The Data Fiduciary for ΛMΛNΛT is:
TODO(counsel): registered legal entity name (TODO(counsel): Pvt Ltd / LLP / proprietorship)
Registered office: TODO(counsel): registered office address (India)
CIN/LLPIN: TODO(counsel): CIN / LLPIN, if incorporated
GSTIN: 29ABCDE1234F1Z5
Questions about how your data is handled, and requests to exercise your rights, go to the person nominated to answer them: TODO(counsel): Grievance Officer name — privacy@quasaars.com.
Your Safe’s contents — every entry and file you save — are encrypted on your device with a key derived from your password, which is never sent to us. We store only ciphertext and cannot read it. This notice is about the account and usage data we do hold in readable form, listed in section 3.
| Data element | Purpose | Lawful basis | Retention |
|---|---|---|---|
| Account email address | Login identity; account + security notifications | Performance of the service (S7 / contract) | Life of the account; pseudonymised in the activity log on deletion |
| First name (mirrored out of the encrypted profile) | Personalising emails ("Hi Asha") | Consent (optional) — withdrawable in Consent & Privacy | Until withdrawn or account deleted |
| Preferred language | Rendering the app and emails | Performance of the service | Life of the account |
| Trusted people: each person’s email, mobile, relationship, label | Inactivity check-in alerts; delivering recovery-share instructions | Consent of the account owner; the trusted person is separately notified and can opt out | Until removed by the owner or the trusted person opts out; pending invites auto-expire |
| DPDPA nominee (if named) | A person authorised to exercise your data-protection rights on your death or incapacity (S14) | Your explicit designation | Until changed or the account is deleted |
| Account + session timestamps (created, each login, session length, last save, password-change) | Single-active-session enforcement; the inactivity safety net; fraud/abuse investigation | Performance of the service; legitimate use (security) | TODO(counsel): 180 days rolling for the behavioural log; contact for account lifecycle timestamps |
| Behavioural activity log (which of the 10 categories opened; entries added/deleted per category; a few key modal opens) | Product analytics — understanding whether the app is usable | Consent (optional) — off by default is available; withdrawing purges existing rows | TODO(counsel): 180 days rolling |
| Vault blob size + last-updated time | Storage-quota enforcement; showing "last saved" | Performance of the service | Life of the account |
| Security-question TEXT (not the answers — those are client-hashed) | Rendering your recovery quiz | Performance of the recovery feature you enabled | Until you change or remove your questions |
| Push subscription endpoint (if push enabled) | Delivering the notification bell + check-in reminders to your device | Consent (optional) | Until push is turned off or the subscription expires |
| Payment reference, invoice number, amount, GST, plan dates | Processing your plan; issuing a GST invoice; statutory books of account | Legal obligation (tax law) | TODO(counsel): the retention period Indian tax law requires (commonly 8 years) — kept even after account deletion; contains no vault content |
| Feedback ratings + support/grievance ticket text | Improving the product; handling your grievance | Consent / legitimate use | TODO(counsel): e.g. 24 months, then purged |
| Document file content (only when you use "Start from a document" AI extraction) | Extracting fields into a draft entry, which you review and correct before anything is saved | Consent -- a separate, explicit opt-in in Consent & Privacy, off by default even on the Annual + Smart Work plan; withdrawable at any time | Not stored anywhere -- the file and the model’s response are used in-flight only. The only trace kept is a coarse per-account monthly usage count (no content) for cost control -- see docs/dpia-smart-work.md |
Creating an account requires consent to the data marked “Performance of the service” above — without it the app cannot function. Everything marked “Consent (optional)” — the first-name mirror, product analytics, web push, and (on the Annual + Smart Work plan only) AI document extraction — is a separate opt-in you can turn off at any time from Settings → Consent & Privacy inside the app. Withdrawing an optional consent is as easy as giving it and stops that processing immediately. For the first three it also purges the data already collected for it; AI document extraction has nothing to purge — it never stores the file or what it read in the first place, so withdrawing it simply stops future use.
| Processor | Role | Location | Contract (S8(2)) |
|---|---|---|---|
| Google Cloud Platform | Application hosting + database + object storage (backups) + AI document extraction (Vertex AI Gemini, Annual + Smart Work plan only, consent-gated per account, off by default -- see docs/dpia-smart-work.md) | United States (data-residency review in progress) | Processor agreement being finalized |
| Titan Email (via BigRock / Newfold) | Outbound transactional email (activation, alerts, invites) | India / United States | Processor agreement being finalized |
| Google / Mozilla push services | Web-push delivery to the browser/PWA (only if push is enabled by the user) | United States | Standard web-push protocol; no account-level contract |
TODO(counsel): cross-border transfer position (S16) and processor DPAs — see docs/data-transfer-register.md and finding D-9.
ΛMΛNΛT is for adults. You must be at least 18 years old to create an account; we ask for your date of birth at sign-up and refuse an account below that age. We do not knowingly process a child’s data and provide no parental-consent path.
If a personal-data breach affects you, we will notify you and the Data Protection Board of India as required by the Act (TODO(counsel): confirm timing against the final Rules — Board within 72h, affected principals without delay).
We will tell you about a material change and, where the law requires it, ask for fresh consent. We do not treat continued use of the app as consent to a change in how your data is processed.