illustration

Privacy Policy

This Privacy Policy explains how Urban Restora Foundation ("Urban Restora", "we", "us", or "our") handles personal data when you use Know2SayNo, including the Hope Agent chat, support-resource finder, church directory, self-assessments, and related website features.

Version: 1.0

Effective: September 9, 2026

Last updated: September 9, 2026

Approval: Approved

1. Who operates Know2SayNo

Know2SayNo is operated by:

Urban Restora Foundation

2EC 313, HRBR 3rd Block

Kalyan Nagar, Bangalore 560084, India

Email: webmaster@urbanrestora.com

Anand Mathew is our Grievance Officer. You may contact him at the address or email above with a privacy complaint or request.

2. Important limits of the service

Know2SayNo is intended only for adults aged 18 to 120. Hope Agent is an automated, faith-informed support tool. It is not a doctor, therapist, emergency service, or substitute for professional care.

Hope Agent is account-free: we do not ask you to create an account or provide your name. It is not necessarily anonymous. The profile is pseudonymous, and information you type—such as names, places, health details, or a distinctive personal story—may identify you directly or indirectly. Please avoid including information that is not needed for the conversation.

If anyone is in immediate danger, contact local emergency services or go to the nearest emergency department.

3. Information we collect

Depending on the feature you use, we collect or process:

- Hope Agent onboarding information: your selected faith or no-faith preference, exact age, gender selection, and approximate country, region, and city inferred from trusted coarse hosting metadata in production, plus the version of the chat notice you accepted and the date and time of consent.

- Chat information: messages you send, Hope Agent responses, conversation timestamps and status, the AI provider and model used, rule-based safety categories, and records of resources displayed in the chat.

- Pseudonymous credentials: a random browser session token and a one-time deletion code. The readable values are shown or stored only on your device. We store only keyed cryptographic digests and key-version information, not the raw values.

- Resource-search information: resource kind, country, region, a city you confirm or type, preferred language, topics, and urgency. A hosting-suggested city may prefill a search, while the initial approximate production city is also held with the pseudonymous chat profile until deletion or expiry. If you type a city in a retained chat message, it remains part of that transcript until deletion or expiry.

- Safety and operational information: automated safety flags, limited human review status and outcomes, deletion receipts, security and staff audit events, and technical error information that does not contain prompts, responses, raw session tokens, or deletion codes.

- Website preferences and progress: cookie choices and, where you use relevant programmes or assessments, browser storage recording completed steps or accepted disclaimers.

- Network and device information handled by infrastructure providers: hosting, security, and network providers necessarily receive information such as IP address, request time, browser or device information, and requested URL to deliver and protect the service. Know2SayNo does not intentionally write raw IP addresses or user-agent strings into its chat database.

We do not ask for a name, email address, telephone number, or account for Hope Agent. If you email us, we receive the information included in that communication.

4. How we use information

We use the information to:

- provide and restore the Hope Agent session;

- generate responses and apply rule-based safeguarding checks;

- return verified church and helpline information appropriate to a confirmed city, language, topic, and urgency;

- operate Delete chat, Quick Exit, abuse prevention, rate limiting, and other security controls;

- review and improve safety and service quality;

- maintain the resource directory and verify providers;

- comply with law, respond to valid legal requests, and establish or defend legal claims; and

- create content-free aggregate statistics about service use.

We rely on your consent where the service asks you to accept the chat or optional-cookie notice. We may also process information where applicable law permits or requires it, including for service delivery, security, safeguarding, legal obligations, and legitimate uses recognised by law.

5. Hope Agent and Anthropic

Messages sent to Hope Agent are processed using Anthropic's API. Know2SayNo does not have a Zero Data Retention arrangement with Anthropic. Anthropic states that inputs and outputs for its commercial API are ordinarily deleted from its backend within 30 days, subject to published exceptions, including legal requirements, policy-enforcement retention, the Files API, covered-model safety requirements, and different contractual arrangements. Anthropic states that material flagged as violating its Usage Policy may be retained for up to two years and related trust-and-safety classification scores for up to seven years.

Anthropic's current notice is available at: https://privacy.claude.com/en/articles/7996866-how-long-do-you-store-my-organization-s-data

This disclosure was checked against Anthropic's notice dated 1 July 2026 on 9 September 2026.

6. Other service providers and recipients

We use service providers to operate the service, including:

- Anthropic for AI processing;

- database and hosting providers, including Supabase/PostgreSQL and Vercel, for storage, delivery, scheduled jobs, and security;

- Prismic for website and legal-page content;

- Clerk for authorised staff sign-in to the separate administration service; and

- Google Tag Manager and any approved Google measurement or advertising destinations, but only after the relevant optional-cookie consent and only after our tag inventory has been approved.

Service providers process information under their own technical and contractual terms and may process it in countries outside India. We do not sell Hope Agent transcripts or disclose them for independent advertising use.

We may disclose information where required by law, to protect a person from a serious threat where permitted, to investigate misuse or security incidents, or as part of a lawful organisational restructuring with appropriate safeguards.

7. Retention

We apply the following retention periods:

- Raw pseudonymous profiles, chat transcripts, ordinary automated safety-review data, resource-delivery records, and active session credentials: up to 90 days after the last chat activity.

- The one-time deletion-code digest: until the related chat is deleted or reaches its retention limit, and never longer than 180 days from issue.

- A separately minimised record of a manually confirmed serious safeguarding incident: three years after the case is closed. An automated safety flag alone does not enter this longer retention category. The minimised record does not preserve the transcript as part of the incident record.

- Content-free deletion receipts and security or staff audit records: three years.

- Temporary backup-deletion suppression records: only for the affected backup window. Production backups are intended to be retained for no more than seven days and must be restored in isolation with current suppressions applied before being returned to service.

- Content-free minute, daily, or category aggregates: indefinitely. These include activity, age-group, approximate-country, approximate-city, conversation-length, and resource-display totals. They contain no reusable profile, conversation, message, delivery, resource-record identifier, or free text. Audience groups below five are suppressed, with complementary suppression where necessary.

- Cookie preferences: up to 12 months, unless the policy version changes or you replace the choice sooner.

- Browser-only programme progress and disclaimer preferences: until you clear them in your browser.

Retention is enforced through a batched, repeatable scheduled job. Legal obligations, disputes, or an active security investigation may require limited information to be preserved for longer where permitted by law.

8. Delete chat

Hope Agent provides one chat-management action: Delete chat. Using it permanently removes the chat, associated pseudonymous profile, ordinary safety data, resource-delivery records, and active session credentials. It also clears the chat cookie. A new session is not created automatically.

When a chat is created, a one-time deletion code is shown. Save it privately if you want to be able to delete the chat after losing the session cookie. The code can be used at /delete-my-data. We store only its digest, rate-limit failed attempts, and cannot recover the readable code.

After a successful deletion, we retain only a content-free receipt and content-free aggregate totals. Backup-suppression controls are used so a deleted profile is not reintroduced during an authorised restore.

If you have neither the active session nor the deletion code, contact webmaster@urbanrestora.com. Do not send chat content unless needed to locate or complete your request.

9. Quick Exit

Quick Exit is a safety control separate from deletion. It revokes browser access to the active chat, clears the session cookie, and navigates to a neutral external page. Quick Exit does not delete retained chat data. Use Delete chat if you want the retained chat removed.

10. Cookies and similar storage

Necessary storage supports the chat session, security, deletion, consent preferences, and local programme progress. Optional analytics and marketing storage is denied by default. Google Tag Manager is configured not to load or contact Google before a valid opt-in. See the Cookie Policy and use the separate Cookie Settings control in the footer to change optional choices.

11. Security

We use safeguards designed for the sensitivity of the service, including opaque random session credentials, HMAC digests, restricted database functions and roles, session expiry and revocation, rate limiting, origin checks, staff access controls, audit events, and minimised public resource results. No internet service is completely secure, so we cannot guarantee absolute security.

Do not share a Hope Agent session token or deletion code. Anyone with a valid deletion code can permanently delete the related chat but cannot use that code to view it.

12. Your choices and rights

Subject to applicable law, you may ask us to provide information about our handling of your personal data, correct inaccurate information, erase information, withdraw consent, or address a grievance. Because Hope Agent is account-free, we may need a valid session, deletion code, or enough limited information to locate a record without exposing somebody else's data.

Withdrawing optional-cookie consent prevents future optional tag loading and removes known first-party analytics or advertising cookies where technically possible. It does not delete a Hope Agent chat.

To exercise a right or complain, contact webmaster@urbanrestora.com and address the request to Anand Mathew, Grievance Officer. We may verify the request and retain a limited record of its completion.

13. Children

Know2SayNo and Hope Agent are not intended for anyone under 18. The interface and API block creation of a persistent chat for ages below 18. We may provide links to independently operated youth resources without creating a Hope Agent profile.

If you believe we have retained information about a child, contact the Grievance Officer promptly.

14. Third-party resources and links

Churches, helplines, emergency services, and linked websites are independently operated. Their own privacy terms apply when you contact or visit them. Directory results use city-level matching and verified structured information; they do not use precise coordinates or guarantee the physically nearest provider.

15. Changes to this policy

We may update this policy when the service, providers, or law changes. The page will show its version, effective date, last-updated date, and approval status. A material change to the cookie policy causes the website to request your cookie choice again. The stored Hope Agent consent record is tied to the published chat-policy version in force when consent is given.

16. Contact

Privacy and grievance contact:

Anand Mathew, Grievance Officer

Urban Restora Foundation

2EC 313, HRBR 3rd Block, Kalyan Nagar, Bangalore 560084, India

webmaster@urbanrestora.com

illustration

You've taken the first step by reading this. Ready to talk?

TALK TO OUR HOPE AGENT

Reach out

You are not alone. Find verified support for your location. In immediate danger, contact local emergency services.