Itsha.com

Privacy Policy

Last updated 24 August 2026

This policy explains what Itsha collects when you use itsha.com or the Itsha mobile apps, why, and how to have it removed. It describes what the service actually does today rather than every possibility, and it is updated when the behaviour changes.

Itsha is operated by Vweb technologies LLP, a limited liability partnership registered in India, which is the data controller for everything described below. Write to support@itsha.com about anything on this page.

The short version

What we collect

When you create a web account:

If you choose “Continue with Google”: Google sends us your name, email address, and profile picture. We do not receive your Google password and we get no access to your Gmail, Drive, contacts, or any other Google service.

While you are signed in, we keep a session record containing a session token, the IP address and browser user-agent the session was created from, and its timestamps. This is what lets you stay signed in and what lets you spot a session you do not recognise.

To stop abuse, we count requests and emails against IP addresses. These counters hold an IP address and a number — nothing about who you are or what you did.

What we do not collect

Analytics

We do not currently use any analytics or attribution service. If that changes we will name the provider here and update the date at the top of this page before it goes live.

Cookies

We set a session cookie when you sign in, and a separate cookie for staff signing in to the internal admin panel. Both are strictly necessary — the site cannot keep you signed in without them. We set no advertising or analytics cookies, which is why you are not asked to accept a cookie banner.

Cloudflare Turnstile — our bot check on sign-up, sign-in, password reset and email verification — may set a short-lived token to confirm you are not automated. It is not used to track you between sites. For most visitors it clears in the background and shows nothing; you only see a challenge if it cannot. Cloudflare describes what it processes to do this in its Turnstile Privacy Addendum.

Who else processes your data

Each acts on our instructions to run the service. None of them is given your data to use for their own advertising.

How long we keep it

Sessions expire after 30 days and are removed when they do. Abuse counters are per-day records that are not tied to an account. Account details stay until you ask us to delete them.

Your choices

Email support@itsha.com to get a copy of what we hold, correct it, or delete your account. Deleting an account removes your details and your sessions. Depending on where you live you may also have rights under the GDPR, the UK GDPR, the CCPA, or India’s DPDP Act; we will honour a request under any of them.

Children

Itsha is not directed to children under 13, and we do not knowingly collect their data. If you believe a child has created an account, email us and we will remove it.

Security

Traffic is encrypted in transit. Passwords are hashed. Sign-up and sign-in are rate-limited and protected by a bot check. No system is perfect, and we will not claim otherwise — if a breach affects your data we will tell you.

Changes

When this policy changes we update the date at the top. Material changes — a new processor, a new category of data — will be described here rather than made quietly.

Questions about this page? Email support@itsha.com. See also our Privacy Policy and Terms of Service.