Capitalised terms used in this Policy have the following meanings, consistent with the DPDPA 2023 and SPDI Rules:
This Policy applies to all personal data processed by Sanatani in connection with your use of the mobile application, whether such data is collected within the territory of India or outside India (where processing is in connection with any activity related to the offering of goods or services to Data Principals within the territory of India), as contemplated under Section 3 of the DPDPA 2023.
This Policy does not apply to (a) personal data made publicly available by you; (b) personal data processed by a court, tribunal, or public authority for statutory purposes; or (c) any third-party service you may access via links or SDKs, each of which is governed by its own privacy policy.
Capacity: Sole proprietor and Data Fiduciary
Registered contact address: Hyderabad, Telangana, India — 500001
Email: infopiyofficial@gmail.com
Sanatani is not, as of the effective date, notified as a "Significant Data Fiduciary" under Section 10 of the DPDPA 2023. If we are so notified in future, we will comply with the additional obligations, including appointment of a Data Protection Officer and independent data audits, and will update this Policy accordingly.
We do not collect any category of Sensitive Personal Data or Information as defined under Rule 3 of the SPDI Rules 2011, including passwords, financial information (bank details, card numbers, UPI VPA), health data, sexual orientation, medical records, biometric information, or precise geolocation.
Under Sections 4 to 7 of the DPDPA 2023, personal data may be processed only for a lawful purpose for which consent has been given, or for certain "legitimate uses". The table below sets out each category we process, together with the specified purpose and the legal ground:
| Data category | Specified purpose | Legal basis (DPDPA 2023) |
|---|---|---|
| Anonymous Firebase User ID | Authenticate the device to serve wallpapers, notifications, and referral credit | Section 6 — Consent (obtained during onboarding) |
| FCM Token | Send daily wallpaper & streak reminders | Section 6 — Consent (revocable via device notification settings) |
| Device fingerprint (hashed) | Prevent duplicate referral rewards from the same physical device | Section 7(a) — Legitimate use: fraud prevention |
| Google Advertising ID | Serve rewarded advertisements via Google AdMob | Section 6 — Consent (opt-out available via Android Settings) |
| Crash logs | Diagnose bugs and maintain service quality | Section 7(b) — Legitimate use: service functionality |
| Referral code entered voluntarily | Credit the referrer with ad-free days | Section 6 — Consent (voluntary act) |
| Google account name, email & profile photo (only if you Sign in with Google) | Display identity on the community Leaderboard; restore streak across devices | Section 6 — Consent (explicit, voluntary sign-in) |
Where processing is based on consent, such consent shall be — in accordance with Section 6(1) of the DPDPA — free, specific, informed, unconditional, unambiguous, and given through a clear affirmative action. On first launch, before any personal data is processed, we present this Policy and require your affirmative acceptance.
Withdrawal. You may withdraw your consent at any time under Section 6(4) of the DPDPA by (a) uninstalling the app; (b) revoking notification permission from Android Settings; (c) resetting your Advertising ID; or (d) writing to the Grievance Officer at the address in Section 11. Withdrawal takes effect prospectively and does not affect processing carried out prior to withdrawal on the basis of the consent then given. Withdrawal of consent may materially limit or terminate your ability to use certain features of Sanatani.
We engage the following Data Processors, each bound by contractual and technical safeguards, and each acting on our instructions in accordance with Section 8(3) of the DPDPA:
| Processor | Purpose | Data shared | Privacy policy |
|---|---|---|---|
| Google LLC (Firebase Authentication, incl. Google Sign-In, FCM, App Check, Crashlytics) | Anonymous authentication, optional Google Sign-In, push messaging, anti-abuse attestation, crash reporting | Anonymous user ID, FCM token, device model, OS version, crash stack traces; and — only if you Sign in with Google — your name, email and profile photo | firebase.google.com/support/privacy |
| Google LLC (Google AdMob) | Rewarded advertisements | Advertising ID, ad-view events | policies.google.com/technologies/ads |
| Supabase Inc. (Delaware, USA) | User profile, leaderboard and referral tracking database | Anonymous user ID, referral code, hashed device fingerprint; and — only if you Sign in with Google — your name, email and profile photo | supabase.com/privacy |
| Cloudflare, Inc. (Delaware, USA) | Wallpaper content delivery via Cloudflare R2 (S3-compatible object storage) | No personal data; standard HTTP request metadata (IP address processed by Cloudflare's edge network) | cloudflare.com/privacypolicy |
Certain Data Processors listed in Section 7 store or process data outside the territory of India, including in the United States and the European Union. Such transfer is permitted under Section 16 of the DPDPA 2023 subject to any restrictions notified by the Central Government of India. As at the effective date of this Policy, no restricted country list has been notified; if one is notified, we will comply.
Each Processor employs industry-standard protection measures including encryption in transit (TLS 1.2+), encryption at rest, and independent certifications such as ISO/IEC 27001, SOC 2 Type II, and, where applicable, GDPR-standard contractual clauses.
In accordance with Section 8(7) of the DPDPA, personal data is retained only for as long as necessary for the specified purposes, or as required to comply with applicable law:
| Data | Retention period |
|---|---|
| Anonymous user ID, FCM token, device fingerprint | Until app uninstall + 12 months of dormancy, after which server-side records are erased |
| Referral linkage | 24 months from date of credit, for anti-fraud reconciliation |
| Google account data (name, email, photo), if you signed in with Google | Until you sign out, delete your account, or 12 months of dormancy — whichever is earliest; erased within 30 days of a verified deletion request |
| Crash logs (Firebase Crashlytics) | 90 days, then automatically purged by the processor |
| Local device data (tasks, streaks, name, language) | Until you uninstall the app or clear app data |
| Records processed pursuant to a verified erasure request | Deleted within 30 days of verified request |
Subject to reasonable identity verification, you have the following statutory rights:
How to exercise your rights. Send an email to infopiyofficial@gmail.com with the subject [DPDPA] <Right requested>, quoting your anonymous Firebase User ID (visible in the app under Account → About) or, if you signed in with Google, your Google email address. We shall acknowledge your request within forty-eight (48) hours and resolve it within thirty (30) days.
Deleting your account. If you signed in with Google, you can request full deletion of your account and all associated data at our dedicated account deletion page, which lists the exact steps and the data that is deleted.
Name: Infopiy
Designation: Grievance Officer, Sanatani
Address: Hyderabad, Telangana, India — 500001
Email: infopiyofficial@gmail.com
Acknowledgment: within 48 hours of receipt
Resolution: within 30 (thirty) days, as prescribed by Rule 5(9) of the SPDI Rules 2011 and Rule 3(2) of the IT Intermediary Rules 2021
If your grievance is not resolved to your satisfaction, you may thereafter approach the Data Protection Board of India under Section 27 of the DPDPA 2023, or seek any other remedy available under law.
We implement and maintain reasonable security practices and procedures as required by Section 43A of the IT Act and Rule 8 of the SPDI Rules, including but not limited to:
FLAG_SECURE) on the wallpaper preview screen;EncryptedSharedPreferences for any locally cached credentials;These practices meet the requirements of the internationally recognised standard IS/ISO/IEC 27001, as contemplated by Rule 8(2) of the SPDI Rules.
In the event of a personal data breach that is likely to affect your rights, we shall notify the Data Protection Board of India and each affected Data Principal without undue delay, in the manner and form prescribed under Section 8(6) of the DPDPA 2023.
Sanatani shows rewarded advertisements only — you affirmatively choose to watch an advertisement in exchange for unlocking a Daily Blessing, an additional wallpaper, or three ad-free days via the referral programme. No interstitial (forced) pop-up advertisements are shown. Advertisements are delivered by Google AdMob and are governed by Google's own privacy practices.
To opt out of personalised advertising, visit support.google.com/ads/answer/2662922 or reset the Advertising ID from Android Settings → Google → Ads.
Sanatani is not directed at children under 18 years of age. Consistent with Section 9 of the DPDPA 2023, we do not knowingly process the personal data of children or of persons with disability who have a lawful guardian, without verifiable parental or guardian consent, and we do not undertake tracking, behavioural monitoring, or targeted advertising directed at such persons.
If we become aware that we have processed such data without the necessary consent, we will delete it. Parents and guardians may contact the Grievance Officer to report or request deletion.
Consistent with the declaration we make in the Google Play Console Data Safety form, the categories of data collected are:
| Category | Type | Collected | Shared | Optional? | Purposes |
|---|---|---|---|---|---|
| Personal info | Name | Yes | No | Optional | App functionality, account management (Google Sign-In & leaderboard) |
| Personal info | Email address | Yes — only if you Sign in with Google | No | Optional | Account management (Google Sign-In) |
| Personal info | User IDs (anonymous Firebase UID, referral code) | Yes | Yes — Google, Supabase | Required | App functionality, analytics |
| Photos and videos | Profile photo | Yes — only if you Sign in with Google | No | Optional | App functionality (leaderboard avatar) |
| App activity | In-app actions (task completion, streak) | Yes | No | Required | App functionality |
| App info & performance | Crash logs, diagnostics | Yes | Yes — Google Firebase | Required | Diagnostics, service maintenance |
| Device or other IDs | Firebase Installation ID, FCM token, Advertising ID | Yes | Yes — Google Firebase, Google AdMob | Required | Analytics, advertising, communications |
Data is encrypted in transit and you can request deletion (Section 10 above).
Sanatani is a native Android application and does not use browser cookies. Certain Google Play Services SDKs (Firebase, AdMob) may use device-level identifiers as described in Section 4.
We do not use personal data for solely automated decision-making, profiling, or evaluation that produces legal or similarly significant effects for you, within the meaning of any applicable data protection standard.
The app may contain links to third-party platforms (e.g. Google Play, WhatsApp, Instagram) or invoke third-party sharing sheets. Such third-party services are governed by their own privacy policies and terms. We are not responsible for the privacy practices or content of any third-party service.
We do not sell, rent, trade, or otherwise transfer your personal data to any third party for monetary or other valuable consideration. We do not participate in cross-context behavioural advertising exchanges beyond the standard Google AdMob rewarded-ads placement described in Section 14.
We may update this Policy from time to time to reflect changes to our practices, technology, legal requirements, or for other operational reasons. Material changes will be notified in-app before they take effect. The "Last updated" and "Version" values at the top of this Policy will always reflect the latest revision. Your continued use of Sanatani after the effective date of any change constitutes fresh consent to the revised Policy under Section 6 of the DPDPA.
If any provision of this Policy is held to be invalid, unlawful, or unenforceable under applicable law by a competent authority, such provision shall be severed to the minimum extent necessary and the remaining provisions shall continue in full force and effect.
This Policy shall be governed by and construed in accordance with the laws of the Republic of India. Subject to the powers of the Data Protection Board of India and any other statutory forum, the courts and tribunals at Hyderabad, Telangana shall have exclusive jurisdiction over any dispute arising out of or in connection with this Policy.
Email: infopiyofficial@gmail.com
Subject line format: [DPDPA] <your request> or [Grievance] <subject>
Postal address: Grievance Officer, Sanatani — Hyderabad, Telangana, India — 500001
Business hours: Monday to Friday, 10:00 to 18:00 IST (excluding Indian public holidays)