent validation; or any purpose where an inaccurate reading could result in injury, illness, financial loss or legal exposure.

19.5 Your acknowledgement

You acknowledge that you use air-quality information from the App at your own risk and on your own judgment, and that AIRTH accepts no liability for any decision, action or omission by you or any third party taken in reliance on it.

20. NOT A MEDICAL OR SAFETY DEVICE

HEALTH AND SAFETY — CRITICAL
AIRTH Devices and the App are not medical devices. They are not registered, approved or certified as medical devices under the Medical Devices Rules, 2017, or under any equivalent law in any jurisdiction. They do not diagnose, treat, cure, mitigate or prevent any disease or condition, and nothing in the App constitutes medical advice.
AIRTH Devices are not life-safety equipment. They are not smoke detectors, fire alarms, carbon-monoxide detectors, combustible-gas detectors, radon detectors or any other form of safety alarm, and they must never be installed or relied upon in place of one. They will not reliably detect fire, smoke, carbon monoxide, gas leaks, chemical spills or any other hazard, and they are not designed or certified to alert you to a life-threatening condition.
Always install and maintain properly certified smoke and carbon-monoxide alarms as required in your jurisdiction. In an emergency, call the emergency services — do not rely on the App.

If you have asthma, chronic obstructive pulmonary disease, cardiovascular disease, an allergy, a respiratory infection, or any other condition affected by air quality — or if you are pregnant, elderly, or caring for an infant — consult a qualified medical practitioner. Never delay seeking medical advice, disregard medical advice, or alter prescribed treatment because of something shown in the App.

The App does not process health data, does not infer health conditions from your Device usage, and its alerts are generic environmental thresholds, not personalised health guidance.

21. SERVICE AVAILABILITY

The Services depend on your internet connection, your Wi-Fi network and router, your phone and its operating system, third-party cloud infrastructure, push-notification gateways, and third-party data feeds — none of which AIRTH controls.

To the maximum extent permitted by law, the Services are provided on an “as is” and “as available” basis without warranties of any kind, whether express, implied or statutory, including implied warranties of merchantability, fitness for a particular purpose, accuracy and non-infringement. We do not warrant uninterrupted or error-free operation, that alerts or notifications will be delivered, delivered on time, or delivered at all, or that defects will be corrected.

We may modify, suspend, limit or discontinue any feature of the Services, in whole or in part, with notice where reasonably practicable. Where a feature is discontinued permanently and you have paid specifically for it, we will provide a pro-rata refund of the unexpired portion or an equivalent remedy, as required by applicable law.

Nothing in this section affects your statutory rights in respect of the physical Device under the Consumer Protection Act, 2019 or the applicable warranty terms.

22. LIMITATION OF LIABILITY

To the maximum extent permitted by applicable law, and subject always to clause 22.3:

22.1 Excluded losses

AIRTH, its directors, officers, employees, affiliates, agents, suppliers and licensors shall not be liable for any indirect, incidental, special, consequential, exemplary or punitive damages, or for any loss of profits, revenue, business, goodwill, anticipated savings, or loss or corruption of data, howsoever arising, whether in contract, tort (including negligence), breach of statutory duty or otherwise, and whether or not AIRTH was advised of the possibility of such loss.

Without limiting the generality of the above, AIRTH shall not be liable for any loss, injury, illness, aggravation of a condition, or damage arising from:

•  Reliance on any air-quality reading, index value, alert, threshold, forecast or recommendation displayed in the App
•  Inaccuracy, delay, interruption, unavailability or discontinuation of third-party air-quality data
•  Failure of a notification or alert to be generated, transmitted or received
•  Failure or malfunction of a Device, sensor, filter or firmware, except to the extent covered by the applicable product warranty
•  Interruption of internet, Wi-Fi, cellular or cloud connectivity, including loss of connection to your Device’s own network
•  Unauthorised access to your account or Device arising from your credentials, phone or network being compromised
•  Any act or omission of a third-party service, service partner or data provider

22.2 Aggregate cap

AIRTH’s total aggregate liability arising out of or in connection with the App, the Services or this Policy, whether in contract, tort or otherwise, shall not exceed the greater of (a) the total amount actually paid by you to AIRTH for the Services in the twelve months immediately preceding the event giving rise to the claim, or (b) INR 1,000.

22.3 What cannot be excluded

MANDATORY CARVE-OUT — KEEP THIS CLAUSE
Nothing in this Policy excludes or limits AIRTH’s liability for death or personal injury caused by its negligence, for fraud or fraudulent misrepresentation, for wilful misconduct or gross negligence, or for any other liability that cannot lawfully be excluded or limited under the Indian Contract Act, 1872, the Consumer Protection Act, 2019, the DPDP Act, or any other applicable law. Where any jurisdiction does not allow the exclusion or limitation of certain damages, the exclusions above apply only to the extent permitted there, and the remaining provisions continue in full force.

22.4 Basis of the bargain

You acknowledge that the limitations in this section are a fundamental basis of the bargain between you and AIRTH, that they reflect a fair allocation of risk given the price paid for the Services, and that AIRTH would not provide the Services on these terms without them.

23. INDEMNITY

You agree to indemnify, defend and hold harmless AIRTH, its affiliates and their respective directors, officers, employees and agents from and against any claim, demand, proceeding, loss, liability, damage, cost or expense (including reasonable legal fees) arising out of or in connection with:

•  Your breach of this Policy, the Terms of Service, or any applicable law
•  Your provision of another person’s personal data to us without their consent or lawful authority
•  Your use of the Services for any prohibited purpose listed in clause 19.4
•  Any republication, redistribution or commercial exploitation by you of air-quality data obtained from the App
•  Your unauthorised modification of a Device, its firmware, or the App

We will notify you of any claim for which we seek indemnity and may, at our option, assume its exclusive defence and control at your cost.

24. MODIFIED DEVICES, ROOTED PHONES AND MISUSE

The security assurances in this Policy assume an unmodified App running on an unmodified operating system, and an AIRTH Device running AIRTH-signed firmware.

AIRTH gives no assurance and accepts no liability in respect of any of the following, and may suspend or terminate access to the Services where it detects them:

•  Use of the App on a rooted, jailbroken or otherwise compromised phone
•  Installation of the App from a source other than the Google Play Store or Apple App Store, or use of a modified, repackaged or cloned build
•  Modification, replacement or downgrading of Device firmware, or connection of a Device to unauthorised third-party software or gateways
•  Reverse engineering, decompilation, automated scraping, or unauthorised access to our APIs
•  Sharing account credentials, or granting a third party access to your account or Device
•  Use of the Services in breach of applicable law

25. BUSINESS TRANSFERS

If AIRTH is involved in a merger, acquisition, financing, reorganisation, sale of assets, insolvency or similar transaction, personal data may be transferred as part of that transaction, subject to the recipient being bound by commitments no less protective than those in this Policy. We will notify you through the App or by email before your personal data becomes subject to a materially different privacy policy, and you will retain the ability to withdraw consent and delete your account.

26. CHANGES TO THIS POLICY

We may update this Policy to reflect changes to the Services, our practices, or legal requirements. The “Last updated” date at the top of this Policy always shows the current version, and we maintain an archive of prior versions available on request.

Where a change is material — for example, a new category of personal data, a new purpose, or a new class of recipient — we will give you reasonable advance notice through the App or by email and, where the law requires it, obtain fresh consent before the change takes effect.

Your continued use of the Services after a non-material change takes effect constitutes acceptance of the updated Policy. If you do not accept it, you may withdraw consent and delete your account under Section 16.

27. GOVERNING LAW AND DISPUTES

This Policy is governed by and construed in accordance with the laws of India, without regard to conflict of laws principles.

Escalation. Before commencing any formal proceeding, you agree to first raise the matter with our Grievance Officer under Section 28 and to allow thirty days for resolution. Many issues are resolved at this stage.

Arbitration. Any dispute, controversy or claim arising out of or relating to this Policy that is not resolved through the grievance process shall be referred to and finally resolved by arbitration under the Arbitration and Conciliation Act, 1996, by a sole arbitrator appointed by mutual agreement. The seat and venue of arbitration shall be New Delhi, India, and the language shall be English. The award shall be final and binding.

Jurisdiction. Subject to the above, the courts at New Delhi, India shall have exclusive jurisdiction.

Consumer rights preserved. Nothing in this section deprives you of the right to approach a Consumer Commission under the Consumer Protection Act, 2019, or the Data Protection Board of India under the DPDP Act, or any other statutory forum whose jurisdiction cannot be ousted by agreement. Where you are a consumer resident in the European Union or the United Kingdom, this section does not deprive you of the protection of the mandatory laws of your country of residence.

28. GRIEVANCE REDRESSAL

If you have a question, concern or complaint about this Policy or about how we handle your personal data, contact our Grievance Officer, appointed under Rule 5(9) of the SPDI Rules, 2011 and Rule 3(2) of the Intermediary Guidelines Rules, 2021, and designated for the purposes of Section 13 of the DPDP Act.

Grievance Officer: Shahana Khan — Customer Support
Email: grievance@airth.in
Telephone: +91 87005 29995, Monday to Saturday, 10:00–18:00 IST
Post: Plot No. C-51B, Rama Park, Najafgarh Road, Uttam Nagar, New Delhi, West Delhi, Delhi 110059

Our response commitment

Acknowledgement of your complaint
Within 24 hours

Resolution of the complaint
Within 15 days of receipt

Response to a rights request under Section 15
Within 30 days

Response where GDPR applies
Within one month, extendable by two further months for complex requests, with notice

If you are not satisfied with our response, you may escalate the matter to the Data Protection Board of India in the manner prescribed under the DPDP Act. Where GDPR applies, you may lodge a complaint with the supervisory authority in your country of residence, place of work or place of the alleged infringement.

29. REGION-SPECIFIC RIGHTS

29.1 European Economic Area and United Kingdom

Where GDPR or the UK GDPR applies, you additionally have the rights to: access your personal data and receive a copy; rectification; erasure (“right to be forgotten”); restriction of processing; data portability in a structured, commonly used, machine-readable format; objection to processing based on legitimate interests or to direct marketing; withdrawal of consent; and to lodge a complaint with a supervisory authority. You also have the right not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects — we do not make such decisions.

29.2 California

Where the California Consumer Privacy Act as amended by the CPRA applies, you have the rights to know what personal information is collected, used, disclosed and shared; to delete personal information; to correct inaccurate personal information; to opt out of sale or sharing; to limit the use of sensitive personal information; and to be free from discrimination for exercising these rights.

AIRTH has not sold or shared personal information in the preceding twelve months, and does not sell or share the personal information of any consumer, including any consumer under sixteen years of age. We use sensitive personal information — precise geolocation, where you grant it — only to perform the services you requested, which is a permitted purpose that does not trigger the right to limit.

29.3 Other jurisdictions

If you reside in a jurisdiction with data protection rights not listed above, write to privacy@airth.in and we will honour rights available to you under applicable law.

30. SEVERABILITY, WAIVER AND ENTIRE AGREEMENT

Severability. If any provision of this Policy is held invalid, unlawful or unenforceable by a court or competent authority, that provision shall be modified to the minimum extent necessary to make it enforceable, or if modification is not possible, severed. The remaining provisions shall continue in full force and effect.

No waiver. Our failure or delay in enforcing any provision is not a waiver of that provision or of any other, and no single or partial exercise of a right precludes any further exercise of it.

Entire agreement. This Policy, together with the AIRTH Terms of Service and applicable warranty or AMC terms, constitutes the entire agreement between you and AIRTH regarding the processing of your personal data, and supersedes all prior understandings on that subject.

Language. This Policy is published in English. Where a translation is provided for convenience and there is a conflict, the English version prevails, except where applicable law requires otherwise.

Assignment. You may not assign your rights under this Policy. AIRTH may assign its rights and obligations to an affiliate or in connection with a transaction described in Section 25.

AIRTH Consumer App — Privacy Policy v1.0 Effective 1 September 2026 privacy@airth.in grievance@airth.in
 

Company

About Us
Contact Us
Technology
Track Order

For Homes

Split AC Air Purifier

Air Purifier for Cooler

Smart Air Quality Monitor

Window AC Air Purifier

Cassette AC Air Purifier

For Business

Commercial Solution

FCU Air Purifier

AHU Filter

Fresh Air Unit

Resources

Blog
Warranty
Privacy & Policy
Terms & Conditions

Replacement Policy

Register Complaint
Become Channel Partner

Bulk Order

Connect

907, 10th Floor, Westend Mall, Janakpuri, New Delhi - 110058

8700529995

hello@airth.in

Copyright © 2026 AIRTH. All Rights Reserved.