🕉Sanatani · सनातनी

Privacy Policy

Effective date: 6 July 2026  ·  Last updated: 25 July 2026  ·  Version: 1.1

Application: Sanatani (सनातनी)  ·  Package ID: com.Sanatani.app  ·  Platform: Android (Google Play Store)

DPDPA 2023 Compliant IT Act 2000 & SPDI Rules 2011 Google Play Data Safety Aligned Governing law: India (Hyderabad jurisdiction)
Scope of this notice. This Privacy Policy (the "Policy") is issued by Infopiy, sole proprietor and Data Fiduciary of the Sanatani mobile application ("Sanatani", "we", "our", or "us"), pursuant to and in compliance with:
  1. The Digital Personal Data Protection Act, 2023 ("DPDPA") and the Rules made thereunder;
  2. The Information Technology Act, 2000 ("IT Act"), particularly Sections 43A and 72A;
  3. The Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 ("SPDI Rules");
  4. The Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021 ("IT Intermediary Rules");
  5. The Consumer Protection (E-Commerce) Rules, 2020;
  6. The Google Play Developer Program Policies, including the Data Safety and User Data policies.
This Policy forms an integral part of the Terms of Use of the Sanatani app. By downloading, installing, or using Sanatani you signify that you have read, understood, and freely accepted this Policy.

1.Definitions

Capitalised terms used in this Policy have the following meanings, consistent with the DPDPA 2023 and SPDI Rules:

Data Fiduciary
The person who alone or in conjunction with others determines the purpose and means of processing personal data (Section 2(i), DPDPA). For Sanatani, this is Infopiy.
Data Principal
The individual to whom the personal data relates (Section 2(j), DPDPA). In this Policy, "you" or "user".
Personal Data
Any data about an individual who is identifiable by or in relation to such data (Section 2(t), DPDPA).
Processing
A wholly or partly automated operation on personal data, including collection, storage, use, sharing, disclosure, or erasure (Section 2(x), DPDPA).
Sensitive Personal Data or Information (SPDI)
Password, financial information, physical/physiological/mental health, sexual orientation, medical records, biometric information, and related categories as defined in Rule 3 of the SPDI Rules 2011.
Consent Manager
A registered entity, as defined under Section 2(g) of the DPDPA, that enables a Data Principal to give, manage, review, and withdraw consent. Sanatani does not currently use a Consent Manager.
Data Protection Board
The Data Protection Board of India, established under Section 18 of the DPDPA 2023.
Data Processor
A person who processes personal data on behalf of a Data Fiduciary (Section 2(k), DPDPA). For Sanatani, includes Google (Firebase, AdMob), Supabase, and Cloudflare.

2.Applicability and scope

This Policy applies to all personal data processed by Sanatani in connection with your use of the mobile application, whether such data is collected within the territory of India or outside India (where processing is in connection with any activity related to the offering of goods or services to Data Principals within the territory of India), as contemplated under Section 3 of the DPDPA 2023.

This Policy does not apply to (a) personal data made publicly available by you; (b) personal data processed by a court, tribunal, or public authority for statutory purposes; or (c) any third-party service you may access via links or SDKs, each of which is governed by its own privacy policy.

3.Data Fiduciary

Infopiy

Capacity: Sole proprietor and Data Fiduciary

Registered contact address: Hyderabad, Telangana, India — 500001

Email: infopiyofficial@gmail.com

Sanatani is not, as of the effective date, notified as a "Significant Data Fiduciary" under Section 10 of the DPDPA 2023. If we are so notified in future, we will comply with the additional obligations, including appointment of a Data Protection Officer and independent data audits, and will update this Policy accordingly.

4.Personal data we collect

4.1 Data collected automatically

4.2 Data you may voluntarily provide

4.3 Data stored only on your device (never transmitted)

4.4 Sensitive Personal Data — expressly NOT collected

We do not collect any category of Sensitive Personal Data or Information as defined under Rule 3 of the SPDI Rules 2011, including passwords, financial information (bank details, card numbers, UPI VPA), health data, sexual orientation, medical records, biometric information, or precise geolocation.

5.Purposes of processing and legal basis

Under Sections 4 to 7 of the DPDPA 2023, personal data may be processed only for a lawful purpose for which consent has been given, or for certain "legitimate uses". The table below sets out each category we process, together with the specified purpose and the legal ground:

Data categorySpecified purposeLegal basis (DPDPA 2023)
Anonymous Firebase User IDAuthenticate the device to serve wallpapers, notifications, and referral creditSection 6 — Consent (obtained during onboarding)
FCM TokenSend daily wallpaper & streak remindersSection 6 — Consent (revocable via device notification settings)
Device fingerprint (hashed)Prevent duplicate referral rewards from the same physical deviceSection 7(a) — Legitimate use: fraud prevention
Google Advertising IDServe rewarded advertisements via Google AdMobSection 6 — Consent (opt-out available via Android Settings)
Crash logsDiagnose bugs and maintain service qualitySection 7(b) — Legitimate use: service functionality
Referral code entered voluntarilyCredit the referrer with ad-free daysSection 6 — Consent (voluntary act)
Google account name, email & profile photo (only if you Sign in with Google)Display identity on the community Leaderboard; restore streak across devicesSection 6 — Consent (explicit, voluntary sign-in)

6.Consent

Where processing is based on consent, such consent shall be — in accordance with Section 6(1) of the DPDPA — free, specific, informed, unconditional, unambiguous, and given through a clear affirmative action. On first launch, before any personal data is processed, we present this Policy and require your affirmative acceptance.

Withdrawal. You may withdraw your consent at any time under Section 6(4) of the DPDPA by (a) uninstalling the app; (b) revoking notification permission from Android Settings; (c) resetting your Advertising ID; or (d) writing to the Grievance Officer at the address in Section 11. Withdrawal takes effect prospectively and does not affect processing carried out prior to withdrawal on the basis of the consent then given. Withdrawal of consent may materially limit or terminate your ability to use certain features of Sanatani.

7.Third-party processors (Data Processors under Section 2(k) DPDPA)

We engage the following Data Processors, each bound by contractual and technical safeguards, and each acting on our instructions in accordance with Section 8(3) of the DPDPA:

ProcessorPurposeData sharedPrivacy policy
Google LLC (Firebase Authentication, incl. Google Sign-In, FCM, App Check, Crashlytics)Anonymous authentication, optional Google Sign-In, push messaging, anti-abuse attestation, crash reportingAnonymous user ID, FCM token, device model, OS version, crash stack traces; and — only if you Sign in with Google — your name, email and profile photofirebase.google.com/support/privacy
Google LLC (Google AdMob)Rewarded advertisementsAdvertising ID, ad-view eventspolicies.google.com/technologies/ads
Supabase Inc. (Delaware, USA)User profile, leaderboard and referral tracking databaseAnonymous user ID, referral code, hashed device fingerprint; and — only if you Sign in with Google — your name, email and profile photosupabase.com/privacy
Cloudflare, Inc. (Delaware, USA)Wallpaper content delivery via Cloudflare R2 (S3-compatible object storage)No personal data; standard HTTP request metadata (IP address processed by Cloudflare's edge network)cloudflare.com/privacypolicy

8.Cross-border transfer of personal data

Certain Data Processors listed in Section 7 store or process data outside the territory of India, including in the United States and the European Union. Such transfer is permitted under Section 16 of the DPDPA 2023 subject to any restrictions notified by the Central Government of India. As at the effective date of this Policy, no restricted country list has been notified; if one is notified, we will comply.

Each Processor employs industry-standard protection measures including encryption in transit (TLS 1.2+), encryption at rest, and independent certifications such as ISO/IEC 27001, SOC 2 Type II, and, where applicable, GDPR-standard contractual clauses.

9.Data retention

In accordance with Section 8(7) of the DPDPA, personal data is retained only for as long as necessary for the specified purposes, or as required to comply with applicable law:

DataRetention period
Anonymous user ID, FCM token, device fingerprintUntil app uninstall + 12 months of dormancy, after which server-side records are erased
Referral linkage24 months from date of credit, for anti-fraud reconciliation
Google account data (name, email, photo), if you signed in with GoogleUntil you sign out, delete your account, or 12 months of dormancy — whichever is earliest; erased within 30 days of a verified deletion request
Crash logs (Firebase Crashlytics)90 days, then automatically purged by the processor
Local device data (tasks, streaks, name, language)Until you uninstall the app or clear app data
Records processed pursuant to a verified erasure requestDeleted within 30 days of verified request

10.Your rights as a Data Principal (Chapter III, DPDPA 2023)

Subject to reasonable identity verification, you have the following statutory rights:

  1. Right to information (Section 11) — to obtain a summary of personal data being processed, the processing activities, and the identities of Data Processors with whom your data has been shared.
  2. Right to correction and erasure (Section 12) — to request correction of inaccurate or misleading data, completion of incomplete data, and erasure of personal data that is no longer necessary.
  3. Right of grievance redressal (Section 13) — see Section 11 of this Policy.
  4. Right to nominate (Section 14) — to nominate any other individual to exercise your rights in the event of your death or incapacity.
  5. Right to withdraw consent (Section 6(4)) — at any time, with prospective effect.
  6. Right of access to public grievance mechanisms — including approaching the Data Protection Board of India under Section 27, once operational.

How to exercise your rights. Send an email to infopiyofficial@gmail.com with the subject [DPDPA] <Right requested>, quoting your anonymous Firebase User ID (visible in the app under Account → About) or, if you signed in with Google, your Google email address. We shall acknowledge your request within forty-eight (48) hours and resolve it within thirty (30) days.

Deleting your account. If you signed in with Google, you can request full deletion of your account and all associated data at our dedicated account deletion page, which lists the exact steps and the data that is deleted.

11.Grievance redressal (Section 13 DPDPA & Rule 5(9) SPDI Rules)

Grievance Officer

Name: Infopiy

Designation: Grievance Officer, Sanatani

Address: Hyderabad, Telangana, India — 500001

Email: infopiyofficial@gmail.com

Acknowledgment: within 48 hours of receipt

Resolution: within 30 (thirty) days, as prescribed by Rule 5(9) of the SPDI Rules 2011 and Rule 3(2) of the IT Intermediary Rules 2021

If your grievance is not resolved to your satisfaction, you may thereafter approach the Data Protection Board of India under Section 27 of the DPDPA 2023, or seek any other remedy available under law.

12.Data security

We implement and maintain reasonable security practices and procedures as required by Section 43A of the IT Act and Rule 8 of the SPDI Rules, including but not limited to:

These practices meet the requirements of the internationally recognised standard IS/ISO/IEC 27001, as contemplated by Rule 8(2) of the SPDI Rules.

13.Data breach notification

In the event of a personal data breach that is likely to affect your rights, we shall notify the Data Protection Board of India and each affected Data Principal without undue delay, in the manner and form prescribed under Section 8(6) of the DPDPA 2023.

14.Advertising

Sanatani shows rewarded advertisements only — you affirmatively choose to watch an advertisement in exchange for unlocking a Daily Blessing, an additional wallpaper, or three ad-free days via the referral programme. No interstitial (forced) pop-up advertisements are shown. Advertisements are delivered by Google AdMob and are governed by Google's own privacy practices.

To opt out of personalised advertising, visit support.google.com/ads/answer/2662922 or reset the Advertising ID from Android Settings → Google → Ads.

15.Children and persons with disability (Section 9 DPDPA)

Sanatani is not directed at children under 18 years of age. Consistent with Section 9 of the DPDPA 2023, we do not knowingly process the personal data of children or of persons with disability who have a lawful guardian, without verifiable parental or guardian consent, and we do not undertake tracking, behavioural monitoring, or targeted advertising directed at such persons.

If we become aware that we have processed such data without the necessary consent, we will delete it. Parents and guardians may contact the Grievance Officer to report or request deletion.

16.Google Play Data Safety declaration mapping

Consistent with the declaration we make in the Google Play Console Data Safety form, the categories of data collected are:

CategoryTypeCollectedSharedOptional?Purposes
Personal infoNameYesNoOptionalApp functionality, account management (Google Sign-In & leaderboard)
Personal infoEmail addressYes — only if you Sign in with GoogleNoOptionalAccount management (Google Sign-In)
Personal infoUser IDs (anonymous Firebase UID, referral code)YesYes — Google, SupabaseRequiredApp functionality, analytics
Photos and videosProfile photoYes — only if you Sign in with GoogleNoOptionalApp functionality (leaderboard avatar)
App activityIn-app actions (task completion, streak)YesNoRequiredApp functionality
App info & performanceCrash logs, diagnosticsYesYes — Google FirebaseRequiredDiagnostics, service maintenance
Device or other IDsFirebase Installation ID, FCM token, Advertising IDYesYes — Google Firebase, Google AdMobRequiredAnalytics, advertising, communications

Data is encrypted in transit and you can request deletion (Section 10 above).

17.Cookies and similar tracking technologies

Sanatani is a native Android application and does not use browser cookies. Certain Google Play Services SDKs (Firebase, AdMob) may use device-level identifiers as described in Section 4.

18.Automated decision-making

We do not use personal data for solely automated decision-making, profiling, or evaluation that produces legal or similarly significant effects for you, within the meaning of any applicable data protection standard.

19.Third-party links and integrations

The app may contain links to third-party platforms (e.g. Google Play, WhatsApp, Instagram) or invoke third-party sharing sheets. Such third-party services are governed by their own privacy policies and terms. We are not responsible for the privacy practices or content of any third-party service.

20.No sale of personal data

We do not sell, rent, trade, or otherwise transfer your personal data to any third party for monetary or other valuable consideration. We do not participate in cross-context behavioural advertising exchanges beyond the standard Google AdMob rewarded-ads placement described in Section 14.

21.Changes to this Policy

We may update this Policy from time to time to reflect changes to our practices, technology, legal requirements, or for other operational reasons. Material changes will be notified in-app before they take effect. The "Last updated" and "Version" values at the top of this Policy will always reflect the latest revision. Your continued use of Sanatani after the effective date of any change constitutes fresh consent to the revised Policy under Section 6 of the DPDPA.

22.Severability

If any provision of this Policy is held to be invalid, unlawful, or unenforceable under applicable law by a competent authority, such provision shall be severed to the minimum extent necessary and the remaining provisions shall continue in full force and effect.

23.Governing law and jurisdiction

This Policy shall be governed by and construed in accordance with the laws of the Republic of India. Subject to the powers of the Data Protection Board of India and any other statutory forum, the courts and tribunals at Hyderabad, Telangana shall have exclusive jurisdiction over any dispute arising out of or in connection with this Policy.

24.Contact us

General queries & grievances

Email: infopiyofficial@gmail.com

Subject line format: [DPDPA] <your request> or [Grievance] <subject>

Postal address: Grievance Officer, Sanatani — Hyderabad, Telangana, India — 500001

Business hours: Monday to Friday, 10:00 to 18:00 IST (excluding Indian public holidays)