Initializing privacy SDK...
Consent management, OTP-verified DSARs, automated privacy scanning, and a hash-chained audit ledger — DPDP-native for Indian businesses, deployed on web and mobile in days, not quarters.
Consents recorded
—
—
Compliance score
—
—
Open DSARs
—
—
Scan status
—
—
Consent artefacts
Hash-verifiedOnboarding Notice · v3
Purpose: KYC · hi
Marketing Consent · v2
Purpose: Analytics · en
KYC Verification · v1
Purpose: KYC · ta
Illustrative product mockup — real metrics render in your authenticated dashboard after sign-in.
22
Indian languages
1 day
Average go-live
100%
RLS-isolated tenants
24/7
Tamper-evident audit
The problem
Checkboxes in CRMs, paper forms, and one-off emails — no way to prove purpose-limitation when the DPB asks.
Spreadsheet logs get edited. Regulator reviews demand tamper-evident, immutable, time-stamped evidence.
India is heading to ₹50-crore penalties. An unverified email inbox is not a data-principal verification workflow.
How it works
Add one script tag or install the npm package. The consent widget renders instantly — web, Android, iOS, Flutter, React Native.
Purpose-linked consent artefacts are recorded with timestamps, versioned notices, and immutable audit entries — automatically.
Scanner reports, DSAR fulfilment, breach timelines, and hash-chained audit logs keep you DPDP-ready at every review.
Platform
Every module maps to a DPDP obligation — nothing is a feature checkbox.
Purpose-linked consent artefacts, notice templates in 22 Indian languages, and granular preference centres — built for the DPDP Act, not bolted on.
Crawl any website, classify cookies and trackers, detect CMP behaviour, and auto-generate statutory privacy and cookie policies from the findings.
Public rights portal with email-OTP identity proofing, SLA tracking, and escalation engines for access, correction, erasure, and portability requests.
Append-only, tamper-evident audit trail with Merkle anchoring. Every consent, request, and policy change is provable — regulator-ready.
Incident register with DPDP statutory countdown timers, automated data-principal breach notices, and Data Protection Board escalation workflows.
One embeddable consent SDK — web, React Native, Flutter, and native WebViews. Collect DPDP-compliant consent everywhere your users are.
Row-Level Security on every table plus company-scoped queries at the repository layer. Tenant data can never cross boundaries — even on a bug.
22 scheduled Indian languages, India data residency, and DPDP statute mappings — with global GDPR-grade security posture underneath.
Industries
Trusted
“We went live with DPDP-compliant consent on web and our Android app in one sprint. The mobile SDK was the deciding factor.”
“The audit ledger and DSAR portal took us from 'we'll get to it' to regulator-ready. The scanner found cookies our old vendor never did.”
“22-language notices out of the box. Our pan-India user base finally sees consent in their own language.”
Security
PrivyStack treats multi-tenancy and evidence as the product. Every layer is engineered so that even a defect in application code cannot leak tenant data.
Postgres RLS via Clerk JWT claims, plus company_id scoping at the repository layer — defence in depth.
Direct inserts revoked at the database; entries written only through the atomic RPC with a growing hash chain.
Bot protection on every public form, DB-backed rate limits, and idempotency keys on consent writes.
Audit ledger sample
Each entry includes a hash of the previous entry — tampering with any record breaks the chain and is instantly detectable.
FAQ
Every artefact maps to DPDP obligations: purpose-linked consent notices, statutory breach timelines with DPBI escalation, data-principal nominations, parental consent flows, grievance redressal SLAs, and notice versions in 22 scheduled languages.
Most teams embed the SDK and record their first consent within a day. The full stack — consent widget, public DSAR portal, scanner, policies, audit ledger — is typically production-ready in under two weeks.
Yes. The SDK runs in React Native WebViews, Flutter, and native Android/iOS web containers, and exposes a programmatic API (window.PrivyStack) so native code can open the widget, read the decision, and react to changes.
All tenant data lives in Supabase Postgres with India data residency, protected by Row-Level Security. Consent records, audit entries, and DSAR artefacts are encrypted in transit and at rest.
The scanning worker is a standalone service that never ships inside your app bundle — it crawls targets from a job queue, writes findings back, and generates policies and PDF reports automatically.
Self-serve with public pricing and a free tier — no per-consent charges and no enterprise sales floor. Start with the free tier and upgrade when you're ready.
Embed the SDK, publish your public rights portal, and scan your first website — all before lunch.