ΛMΛNΛT

Privacy Notice

Version 2026-09-draft · Digital Personal Data Protection Act, 2023 (India)
Draft. This notice is complete in structure but not yet in content: every TODO(counsel): marker below is a wording or a number that the operator and legal counsel must finalise before go-live. It is served now so the mechanisms it describes (consent, withdrawal, data export, grievance) can be built and tested against it.

1. Who processes your data

The Data Fiduciary for ΛMΛNΛT is:
TODO(counsel): registered legal entity name (TODO(counsel): Pvt Ltd / LLP / proprietorship)
Registered office: TODO(counsel): registered office address (India)
CIN/LLPIN: TODO(counsel): CIN / LLPIN, if incorporated
GSTIN: 29ABCDE1234F1Z5

Questions about how your data is handled, and requests to exercise your rights, go to the person nominated to answer them: TODO(counsel): Grievance Officer nameprivacy@quasaars.com.

2. What this notice does and does not cover

Your Safe’s contents — every entry and file you save — are encrypted on your device with a key derived from your password, which is never sent to us. We store only ciphertext and cannot read it. This notice is about the account and usage data we do hold in readable form, listed in section 3.

A court order, a subpoena, or a data breach reaches the readable data in section 3. It does not reach your Safe’s contents, because we hold no key to them.

3. What we collect, why, and for how long

Data elementPurposeLawful basisRetention
Account email address Login identity; account + security notifications Performance of the service (S7 / contract) Life of the account; pseudonymised in the activity log on deletion
First name (mirrored out of the encrypted profile) Personalising emails ("Hi Asha") Consent (optional) — withdrawable in Consent & Privacy Until withdrawn or account deleted
Preferred language Rendering the app and emails Performance of the service Life of the account
Trusted people: each person’s email, mobile, relationship, label Inactivity check-in alerts; delivering recovery-share instructions Consent of the account owner; the trusted person is separately notified and can opt out Until removed by the owner or the trusted person opts out; pending invites auto-expire
DPDPA nominee (if named) A person authorised to exercise your data-protection rights on your death or incapacity (S14) Your explicit designation Until changed or the account is deleted
Account + session timestamps (created, each login, session length, last save, password-change) Single-active-session enforcement; the inactivity safety net; fraud/abuse investigation Performance of the service; legitimate use (security) TODO(counsel): 180 days rolling for the behavioural log; contact for account lifecycle timestamps
Behavioural activity log (which of the 10 categories opened; entries added/deleted per category; a few key modal opens) Product analytics — understanding whether the app is usable Consent (optional) — off by default is available; withdrawing purges existing rows TODO(counsel): 180 days rolling
Vault blob size + last-updated time Storage-quota enforcement; showing "last saved" Performance of the service Life of the account
Security-question TEXT (not the answers — those are client-hashed) Rendering your recovery quiz Performance of the recovery feature you enabled Until you change or remove your questions
Push subscription endpoint (if push enabled) Delivering the notification bell + check-in reminders to your device Consent (optional) Until push is turned off or the subscription expires
Payment reference, invoice number, amount, GST, plan dates Processing your plan; issuing a GST invoice; statutory books of account Legal obligation (tax law) TODO(counsel): the retention period Indian tax law requires (commonly 8 years) — kept even after account deletion; contains no vault content
Feedback ratings + support/grievance ticket text Improving the product; handling your grievance Consent / legitimate use TODO(counsel): e.g. 24 months, then purged
Document file content (only when you use "Start from a document" AI extraction) Extracting fields into a draft entry, which you review and correct before anything is saved Consent -- a separate, explicit opt-in in Consent & Privacy, off by default even on the Annual + Smart Work plan; withdrawable at any time Not stored anywhere -- the file and the model’s response are used in-flight only. The only trace kept is a coarse per-account monthly usage count (no content) for cost control -- see docs/dpia-smart-work.md

4. Consent, and withdrawing it

Creating an account requires consent to the data marked “Performance of the service” above — without it the app cannot function. Everything marked “Consent (optional)” — the first-name mirror, product analytics, web push, and (on the Annual + Smart Work plan only) AI document extraction — is a separate opt-in you can turn off at any time from Settings → Consent & Privacy inside the app. Withdrawing an optional consent is as easy as giving it and stops that processing immediately. For the first three it also purges the data already collected for it; AI document extraction has nothing to purge — it never stores the file or what it read in the first place, so withdrawing it simply stops future use.

5. Who else touches your data (processors & transfers)

ProcessorRoleLocationContract (S8(2))
Google Cloud Platform Application hosting + database + object storage (backups) + AI document extraction (Vertex AI Gemini, Annual + Smart Work plan only, consent-gated per account, off by default -- see docs/dpia-smart-work.md) United States (data-residency review in progress) Processor agreement being finalized
Titan Email (via BigRock / Newfold) Outbound transactional email (activation, alerts, invites) India / United States Processor agreement being finalized
Google / Mozilla push services Web-push delivery to the browser/PWA (only if push is enabled by the user) United States Standard web-push protocol; no account-level contract

TODO(counsel): cross-border transfer position (S16) and processor DPAs — see docs/data-transfer-register.md and finding D-9.

6. Your rights

7. Children

ΛMΛNΛT is for adults. You must be at least 18 years old to create an account; we ask for your date of birth at sign-up and refuse an account below that age. We do not knowingly process a child’s data and provide no parental-consent path.

8. Breach notification

If a personal-data breach affects you, we will notify you and the Data Protection Board of India as required by the Act (TODO(counsel): confirm timing against the final Rules — Board within 72h, affected principals without delay).

9. Changes to this notice

We will tell you about a material change and, where the law requires it, ask for fresh consent. We do not treat continued use of the app as consent to a change in how your data is processed.

Data Fiduciary: TODO(counsel): registered legal entity name · Contact: privacy@quasaars.com · Grievance: grievance@quasaars.com